Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://www.bn3b2b2.livelovesouthatlanta.com/#.==wZy9mLilWZANHduVWblNnc1J2cpRWL0NHcuVWLilWZ6pneyImMiNjbi9ievsWYu8Sai9WbuUGbpJ2btxWYi9Gbn5SZt9Ga

Overview

General Information

Sample URL:http://www.bn3b2b2.livelovesouthatlanta.com/#.==wZy9mLilWZANHduVWblNnc1J2cpRWL0NHcuVWLilWZ6pneyImMiNjbi9ievsWYu8Sai9WbuUGbpJ2btxWYi9Gbn5SZt9Ga
Analysis ID:764041
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5852 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 2080 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1568,i,14781660650222300864,2008606683164464388,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 676 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.bn3b2b2.livelovesouthatlanta.com/#.==wZy9mLilWZANHduVWblNnc1J2cpRWL0NHcuVWLilWZ6pneyImMiNjbi9ievsWYu8Sai9WbuUGbpJ2btxWYi9Gbn5SZt9Ga MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.bn3b2b2.livelovesouthatlanta.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.bn3b2b2.livelovesouthatlanta.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.bn3b2b2.livelovesouthatlanta.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 09 Dec 2022 09:57:22 GMTServer: ApacheUpgrade: h2,h2cConnection: Upgrade, Keep-AliveVary: Accept-EncodingContent-Encoding: gzipContent-Length: 90Keep-Alive: timeout=5, max=75Content-Type: text/html; charset=UTF-8Data Raw: 1f 8b 08 00 00 00 00 00 00 03 b3 c9 30 b4 33 31 30 51 f0 cb 2f 51 70 cb 2f cd 4b b1 d1 07 8a 84 64 a4 2a 14 24 a6 a7 2a 94 64 24 96 28 54 e6 97 2a 64 24 96 a5 2a 14 a5 16 96 a6 16 97 a4 a6 28 24 e7 97 e6 a4 28 e4 01 35 25 a5 2a a4 81 f4 e9 01 00 96 f5 b5 25 4a 00 00 00 Data Ascii: 0310Q/Qp/Kd*$*d$(T*d$*($(5%*%J
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 09 Dec 2022 09:57:23 GMTServer: ApacheVary: Accept-EncodingContent-Encoding: gzipContent-Length: 90Keep-Alive: timeout=5, max=74Connection: Keep-AliveContent-Type: text/html; charset=UTF-8Data Raw: 1f 8b 08 00 00 00 00 00 00 03 b3 c9 30 b4 33 31 30 51 f0 cb 2f 51 70 cb 2f cd 4b b1 d1 07 8a 84 64 a4 2a 14 24 a6 a7 2a 94 64 24 96 28 54 e6 97 2a 64 24 96 a5 2a 14 a5 16 96 a6 16 97 a4 a6 28 24 e7 97 e6 a4 28 e4 01 35 25 a5 2a a4 81 f4 e9 01 00 96 f5 b5 25 4a 00 00 00 Data Ascii: 0310Q/Qp/Kd*$*d$(T*d$*($(5%*%J
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
Source: classification engineClassification label: clean0.win@25/0@5/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1568,i,14781660650222300864,2008606683164464388,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.bn3b2b2.livelovesouthatlanta.com/#.==wZy9mLilWZANHduVWblNnc1J2cpRWL0NHcuVWLilWZ6pneyImMiNjbi9ievsWYu8Sai9WbuUGbpJ2btxWYi9Gbn5SZt9Ga
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1568,i,14781660650222300864,2008606683164464388,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.bn3b2b2.livelovesouthatlanta.com/#.==wZy9mLilWZANHduVWblNnc1J2cpRWL0NHcuVWLilWZ6pneyImMiNjbi9ievsWYu8Sai9WbuUGbpJ2btxWYi9Gbn5SZt9Ga0%VirustotalBrowse
http://www.bn3b2b2.livelovesouthatlanta.com/#.==wZy9mLilWZANHduVWblNnc1J2cpRWL0NHcuVWLilWZ6pneyImMiNjbi9ievsWYu8Sai9WbuUGbpJ2btxWYi9Gbn5SZt9Ga0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://www.bn3b2b2.livelovesouthatlanta.com/favicon.ico0%Avira URL Cloudsafe
http://www.bn3b2b2.livelovesouthatlanta.com/0%VirustotalBrowse
http://www.bn3b2b2.livelovesouthatlanta.com/0%Avira URL Cloudsafe
http://www.bn3b2b2.livelovesouthatlanta.com/#.==wZy9mLilWZANHduVWblNnc1J2cpRWL0NHcuVWLilWZ6pneyImMiNjbi9ievsWYu8Sai9WbuUGbpJ2btxWYi9Gbn5SZt9Ga0%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
www.bn3b2b2.livelovesouthatlanta.com
192.185.72.57
truefalse
    unknown
    accounts.google.com
    142.250.184.45
    truefalse
      high
      www.google.com
      142.250.184.100
      truefalse
        high
        clients.l.google.com
        142.250.180.174
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              http://www.bn3b2b2.livelovesouthatlanta.com/favicon.icofalse
              • Avira URL Cloud: safe
              unknown
              http://www.bn3b2b2.livelovesouthatlanta.com/false
              • 0%, Virustotal, Browse
              • Avira URL Cloud: safe
              unknown
              http://www.bn3b2b2.livelovesouthatlanta.com/#.==wZy9mLilWZANHduVWblNnc1J2cpRWL0NHcuVWLilWZ6pneyImMiNjbi9ievsWYu8Sai9WbuUGbpJ2btxWYi9Gbn5SZt9Gafalseunknown
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.250.184.45
