Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://listfoo.org/zmg5f

Overview

General Information

Sample URL:https://listfoo.org/zmg5f
Analysis ID:791296
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5112 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 4136 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1972 --field-trial-handle=1772,i,13714808044369432181,11901859910510463980,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6288 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://listfoo.org/zmg5f MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownHTTPS traffic detected: 142.250.203.100:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /zmg5f HTTP/1.1Host: listfoo.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEIk6HLAQiQvMwBCNS8zAEIssHMAQjFwcwBCNbBzAE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://listfoo.org/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: listfoo.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://listfoo.org/zmg5fAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.google.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEIk6HLAQiQvMwBCNS8zAEIssHMAQjFwcwBCNbBzAE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://listfoo.org/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605
Source: global trafficHTTP traffic detected: GET /images/branding/googlelogo/1x/googlelogo_color_272x92dp.png HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; __Secure-ENID=10.SE=rxeIaTyIOy9jvV9euSuawacjiWICJhymkzUVWH2HD2RDtSxeu71HLmeQFHp4TevkZZiCGMomUAh6rCb_bqWSB4wLcjLEZPM7DiRPynCzjLp5Ndh5EE9BekUAY_vsUkHATrOJYIU8KhR0mm8R0iBZ3HQLXPc9SXX0oCh5R3iDBkY
Source: global trafficHTTP traffic detected: GET /images/searchbox/desktop_searchbox_sprites318_hr.webp HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; __Secure-ENID=10.SE=rxeIaTyIOy9jvV9euSuawacjiWICJhymkzUVWH2HD2RDtSxeu71HLmeQFHp4TevkZZiCGMomUAh6rCb_bqWSB4wLcjLEZPM7DiRPynCzjLp5Ndh5EE9BekUAY_vsUkHATrOJYIU8KhR0mm8R0iBZ3HQLXPc9SXX0oCh5R3iDBkY
Source: global trafficHTTP traffic detected: GET /gen_204?atyp=i&ct=bxjs&cad=&b=0&ei=ruvQY6uHDeSP9u8PlpqO-Ak&zx=1674636206145 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; __Secure-ENID=10.SE=rxeIaTyIOy9jvV9euSuawacjiWICJhymkzUVWH2HD2RDtSxeu71HLmeQFHp4TevkZZiCGMomUAh6rCb_bqWSB4wLcjLEZPM7DiRPynCzjLp5Ndh5EE9BekUAY_vsUkHATrOJYIU8KhR0mm8R0iBZ3HQLXPc9SXX0oCh5R3iDBkY
Source: global trafficHTTP traffic detected: GET /_/scs/abc-static/_/js/k=gapi.gapi.en.WEPncdil2Uw.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-eOecLLtOXEl3I3kIuMsKXRkDMmA/cb=gapi.loaded_0 HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; __Secure-ENID=10.SE=rxeIaTyIOy9jvV9euSuawacjiWICJhymkzUVWH2HD2RDtSxeu71HLmeQFHp4TevkZZiCGMomUAh6rCb_bqWSB4wLcjLEZPM7DiRPynCzjLp5Ndh5EE9BekUAY_vsUkHATrOJYIU8KhR0mm8R0iBZ3HQLXPc9SXX0oCh5R3iDBkY
Source: global trafficHTTP traffic detected: GET /manifest?pwa=webhp HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: manifestReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; __Secure-ENID=10.SE=rxeIaTyIOy9jvV9euSuawacjiWICJhymkzUVWH2HD2RDtSxeu71HLmeQFHp4TevkZZiCGMomUAh6rCb_bqWSB4wLcjLEZPM7DiRPynCzjLp5Ndh5EE9BekUAY_vsUkHATrOJYIU8KhR0mm8R0iBZ3HQLXPc9SXX0oCh5R3iDBkY
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; __Secure-ENID=10.SE=rxeIaTyIOy9jvV9euSuawacjiWICJhymkzUVWH2HD2RDtSxeu71HLmeQFHp4TevkZZiCGMomUAh6rCb_bqWSB4wLcjLEZPM7DiRPynCzjLp5Ndh5EE9BekUAY_vsUkHATrOJYIU8KhR0mm8R0iBZ3HQLXPc9SXX0oCh5R3iDBkY
Source: global trafficHTTP traffic detected: GET /images/branding/googlelogo/2x/googlelogo_color_272x92dp.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.google.comCookie: CONSENT=YES+GB.en-GB+V9+BX
Source: global trafficHTTP traffic detected: GET /xjs/_/js/k=xjs.s.en_GB.zobC7UqdsqU.O/am=AAEqCFcAOAAAQAAAAAAkIAAAAAAAAgAwBkDwlA0I2BAOEIMBsCwBIAAgiNEPEQAABgADGBYABAAAAED-AAQ8AQCDCQsAAAAAAAAAELAEweAGCQoCQAAAAAAAAACU0uTFASAIAgAAAQ/d=1/ed=1/dg=2/br=1/rs=ACT90oFLXSotrQJhVFHbtpFxrnCGNSmSlQ/m=cdos,dpf,hsm,jsa,d,csi HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; __Secure-ENID=10.SE=rxeIaTyIOy9jvV9euSuawacjiWICJhymkzUVWH2HD2RDtSxeu71HLmeQFHp4TevkZZiCGMomUAh6rCb_bqWSB4wLcjLEZPM7DiRPynCzjLp5Ndh5EE9BekUAY_vsUkHATrOJYIU8KhR0mm8R0iBZ3HQLXPc9SXX0oCh5R3iDBkY; SOCS=CAISHAgBEhJnd3NfMjAyMzAxMTgtMF9SQzEaAmVuIAEaBgiA4sGeBg
Source: global trafficHTTP traffic detected: GET /gen_204?atyp=i&ct=bxjs&cad=&b=1&ei=ruvQY6uHDeSP9u8PlpqO-Ak&zx=1674636232161 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; __Secure-ENID=10.SE=rxeIaTyIOy9jvV9euSuawacjiWICJhymkzUVWH2HD2RDtSxeu71HLmeQFHp4TevkZZiCGMomUAh6rCb_bqWSB4wLcjLEZPM7DiRPynCzjLp5Ndh5EE9BekUAY_vsUkHATrOJYIU8KhR0mm8R0iBZ3HQLXPc9SXX0oCh5R3iDBkY; SOCS=CAISHAgBEhJnd3NfMjAyMzAxMTgtMF9SQzEaAmVuIAEaBgiA4sGeBg
Source: global trafficHTTP traffic detected: GET /complete/search?q&cp=0&client=gws-wiz&xssi=t&hl=en-HR&authuser=0&psi=ruvQY6uHDeSP9u8PlpqO-Ak.1674636232907&nolsbt=1&dpr=1 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; SOCS=CAISHAgBEhJnd3NfMjAyMzAxMTgtMF9SQzEaAmVuIAEaBgiA4sGeBg; NID=511=lhcqvASiDCO0DxZodcjlI6Ue9orYswUE8f7gKzLn_y1iAmcC7yPcUyJCzWUgV3pzof4UWqx9ONQ5GIrhYGNE0bjIeifCg6kTSRel7Hy66LJITNJHw7i1iThpWUtVQym0cJmjWOHVdyjs23AgDrapDyuK_GqnwW_fmk_5GMmJ_vg
Source: global trafficHTTP traffic detected: GET /xjs/_/js/k=xjs.s.en_GB.zobC7UqdsqU.O/ck=xjs.s.F0fY5Pm-eS0.L.W.O/am=AAEqCFcAOAAAQAAAAAAkIAAAAAAAAgAwBkDwlA0I2BAOEIMBsCwBIAAgiNEPEQAABgADGBYABAAAAED-AAQ8AQCDCQsAAAAAAAAAELAEweAGCQoCQAAAAAAAAACU0uTFASAIAgAAAQ/d=1/exm=cdos,csi,d,dpf,hsm,jsa/ed=1/dg=2/br=1/rs=ACT90oHWjJk68F8W9qa5QTlNuGD_7xu0jA/ee=Pjplud:PoEs9b;QGR0gd:Mlhmy;uY49fb:COQbmf;EVNhjf:pw70Gc;sTsDMc:kHVSUb;g8nkx:U4MzKc;wQlYve:aLUfP;kbAm9d:MkHyGd;F9mqte:UoRcbe;oUlnpc:RagDlc;YV5bee:IvPZ6d;dtl0hd:lLQWFe;yGxLoc:FmAr0c;dIoSBb:ZgGg9b;pXdRYb:JKoKVe;wR5FRb:TtcOte;KpRAue:Tia57b;aZ61od:arTwJ;JXS8fb:Qj0suc;rQSrae:C6D5Fc;qavrXe:zQzcXe;UDrY1c:eps46d;w3bZCb:ZPGaIb;VGRfx:VFqbr;imqimf:jKGL2e;Np8Qkd:Dpx6qc;BjwMce:cXX2Wb;oGtAuc:sOXFj;NPKaK:PVlQOd;EmZ2Bf:zr1jrb;daB6be:lMxGPd;Fmv9Nc:O1Tzwc;hK67qb:QWEO5b;R4IIIb:QWfeKf;BMxAGc:E5bFse;WDGyFe:jcVOxd;wV5Pjc:L8KGxe;xbe2wc:wbTLEd;DpcR3d:zL72xf;tosKvd:ZCqP3;ESrPQc:mNTJvc;NSEoX:lazG7b;G6wU6e:hezEbd;kCQyJ:ueyPK;okUaUd:wItadb;GleZL:J1A7Od;Xeq57c:wZTUNc;eJZqRc:wUwbse;RiX1h:uiAbXc;oSUNyd:fTfGO;SJsSc:H1GVub;SMDL4c:fTfGO;JsbNhc:Xd8iUd;zOsCQe:Ko78Df;KcokUb:KiuZBf;WCEKNd:I46Hvd;LBgRLc:XVMNvd;LsNahb:ucGLNb;UyG7Kb:wQd0G;TxfV6d:YORN0b;qaS3gd:yiLg6e;aAJE9c:WHW6Ef;BgS6mb:fidj5d;UVmjEd:EesRsb;z97YGf:oug9te;CxXAWb:YyRLvc;VN6jIc:ddQyuf;SLtqO:Kh1xYe;VxQ32b:k0XsBb;DULqB:RKfG5c;bcPXSc:gSZLJb;cFTWae:gT8qnd;gaub4:TN6bMe;hjRo6e:F62sG;whEZac:F4AmNb;qddgKe:x4FYXe;eBAeSb:Ck63tb;vfVwPd:OXTqFb;w9w86d:dt4g2b;lkq0A:Z0MWEf;KQzWid:mB4wNe;pNsl2d:j9Yuyc;eHDfl:ofjVkb;Nyt6ic:jn2sGd;SNUn3:x8cHvb;LEikZe:byfTOb,lsjVmc;io8t5d:sgY6Zb;Oj465e:KG2eXe;sP4Vbe:VwDzFe;kMFpHd:OTA3Ae;nAFL3:s39S4;iFQyKf:QIhFr/m=DhPYme,EkevXb,GU4Gab,MpJwZc,NzU6V,UUJqVe,aa,abd,async,epYOx,pHXghd,q0xTif,s39S4,sOXFj,sb_wiz,sf,sonic,spch?xjs=s1 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; SOCS=CAISHAgBEhJnd3NfMjAyMzAxMTgtMF9SQzEaAmVuIAEaBgiA4sGeBg; NID=511=lhcqvASiDCO0DxZodcjlI6Ue9orYswUE8f7gKzLn_y1iAmcC7yPcUyJCzWUgV3pzof4UWqx9ONQ5GIrhYGNE0bjIeifCg6kTSRel7Hy66LJITNJHw7i1iThpWUtVQym0cJmjWOHVdyjs23AgDrapDyuK_GqnwW_fmk_5GMmJ_vg
