Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://suzy_lamplugh@email.dhqbmail.co.uk

Overview

General Information

Sample URL:http://suzy_lamplugh@email.dhqbmail.co.uk
Analysis ID:800689
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

URL contains potential PII (phishing indication)

Classification

  • System is w10x64
  • chrome.exe (PID: 5504 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 4720 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1948 --field-trial-handle=1776,i,12988346674410521245,11443754851562044237,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 5268 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://suzy_lamplugh@email.dhqbmail.co.uk MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://suzy_lamplugh@email.dhqbmail.co.ukSample URL: PII: suzy_lamplugh@email.dhqbmail.co.uk
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __Secure-ENID=6.SE=Md0Ynyf9ahpkx1CxTGF0vY434NJ6ymH-gDI2Tl5Ly-NQYGPjnNfggtiFRMAwx4JRDOC_gavEPcD5cTBJzUgtbJobmBEuJ8xi2UuotxvOZgApoqSIg1b0RP47U08XG8Bz_SExSzKy0ETSsajbToDlYyFsxfI93p7AyRAd-OeIBA0; CONSENT=PENDING+070
Source: classification engineClassification label: unknown0.win@26/0@5/7
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1948 --field-trial-handle=1776,i,12988346674410521245,11443754851562044237,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://suzy_lamplugh@email.dhqbmail.co.uk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1948 --field-trial-handle=1776,i,12988346674410521245,11443754851562044237,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://suzy_lamplugh@email.dhqbmail.co.uk0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
216.58.209.45
truefalse
    high
    display-block.smtp.dnsrt.co.uk
    185.105.66.3
    truefalse
      unknown
      www.google.com
      142.250.184.100
      truefalse
        high
        clients.l.google.com
        142.250.180.174
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            email.dhqbmail.co.uk
            unknown
            unknownfalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  185.105.66.3
                  display-block.smtp.dnsrt.co.ukUnited Kingdom
                  16376SYSGROUP-PLCSysGroupPlcGBfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  216.58.209.45
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.184.100
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.180.174
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.1
                  127.0.0.1
                  Joe Sandbox Version:36.0.0 Rainbow Opal
                  Analysis ID:800689
                  Start date and time:2023-02-07 18:11:59 +01:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 3m 57s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://suzy_lamplugh@email.dhqbmail.co.uk
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:10
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:UNKNOWN
                  Classification:unknown0.win@26/0@5/7
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  Cookbook Comments:
                  • URL browsing timeout or error
                  • URL not reachable
                  • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.184.99, 34.104.35.123, 173.222.108.226, 173.222.108.147, 20.90.156.32
                  • Excluded domains from analysis (whitelisted): client.wns.windows.com, wns.notify.trafficmanager.net, fs.microsoft.com, edgedl.me.gvt1.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 7, 2023 18:13:08.977057934 CET49716443192.168.2.6142.250.180.174
                  Feb 7, 2023 18:13:08.977112055 CET44349716142.250.180.174192.168.2.6
                  Feb 7, 2023 18:13:08.977189064 CET49716443192.168.2.6142.250.180.174
                  Feb 7, 2023 18:13:08.977653980 CET49716443192.168.2.6142.250.180.174
                  Feb 7, 2023 18:13:08.977675915 CET44349716142.250.180.174192.168.2.6
                  Feb 7, 2023 18:13:08.991761923 CET49717443192.168.2.6216.58.209.45
                  Feb 7, 2023 18:13:08.991813898 CET44349717216.58.209.45192.168.2.6
                  Feb 7, 2023 18:13:08.991892099 CET49717443192.168.2.6216.58.209.45
                  Feb 7, 2023 18:13:08.992202997 CET49717443192.168.2.6216.58.209.45
                  Feb 7, 2023 18:13:08.992223024 CET44349717216.58.209.45192.168.2.6
                  Feb 7, 2023 18:13:08.994379044 CET4971880192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:08.994667053 CET4971980192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:09.021274090 CET49720443192.168.2.6142.250.184.100
                  Feb 7, 2023 18:13:09.021325111 CET44349720142.250.184.100192.168.2.6
                  Feb 7, 2023 18:13:09.021403074 CET49720443192.168.2.6142.250.184.100
                  Feb 7, 2023 18:13:09.021858931 CET49720443192.168.2.6142.250.184.100
                  Feb 7, 2023 18:13:09.021876097 CET44349720142.250.184.100192.168.2.6
                  Feb 7, 2023 18:13:09.067209005 CET44349717216.58.209.45192.168.2.6
                  Feb 7, 2023 18:13:09.067732096 CET49717443192.168.2.6216.58.209.45
                  Feb 7, 2023 18:13:09.067771912 CET44349717216.58.209.45192.168.2.6
                  Feb 7, 2023 18:13:09.069708109 CET44349717216.58.209.45192.168.2.6
                  Feb 7, 2023 18:13:09.069825888 CET49717443192.168.2.6216.58.209.45
                  Feb 7, 2023 18:13:09.083945990 CET44349716142.250.180.174192.168.2.6
