Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://185.177.92.29

Overview

General Information

Sample URL:http://185.177.92.29
Analysis ID:764032
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5488 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 5200 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1808,i,1709527060102746292,9450787675187643490,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 2224 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://185.177.92.29 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 185.177.92.29Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 185.177.92.29Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 185.177.92.29Connection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://185.177.92.29/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __Secure-ENID=6.SE=Md0Ynyf9ahpkx1CxTGF0vY434NJ6ymH-gDI2Tl5Ly-NQYGPjnNfggtiFRMAwx4JRDOC_gavEPcD5cTBJzUgtbJobmBEuJ8xi2UuotxvOZgApoqSIg1b0RP47U08XG8Bz_SExSzKy0ETSsajbToDlYyFsxfI93p7AyRAd-OeIBA0; CONSENT=PENDING+070
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: unknownTCP traffic detected without corresponding DNS query: 185.177.92.29
Source: classification engineClassification label: clean0.win@24/0@6/8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1808,i,1709527060102746292,9450787675187643490,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://185.177.92.29
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1808,i,1709527060102746292,9450787675187643490,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://185.177.92.291%VirustotalBrowse
http://185.177.92.290%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://185.177.92.29/0%Avira URL Cloudsafe
http://185.177.92.29/favicon.ico0%Avira URL Cloudsafe
http://185.177.92.29/1%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.184.45
truefalse
    high
    www.google.com
    142.250.184.100
    truefalse
      high
      clients.l.google.com
      142.250.180.174
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
            high
            http://185.177.92.29/false
            • 1%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            http://185.177.92.29/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              142.250.184.45
              accounts.google.comUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              185.177.92.29
              unknownNetherlands
              39572ADVANCEDHOSTERS-ASNLfalse
              142.250.184.100
              www.google.comUnited States
              15169GOOGLEUSfalse
              142.250.180.174
              clients.l.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.30
              192.168.2.1
              127.0.0.1
              Joe Sandbox Version:36.0.0 Rainbow Opal
              Analysis ID:764032
              Start date and time:2022-12-09 10:33:25 +01:00
              Joe Sandbox Product:CloudBasic
              Overall analysis duration:0h 4m 26s
              Hypervisor based Inspection enabled:false
              Report type:light
              Cookbook file name:browseurl.jbs
              Sample URL:http://185.177.92.29
              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
              Number of analysed new started processes analysed:10
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • HDC enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@24/0@6/8
              EGA Information:Failed
              HDC Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
              • TCP Packets have been reduced to 100
              • Excluded IPs from analysis (whitelisted): 142.250.184.99, 34.104.35.123, 142.250.180.131
              • Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, fs.microsoft.com, edgedl.me.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtWriteVirtualMemory calls found.
              No simulations
              No context
              No context
              No context
              No context