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                192.185.72.57
                www.bn3b2b2.livelovesouthatlanta.comUnited States
                46606UNIFIEDLAYER-AS-1USfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.250.184.100
                www.google.comUnited States
                15169GOOGLEUSfalse
                142.250.180.174
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.1
                127.0.0.1
                Joe Sandbox Version:36.0.0 Rainbow Opal
                Analysis ID:764041
                Start date and time:2022-12-09 10:56:20 +01:00
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 4m 25s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://www.bn3b2b2.livelovesouthatlanta.com/#.==wZy9mLilWZANHduVWblNnc1J2cpRWL0NHcuVWLilWZ6pneyImMiNjbi9ievsWYu8Sai9WbuUGbpJ2btxWYi9Gbn5SZt9Ga
                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                Number of analysed new started processes analysed:12
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • HDC enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@25/0@5/7
                EGA Information:Failed
                HDC Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.184.99, 34.104.35.123, 142.250.180.131
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtWriteVirtualMemory calls found.
                No simulations
                No context
                No context
                No context
                No context
                No context
                No created / dropped files found
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Dec 9, 2022 10:57:20.724873066 CET49697443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:20.724934101 CET44349697142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:20.725014925 CET49697443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:20.726068974 CET49698443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:20.726111889 CET44349698142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:20.726172924 CET49698443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:20.728313923 CET49697443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:20.728343010 CET44349697142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:20.728728056 CET49698443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:20.728750944 CET44349698142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:20.730803013 CET49700443192.168.2.3142.250.180.174
                Dec 9, 2022 10:57:20.730840921 CET44349700142.250.180.174192.168.2.3
                Dec 9, 2022 10:57:20.730901957 CET49700443192.168.2.3142.250.180.174
                Dec 9, 2022 10:57:20.731277943 CET49700443192.168.2.3142.250.180.174
                Dec 9, 2022 10:57:20.731292963 CET44349700142.250.180.174192.168.2.3
                Dec 9, 2022 10:57:20.835386992 CET44349697142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:20.864635944 CET49697443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:20.864667892 CET44349697142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:20.867883921 CET44349697142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:20.867994070 CET49697443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:20.918857098 CET44349698142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:20.932934999 CET44349700142.250.180.174192.168.2.3
                Dec 9, 2022 10:57:20.960460901 CET49700443192.168.2.3142.250.180.174
                Dec 9, 2022 10:57:20.960499048 CET44349700142.250.180.174192.168.2.3
                Dec 9, 2022 10:57:20.960747004 CET49698443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:20.960781097 CET44349698142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:20.961427927 CET44349700142.250.180.174192.168.2.3
                Dec 9, 2022 10:57:20.961510897 CET49700443192.168.2.3142.250.180.174
                Dec 9, 2022 10:57:20.962198019 CET44349698142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:20.962276936 CET49698443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:20.962980032 CET44349700142.250.180.174192.168.2.3
                Dec 9, 2022 10:57:20.963032961 CET49700443192.168.2.3142.250.180.174
                Dec 9, 2022 10:57:22.636409044 CET4970180192.168.2.3192.185.72.57
                Dec 9, 2022 10:57:22.637362957 CET49700443192.168.2.3142.250.180.174