                  Feb 7, 2023 18:13:09.091051102 CET44349720142.250.184.100192.168.2.6
                  Feb 7, 2023 18:13:09.103393078 CET4972180192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:09.103852987 CET49720443192.168.2.6142.250.184.100
                  Feb 7, 2023 18:13:09.103885889 CET44349720142.250.184.100192.168.2.6
                  Feb 7, 2023 18:13:09.104120016 CET49716443192.168.2.6142.250.180.174
                  Feb 7, 2023 18:13:09.104152918 CET44349716142.250.180.174192.168.2.6
                  Feb 7, 2023 18:13:09.105175972 CET44349720142.250.184.100192.168.2.6
                  Feb 7, 2023 18:13:09.105264902 CET49720443192.168.2.6142.250.184.100
                  Feb 7, 2023 18:13:09.106584072 CET44349716142.250.180.174192.168.2.6
                  Feb 7, 2023 18:13:09.106652975 CET49716443192.168.2.6142.250.180.174
                  Feb 7, 2023 18:13:09.108134031 CET44349716142.250.180.174192.168.2.6
                  Feb 7, 2023 18:13:09.108233929 CET49716443192.168.2.6142.250.180.174
                  Feb 7, 2023 18:13:09.372176886 CET49717443192.168.2.6216.58.209.45
                  Feb 7, 2023 18:13:09.372239113 CET44349717216.58.209.45192.168.2.6
                  Feb 7, 2023 18:13:09.372409105 CET44349717216.58.209.45192.168.2.6
                  Feb 7, 2023 18:13:09.372714043 CET49717443192.168.2.6216.58.209.45
                  Feb 7, 2023 18:13:09.372754097 CET44349717216.58.209.45192.168.2.6
                  Feb 7, 2023 18:13:09.373064041 CET49720443192.168.2.6142.250.184.100
                  Feb 7, 2023 18:13:09.373100996 CET44349720142.250.184.100192.168.2.6
                  Feb 7, 2023 18:13:09.373191118 CET44349720142.250.184.100192.168.2.6
                  Feb 7, 2023 18:13:09.378617048 CET49716443192.168.2.6142.250.180.174
                  Feb 7, 2023 18:13:09.378680944 CET44349716142.250.180.174192.168.2.6
                  Feb 7, 2023 18:13:09.378803015 CET49716443192.168.2.6142.250.180.174
                  Feb 7, 2023 18:13:09.378812075 CET44349716142.250.180.174192.168.2.6
                  Feb 7, 2023 18:13:09.378967047 CET44349716142.250.180.174192.168.2.6
                  Feb 7, 2023 18:13:09.421870947 CET44349716142.250.180.174192.168.2.6
                  Feb 7, 2023 18:13:09.422056913 CET49716443192.168.2.6142.250.180.174
                  Feb 7, 2023 18:13:09.422074080 CET44349716142.250.180.174192.168.2.6
                  Feb 7, 2023 18:13:09.422128916 CET49716443192.168.2.6142.250.180.174
                  Feb 7, 2023 18:13:09.424755096 CET49716443192.168.2.6142.250.180.174
                  Feb 7, 2023 18:13:09.424787045 CET44349716142.250.180.174192.168.2.6
                  Feb 7, 2023 18:13:09.439872026 CET44349717216.58.209.45192.168.2.6
                  Feb 7, 2023 18:13:09.439980030 CET49717443192.168.2.6216.58.209.45
                  Feb 7, 2023 18:13:09.440031052 CET44349717216.58.209.45192.168.2.6
                  Feb 7, 2023 18:13:09.440068960 CET44349717216.58.209.45192.168.2.6
                  Feb 7, 2023 18:13:09.440126896 CET49717443192.168.2.6216.58.209.45
                  Feb 7, 2023 18:13:09.442322016 CET49717443192.168.2.6216.58.209.45
                  Feb 7, 2023 18:13:09.442367077 CET44349717216.58.209.45192.168.2.6
                  Feb 7, 2023 18:13:09.457576036 CET49720443192.168.2.6142.250.184.100
                  Feb 7, 2023 18:13:09.457597017 CET44349720142.250.184.100192.168.2.6
                  Feb 7, 2023 18:13:09.557614088 CET49720443192.168.2.6142.250.184.100
                  Feb 7, 2023 18:13:12.057815075 CET4971980192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:12.087819099 CET4971880192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:12.157824039 CET4972180192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:18.058303118 CET4971980192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:18.088257074 CET4971880192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:18.158711910 CET4972180192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:19.067739964 CET44349720142.250.184.100192.168.2.6
                  Feb 7, 2023 18:13:19.067867994 CET44349720142.250.184.100192.168.2.6
                  Feb 7, 2023 18:13:19.067989111 CET49720443192.168.2.6142.250.184.100
                  Feb 7, 2023 18:13:20.547534943 CET49720443192.168.2.6142.250.184.100
                  Feb 7, 2023 18:13:20.547583103 CET44349720142.250.184.100192.168.2.6
                  Feb 7, 2023 18:13:31.136977911 CET4973580192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:31.137228012 CET4973680192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:31.393841982 CET4973780192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:34.159620047 CET4973680192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:34.190045118 CET4973580192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:34.489706039 CET4973780192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:40.160026073 CET4973680192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:40.193042040 CET4973580192.168.2.6185.105.66.3
                  Feb 7, 2023 18:13:40.490796089 CET4973780192.168.2.6185.105.66.3
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 7, 2023 18:13:08.940345049 CET6291053192.168.2.68.8.8.8
                  Feb 7, 2023 18:13:08.942428112 CET6322953192.168.2.68.8.8.8
