Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://fsscmsprod.wipro.com/

Overview

General Information

Sample URL:https://fsscmsprod.wipro.com/
Analysis ID:800691
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3124 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 1876 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1660 --field-trial-handle=1732,i,3982568901732112948,1407788595426497895,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6152 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fsscmsprod.wipro.com/ MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: clean0.win@30/0@9/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1660 --field-trial-handle=1732,i,3982568901732112948,1407788595426497895,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fsscmsprod.wipro.com/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1660 --field-trial-handle=1732,i,3982568901732112948,1407788595426497895,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://fsscmsprod.wipro.com/0%VirustotalBrowse
https://fsscmsprod.wipro.com/0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.251.209.14
truefalse
    high
    accounts.google.com
    216.58.209.45
    truefalse
      high
      www.google.com
      142.250.184.100
      truefalse
        high
        clients.l.google.com
        142.250.180.174
        truefalse
          high
          fsscmsprod.wipro.com
          unknown
          unknownfalse
            high
            clients2.google.com
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  216.58.209.45
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.184.100
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.180.174
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.1
                  127.0.0.1
                  Joe Sandbox Version:36.0.0 Rainbow Opal
                  Analysis ID:800691
                  Start date and time:2023-02-07 18:13:45 +01:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 4m 52s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:https://fsscmsprod.wipro.com/
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:5
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@30/0@9/6
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, conhost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.184.99, 34.104.35.123, 142.250.180.163
                  • Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, edgedl.me.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 7, 2023 18:14:57.288343906 CET49699443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:14:57.288394928 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:57.288670063 CET49699443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:14:57.289661884 CET49701443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:14:57.289724112 CET44349701216.58.209.45192.168.2.5
                  Feb 7, 2023 18:14:57.289840937 CET49701443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:14:57.292113066 CET49699443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:14:57.292140007 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:57.293378115 CET49701443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:14:57.293402910 CET44349701216.58.209.45192.168.2.5
                  Feb 7, 2023 18:14:57.483403921 CET44349701216.58.209.45192.168.2.5
                  Feb 7, 2023 18:14:57.484039068 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:57.552762985 CET49701443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:14:57.596004009 CET49699443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:14:57.596062899 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:57.596491098 CET49701443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:14:57.596524954 CET44349701216.58.209.45192.168.2.5
                  Feb 7, 2023 18:14:57.597012997 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:57.597042084 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:57.597146988 CET49699443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:14:57.599802971 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:57.599973917 CET49699443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:14:57.600169897 CET44349701216.58.209.45192.168.2.5
                  Feb 7, 2023 18:14:57.600229979 CET44349701216.58.209.45192.168.2.5
                  Feb 7, 2023 18:14:57.600286961 CET49701443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:14:57.652796030 CET49701443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:14:58.117115974 CET49701443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:14:58.117175102 CET44349701216.58.209.45192.168.2.5
                  Feb 7, 2023 18:14:58.117331028 CET44349701216.58.209.45192.168.2.5
                  Feb 7, 2023 18:14:58.117455959 CET49701443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:14:58.117491961 CET44349701216.58.209.45192.168.2.5