                Dec 9, 2022 10:57:22.637438059 CET44349700142.250.180.174192.168.2.3
                Dec 9, 2022 10:57:22.637751102 CET49700443192.168.2.3142.250.180.174
                Dec 9, 2022 10:57:22.637768984 CET44349700142.250.180.174192.168.2.3
                Dec 9, 2022 10:57:22.638407946 CET44349700142.250.180.174192.168.2.3
                Dec 9, 2022 10:57:22.638686895 CET49697443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:22.638722897 CET44349697142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:22.638853073 CET49698443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:22.638897896 CET44349698142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:22.639143944 CET44349697142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:22.639234066 CET44349698142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:22.640693903 CET4970280192.168.2.3192.185.72.57
                Dec 9, 2022 10:57:22.640885115 CET49697443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:22.640924931 CET44349697142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:22.683183908 CET44349700142.250.180.174192.168.2.3
                Dec 9, 2022 10:57:22.683331966 CET49700443192.168.2.3142.250.180.174
                Dec 9, 2022 10:57:22.683383942 CET44349700142.250.180.174192.168.2.3
                Dec 9, 2022 10:57:22.683446884 CET44349700142.250.180.174192.168.2.3
                Dec 9, 2022 10:57:22.683516979 CET49700443192.168.2.3142.250.180.174
                Dec 9, 2022 10:57:22.702456951 CET49700443192.168.2.3142.250.180.174
                Dec 9, 2022 10:57:22.702514887 CET44349700142.250.180.174192.168.2.3
                Dec 9, 2022 10:57:22.725333929 CET49698443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:22.725374937 CET44349698142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:22.746534109 CET44349697142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:22.746670008 CET49697443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:22.746696949 CET44349697142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:22.746809006 CET44349697142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:22.746889114 CET49697443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:22.755578041 CET8049701192.185.72.57192.168.2.3
                Dec 9, 2022 10:57:22.755878925 CET4970180192.168.2.3192.185.72.57
                Dec 9, 2022 10:57:22.759623051 CET8049702192.185.72.57192.168.2.3
                Dec 9, 2022 10:57:22.759800911 CET4970280192.168.2.3192.185.72.57
                Dec 9, 2022 10:57:22.788525105 CET49697443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:22.788569927 CET44349697142.250.184.45192.168.2.3
                Dec 9, 2022 10:57:22.789776087 CET4970180192.168.2.3192.185.72.57
                Dec 9, 2022 10:57:22.825318098 CET49698443192.168.2.3142.250.184.45
                Dec 9, 2022 10:57:22.908603907 CET8049701192.185.72.57192.168.2.3
                Dec 9, 2022 10:57:22.998321056 CET8049701192.185.72.57192.168.2.3
                Dec 9, 2022 10:57:23.125403881 CET4970180192.168.2.3192.185.72.57
                Dec 9, 2022 10:57:23.173238993 CET49705443192.168.2.3142.250.184.100
                Dec 9, 2022 10:57:23.173305035 CET44349705142.250.184.100192.168.2.3
                Dec 9, 2022 10:57:23.173408985 CET49705443192.168.2.3142.250.184.100
                Dec 9, 2022 10:57:23.173826933 CET49705443192.168.2.3142.250.184.100
                Dec 9, 2022 10:57:23.173846960 CET44349705142.250.184.100192.168.2.3
                Dec 9, 2022 10:57:23.178301096 CET4970180192.168.2.3192.185.72.57
                Dec 9, 2022 10:57:23.251678944 CET44349705142.250.184.100192.168.2.3
                Dec 9, 2022 10:57:23.252096891 CET49705443192.168.2.3142.250.184.100
                Dec 9, 2022 10:57:23.252139091 CET44349705142.250.184.100192.168.2.3
                Dec 9, 2022 10:57:23.253683090 CET44349705142.250.184.100192.168.2.3
                Dec 9, 2022 10:57:23.253808975 CET49705443192.168.2.3142.250.184.100
                Dec 9, 2022 10:57:23.260540962 CET49705443192.168.2.3142.250.184.100
                Dec 9, 2022 10:57:23.260575056 CET44349705142.250.184.100192.168.2.3
                Dec 9, 2022 10:57:23.260813951 CET44349705142.250.184.100192.168.2.3
                Dec 9, 2022 10:57:23.296937943 CET8049701192.185.72.57192.168.2.3