Source: global trafficHTTP traffic detected: GET /client_204?&atyp=i&biw=1280&bih=913&ei=ruvQY6uHDeSP9u8PlpqO-Ak HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; SOCS=CAISHAgBEhJnd3NfMjAyMzAxMTgtMF9SQzEaAmVuIAEaBgiA4sGeBg; NID=511=lhcqvASiDCO0DxZodcjlI6Ue9orYswUE8f7gKzLn_y1iAmcC7yPcUyJCzWUgV3pzof4UWqx9ONQ5GIrhYGNE0bjIeifCg6kTSRel7Hy66LJITNJHw7i1iThpWUtVQym0cJmjWOHVdyjs23AgDrapDyuK_GqnwW_fmk_5GMmJ_vg
Source: global trafficHTTP traffic detected: GET /xjs/_/js/k=xjs.s.en_GB.zobC7UqdsqU.O/ck=xjs.s.F0fY5Pm-eS0.L.W.O/am=AAEqCFcAOAAAQAAAAAAkIAAAAAAAAgAwBkDwlA0I2BAOEIMBsCwBIAAgiNEPEQAABgADGBYABAAAAED-AAQ8AQCDCQsAAAAAAAAAELAEweAGCQoCQAAAAAAAAACU0uTFASAIAgAAAQ/d=1/exm=DhPYme,EkevXb,GU4Gab,MpJwZc,NzU6V,UUJqVe,aa,abd,async,cdos,csi,d,dpf,epYOx,hsm,jsa,pHXghd,q0xTif,s39S4,sOXFj,sb_wiz,sf,sonic,spch/ed=1/dg=2/br=1/rs=ACT90oHWjJk68F8W9qa5QTlNuGD_7xu0jA/ee=Pjplud:PoEs9b;QGR0gd:Mlhmy;uY49fb:COQbmf;EVNhjf:pw70Gc;sTsDMc:kHVSUb;g8nkx:U4MzKc;wQlYve:aLUfP;kbAm9d:MkHyGd;F9mqte:UoRcbe;oUlnpc:RagDlc;YV5bee:IvPZ6d;dtl0hd:lLQWFe;yGxLoc:FmAr0c;dIoSBb:ZgGg9b;pXdRYb:JKoKVe;wR5FRb:TtcOte;KpRAue:Tia57b;aZ61od:arTwJ;JXS8fb:Qj0suc;rQSrae:C6D5Fc;qavrXe:zQzcXe;UDrY1c:eps46d;w3bZCb:ZPGaIb;VGRfx:VFqbr;imqimf:jKGL2e;Np8Qkd:Dpx6qc;BjwMce:cXX2Wb;oGtAuc:sOXFj;NPKaK:PVlQOd;EmZ2Bf:zr1jrb;daB6be:lMxGPd;Fmv9Nc:O1Tzwc;hK67qb:QWEO5b;R4IIIb:QWfeKf;BMxAGc:E5bFse;WDGyFe:jcVOxd;wV5Pjc:L8KGxe;xbe2wc:wbTLEd;DpcR3d:zL72xf;tosKvd:ZCqP3;ESrPQc:mNTJvc;NSEoX:lazG7b;G6wU6e:hezEbd;kCQyJ:ueyPK;okUaUd:wItadb;GleZL:J1A7Od;Xeq57c:wZTUNc;eJZqRc:wUwbse;RiX1h:uiAbXc;oSUNyd:fTfGO;SJsSc:H1GVub;SMDL4c:fTfGO;JsbNhc:Xd8iUd;zOsCQe:Ko78Df;KcokUb:KiuZBf;WCEKNd:I46Hvd;LBgRLc:XVMNvd;LsNahb:ucGLNb;UyG7Kb:wQd0G;TxfV6d:YORN0b;qaS3gd:yiLg6e;aAJE9c:WHW6Ef;BgS6mb:fidj5d;UVmjEd:EesRsb;z97YGf:oug9te;CxXAWb:YyRLvc;VN6jIc:ddQyuf;SLtqO:Kh1xYe;VxQ32b:k0XsBb;DULqB:RKfG5c;bcPXSc:gSZLJb;cFTWae:gT8qnd;gaub4:TN6bMe;hjRo6e:F62sG;whEZac:F4AmNb;qddgKe:x4FYXe;eBAeSb:Ck63tb;vfVwPd:OXTqFb;w9w86d:dt4g2b;lkq0A:Z0MWEf;KQzWid:mB4wNe;pNsl2d:j9Yuyc;eHDfl:ofjVkb;Nyt6ic:jn2sGd;SNUn3:x8cHvb;LEikZe:byfTOb,lsjVmc;io8t5d:sgY6Zb;Oj465e:KG2eXe;sP4Vbe:VwDzFe;kMFpHd:OTA3Ae;nAFL3:s39S4;iFQyKf:QIhFr/m=CnSW2d,DPreE,WlNQGd,fXO0xe,kQvlef,nabPbb?xjs=s2 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; SOCS=CAISHAgBEhJnd3NfMjAyMzAxMTgtMF9SQzEaAmVuIAEaBgiA4sGeBg; NID=511=lhcqvASiDCO0DxZodcjlI6Ue9orYswUE8f7gKzLn_y1iAmcC7yPcUyJCzWUgV3pzof4UWqx9ONQ5GIrhYGNE0bjIeifCg6kTSRel7Hy66LJITNJHw7i1iThpWUtVQym0cJmjWOHVdyjs23AgDrapDyuK_GqnwW_fmk_
Source: global trafficHTTP traffic detected: GET /client_204?cs=1 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; SOCS=CAISHAgBEhJnd3NfMjAyMzAxMTgtMF9SQzEaAmVuIAEaBgiA4sGeBg; NID=511=lhcqvASiDCO0DxZodcjlI6Ue9orYswUE8f7gKzLn_y1iAmcC7yPcUyJCzWUgV3pzof4UWqx9ONQ5GIrhYGNE0bjIeifCg6kTSRel7Hy66LJITNJHw7i1iThpWUtVQym0cJmjWOHVdyjs23AgDrapDyuK_GqnwW_fmk_5GMmJ_vg
Source: global trafficHTTP traffic detected: GET /xjs/_/js/md=1/k=xjs.s.en_GB.zobC7UqdsqU.O/am=AAEqCFcAOAAAQAAAAAAkIAAAAAAAAgAwBkDwlA0I2BAOEIMBsCwBIAAgiNEPEQAABgADGBYABAAAAED-AAQ8AQCDCQsAAAAAAAAAELAEweAGCQoCQAAAAAAAAACU0uTFASAIAgAAAQ/rs=ACT90oFLXSotrQJhVFHbtpFxrnCGNSmSlQ HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; SOCS=CAISHAgBEhJnd3NfMjAyMzAxMTgtMF9SQzEaAmVuIAEaBgiA4sGeBg; NID=511=lhcqvASiDCO0DxZodcjlI6Ue9orYswUE8f7gKzLn_y1iAmcC7yPcUyJCzWUgV3pzof4UWqx9ONQ5GIrhYGNE0bjIeifCg6kTSRel7Hy66LJITNJHw7i1iThpWUtVQym0cJmjWOHVdyjs23AgDrapDyuK_GqnwW_fmk_5GMmJ_vg
Source: global trafficHTTP traffic detected: GET /xjs/_/js/k=xjs.s.en_GB.zobC7UqdsqU.O/ck=xjs.s.F0fY5Pm-eS0.L.W.O/am=AAEqCFcAOAAAQAAAAAAkIAAAAAAAAgAwBkDwlA0I2BAOEIMBsCwBIAAgiNEPEQAABgADGBYABAAAAED-AAQ8AQCDCQsAAAAAAAAAELAEweAGCQoCQAAAAAAAAACU0uTFASAIAgAAAQ/d=1/exm=CnSW2d,DPreE,DhPYme,EkevXb,GU4Gab,MpJwZc,NzU6V,UUJqVe,WlNQGd,aa,abd,async,cdos,csi,d,dpf,epYOx,fXO0xe,hsm,jsa,kQvlef,nabPbb,pHXghd,q0xTif,s39S4,sOXFj,sb_wiz,sf,sonic,spch/ed=1/dg=2/br=1/rs=ACT90oHWjJk68F8W9qa5QTlNuGD_7xu0jA/ee=Pjplud:PoEs9b;QGR0gd:Mlhmy;uY49fb:COQbmf;EVNhjf:pw70Gc;sTsDMc:kHVSUb;g8nkx:U4MzKc;wQlYve:aLUfP;kbAm9d:MkHyGd;F9mqte:UoRcbe;oUlnpc:RagDlc;YV5bee:IvPZ6d;dtl0hd:lLQWFe;yGxLoc:FmAr0c;dIoSBb:ZgGg9b;pXdRYb:JKoKVe;wR5FRb:TtcOte;KpRAue:Tia57b;aZ61od:arTwJ;JXS8fb:Qj0suc;rQSrae:C6D5Fc;qavrXe:zQzcXe;UDrY1c:eps46d;w3bZCb:ZPGaIb;VGRfx:VFqbr;imqimf:jKGL2e;Np8Qkd:Dpx6qc;BjwMce:cXX2Wb;oGtAuc:sOXFj;NPKaK:PVlQOd;EmZ2Bf:zr1jrb;daB6be:lMxGPd;Fmv9Nc:O1Tzwc;hK67qb:QWEO5b;R4IIIb:QWfeKf;BMxAGc:E5bFse;WDGyFe:jcVOxd;wV5Pjc:L8KGxe;xbe2wc:wbTLEd;DpcR3d:zL72xf;tosKvd:ZCqP3;ESrPQc:mNTJvc;NSEoX:lazG7b;G6wU6e:hezEbd;kCQyJ:ueyPK;okUaUd:wItadb;GleZL:J1A7Od;Xeq57c:wZTUNc;eJZqRc:wUwbse;RiX1h:uiAbXc;oSUNyd:fTfGO;SJsSc:H1GVub;SMDL4c:fTfGO;JsbNhc:Xd8iUd;zOsCQe:Ko78Df;KcokUb:KiuZBf;WCEKNd:I46Hvd;LBgRLc:XVMNvd;LsNahb:ucGLNb;UyG7Kb:wQd0G;TxfV6d:YORN0b;qaS3gd:yiLg6e;aAJE9c:WHW6Ef;BgS6mb:fidj5d;UVmjEd:EesRsb;z97YGf:oug9te;CxXAWb:YyRLvc;VN6jIc:ddQyuf;SLtqO:Kh1xYe;VxQ32b:k0XsBb;DULqB:RKfG5c;bcPXSc:gSZLJb;cFTWae:gT8qnd;gaub4:TN6bMe;hjRo6e:F62sG;whEZac:F4AmNb;qddgKe:x4FYXe;eBAeSb:Ck63tb;vfVwPd:OXTqFb;w9w86d:dt4g2b;lkq0A:Z0MWEf;KQzWid:mB4wNe;pNsl2d:j9Yuyc;eHDfl:ofjVkb;Nyt6ic:jn2sGd;SNUn3:x8cHvb;LEikZe:byfTOb,lsjVmc;io8t5d:sgY6Zb;Oj465e:KG2eXe;sP4Vbe:VwDzFe;kMFpHd:OTA3Ae;nAFL3:s39S4;iFQyKf:QIhFr/m=aLUfP?xjs=s2 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-full-version-list: "Chromium";v="104.0.5112.81", " Not A;Brand";v="99.0.0.0", "Google Chrome";v="104.0.5112.81"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "104.0.5112.81"sec-ch-ua-platform-version: "6.0.0"sec-ch-ua-bitness: "64"sec-ch-ua-wow64: ?0sec-ch-ua-model: sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CJW2yQEIo7bJAQjEtskBCKmdygEI6PPKAQiTocsBCLm0zAEIkLzMAQjUvMwBCPTAzAEIm8HMAQiywcwBCMXBzAEI1sHMAQjcxMwBCN/EzAEI1sbMAQidycwBCOPLzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8Cookie: CONSENT=PENDING+605; AEC=ARSKqsLf93qkGcXLgjc6TtVyNdibUWvHrhH1XKQc2B0L9uF7P0CyJ_n74Q; SOCS=CAISHAgBEhJnd3NfMjAyMzAxMTgtMF9SQzEaAmVuIAEaBgiA4sGeBg; NID=511=lhcqvASiDCO0DxZodcjlI6Ue9orYswUE8f7gKzLn_y1iAmcC7yPcUyJCzWUgV3pzof4UWqx9ONQ5GIrhYGNE0bjIeifCg6kTSRel7Hy66LJITNJHw7i1iThpWUtVQym0cJmjWOHVdyjs23AgDrapDyuK_Gqnw
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Wed, 25 Jan 2023 08:43:25 GMTContent-Type: text/html; charset=UTF-8Content-Length: 59Connection: closeLast-Modified: Wed, 25 Jan 2023 03:40:04 GMTETag: "3b-5f30e6349b9f2"Accept-Ranges: bytes
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Wed, 25 Jan 2023 08:43:26 GMTContent-Type: text/html; charset=UTF-8Content-Length: 59Connection: closeLast-Modified: Wed, 25 Jan 2023 03:40:04 GMTETag: "3b-5f30e6349b9f2"Accept-Ranges: bytes
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: unknownHTTPS traffic detected: 142.250.203.100:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: classification engineClassification label: clean0.win@26/0@11/10
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1972 --field-trial-handle=1772,i,13714808044369432181,11901859910510463980,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://listfoo.org/zmg5f
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1972 --field-trial-handle=1772,i,13714808044369432181,11901859910510463980,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Accept
Source: C:\Program Files\Google\Chrome\Application\chrome.exeAutomated click: Accept
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://listfoo.org/zmg5f0%VirustotalBrowse