              No context
              No created / dropped files found
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Dec 9, 2022 10:34:22.735033989 CET49710443192.168.2.6142.250.180.174
              Dec 9, 2022 10:34:22.735081911 CET44349710142.250.180.174192.168.2.6
              Dec 9, 2022 10:34:22.735143900 CET49710443192.168.2.6142.250.180.174
              Dec 9, 2022 10:34:22.735780954 CET49710443192.168.2.6142.250.180.174
              Dec 9, 2022 10:34:22.735807896 CET44349710142.250.180.174192.168.2.6
              Dec 9, 2022 10:34:22.754671097 CET49711443192.168.2.6142.250.184.45
              Dec 9, 2022 10:34:22.754729986 CET44349711142.250.184.45192.168.2.6
              Dec 9, 2022 10:34:22.754796028 CET49711443192.168.2.6142.250.184.45
              Dec 9, 2022 10:34:22.755620956 CET49711443192.168.2.6142.250.184.45
              Dec 9, 2022 10:34:22.755667925 CET44349711142.250.184.45192.168.2.6
              Dec 9, 2022 10:34:22.863084078 CET4971280192.168.2.6185.177.92.29
              Dec 9, 2022 10:34:22.866375923 CET44349711142.250.184.45192.168.2.6
              Dec 9, 2022 10:34:22.866501093 CET44349710142.250.180.174192.168.2.6
              Dec 9, 2022 10:34:22.869489908 CET49710443192.168.2.6142.250.180.174
              Dec 9, 2022 10:34:22.869518042 CET44349710142.250.180.174192.168.2.6
              Dec 9, 2022 10:34:22.869862080 CET49711443192.168.2.6142.250.184.45
              Dec 9, 2022 10:34:22.869924068 CET44349711142.250.184.45192.168.2.6
              Dec 9, 2022 10:34:22.870202065 CET44349710142.250.180.174192.168.2.6
              Dec 9, 2022 10:34:22.870269060 CET49710443192.168.2.6142.250.180.174
              Dec 9, 2022 10:34:22.872394085 CET44349710142.250.180.174192.168.2.6
              Dec 9, 2022 10:34:22.872399092 CET44349711142.250.184.45192.168.2.6
              Dec 9, 2022 10:34:22.872478962 CET49710443192.168.2.6142.250.180.174
              Dec 9, 2022 10:34:22.872961044 CET49711443192.168.2.6142.250.184.45
              Dec 9, 2022 10:34:22.891906023 CET8049712185.177.92.29192.168.2.6
              Dec 9, 2022 10:34:22.892153978 CET4971280192.168.2.6185.177.92.29
              Dec 9, 2022 10:34:22.912318945 CET49711443192.168.2.6142.250.184.45
              Dec 9, 2022 10:34:24.200963974 CET49710443192.168.2.6142.250.180.174
              Dec 9, 2022 10:34:24.201046944 CET44349710142.250.180.174192.168.2.6
              Dec 9, 2022 10:34:24.201324940 CET44349710142.250.180.174192.168.2.6
              Dec 9, 2022 10:34:24.201419115 CET49711443192.168.2.6142.250.184.45
              Dec 9, 2022 10:34:24.201471090 CET44349711142.250.184.45192.168.2.6
              Dec 9, 2022 10:34:24.201757908 CET44349711142.250.184.45192.168.2.6
              Dec 9, 2022 10:34:24.201817989 CET49711443192.168.2.6142.250.184.45
              Dec 9, 2022 10:34:24.201828957 CET44349711142.250.184.45192.168.2.6
              Dec 9, 2022 10:34:24.202291012 CET4971380192.168.2.6185.177.92.29
              Dec 9, 2022 10:34:24.202711105 CET49710443192.168.2.6142.250.180.174
              Dec 9, 2022 10:34:24.202781916 CET44349710142.250.180.174192.168.2.6
              Dec 9, 2022 10:34:24.234795094 CET8049713185.177.92.29192.168.2.6
              Dec 9, 2022 10:34:24.234926939 CET4971380192.168.2.6185.177.92.29
              Dec 9, 2022 10:34:24.249095917 CET44349710142.250.180.174192.168.2.6
              Dec 9, 2022 10:34:24.249267101 CET49710443192.168.2.6142.250.180.174
              Dec 9, 2022 10:34:24.249281883 CET44349710142.250.180.174192.168.2.6
              Dec 9, 2022 10:34:24.249387980 CET49710443192.168.2.6142.250.180.174
              Dec 9, 2022 10:34:24.272407055 CET49711443192.168.2.6142.250.184.45
              Dec 9, 2022 10:34:24.272469044 CET44349711142.250.184.45192.168.2.6
              Dec 9, 2022 10:34:24.275439978 CET44349711142.250.184.45192.168.2.6
              Dec 9, 2022 10:34:24.275511980 CET49711443192.168.2.6142.250.184.45