                Dec 9, 2022 10:57:23.313225031 CET8049701192.185.72.57192.168.2.3
                Dec 9, 2022 10:57:23.333353996 CET49705443192.168.2.3142.250.184.100
                Dec 9, 2022 10:57:23.333395958 CET44349705142.250.184.100192.168.2.3
                Dec 9, 2022 10:57:23.537157059 CET49705443192.168.2.3142.250.184.100
                Dec 9, 2022 10:57:23.537168026 CET4970180192.168.2.3192.185.72.57
                Dec 9, 2022 10:57:28.316688061 CET8049701192.185.72.57192.168.2.3
                Dec 9, 2022 10:57:28.316771984 CET4970180192.168.2.3192.185.72.57
                Dec 9, 2022 10:57:29.651099920 CET4970180192.168.2.3192.185.72.57
                Dec 9, 2022 10:57:29.770451069 CET8049701192.185.72.57192.168.2.3
                Dec 9, 2022 10:57:33.227669954 CET44349705142.250.184.100192.168.2.3
                Dec 9, 2022 10:57:33.227756023 CET44349705142.250.184.100192.168.2.3
                Dec 9, 2022 10:57:33.227863073 CET49705443192.168.2.3142.250.184.100
                Dec 9, 2022 10:57:36.984302998 CET49705443192.168.2.3142.250.184.100
                Dec 9, 2022 10:57:36.984364033 CET44349705142.250.184.100192.168.2.3
                Dec 9, 2022 10:57:54.372998953 CET8049702192.185.72.57192.168.2.3
                Dec 9, 2022 10:57:54.373243093 CET4970280192.168.2.3192.185.72.57
                Dec 9, 2022 10:58:07.737446070 CET49698443192.168.2.3142.250.184.45
                Dec 9, 2022 10:58:07.737483978 CET44349698142.250.184.45192.168.2.3
                Dec 9, 2022 10:58:07.768800974 CET4970280192.168.2.3192.185.72.57
                Dec 9, 2022 10:58:07.888163090 CET8049702192.185.72.57192.168.2.3
                Dec 9, 2022 10:58:23.233217955 CET4970280192.168.2.3192.185.72.57
                Dec 9, 2022 10:58:23.233304024 CET49698443192.168.2.3142.250.184.45
                Dec 9, 2022 10:58:23.233438969 CET44349698142.250.184.45192.168.2.3
                Dec 9, 2022 10:58:23.233500004 CET49698443192.168.2.3142.250.184.45
                Dec 9, 2022 10:58:23.234039068 CET49729443192.168.2.3142.250.184.100
                Dec 9, 2022 10:58:23.234086037 CET44349729142.250.184.100192.168.2.3
                Dec 9, 2022 10:58:23.234154940 CET49729443192.168.2.3142.250.184.100
                Dec 9, 2022 10:58:23.234710932 CET49729443192.168.2.3142.250.184.100
                Dec 9, 2022 10:58:23.234731913 CET44349729142.250.184.100192.168.2.3
                Dec 9, 2022 10:58:23.299644947 CET44349729142.250.184.100192.168.2.3
                Dec 9, 2022 10:58:23.300156116 CET49729443192.168.2.3142.250.184.100
                Dec 9, 2022 10:58:23.300192118 CET44349729142.250.184.100192.168.2.3
                Dec 9, 2022 10:58:23.300615072 CET44349729142.250.184.100192.168.2.3
                Dec 9, 2022 10:58:23.301311970 CET49729443192.168.2.3142.250.184.100
                Dec 9, 2022 10:58:23.301330090 CET44349729142.250.184.100192.168.2.3
                Dec 9, 2022 10:58:23.301404953 CET44349729142.250.184.100192.168.2.3
                Dec 9, 2022 10:58:23.352529049 CET8049702192.185.72.57192.168.2.3
                Dec 9, 2022 10:58:23.352611065 CET4970280192.168.2.3192.185.72.57
                Dec 9, 2022 10:58:23.356554985 CET49729443192.168.2.3142.250.184.100
                Dec 9, 2022 10:58:33.314403057 CET44349729142.250.184.100192.168.2.3
                Dec 9, 2022 10:58:33.314507961 CET44349729142.250.184.100192.168.2.3
                Dec 9, 2022 10:58:33.314848900 CET49729443192.168.2.3142.250.184.100
                TimestampSource PortDest PortSource IPDest IP
                Dec 9, 2022 10:57:19.726564884 CET6270453192.168.2.38.8.8.8
                Dec 9, 2022 10:57:19.744106054 CET53627048.8.8.8192.168.2.3
                Dec 9, 2022 10:57:20.031619072 CET5784053192.168.2.38.8.8.8
                Dec 9, 2022 10:57:20.057452917 CET53578408.8.8.8192.168.2.3
                Dec 9, 2022 10:57:22.112679958 CET5238753192.168.2.38.8.8.8
                Dec 9, 2022 10:57:22.237191916 CET53523878.8.8.8192.168.2.3
                Dec 9, 2022 10:57:23.136977911 CET5397553192.168.2.38.8.8.8
                Dec 9, 2022 10:57:23.154027939 CET53539758.8.8.8192.168.2.3
                Dec 9, 2022 10:58:23.204354048 CET5869153192.168.2.38.8.8.8
                Dec 9, 2022 10:58:23.222253084 CET53586918.8.8.8192.168.2.3