https://listfoo.org/zmg5f0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://listfoo.org/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
172.217.168.14
truefalse
    high
    consent.google.com
    216.58.215.238
    truefalse
      high
      accounts.google.com
      142.250.203.109
      truefalse
        high
        plus.l.google.com
        172.217.168.78
        truefalse
          high
          listfoo.org
          185.180.199.229
          truefalse
            unknown
            www.google.com
            142.250.203.100
            truefalse
              high
              clients.l.google.com
              142.250.203.110
              truefalse
                high
                clients2.google.com
                unknown
                unknownfalse
                  high
                  apis.google.com
                  unknown
                  unknownfalse
                    high
                    NameMaliciousAntivirus DetectionReputation
                    https://www.google.com/gen_204?atyp=i&ct=bxjs&cad=&b=0&ei=ruvQY6uHDeSP9u8PlpqO-Ak&zx=1674636206145false
                      high
                      https://www.google.com/false
                        high
                        https://www.google.com/manifest?pwa=webhpfalse
                          high
                          https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                            high
                            https://www.google.com/gen_204?s=webhp&t=aft&atyp=csi&ei=ruvQY6uHDeSP9u8PlpqO-Ak&rt=wsrt.486,aft.423,afti.423,prt.322&wh=913&imn=3&ima=3&imad=0&imac=0&aftp=913&bl=m-wtfalse
                              high
                              https://www.google.com/client_204?cs=1false
                                high
                                https://www.google.com/images/branding/googlelogo/1x/googlelogo_color_272x92dp.pngfalse
                                  high
                                  https://www.google.com/gen_204?atyp=i&ct=bxjs&cad=&b=1&ei=ruvQY6uHDeSP9u8PlpqO-Ak&zx=1674636232161false
                                    high
                                    https://listfoo.org/zmg5ffalse
                                      unknown
                                      https://www.google.com/gen_204?atyp=csi&ei=ruvQY6uHDeSP9u8PlpqO-Ak&s=webhp&t=all&bl=m-wt&wh=913&imn=3&ima=3&imad=0&imac=0&aftp=913&adh=&ime=3&imex=3&imeh=0&imea=0&imeb=0&imel=0&scp=0&net=dl.1300,ect.4g,rtt.100&mem=ujhs.10,tjhs.11,jhsl.2173,dm.8&sys=hc.4&rt=aft.423,afti.423,prt.322,dcl.327,aftqf.424,ol.904,xjsls.26226,xjses.26870,xjsee.26920,xjs.26921,lcp.356,fcp.193,wsrt.486,cst.75,dnst.32,rqst.232,rspt.116,sslt.75,rqstt.370,unt.257,cstt.295,dit.813&zx=1674636232860false
                                        high
                                        https://apis.google.com/_/scs/abc-static/_/js/k=gapi.gapi.en.WEPncdil2Uw.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-eOecLLtOXEl3I3kIuMsKXRkDMmA/cb=gapi.loaded_0false
                                          high
                                          https://www.google.com/gen_204?atyp=i&ei=ruvQY6uHDeSP9u8PlpqO-Ak&dt19=2&zx=1674636233492false
                                            high
                                            https://www.google.com/xjs/_/js/k=xjs.s.en_GB.zobC7UqdsqU.O/ck=xjs.s.F0fY5Pm-eS0.L.W.O/am=AAEqCFcAOAAAQAAAAAAkIAAAAAAAAgAwBkDwlA0I2BAOEIMBsCwBIAAgiNEPEQAABgADGBYABAAAAED-AAQ8AQCDCQsAAAAAAAAAELAEweAGCQoCQAAAAAAAAACU0uTFASAIAgAAAQ/d=1/exm=cdos,csi,d,dpf,hsm,jsa/ed=1/dg=2/br=1/rs=ACT90oHWjJk68F8W9qa5QTlNuGD_7xu0jA/ee=Pjplud:PoEs9b;QGR0gd:Mlhmy;uY49fb:COQbmf;EVNhjf:pw70Gc;sTsDMc:kHVSUb;g8nkx:U4MzKc;wQlYve:aLUfP;kbAm9d:MkHyGd;F9mqte:UoRcbe;oUlnpc:RagDlc;YV5bee:IvPZ6d;dtl0hd:lLQWFe;yGxLoc:FmAr0c;dIoSBb:ZgGg9b;pXdRYb:JKoKVe;wR5FRb:TtcOte;KpRAue:Tia57b;aZ61od:arTwJ;JXS8fb:Qj0suc;rQSrae:C6D5Fc;qavrXe:zQzcXe;UDrY1c:eps46d;w3bZCb:ZPGaIb;VGRfx:VFqbr;imqimf:jKGL2e;Np8Qkd:Dpx6qc;BjwMce:cXX2Wb;oGtAuc:sOXFj;NPKaK:PVlQOd;EmZ2Bf:zr1jrb;daB6be:lMxGPd;Fmv9Nc:O1Tzwc;hK67qb:QWEO5b;R4IIIb:QWfeKf;BMxAGc:E5bFse;WDGyFe:jcVOxd;wV5Pjc:L8KGxe;xbe2wc:wbTLEd;DpcR3d:zL72xf;tosKvd:ZCqP3;ESrPQc:mNTJvc;NSEoX:lazG7b;G6wU6e:hezEbd;kCQyJ:ueyPK;okUaUd:wItadb;GleZL:J1A7Od;Xeq57c:wZTUNc;eJZqRc:wUwbse;RiX1h:uiAbXc;oSUNyd:fTfGO;SJsSc:H1GVub;SMDL4c:fTfGO;JsbNhc:Xd8iUd;zOsCQe:Ko78Df;KcokUb:KiuZBf;WCEKNd:I46Hvd;LBgRLc:XVMNvd;LsNahb:ucGLNb;UyG7Kb:wQd0G;TxfV6d:YORN0b;qaS3gd:yiLg6e;aAJE9c:WHW6Ef;BgS6mb:fidj5d;UVmjEd:EesRsb;z97YGf:oug9te;CxXAWb:YyRLvc;VN6jIc:ddQyuf;SLtqO:Kh1xYe;VxQ32b:k0XsBb;DULqB:RKfG5c;bcPXSc:gSZLJb;cFTWae:gT8qnd;gaub4:TN6bMe;hjRo6e:F62sG;whEZac:F4AmNb;qddgKe:x4FYXe;eBAeSb:Ck63tb;vfVwPd:OXTqFb;w9w86d:dt4g2b;lkq0A:Z0MWEf;KQzWid:mB4wNe;pNsl2d:j9Yuyc;eHDfl:ofjVkb;Nyt6ic:jn2sGd;SNUn3:x8cHvb;LEikZe:byfTOb,lsjVmc;io8t5d:sgY6Zb;Oj465e:KG2eXe;sP4Vbe:VwDzFe;kMFpHd:OTA3Ae;nAFL3:s39S4;iFQyKf:QIhFr/m=DhPYme,EkevXb,GU4Gab,MpJwZc,NzU6V,UUJqVe,aa,abd,async,epYOx,pHXghd,q0xTif,s39S4,sOXFj,sb_wiz,sf,sonic,spch?xjs=s1false
                                              high
                                              https://www.google.com/xjs/_/js/k=xjs.s.en_GB.zobC7UqdsqU.O/ck=xjs.s.F0fY5Pm-eS0.L.W.O/am=AAEqCFcAOAAAQAAAAAAkIAAAAAAAAgAwBkDwlA0I2BAOEIMBsCwBIAAgiNEPEQAABgADGBYABAAAAED-AAQ8AQCDCQsAAAAAAAAAELAEweAGCQoCQAAAAAAAAACU0uTFASAIAgAAAQ/d=1/exm=CnSW2d,DPreE,DhPYme,EkevXb,GU4Gab,MpJwZc,NzU6V,UUJqVe,WlNQGd,aa,abd,async,cdos,csi,d,dpf,epYOx,fXO0xe,hsm,jsa,kQvlef,nabPbb,pHXghd,q0xTif,s39S4,sOXFj,sb_wiz,sf,sonic,spch/ed=1/dg=2/br=1/rs=ACT90oHWjJk68F8W9qa5QTlNuGD_7xu0jA/ee=Pjplud:PoEs9b;QGR0gd:Mlhmy;uY49fb:COQbmf;EVNhjf:pw70Gc;sTsDMc:kHVSUb;g8nkx:U4MzKc;wQlYve:aLUfP;kbAm9d:MkHyGd;F9mqte:UoRcbe;oUlnpc:RagDlc;YV5bee:IvPZ6d;dtl0hd:lLQWFe;yGxLoc:FmAr0c;dIoSBb:ZgGg9b;pXdRYb:JKoKVe;wR5FRb:TtcOte;KpRAue:Tia57b;aZ61od:arTwJ;JXS8fb:Qj0suc;rQSrae:C6D5Fc;qavrXe:zQzcXe;UDrY1c:eps46d;w3bZCb:ZPGaIb;VGRfx:VFqbr;imqimf:jKGL2e;Np8Qkd:Dpx6qc;BjwMce:cXX2Wb;oGtAuc:sOXFj;NPKaK:PVlQOd;EmZ2Bf:zr1jrb;daB6be:lMxGPd;Fmv9Nc:O1Tzwc;hK67qb:QWEO5b;R4IIIb:QWfeKf;BMxAGc:E5bFse;WDGyFe:jcVOxd;wV5Pjc:L8KGxe;xbe2wc:wbTLEd;DpcR3d:zL72xf;tosKvd:ZCqP3;ESrPQc:mNTJvc;NSEoX:lazG7b;G6wU6e:hezEbd;kCQyJ:ueyPK;okUaUd:wItadb;GleZL:J1A7Od;Xeq57c:wZTUNc;eJZqRc:wUwbse;RiX1h:uiAbXc;oSUNyd:fTfGO;SJsSc:H1GVub;SMDL4c:fTfGO;JsbNhc:Xd8iUd;zOsCQe:Ko78Df;KcokUb:KiuZBf;WCEKNd:I46Hvd;LBgRLc:XVMNvd;LsNahb:ucGLNb;UyG7Kb:wQd0G;TxfV6d:YORN0b;qaS3gd:yiLg6e;aAJE9c:WHW6Ef;BgS6mb:fidj5d;UVmjEd:EesRsb;z97YGf:oug9te;CxXAWb:YyRLvc;VN6jIc:ddQyuf;SLtqO:Kh1xYe;VxQ32b:k0XsBb;DULqB:RKfG5c;bcPXSc:gSZLJb;cFTWae:gT8qnd;gaub4:TN6bMe;hjRo6e:F62sG;whEZac:F4AmNb;qddgKe:x4FYXe;eBAeSb:Ck63tb;vfVwPd:OXTqFb;w9w86d:dt4g2b;lkq0A:Z0MWEf;KQzWid:mB4wNe;pNsl2d:j9Yuyc;eHDfl:ofjVkb;Nyt6ic:jn2sGd;SNUn3:x8cHvb;LEikZe:byfTOb,lsjVmc;io8t5d:sgY6Zb;Oj465e:KG2eXe;sP4Vbe:VwDzFe;kMFpHd:OTA3Ae;nAFL3:s39S4;iFQyKf:QIhFr/m=aLUfP?xjs=s2false
                                                high
                                                https://www.google.com/favicon.icofalse
                                                  high
                                                  https://google.com/false
                                                    high
                                                    https://www.google.com/images/branding/googlelogo/2x/googlelogo_color_272x92dp.pngfalse
                                                      high