              Dec 9, 2022 10:34:24.275543928 CET44349711142.250.184.45192.168.2.6
              Dec 9, 2022 10:34:24.276645899 CET44349711142.250.184.45192.168.2.6
              Dec 9, 2022 10:34:24.276937008 CET49711443192.168.2.6142.250.184.45
              Dec 9, 2022 10:34:24.305089951 CET49711443192.168.2.6142.250.184.45
              Dec 9, 2022 10:34:24.305161953 CET44349711142.250.184.45192.168.2.6
              Dec 9, 2022 10:34:24.305927038 CET49710443192.168.2.6142.250.180.174
              Dec 9, 2022 10:34:24.305963993 CET44349710142.250.180.174192.168.2.6
              Dec 9, 2022 10:34:24.637243032 CET4971280192.168.2.6185.177.92.29
              Dec 9, 2022 10:34:24.972381115 CET4971280192.168.2.6185.177.92.29
              Dec 9, 2022 10:34:25.002809048 CET8049712185.177.92.29192.168.2.6
              Dec 9, 2022 10:34:25.003992081 CET8049712185.177.92.29192.168.2.6
              Dec 9, 2022 10:34:25.072685957 CET4971280192.168.2.6185.177.92.29
              Dec 9, 2022 10:34:25.540122986 CET4971280192.168.2.6185.177.92.29
              Dec 9, 2022 10:34:25.570705891 CET8049712185.177.92.29192.168.2.6
              Dec 9, 2022 10:34:25.672586918 CET4971280192.168.2.6185.177.92.29
              Dec 9, 2022 10:34:26.015187979 CET49716443192.168.2.6142.250.184.100
              Dec 9, 2022 10:34:26.015254021 CET44349716142.250.184.100192.168.2.6
              Dec 9, 2022 10:34:26.015337944 CET49716443192.168.2.6142.250.184.100
              Dec 9, 2022 10:34:26.015674114 CET49716443192.168.2.6142.250.184.100
              Dec 9, 2022 10:34:26.015711069 CET44349716142.250.184.100192.168.2.6
              Dec 9, 2022 10:34:26.098593950 CET44349716142.250.184.100192.168.2.6
              Dec 9, 2022 10:34:26.102895975 CET49716443192.168.2.6142.250.184.100
              Dec 9, 2022 10:34:26.102962017 CET44349716142.250.184.100192.168.2.6
              Dec 9, 2022 10:34:26.104382038 CET44349716142.250.184.100192.168.2.6
              Dec 9, 2022 10:34:26.104476929 CET49716443192.168.2.6142.250.184.100
              Dec 9, 2022 10:34:26.122087955 CET49716443192.168.2.6142.250.184.100
              Dec 9, 2022 10:34:26.122143030 CET44349716142.250.184.100192.168.2.6
              Dec 9, 2022 10:34:26.122371912 CET44349716142.250.184.100192.168.2.6
              Dec 9, 2022 10:34:26.284734011 CET49716443192.168.2.6142.250.184.100
              Dec 9, 2022 10:34:26.284784079 CET44349716142.250.184.100192.168.2.6
              Dec 9, 2022 10:34:26.471683979 CET49716443192.168.2.6142.250.184.100
              Dec 9, 2022 10:34:35.571254015 CET8049712185.177.92.29192.168.2.6
              Dec 9, 2022 10:34:35.571433067 CET4971280192.168.2.6185.177.92.29
              Dec 9, 2022 10:34:36.075532913 CET44349716142.250.184.100192.168.2.6
              Dec 9, 2022 10:34:36.075679064 CET44349716142.250.184.100192.168.2.6
              Dec 9, 2022 10:34:36.076024055 CET49716443192.168.2.6142.250.184.100
              Dec 9, 2022 10:34:39.502851009 CET4971280192.168.2.6185.177.92.29
              Dec 9, 2022 10:34:39.502976894 CET49716443192.168.2.6142.250.184.100
              Dec 9, 2022 10:34:39.503002882 CET44349716142.250.184.100192.168.2.6
              Dec 9, 2022 10:34:39.531876087 CET8049712185.177.92.29192.168.2.6
              Dec 9, 2022 10:35:09.247124910 CET4971380192.168.2.6185.177.92.29
              Dec 9, 2022 10:35:09.275846958 CET8049713185.177.92.29192.168.2.6
              Dec 9, 2022 10:35:24.265500069 CET8049713185.177.92.29192.168.2.6
              Dec 9, 2022 10:35:24.265609026 CET4971380192.168.2.6185.177.92.29
              Dec 9, 2022 10:35:26.065893888 CET4971380192.168.2.6185.177.92.29
              Dec 9, 2022 10:35:26.094943047 CET8049713185.177.92.29192.168.2.6
              Dec 9, 2022 10:35:26.160391092 CET49745443192.168.2.6142.250.184.100
              Dec 9, 2022 10:35:26.160454988 CET44349745142.250.184.100192.168.2.6
              Dec 9, 2022 10:35:26.160525084 CET49745443192.168.2.6142.250.184.100