                  Feb 7, 2023 18:14:58.117719889 CET49699443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:14:58.117769003 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:58.117876053 CET49699443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:14:58.117889881 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:58.118025064 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:58.162638903 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:58.162784100 CET49699443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:14:58.162816048 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:58.162913084 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:58.162967920 CET49699443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:14:58.166218042 CET49699443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:14:58.166253090 CET44349699142.250.180.174192.168.2.5
                  Feb 7, 2023 18:14:58.183661938 CET44349701216.58.209.45192.168.2.5
                  Feb 7, 2023 18:14:58.183808088 CET49701443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:14:58.183830976 CET44349701216.58.209.45192.168.2.5
                  Feb 7, 2023 18:14:58.185111046 CET44349701216.58.209.45192.168.2.5
                  Feb 7, 2023 18:14:58.185201883 CET49701443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:14:58.186825991 CET49701443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:14:58.186855078 CET44349701216.58.209.45192.168.2.5
                  Feb 7, 2023 18:14:58.915904045 CET49703443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:14:58.915951014 CET44349703142.250.184.100192.168.2.5
                  Feb 7, 2023 18:14:58.916050911 CET49703443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:14:58.920074940 CET49703443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:14:58.920099020 CET44349703142.250.184.100192.168.2.5
                  Feb 7, 2023 18:14:58.998572111 CET44349703142.250.184.100192.168.2.5
                  Feb 7, 2023 18:14:59.001359940 CET49703443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:14:59.001408100 CET44349703142.250.184.100192.168.2.5
                  Feb 7, 2023 18:14:59.003814936 CET44349703142.250.184.100192.168.2.5
                  Feb 7, 2023 18:14:59.003993034 CET49703443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:14:59.006789923 CET49703443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:14:59.006819963 CET44349703142.250.184.100192.168.2.5
                  Feb 7, 2023 18:14:59.007064104 CET44349703142.250.184.100192.168.2.5
                  Feb 7, 2023 18:14:59.052901030 CET49703443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:14:59.052920103 CET44349703142.250.184.100192.168.2.5
                  Feb 7, 2023 18:14:59.152889013 CET49703443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:15:08.969372988 CET44349703142.250.184.100192.168.2.5
                  Feb 7, 2023 18:15:08.969458103 CET44349703142.250.184.100192.168.2.5
                  Feb 7, 2023 18:15:08.969584942 CET49703443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:15:14.296684980 CET49703443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:15:14.296722889 CET44349703142.250.184.100192.168.2.5
                  Feb 7, 2023 18:15:58.776391983 CET49749443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:15:58.776454926 CET44349749142.250.184.100192.168.2.5
                  Feb 7, 2023 18:15:58.776557922 CET49749443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:15:58.777013063 CET49749443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:15:58.777026892 CET44349749142.250.184.100192.168.2.5
                  Feb 7, 2023 18:15:58.842084885 CET44349749142.250.184.100192.168.2.5
                  Feb 7, 2023 18:15:58.850186110 CET49749443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:15:58.850228071 CET44349749142.250.184.100192.168.2.5
                  Feb 7, 2023 18:15:58.850797892 CET44349749142.250.184.100192.168.2.5
                  Feb 7, 2023 18:15:58.851706982 CET49749443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:15:58.851722002 CET44349749142.250.184.100192.168.2.5
                  Feb 7, 2023 18:15:58.851814985 CET44349749142.250.184.100192.168.2.5
                  Feb 7, 2023 18:15:58.897332907 CET49749443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:16:08.824709892 CET44349749142.250.184.100192.168.2.5
                  Feb 7, 2023 18:16:08.824803114 CET44349749142.250.184.100192.168.2.5
                  Feb 7, 2023 18:16:08.824922085 CET49749443192.168.2.5142.250.184.100
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 7, 2023 18:14:57.099898100 CET6064953192.168.2.58.8.8.8
                  Feb 7, 2023 18:14:57.103879929 CET5144153192.168.2.58.8.8.8
                  Feb 7, 2023 18:14:57.118413925 CET53606498.8.8.8192.168.2.5
                  Feb 7, 2023 18:14:57.126085997 CET53514418.8.8.8192.168.2.5
                  Feb 7, 2023 18:14:57.127448082 CET4972453192.168.2.58.8.8.8
                  Feb 7, 2023 18:14:57.154201031 CET53497248.8.8.8192.168.2.5
                  Feb 7, 2023 18:14:58.324964046 CET6532353192.168.2.58.8.8.8
                  Feb 7, 2023 18:14:58.326065063 CET5148453192.168.2.58.8.8.8
                  Feb 7, 2023 18:14:58.344638109 CET53653238.8.8.8192.168.2.5
                  Feb 7, 2023 18:14:58.346194983 CET53514848.8.8.8192.168.2.5
                  Feb 7, 2023 18:14:58.738246918 CET5675153192.168.2.58.8.8.8