                                                      https://listfoo.org/favicon.icofalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      https://www.google.com/xjs/_/js/k=xjs.s.en_GB.zobC7UqdsqU.O/ck=xjs.s.F0fY5Pm-eS0.L.W.O/am=AAEqCFcAOAAAQAAAAAAkIAAAAAAAAgAwBkDwlA0I2BAOEIMBsCwBIAAgiNEPEQAABgADGBYABAAAAED-AAQ8AQCDCQsAAAAAAAAAELAEweAGCQoCQAAAAAAAAACU0uTFASAIAgAAAQ/d=1/exm=DhPYme,EkevXb,GU4Gab,MpJwZc,NzU6V,UUJqVe,aa,abd,async,cdos,csi,d,dpf,epYOx,hsm,jsa,pHXghd,q0xTif,s39S4,sOXFj,sb_wiz,sf,sonic,spch/ed=1/dg=2/br=1/rs=ACT90oHWjJk68F8W9qa5QTlNuGD_7xu0jA/ee=Pjplud:PoEs9b;QGR0gd:Mlhmy;uY49fb:COQbmf;EVNhjf:pw70Gc;sTsDMc:kHVSUb;g8nkx:U4MzKc;wQlYve:aLUfP;kbAm9d:MkHyGd;F9mqte:UoRcbe;oUlnpc:RagDlc;YV5bee:IvPZ6d;dtl0hd:lLQWFe;yGxLoc:FmAr0c;dIoSBb:ZgGg9b;pXdRYb:JKoKVe;wR5FRb:TtcOte;KpRAue:Tia57b;aZ61od:arTwJ;JXS8fb:Qj0suc;rQSrae:C6D5Fc;qavrXe:zQzcXe;UDrY1c:eps46d;w3bZCb:ZPGaIb;VGRfx:VFqbr;imqimf:jKGL2e;Np8Qkd:Dpx6qc;BjwMce:cXX2Wb;oGtAuc:sOXFj;NPKaK:PVlQOd;EmZ2Bf:zr1jrb;daB6be:lMxGPd;Fmv9Nc:O1Tzwc;hK67qb:QWEO5b;R4IIIb:QWfeKf;BMxAGc:E5bFse;WDGyFe:jcVOxd;wV5Pjc:L8KGxe;xbe2wc:wbTLEd;DpcR3d:zL72xf;tosKvd:ZCqP3;ESrPQc:mNTJvc;NSEoX:lazG7b;G6wU6e:hezEbd;kCQyJ:ueyPK;okUaUd:wItadb;GleZL:J1A7Od;Xeq57c:wZTUNc;eJZqRc:wUwbse;RiX1h:uiAbXc;oSUNyd:fTfGO;SJsSc:H1GVub;SMDL4c:fTfGO;JsbNhc:Xd8iUd;zOsCQe:Ko78Df;KcokUb:KiuZBf;WCEKNd:I46Hvd;LBgRLc:XVMNvd;LsNahb:ucGLNb;UyG7Kb:wQd0G;TxfV6d:YORN0b;qaS3gd:yiLg6e;aAJE9c:WHW6Ef;BgS6mb:fidj5d;UVmjEd:EesRsb;z97YGf:oug9te;CxXAWb:YyRLvc;VN6jIc:ddQyuf;SLtqO:Kh1xYe;VxQ32b:k0XsBb;DULqB:RKfG5c;bcPXSc:gSZLJb;cFTWae:gT8qnd;gaub4:TN6bMe;hjRo6e:F62sG;whEZac:F4AmNb;qddgKe:x4FYXe;eBAeSb:Ck63tb;vfVwPd:OXTqFb;w9w86d:dt4g2b;lkq0A:Z0MWEf;KQzWid:mB4wNe;pNsl2d:j9Yuyc;eHDfl:ofjVkb;Nyt6ic:jn2sGd;SNUn3:x8cHvb;LEikZe:byfTOb,lsjVmc;io8t5d:sgY6Zb;Oj465e:KG2eXe;sP4Vbe:VwDzFe;kMFpHd:OTA3Ae;nAFL3:s39S4;iFQyKf:QIhFr/m=CnSW2d,DPreE,WlNQGd,fXO0xe,kQvlef,nabPbb?xjs=s2false
                                                        high
                                                        https://www.google.com/xjs/_/js/md=1/k=xjs.s.en_GB.zobC7UqdsqU.O/am=AAEqCFcAOAAAQAAAAAAkIAAAAAAAAgAwBkDwlA0I2BAOEIMBsCwBIAAgiNEPEQAABgADGBYABAAAAED-AAQ8AQCDCQsAAAAAAAAAELAEweAGCQoCQAAAAAAAAACU0uTFASAIAgAAAQ/rs=ACT90oFLXSotrQJhVFHbtpFxrnCGNSmSlQfalse
                                                          high
                                                          https://www.google.com/gen_204?ei=ruvQY6uHDeSP9u8PlpqO-Ak&ved=0ahUKEwirlsyBquL8AhXkh_0HHRaNA58QiZAHCCA&uact=3false
                                                            high
                                                            https://consent.google.com/save?continue=https://www.google.com/&gl=HR&m=0&pc=shp&x=5&src=2&hl=en&bl=gws_20230118-0_RC1&uxe=none&set_eom=false&set_aps=true&set_sc=truefalse
                                                              high
                                                              https://www.google.com/images/searchbox/desktop_searchbox_sprites318_hr.webpfalse
                                                                high
                                                                https://www.google.com/complete/search?q&cp=0&client=gws-wiz&xssi=t&hl=en-HR&authuser=0&psi=ruvQY6uHDeSP9u8PlpqO-Ak.1674636232907&nolsbt=1&dpr=1false
                                                                  high
                                                                  https://www.google.com/gen_204?atyp=csi&ei=ruvQY6uHDeSP9u8PlpqO-Ak&s=webhp&st=20420&fid=1&t=fi&zx=1674636232867false
                                                                    high
                                                                    https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                                                                      high
                                                                      https://www.google.com/client_204?&atyp=i&biw=1280&bih=913&ei=ruvQY6uHDeSP9u8PlpqO-Akfalse
                                                                        high
                                                                        https://www.google.com/gen_204?ei=ruvQY6uHDeSP9u8PlpqO-Ak&vet=10ahUKEwirlsyBquL8AhXkh_0HHRaNA58QhJAHCBk..s&gl=HR&pc=SEARCH_HOMEPAGE&isMobile=falsefalse
                                                                          high
                                                                          https://www.google.com/gen_204?ei=ruvQY6uHDeSP9u8PlpqO-Ak&vet=10ahUKEwirlsyBquL8AhXkh_0HHRaNA58QhJAHCBk..h&va=26014false
                                                                            high
                                                                            https://www.google.com/false
                                                                              high
                                                                              https://www.google.com/xjs/_/js/k=xjs.s.en_GB.zobC7UqdsqU.O/am=AAEqCFcAOAAAQAAAAAAkIAAAAAAAAgAwBkDwlA0I2BAOEIMBsCwBIAAgiNEPEQAABgADGBYABAAAAED-AAQ8AQCDCQsAAAAAAAAAELAEweAGCQoCQAAAAAAAAACU0uTFASAIAgAAAQ/d=1/ed=1/dg=2/br=1/rs=ACT90oFLXSotrQJhVFHbtpFxrnCGNSmSlQ/m=cdos,dpf,hsm,jsa,d,csifalse
                                                                                high
                                                                                • No. of IPs < 25%
                                                                                • 25% < No. of IPs < 50%
                                                                                • 50% < No. of IPs < 75%
                                                                                • 75% < No. of IPs
                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                216.58.215.238
                                                                                consent.google.comUnited States
                                                                                15169GOOGLEUSfalse
                                                                                142.250.203.100
                                                                                www.google.comUnited States
                                                                                15169GOOGLEUSfalse
                                                                                185.180.199.229
                                                                                listfoo.orgNetherlands
                                                                                14576HOSTING-SOLUTIONSUSfalse
                                                                                142.250.203.110
                                                                                clients.l.google.comUnited States
                                                                                15169GOOGLEUSfalse
                                                                                172.217.168.78
                                                                                plus.l.google.comUnited States
                                                                                15169GOOGLEUSfalse
                                                                                172.217.168.14
