Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://sb.scorecardresearch.com/b?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9=

Overview

General Information

Sample URL:http://sb.scorecardresearch.com/b?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9=
Analysis ID:800694
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4964 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 1648 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1748,i,13924636935230247093,10287414604649073630,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 2944 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://sb.scorecardresearch.com/b?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9= MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /b?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9= HTTP/1.1Host: sb.scorecardresearch.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /b2?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9= HTTP/1.1Host: sb.scorecardresearch.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: clean0.win@24/0@5/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1748,i,13924636935230247093,10287414604649073630,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://sb.scorecardresearch.com/b?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9=
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1748,i,13924636935230247093,10287414604649073630,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://sb.scorecardresearch.com/b?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9=0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://sb.scorecardresearch.com/b2?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9=0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
216.58.209.45
truefalse
    high
    sb.scorecardresearch.com
    13.224.103.60
    truefalse
      unknown
      www.google.com
      142.250.184.100
      truefalse
        high
        clients.l.google.com
        142.250.180.174
        truefalse
          high
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            http://sb.scorecardresearch.com/b?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9=false
              unknown
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                http://sb.scorecardresearch.com/b2?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9=false
                • Avira URL Cloud: safe
                unknown
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  13.224.103.60
                  sb.scorecardresearch.comUnited States
                  16509AMAZON-02USfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  216.58.209.45
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.184.100
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.180.174
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.1
                  127.0.0.1
                  Joe Sandbox Version:36.0.0 Rainbow Opal
                  Analysis ID:800694
                  Start date and time:2023-02-07 18:18:58 +01:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 6m 41s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://sb.scorecardresearch.com/b?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9=
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:8
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@24/0@5/7
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, HxTsr.exe, RuntimeBroker.exe, backgroundTaskHost.exe, conhost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.184.99, 34.104.35.123, 142.250.180.163
                  • Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, edgedl.me.gvt1.com, login.live.com, tile-service.weather.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 7, 2023 18:20:05.732501030 CET4969780192.168.2.513.224.103.60
                  Feb 7, 2023 18:20:05.734225988 CET49698443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:20:05.734299898 CET44349698216.58.209.45192.168.2.5
                  Feb 7, 2023 18:20:05.734414101 CET49698443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:20:05.735934019 CET4970080192.168.2.513.224.103.60
                  Feb 7, 2023 18:20:05.737338066 CET49698443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:20:05.737374067 CET44349698216.58.209.45192.168.2.5
                  Feb 7, 2023 18:20:05.744061947 CET804969713.224.103.60192.168.2.5
                  Feb 7, 2023 18:20:05.744252920 CET4969780192.168.2.513.224.103.60
                  Feb 7, 2023 18:20:05.747445107 CET804970013.224.103.60192.168.2.5
                  Feb 7, 2023 18:20:05.747759104 CET49701443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:20:05.747831106 CET4970080192.168.2.513.224.103.60
                  Feb 7, 2023 18:20:05.747842073 CET44349701142.250.180.174192.168.2.5
                  Feb 7, 2023 18:20:05.747931957 CET49701443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:20:05.748390913 CET49701443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:20:05.748415947 CET44349701142.250.180.174192.168.2.5
                  Feb 7, 2023 18:20:05.749773979 CET4969780192.168.2.513.224.103.60
                  Feb 7, 2023 18:20:05.761475086 CET804969713.224.103.60192.168.2.5
                  Feb 7, 2023 18:20:05.769701004 CET804969713.224.103.60192.168.2.5
                  Feb 7, 2023 18:20:05.811115026 CET4969780192.168.2.513.224.103.60
                  Feb 7, 2023 18:20:05.822870016 CET804969713.224.103.60192.168.2.5
                  Feb 7, 2023 18:20:05.838092089 CET804969713.224.103.60192.168.2.5