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Dec 9, 2022 10:57:19.726564884 CET192.168.2.38.8.8.80x1e04Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Dec 9, 2022 10:57:20.031619072 CET192.168.2.38.8.8.80xc336Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Dec 9, 2022 10:57:22.112679958 CET192.168.2.38.8.8.80x266dStandard query (0)www.bn3b2b2.livelovesouthatlanta.comA (IP address)IN (0x0001)false
                Dec 9, 2022 10:57:23.136977911 CET192.168.2.38.8.8.80x9b61Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Dec 9, 2022 10:58:23.204354048 CET192.168.2.38.8.8.80xdc03Standard query (0)www.google.comA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Dec 9, 2022 10:57:19.744106054 CET8.8.8.8192.168.2.30x1e04No error (0)accounts.google.com142.250.184.45A (IP address)IN (0x0001)false
                Dec 9, 2022 10:57:20.057452917 CET8.8.8.8192.168.2.30xc336No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Dec 9, 2022 10:57:20.057452917 CET8.8.8.8192.168.2.30xc336No error (0)clients.l.google.com142.250.180.174A (IP address)IN (0x0001)false
                Dec 9, 2022 10:57:22.237191916 CET8.8.8.8192.168.2.30x266dNo error (0)www.bn3b2b2.livelovesouthatlanta.com192.185.72.57A (IP address)IN (0x0001)false
                Dec 9, 2022 10:57:23.154027939 CET8.8.8.8192.168.2.30x9b61No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                Dec 9, 2022 10:58:23.222253084 CET8.8.8.8192.168.2.30xdc03No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                • clients2.google.com
                • accounts.google.com
                • www.bn3b2b2.livelovesouthatlanta.com
                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.349700142.250.180.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.349697142.250.184.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                2192.168.2.349701192.185.72.5780C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Dec 9, 2022 10:57:22.789776087 CET188OUTGET / HTTP/1.1
                Host: www.bn3b2b2.livelovesouthatlanta.com
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Dec 9, 2022 10:57:22.998321056 CET377INHTTP/1.1 404 Not Found
                Date: Fri, 09 Dec 2022 09:57:22 GMT
                Server: Apache
                Upgrade: h2,h2c
                Connection: Upgrade, Keep-Alive
                Vary: Accept-Encoding
                Content-Encoding: gzip
                Content-Length: 90
                Keep-Alive: timeout=5, max=75
                Content-Type: text/html; charset=UTF-8
                Data Raw: 1f 8b 08 00 00 00 00 00 00 03 b3 c9 30 b4 33 31 30 51 f0 cb 2f 51 70 cb 2f cd 4b b1 d1 07 8a 84 64 a4 2a 14 24 a6 a7 2a 94 64 24 96 28 54 e6 97 2a 64 24 96 a5 2a 14 a5 16 96 a6 16 97 a4 a6 28 24 e7 97 e6 a4 28 e4 01 35 25 a5 2a a4 81 f4 e9 01 00 96 f5 b5 25 4a 00 00 00
                Data Ascii: 0310Q/Qp/Kd*$*d$(T*d$*($(5%*%J
                Dec 9, 2022 10:57:23.178301096 CET456OUTGET /favicon.ico HTTP/1.1
                Host: www.bn3b2b2.livelovesouthatlanta.com
                Connection: keep-alive
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Referer: http://www.bn3b2b2.livelovesouthatlanta.com/
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Dec 9, 2022 10:57:23.313225031 CET463INHTTP/1.1 404 Not Found
                Date: Fri, 09 Dec 2022 09:57:23 GMT
                Server: Apache
                Vary: Accept-Encoding
                Content-Encoding: gzip
                Content-Length: 90
                Keep-Alive: timeout=5, max=74
                Connection: Keep-Alive
                Content-Type: text/html; charset=UTF-8
                Data Raw: 1f 8b 08 00 00 00 00 00 00 03 b3 c9 30 b4 33 31 30 51 f0 cb 2f 51 70 cb 2f cd 4b b1 d1 07 8a 84 64 a4 2a 14 24 a6 a7 2a 94 64 24 96 28 54 e6 97 2a 64 24 96 a5 2a 14 a5 16 96 a6 16 97 a4 a6 28 24 e7 97 e6 a4 28 e4 01 35 25 a5 2a a4 81 f4 e9 01 00 96 f5 b5 25 4a 00 00 00
                Data Ascii: 0310Q/Qp/Kd*$*d$(T*d$*($(5%*%J


                Session IDSource IPSource PortDestination IPDestination PortProcess
                3192.168.2.349702192.185.72.5780C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Dec 9, 2022 10:58:07.768800974 CET465OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.349700142.250.180.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2022-12-09 09:57:22 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                Host: clients2.google.com