                                                                                google.comUnited States
                                                                                15169GOOGLEUSfalse
                                                                                239.255.255.250
                                                                                unknownReserved
                                                                                unknownunknownfalse
                                                                                142.250.203.109
                                                                                accounts.google.comUnited States
                                                                                15169GOOGLEUSfalse
                                                                                IP
                                                                                192.168.2.1
                                                                                127.0.0.1
                                                                                Joe Sandbox Version:36.0.0 Rainbow Opal
                                                                                Analysis ID:791296
                                                                                Start date and time:2023-01-25 09:42:25 +01:00
                                                                                Joe Sandbox Product:CloudBasic
                                                                                Overall analysis duration:0h 4m 2s
                                                                                Hypervisor based Inspection enabled:false
                                                                                Report type:light
                                                                                Cookbook file name:browseurl.jbs
                                                                                Sample URL:https://listfoo.org/zmg5f
                                                                                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                Number of analysed new started processes analysed:12
                                                                                Number of new started drivers analysed:0
                                                                                Number of existing processes analysed:0
                                                                                Number of existing drivers analysed:0
                                                                                Number of injected processes analysed:0
                                                                                Technologies:
                                                                                • HCA enabled
                                                                                • EGA enabled
                                                                                • HDC enabled
                                                                                • AMSI enabled
                                                                                Analysis Mode:default
                                                                                Analysis stop reason:Timeout
                                                                                Detection:CLEAN
                                                                                Classification:clean0.win@26/0@11/10
                                                                                EGA Information:Failed
                                                                                HDC Information:Failed
                                                                                HCA Information:
                                                                                • Successful, ratio: 100%
                                                                                • Number of executed functions: 0
                                                                                • Number of non-executed functions: 0
                                                                                Cookbook Comments:
                                                                                • Browse: https://mail.google.com/mail/&ogbl
                                                                                • Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
                                                                                • TCP Packets have been reduced to 100
                                                                                • Excluded IPs from analysis (whitelisted): 142.250.203.99, 34.104.35.123, 172.217.168.74, 142.250.203.106, 216.58.215.234
                                                                                • Excluded domains from analysis (whitelisted): ris.api.iris.microsoft.com, edgedl.me.gvt1.com, content-autofill.googleapis.com, login.live.com, eudb.ris.api.iris.microsoft.com, fonts.gstatic.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, img-prod-cms-rt-microsoft-com.akamaized.net, www.gstatic.com, arc.msn.com
                                                                                • Not all processes where analyzed, report is missing behavior information
                                                                                • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                                No simulations
                                                                                No context
                                                                                No context
                                                                                No context
                                                                                No context
                                                                                No context
                                                                                No created / dropped files found
                                                                                No static file info
                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                Jan 25, 2023 09:43:23.907602072 CET49704443192.168.2.4142.250.203.110
                                                                                Jan 25, 2023 09:43:23.907681942 CET44349704142.250.203.110192.168.2.4
                                                                                Jan 25, 2023 09:43:23.907773972 CET49704443192.168.2.4142.250.203.110
                                                                                Jan 25, 2023 09:43:23.908062935 CET49705443192.168.2.4142.250.203.109
                                                                                Jan 25, 2023 09:43:23.908127069 CET44349705142.250.203.109192.168.2.4
                                                                                Jan 25, 2023 09:43:23.908193111 CET49705443192.168.2.4142.250.203.109