                  Feb 7, 2023 18:20:05.886651039 CET44349698216.58.209.45192.168.2.5
                  Feb 7, 2023 18:20:05.888503075 CET44349701142.250.180.174192.168.2.5
                  Feb 7, 2023 18:20:05.898973942 CET49701443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:20:05.899017096 CET44349701142.250.180.174192.168.2.5
                  Feb 7, 2023 18:20:05.899305105 CET49698443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:20:05.899331093 CET44349698216.58.209.45192.168.2.5
                  Feb 7, 2023 18:20:05.899679899 CET44349701142.250.180.174192.168.2.5
                  Feb 7, 2023 18:20:05.899791002 CET49701443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:20:05.901518106 CET44349701142.250.180.174192.168.2.5
                  Feb 7, 2023 18:20:05.901526928 CET44349698216.58.209.45192.168.2.5
                  Feb 7, 2023 18:20:05.901694059 CET49701443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:20:05.901941061 CET49698443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:20:06.041098118 CET4969780192.168.2.513.224.103.60
                  Feb 7, 2023 18:20:06.366352081 CET49698443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:20:06.366447926 CET44349698216.58.209.45192.168.2.5
                  Feb 7, 2023 18:20:06.366611958 CET49698443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:20:06.366626978 CET44349698216.58.209.45192.168.2.5
                  Feb 7, 2023 18:20:06.366667986 CET44349698216.58.209.45192.168.2.5
                  Feb 7, 2023 18:20:06.366842031 CET49701443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:20:06.366869926 CET44349701142.250.180.174192.168.2.5
                  Feb 7, 2023 18:20:06.367115021 CET44349701142.250.180.174192.168.2.5
                  Feb 7, 2023 18:20:06.367336988 CET49701443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:20:06.367369890 CET44349701142.250.180.174192.168.2.5
                  Feb 7, 2023 18:20:06.411986113 CET44349701142.250.180.174192.168.2.5
                  Feb 7, 2023 18:20:06.412146091 CET49701443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:20:06.412159920 CET44349701142.250.180.174192.168.2.5
                  Feb 7, 2023 18:20:06.412237883 CET49701443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:20:06.413670063 CET49701443192.168.2.5142.250.180.174
                  Feb 7, 2023 18:20:06.413722038 CET44349701142.250.180.174192.168.2.5
                  Feb 7, 2023 18:20:06.432389021 CET44349698216.58.209.45192.168.2.5
                  Feb 7, 2023 18:20:06.432605028 CET44349698216.58.209.45192.168.2.5
                  Feb 7, 2023 18:20:06.432625055 CET49698443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:20:06.432683945 CET49698443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:20:06.434312105 CET49698443192.168.2.5216.58.209.45
                  Feb 7, 2023 18:20:06.434350967 CET44349698216.58.209.45192.168.2.5
                  Feb 7, 2023 18:20:08.280395031 CET49704443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:20:08.280494928 CET44349704142.250.184.100192.168.2.5
                  Feb 7, 2023 18:20:08.280596972 CET49704443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:20:08.281091928 CET49704443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:20:08.281132936 CET44349704142.250.184.100192.168.2.5
                  Feb 7, 2023 18:20:08.369160891 CET44349704142.250.184.100192.168.2.5
                  Feb 7, 2023 18:20:08.380392075 CET49704443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:20:08.380417109 CET44349704142.250.184.100192.168.2.5
                  Feb 7, 2023 18:20:08.381795883 CET44349704142.250.184.100192.168.2.5
                  Feb 7, 2023 18:20:08.381872892 CET49704443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:20:08.392890930 CET49704443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:20:08.392921925 CET44349704142.250.184.100192.168.2.5
                  Feb 7, 2023 18:20:08.393063068 CET44349704142.250.184.100192.168.2.5
                  Feb 7, 2023 18:20:08.598723888 CET44349704142.250.184.100192.168.2.5
                  Feb 7, 2023 18:20:08.599612951 CET49704443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:20:18.338906050 CET44349704142.250.184.100192.168.2.5
                  Feb 7, 2023 18:20:18.339034081 CET44349704142.250.184.100192.168.2.5
                  Feb 7, 2023 18:20:18.339157104 CET49704443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:20:22.061120987 CET49704443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:20:22.061166048 CET44349704142.250.184.100192.168.2.5
                  Feb 7, 2023 18:20:35.758924961 CET804970013.224.103.60192.168.2.5
                  Feb 7, 2023 18:20:35.759124994 CET4970080192.168.2.513.224.103.60
                  Feb 7, 2023 18:20:50.989067078 CET4969780192.168.2.513.224.103.60
                  Feb 7, 2023 18:20:51.000827074 CET804969713.224.103.60192.168.2.5
                  Feb 7, 2023 18:21:08.334916115 CET4970080192.168.2.513.224.103.60
                  Feb 7, 2023 18:21:08.335474968 CET49730443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:21:08.335525036 CET44349730142.250.184.100192.168.2.5
                  Feb 7, 2023 18:21:08.335633039 CET49730443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:21:08.336812019 CET49730443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:21:08.336834908 CET44349730142.250.184.100192.168.2.5
                  Feb 7, 2023 18:21:08.346503973 CET804970013.224.103.60192.168.2.5