                Connection: keep-alive
                X-Goog-Update-Interactivity: fg
                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                X-Goog-Update-Updater: chromecrx-104.0.5112.81
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2022-12-09 09:57:22 UTC1INHTTP/1.1 200 OK
                Content-Security-Policy: script-src 'report-sample' 'nonce-NH4OnUeRsQoQyJ1Ag9mKbQ' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Fri, 09 Dec 2022 09:57:22 GMT
                Content-Type: text/xml; charset=UTF-8
                X-Daynum: 5821
                X-Daystart: 7042
                X-Content-Type-Options: nosniff
                X-Frame-Options: SAMEORIGIN
                X-XSS-Protection: 1; mode=block
                Server: GSE
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2022-12-09 09:57:22 UTC2INData Raw: 32 63 38 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 38 32 31 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 37 30 34 32 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22 20
                Data Ascii: 2c8<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5821" elapsed_seconds="7042"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                2022-12-09 09:57:22 UTC2INData Raw: 76 59 6e 4d 76 4e 7a 49 30 51 55 46 58 4e 56 39 7a 54 32 52 76 64 55 77 79 4d 45 52 45 53 45 5a 47 56 6d 4a 6e 51 51 2f 31 2e 30 2e 30 2e 36 5f 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 2e 63 72 78 22 20 66 70 3d 22 31 2e 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65
                Data Ascii: vYnMvNzI0QUFXNV9zT2RvdUwyMERESEZGVmJnQQ/1.0.0.6_nmmhkkegccagdldgiimedpiccmgmieda.crx" fp="1.81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size
                2022-12-09 09:57:22 UTC3INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.349697142.250.184.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2022-12-09 09:57:22 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                Host: accounts.google.com
                Connection: keep-alive
                Content-Length: 1
                Origin: https://www.google.com
                Content-Type: application/x-www-form-urlencoded
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
                2022-12-09 09:57:22 UTC1OUTData Raw: 20
                Data Ascii:
                2022-12-09 09:57:22 UTC3INHTTP/1.1 200 OK
                Content-Type: application/json; charset=utf-8
                Access-Control-Allow-Origin: https://www.google.com
                Access-Control-Allow-Credentials: true
                X-Content-Type-Options: nosniff
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Fri, 09 Dec 2022 09:57:22 GMT
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                Content-Security-Policy: script-src 'report-sample' 'nonce-BoE7k8ZMezs6sztjTjAhxw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                Server: ESF
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2022-12-09 09:57:22 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                Data Ascii: 11["gaia.l.a.r",[]]
                2022-12-09 09:57:22 UTC4INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Click to jump to process

                Click to jump to process

                Click to dive into process behavior distribution

                Click to jump to process

                Target ID:0
                Start time:10:58:07
                Start date:09/12/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff614650000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                Target ID:1
                Start time:10:58:08
                Start date:09/12/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1956 --field-trial-handle=1568,i,14781660650222300864,2008606683164464388,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff614650000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                Target ID:2
                Start time:10:58:09
                Start date:09/12/2022
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.bn3b2b2.livelovesouthatlanta.com/#.==wZy9mLilWZANHduVWblNnc1J2cpRWL0NHcuVWLilWZ6pneyImMiNjbi9ievsWYu8Sai9WbuUGbpJ2btxWYi9Gbn5SZt9Ga
                Imagebase:0x7ff614650000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                No disassembly