                                                                                Jan 25, 2023 09:43:23.909796000 CET49704443192.168.2.4142.250.203.110
                                                                                Jan 25, 2023 09:43:23.909835100 CET44349704142.250.203.110192.168.2.4
                                                                                Jan 25, 2023 09:43:23.911474943 CET49705443192.168.2.4142.250.203.109
                                                                                Jan 25, 2023 09:43:23.911506891 CET44349705142.250.203.109192.168.2.4
                                                                                Jan 25, 2023 09:43:24.020153046 CET44349704142.250.203.110192.168.2.4
                                                                                Jan 25, 2023 09:43:24.024331093 CET44349705142.250.203.109192.168.2.4
                                                                                Jan 25, 2023 09:43:24.061716080 CET49704443192.168.2.4142.250.203.110
                                                                                Jan 25, 2023 09:43:24.065656900 CET49705443192.168.2.4142.250.203.109
                                                                                Jan 25, 2023 09:43:24.183048010 CET49705443192.168.2.4142.250.203.109
                                                                                Jan 25, 2023 09:43:24.183094978 CET44349705142.250.203.109192.168.2.4
                                                                                Jan 25, 2023 09:43:24.183289051 CET49704443192.168.2.4142.250.203.110
                                                                                Jan 25, 2023 09:43:24.183329105 CET44349704142.250.203.110192.168.2.4
                                                                                Jan 25, 2023 09:43:24.185353994 CET44349704142.250.203.110192.168.2.4
                                                                                Jan 25, 2023 09:43:24.185482979 CET49704443192.168.2.4142.250.203.110
                                                                                Jan 25, 2023 09:43:24.186855078 CET44349705142.250.203.109192.168.2.4
                                                                                Jan 25, 2023 09:43:24.186943054 CET49705443192.168.2.4142.250.203.109
                                                                                Jan 25, 2023 09:43:24.187645912 CET44349704142.250.203.110192.168.2.4
                                                                                Jan 25, 2023 09:43:24.187722921 CET49704443192.168.2.4142.250.203.110
                                                                                Jan 25, 2023 09:43:25.366568089 CET49706443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:25.366636038 CET44349706185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:25.366767883 CET49706443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:25.367397070 CET49705443192.168.2.4142.250.203.109
                                                                                Jan 25, 2023 09:43:25.367418051 CET44349705142.250.203.109192.168.2.4
                                                                                Jan 25, 2023 09:43:25.367835999 CET44349705142.250.203.109192.168.2.4
                                                                                Jan 25, 2023 09:43:25.368930101 CET49706443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:25.368976116 CET44349706185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:25.369982004 CET49704443192.168.2.4142.250.203.110
                                                                                Jan 25, 2023 09:43:25.370057106 CET44349704142.250.203.110192.168.2.4
                                                                                Jan 25, 2023 09:43:25.370682955 CET44349704142.250.203.110192.168.2.4
                                                                                Jan 25, 2023 09:43:25.371494055 CET49705443192.168.2.4142.250.203.109
                                                                                Jan 25, 2023 09:43:25.371515036 CET44349705142.250.203.109192.168.2.4
                                                                                Jan 25, 2023 09:43:25.371959925 CET49704443192.168.2.4142.250.203.110
                                                                                Jan 25, 2023 09:43:25.371999025 CET44349704142.250.203.110192.168.2.4
                                                                                Jan 25, 2023 09:43:25.411290884 CET44349704142.250.203.110192.168.2.4
                                                                                Jan 25, 2023 09:43:25.411470890 CET49704443192.168.2.4142.250.203.110
                                                                                Jan 25, 2023 09:43:25.411539078 CET44349704142.250.203.110192.168.2.4
                                                                                Jan 25, 2023 09:43:25.411586046 CET44349704142.250.203.110192.168.2.4
                                                                                Jan 25, 2023 09:43:25.411679029 CET49704443192.168.2.4142.250.203.110
                                                                                Jan 25, 2023 09:43:25.445579052 CET44349705142.250.203.109192.168.2.4
                                                                                Jan 25, 2023 09:43:25.445696115 CET49705443192.168.2.4142.250.203.109
                                                                                Jan 25, 2023 09:43:25.445719957 CET44349705142.250.203.109192.168.2.4
                                                                                Jan 25, 2023 09:43:25.445899010 CET44349705142.250.203.109192.168.2.4
                                                                                Jan 25, 2023 09:43:25.445983887 CET49705443192.168.2.4142.250.203.109
                                                                                Jan 25, 2023 09:43:25.503937960 CET49705443192.168.2.4142.250.203.109
                                                                                Jan 25, 2023 09:43:25.503981113 CET44349705142.250.203.109192.168.2.4
                                                                                Jan 25, 2023 09:43:25.505192041 CET49704443192.168.2.4142.250.203.110
                                                                                Jan 25, 2023 09:43:25.505253077 CET44349704142.250.203.110192.168.2.4