              Dec 9, 2022 10:35:26.160809040 CET49745443192.168.2.6142.250.184.100
              Dec 9, 2022 10:35:26.160835028 CET44349745142.250.184.100192.168.2.6
              Dec 9, 2022 10:35:26.245858908 CET44349745142.250.184.100192.168.2.6
              Dec 9, 2022 10:35:26.247443914 CET49745443192.168.2.6142.250.184.100
              TimestampSource PortDest PortSource IPDest IP
              Dec 9, 2022 10:34:22.673918009 CET5050653192.168.2.68.8.8.8
              Dec 9, 2022 10:34:22.699500084 CET53505068.8.8.8192.168.2.6
              Dec 9, 2022 10:34:22.721760988 CET5908253192.168.2.68.8.8.8
              Dec 9, 2022 10:34:22.739170074 CET53590828.8.8.8192.168.2.6
              Dec 9, 2022 10:34:25.973275900 CET6322953192.168.2.68.8.8.8
              Dec 9, 2022 10:34:25.992341995 CET53632298.8.8.8192.168.2.6
              Dec 9, 2022 10:34:25.996773005 CET6253853192.168.2.68.8.8.8
              Dec 9, 2022 10:34:26.013273001 CET53625388.8.8.8192.168.2.6
              Dec 9, 2022 10:35:26.042067051 CET6003253192.168.2.68.8.8.8
              Dec 9, 2022 10:35:26.064016104 CET53600328.8.8.8192.168.2.6
              Dec 9, 2022 10:35:26.068048000 CET4923253192.168.2.68.8.8.8
              Dec 9, 2022 10:35:26.094676018 CET53492328.8.8.8192.168.2.6
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Dec 9, 2022 10:34:22.673918009 CET192.168.2.68.8.8.80xe616Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
              Dec 9, 2022 10:34:22.721760988 CET192.168.2.68.8.8.80x1f0fStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
              Dec 9, 2022 10:34:25.973275900 CET192.168.2.68.8.8.80x3204Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Dec 9, 2022 10:34:25.996773005 CET192.168.2.68.8.8.80x4318Standard query (0)www.google.comA (IP address)IN (0x0001)false
              Dec 9, 2022 10:35:26.042067051 CET192.168.2.68.8.8.80x751aStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Dec 9, 2022 10:35:26.068048000 CET192.168.2.68.8.8.80x5959Standard query (0)www.google.comA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Dec 9, 2022 10:34:22.699500084 CET8.8.8.8192.168.2.60xe616No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
              Dec 9, 2022 10:34:22.699500084 CET8.8.8.8192.168.2.60xe616No error (0)clients.l.google.com142.250.180.174A (IP address)IN (0x0001)false
              Dec 9, 2022 10:34:22.739170074 CET8.8.8.8192.168.2.60x1f0fNo error (0)accounts.google.com142.250.184.45A (IP address)IN (0x0001)false
              Dec 9, 2022 10:34:25.992341995 CET8.8.8.8192.168.2.60x3204No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
              Dec 9, 2022 10:34:26.013273001 CET8.8.8.8192.168.2.60x4318No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
              Dec 9, 2022 10:35:26.064016104 CET8.8.8.8192.168.2.60x751aNo error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
              Dec 9, 2022 10:35:26.094676018 CET8.8.8.8192.168.2.60x5959No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
              • accounts.google.com
              • clients2.google.com
              • 185.177.92.29

              Click to jump to process

              Target ID:0
              Start time:10:34:19
              Start date:09/12/2022
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
              Imagebase:0x7ff6f9750000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              Target ID:1
              Start time:10:34:21
              Start date:09/12/2022
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1808,i,1709527060102746292,9450787675187643490,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff6f9750000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              Target ID:2
              Start time:10:34:22
              Start date:09/12/2022
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://185.177.92.29
              Imagebase:0x7ff6f9750000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              No disassembly