                  Feb 7, 2023 18:13:08.945241928 CET6253853192.168.2.68.8.8.8
                  Feb 7, 2023 18:13:08.946662903 CET5490353192.168.2.68.8.8.8
                  Feb 7, 2023 18:13:08.969158888 CET53629108.8.8.8192.168.2.6
                  Feb 7, 2023 18:13:08.974514008 CET53549038.8.8.8192.168.2.6
                  Feb 7, 2023 18:13:08.981478930 CET53632298.8.8.8192.168.2.6
                  Feb 7, 2023 18:13:08.983982086 CET53625388.8.8.8192.168.2.6
                  Feb 7, 2023 18:13:08.990489006 CET5153053192.168.2.68.8.8.8
                  Feb 7, 2023 18:13:09.019473076 CET53515308.8.8.8192.168.2.6
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Feb 7, 2023 18:13:08.940345049 CET192.168.2.68.8.8.80x648bStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:13:08.942428112 CET192.168.2.68.8.8.80x7199Standard query (0)email.dhqbmail.co.ukA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:13:08.945241928 CET192.168.2.68.8.8.80x2298Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:13:08.946662903 CET192.168.2.68.8.8.80xdf55Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:13:08.990489006 CET192.168.2.68.8.8.80x3352Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Feb 7, 2023 18:13:08.969158888 CET8.8.8.8192.168.2.60x648bNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Feb 7, 2023 18:13:08.969158888 CET8.8.8.8192.168.2.60x648bNo error (0)clients.l.google.com142.250.180.174A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:13:08.974514008 CET8.8.8.8192.168.2.60xdf55No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:13:08.981478930 CET8.8.8.8192.168.2.60x7199No error (0)email.dhqbmail.co.ukdisplay-block.smtp.dnsrt.co.ukCNAME (Canonical name)IN (0x0001)false
                  Feb 7, 2023 18:13:08.981478930 CET8.8.8.8192.168.2.60x7199No error (0)display-block.smtp.dnsrt.co.uk185.105.66.3A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:13:08.983982086 CET8.8.8.8192.168.2.60x2298No error (0)accounts.google.com216.58.209.45A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:13:09.019473076 CET8.8.8.8192.168.2.60x3352No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                  • accounts.google.com
                  • clients2.google.com
                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.649717216.58.209.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-02-07 17:13:09 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  Cookie: __Secure-ENID=6.SE=Md0Ynyf9ahpkx1CxTGF0vY434NJ6ymH-gDI2Tl5Ly-NQYGPjnNfggtiFRMAwx4JRDOC_gavEPcD5cTBJzUgtbJobmBEuJ8xi2UuotxvOZgApoqSIg1b0RP47U08XG8Bz_SExSzKy0ETSsajbToDlYyFsxfI93p7AyRAd-OeIBA0; CONSENT=PENDING+070
                  2023-02-07 17:13:09 UTC0OUTData Raw: 20
                  Data Ascii:
                  2023-02-07 17:13:09 UTC2INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Tue, 07 Feb 2023 17:13:09 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  Content-Security-Policy: script-src 'report-sample' 'nonce-kJvSG9Ket8EYDfqjbugplw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                  Cross-Origin-Opener-Policy: same-origin
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-02-07 17:13:09 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2023-02-07 17:13:09 UTC4INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.649716142.250.180.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-02-07 17:13:09 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                  X-Goog-Update-Updater: chromecrx-104.0.5112.81
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2023-02-07 17:13:09 UTC1INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-H40fz_fmAHkBMtDke4TJhw' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Tue, 07 Feb 2023 17:13:09 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 5881
                  X-Daystart: 33189
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-02-07 17:13:09 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 38 38 31 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 33 31 38 39 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5881" elapsed_seconds="33189"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2023-02-07 17:13:09 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                  Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                  2023-02-07 17:13:09 UTC2INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Click to jump to process

                  Click to jump to process

                  Click to dive into process behavior distribution

                  Click to jump to process

                  Target ID:0
                  Start time:18:13:02
                  Start date:07/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff6f9750000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:1
                  Start time:18:13:04
                  Start date:07/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1948 --field-trial-handle=1776,i,12988346674410521245,11443754851562044237,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff6f9750000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:2
                  Start time:18:13:04
                  Start date:07/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://suzy_lamplugh@email.dhqbmail.co.uk
                  Imagebase:0x7ff6f9750000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  No disassembly