                                                                                Jan 25, 2023 09:43:25.594564915 CET44349706185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:25.625833035 CET49706443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:25.625906944 CET44349706185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:25.628380060 CET44349706185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:25.628463984 CET49706443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:25.681019068 CET49706443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:25.681056976 CET44349706185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:25.681278944 CET44349706185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:25.681668997 CET49706443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:25.681696892 CET44349706185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:25.747380972 CET44349706185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:25.747494936 CET49706443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:25.752106905 CET49706443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:25.752141953 CET44349706185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:25.898211956 CET49707443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:25.898288012 CET44349707185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:25.898396015 CET49707443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:25.898858070 CET49707443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:25.898901939 CET44349707185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:25.916371107 CET49708443192.168.2.4172.217.168.14
                                                                                Jan 25, 2023 09:43:25.916464090 CET44349708172.217.168.14192.168.2.4
                                                                                Jan 25, 2023 09:43:25.916610956 CET49708443192.168.2.4172.217.168.14
                                                                                Jan 25, 2023 09:43:25.922799110 CET49708443192.168.2.4172.217.168.14
                                                                                Jan 25, 2023 09:43:25.922852993 CET44349708172.217.168.14192.168.2.4
                                                                                Jan 25, 2023 09:43:25.985939026 CET44349708172.217.168.14192.168.2.4
                                                                                Jan 25, 2023 09:43:25.996577024 CET49708443192.168.2.4172.217.168.14
                                                                                Jan 25, 2023 09:43:25.996627092 CET44349708172.217.168.14192.168.2.4
                                                                                Jan 25, 2023 09:43:25.997574091 CET44349708172.217.168.14192.168.2.4
                                                                                Jan 25, 2023 09:43:25.997658968 CET49708443192.168.2.4172.217.168.14
                                                                                Jan 25, 2023 09:43:25.998918056 CET44349708172.217.168.14192.168.2.4
                                                                                Jan 25, 2023 09:43:25.998984098 CET49708443192.168.2.4172.217.168.14
                                                                                Jan 25, 2023 09:43:26.000960112 CET49708443192.168.2.4172.217.168.14
                                                                                Jan 25, 2023 09:43:26.000996113 CET44349708172.217.168.14192.168.2.4
                                                                                Jan 25, 2023 09:43:26.001152992 CET44349708172.217.168.14192.168.2.4
                                                                                Jan 25, 2023 09:43:26.001674891 CET49708443192.168.2.4172.217.168.14
                                                                                Jan 25, 2023 09:43:26.001723051 CET44349708172.217.168.14192.168.2.4
                                                                                Jan 25, 2023 09:43:26.028537035 CET44349707185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:26.030111074 CET49707443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:26.030160904 CET44349707185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:26.031291008 CET44349707185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:26.031903982 CET49707443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:26.031945944 CET44349707185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:26.032047033 CET49707443192.168.2.4185.180.199.229
                                                                                Jan 25, 2023 09:43:26.032061100 CET44349707185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:26.032116890 CET44349707185.180.199.229192.168.2.4
                                                                                Jan 25, 2023 09:43:26.041414022 CET44349708172.217.168.14192.168.2.4
                                                                                Jan 25, 2023 09:43:26.041522026 CET49708443192.168.2.4172.217.168.14
                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                Jan 25, 2023 09:43:23.711551905 CET6416753192.168.2.48.8.8.8
                                                                                Jan 25, 2023 09:43:23.711925983 CET5856553192.168.2.48.8.8.8
                                                                                Jan 25, 2023 09:43:23.737365961 CET53641678.8.8.8192.168.2.4
                                                                                Jan 25, 2023 09:43:23.738249063 CET53585658.8.8.8192.168.2.4
                                                                                Jan 25, 2023 09:43:23.835452080 CET5680753192.168.2.48.8.8.8
                                                                                Jan 25, 2023 09:43:23.882839918 CET53568078.8.8.8192.168.2.4
                                                                                Jan 25, 2023 09:43:25.876192093 CET6112453192.168.2.48.8.8.8
                                                                                Jan 25, 2023 09:43:25.895842075 CET53611248.8.8.8192.168.2.4
                                                                                Jan 25, 2023 09:43:26.088342905 CET5557053192.168.2.48.8.8.8
                                                                                Jan 25, 2023 09:43:26.114576101 CET53555708.8.8.8192.168.2.4
                                                                                Jan 25, 2023 09:43:27.011023045 CET5872953192.168.2.48.8.8.8
                                                                                Jan 25, 2023 09:43:27.038729906 CET53587298.8.8.8192.168.2.4
                                                                                Jan 25, 2023 09:43:27.238797903 CET6470053192.168.2.48.8.8.8
                                                                                Jan 25, 2023 09:43:27.258802891 CET53647008.8.8.8192.168.2.4
                                                                                Jan 25, 2023 09:43:29.870573997 CET6055053192.168.2.48.8.8.8
                                                                                Jan 25, 2023 09:43:29.898292065 CET53605508.8.8.8192.168.2.4
                                                                                Jan 25, 2023 09:43:52.546322107 CET5141953192.168.2.48.8.8.8
                                                                                Jan 25, 2023 09:43:52.573548079 CET53514198.8.8.8192.168.2.4
                                                                                Jan 25, 2023 09:44:27.441205978 CET6513353192.168.2.48.8.8.8