                  Feb 7, 2023 18:14:58.756057978 CET53567518.8.8.8192.168.2.5
                  Feb 7, 2023 18:14:59.511797905 CET6097553192.168.2.58.8.8.8
                  Feb 7, 2023 18:14:59.535020113 CET53609758.8.8.8192.168.2.5
                  Feb 7, 2023 18:15:05.027570009 CET5668253192.168.2.58.8.8.8
                  Feb 7, 2023 18:15:05.045797110 CET53566828.8.8.8192.168.2.5
                  Feb 7, 2023 18:15:35.354403019 CET5668753192.168.2.58.8.8.8
                  Feb 7, 2023 18:15:35.374531984 CET53566878.8.8.8192.168.2.5
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Feb 7, 2023 18:14:57.099898100 CET192.168.2.58.8.8.80x5e88Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:14:57.103879929 CET192.168.2.58.8.8.80xfa2bStandard query (0)fsscmsprod.wipro.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:14:57.127448082 CET192.168.2.58.8.8.80x646aStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:14:58.324964046 CET192.168.2.58.8.8.80x8a83Standard query (0)google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:14:58.326065063 CET192.168.2.58.8.8.80x4f63Standard query (0)google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:14:58.738246918 CET192.168.2.58.8.8.80xbac1Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:14:59.511797905 CET192.168.2.58.8.8.80xc715Standard query (0)fsscmsprod.wipro.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:15:05.027570009 CET192.168.2.58.8.8.80xf597Standard query (0)fsscmsprod.wipro.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:15:35.354403019 CET192.168.2.58.8.8.80xff52Standard query (0)fsscmsprod.wipro.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Feb 7, 2023 18:14:57.118413925 CET8.8.8.8192.168.2.50x5e88No error (0)accounts.google.com216.58.209.45A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:14:57.154201031 CET8.8.8.8192.168.2.50x646aNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Feb 7, 2023 18:14:57.154201031 CET8.8.8.8192.168.2.50x646aNo error (0)clients.l.google.com142.250.180.174A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:14:58.344638109 CET8.8.8.8192.168.2.50x8a83No error (0)google.com142.251.209.14A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:14:58.346194983 CET8.8.8.8192.168.2.50x4f63No error (0)google.com142.251.209.14A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:14:58.756057978 CET8.8.8.8192.168.2.50xbac1No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                  • accounts.google.com
                  • clients2.google.com
                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.549701216.58.209.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-02-07 17:14:58 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2023-02-07 17:14:58 UTC0OUTData Raw: 20
                  Data Ascii:
                  2023-02-07 17:14:58 UTC2INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Tue, 07 Feb 2023 17:14:58 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  Content-Security-Policy: script-src 'report-sample' 'nonce-ZSrCdgUniF1l-GTJJvOH1w' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                  Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-02-07 17:14:58 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2023-02-07 17:14:58 UTC4INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.549699142.250.180.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-02-07 17:14:58 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                  X-Goog-Update-Updater: chromecrx-104.0.5112.81
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2023-02-07 17:14:58 UTC1INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-qiAVYPraQMsUz9enk9LzfQ' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Tue, 07 Feb 2023 17:14:58 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 5881
                  X-Daystart: 33298
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-02-07 17:14:58 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 38 38 31 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 33 32 39 38 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5881" elapsed_seconds="33298"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2023-02-07 17:14:58 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                  Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                  2023-02-07 17:14:58 UTC2INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Click to jump to process

                  Click to jump to process

                  Click to dive into process behavior distribution

                  Click to jump to process

                  Target ID:0
                  Start time:18:14:51
                  Start date:07/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:1
                  Start time:18:14:53
                  Start date:07/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1660 --field-trial-handle=1732,i,3982568901732112948,1407788595426497895,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:2
                  Start time:18:14:54
                  Start date:07/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fsscmsprod.wipro.com/
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  No disassembly