                                                                                Jan 25, 2023 09:44:27.461000919 CET53651338.8.8.8192.168.2.4
                                                                                Jan 25, 2023 09:44:27.500570059 CET6099853192.168.2.48.8.8.8
                                                                                Jan 25, 2023 09:44:27.520157099 CET53609988.8.8.8192.168.2.4
                                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                Jan 25, 2023 09:43:23.711551905 CET192.168.2.48.8.8.80x88f4Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:23.711925983 CET192.168.2.48.8.8.80x4787Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:23.835452080 CET192.168.2.48.8.8.80x51e3Standard query (0)listfoo.orgA (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:25.876192093 CET192.168.2.48.8.8.80xe9c3Standard query (0)google.comA (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:26.088342905 CET192.168.2.48.8.8.80x5681Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:27.011023045 CET192.168.2.48.8.8.80xcc03Standard query (0)apis.google.comA (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:27.238797903 CET192.168.2.48.8.8.80xeb89Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:29.870573997 CET192.168.2.48.8.8.80x931eStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:52.546322107 CET192.168.2.48.8.8.80x5baaStandard query (0)consent.google.comA (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:44:27.441205978 CET192.168.2.48.8.8.80xa820Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:44:27.500570059 CET192.168.2.48.8.8.80x432fStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                Jan 25, 2023 09:43:23.737365961 CET8.8.8.8192.168.2.40x88f4No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:23.737365961 CET8.8.8.8192.168.2.40x88f4No error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:23.738249063 CET8.8.8.8192.168.2.40x4787No error (0)accounts.google.com142.250.203.109A (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:23.882839918 CET8.8.8.8192.168.2.40x51e3No error (0)listfoo.org185.180.199.229A (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:25.895842075 CET8.8.8.8192.168.2.40xe9c3No error (0)google.com172.217.168.14A (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:26.114576101 CET8.8.8.8192.168.2.40x5681No error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:27.038729906 CET8.8.8.8192.168.2.40xcc03No error (0)apis.google.complus.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:27.038729906 CET8.8.8.8192.168.2.40xcc03No error (0)plus.l.google.com172.217.168.78A (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:27.258802891 CET8.8.8.8192.168.2.40xeb89No error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:29.898292065 CET8.8.8.8192.168.2.40x931eNo error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:43:52.573548079 CET8.8.8.8192.168.2.40x5baaNo error (0)consent.google.com216.58.215.238A (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:44:27.461000919 CET8.8.8.8192.168.2.40xa820No error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                                                                                Jan 25, 2023 09:44:27.520157099 CET8.8.8.8192.168.2.40x432fNo error (0)www.google.com142.250.203.100A (IP address)IN (0x0001)false
                                                                                • accounts.google.com
                                                                                • clients2.google.com
                                                                                • listfoo.org
                                                                                • https:
                                                                                  • google.com
                                                                                  • www.google.com
                                                                                  • apis.google.com
                                                                                  • consent.google.com

                                                                                Click to jump to process

                                                                                Target ID:0
                                                                                Start time:09:43:20
                                                                                Start date:25/01/2023
                                                                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                Wow64 process (32bit):false
                                                                                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                                                                Imagebase:0x7ff683680000
                                                                                File size:2851656 bytes
                                                                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Reputation:low

                                                                                Target ID:1
                                                                                Start time:09:43:21
                                                                                Start date:25/01/2023
                                                                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                Wow64 process (32bit):false
                                                                                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1972 --field-trial-handle=1772,i,13714808044369432181,11901859910510463980,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                                                                Imagebase:0x7ff683680000
                                                                                File size:2851656 bytes
                                                                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Reputation:low

                                                                                Target ID:2
                                                                                Start time:09:43:22
                                                                                Start date:25/01/2023
                                                                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                Wow64 process (32bit):false
                                                                                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://listfoo.org/zmg5f
                                                                                Imagebase:0x7ff683680000
                                                                                File size:2851656 bytes
                                                                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Reputation:low

                                                                                No disassembly