                  Feb 7, 2023 18:21:08.401797056 CET44349730142.250.184.100192.168.2.5
                  Feb 7, 2023 18:21:08.402482986 CET49730443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:21:08.402517080 CET44349730142.250.184.100192.168.2.5
                  Feb 7, 2023 18:21:08.403059959 CET44349730142.250.184.100192.168.2.5
                  Feb 7, 2023 18:21:08.403882027 CET49730443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:21:08.403912067 CET44349730142.250.184.100192.168.2.5
                  Feb 7, 2023 18:21:08.404023886 CET44349730142.250.184.100192.168.2.5
                  Feb 7, 2023 18:21:08.466547966 CET49730443192.168.2.5142.250.184.100
                  Feb 7, 2023 18:21:18.399393082 CET44349730142.250.184.100192.168.2.5
                  Feb 7, 2023 18:21:18.399486065 CET44349730142.250.184.100192.168.2.5
                  Feb 7, 2023 18:21:18.399636030 CET49730443192.168.2.5142.250.184.100
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 7, 2023 18:20:05.459229946 CET6084153192.168.2.58.8.8.8
                  Feb 7, 2023 18:20:05.459430933 CET6189353192.168.2.58.8.8.8
                  Feb 7, 2023 18:20:05.479124069 CET53608418.8.8.8192.168.2.5
                  Feb 7, 2023 18:20:05.485682011 CET53618938.8.8.8192.168.2.5
                  Feb 7, 2023 18:20:05.637465954 CET5144153192.168.2.58.8.8.8
                  Feb 7, 2023 18:20:05.673083067 CET53514418.8.8.8192.168.2.5
                  Feb 7, 2023 18:20:08.250581026 CET6532353192.168.2.58.8.8.8
                  Feb 7, 2023 18:20:08.278068066 CET53653238.8.8.8192.168.2.5
                  Feb 7, 2023 18:21:08.312211037 CET6028453192.168.2.58.8.8.8
                  Feb 7, 2023 18:21:08.332212925 CET53602848.8.8.8192.168.2.5
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Feb 7, 2023 18:20:05.459229946 CET192.168.2.58.8.8.80x2fa0Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:20:05.459430933 CET192.168.2.58.8.8.80x64dStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:20:05.637465954 CET192.168.2.58.8.8.80x4222Standard query (0)sb.scorecardresearch.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:20:08.250581026 CET192.168.2.58.8.8.80x1741Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:21:08.312211037 CET192.168.2.58.8.8.80x715eStandard query (0)www.google.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Feb 7, 2023 18:20:05.479124069 CET8.8.8.8192.168.2.50x2fa0No error (0)accounts.google.com216.58.209.45A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:20:05.485682011 CET8.8.8.8192.168.2.50x64dNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Feb 7, 2023 18:20:05.485682011 CET8.8.8.8192.168.2.50x64dNo error (0)clients.l.google.com142.250.180.174A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:20:05.673083067 CET8.8.8.8192.168.2.50x4222No error (0)sb.scorecardresearch.com13.224.103.60A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:20:05.673083067 CET8.8.8.8192.168.2.50x4222No error (0)sb.scorecardresearch.com13.224.103.24A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:20:05.673083067 CET8.8.8.8192.168.2.50x4222No error (0)sb.scorecardresearch.com13.224.103.91A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:20:05.673083067 CET8.8.8.8192.168.2.50x4222No error (0)sb.scorecardresearch.com13.224.103.48A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:20:08.278068066 CET8.8.8.8192.168.2.50x1741No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:21:08.332212925 CET8.8.8.8192.168.2.50x715eNo error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                  • accounts.google.com
                  • clients2.google.com
                  • sb.scorecardresearch.com
                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.549698216.58.209.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.549701142.250.180.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  2192.168.2.54969713.224.103.6080C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  Feb 7, 2023 18:20:05.749773979 CET4OUTGET /b?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9= HTTP/1.1
                  Host: sb.scorecardresearch.com
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9
                  Feb 7, 2023 18:20:05.769701004 CET4INHTTP/1.1 302 Found
                  Content-Length: 0
                  Connection: keep-alive
                  Date: Tue, 07 Feb 2023 17:20:05 GMT
                  Location: /b2?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9=
                  set-cookie: UID=1884244ed20089a44c399471675790405; SameSite=None; Secure; domain=.scorecardresearch.com; path=/; max-age=62208000
                  X-Cache: Miss from cloudfront
                  Via: 1.1 d7147e532e5cf73689fcb39fa760bcf2.cloudfront.net (CloudFront)
                  X-Amz-Cf-Pop: ZRH50-C1
                  X-Amz-Cf-Id: 424wEdYGs-lmKKCJPPK7flZqHAF3BTUNw3vnv1XwNTLsT__U35A4kA==
                  Feb 7, 2023 18:20:05.811115026 CET5OUTGET /b2?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9= HTTP/1.1
                  Host: sb.scorecardresearch.com
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9
                  Feb 7, 2023 18:20:05.838092089 CET5INHTTP/1.1 204 No Content
                  Connection: keep-alive
                  Date: Tue, 07 Feb 2023 17:20:05 GMT
                  X-Cache: Miss from cloudfront
                  Via: 1.1 d7147e532e5cf73689fcb39fa760bcf2.cloudfront.net (CloudFront)
                  X-Amz-Cf-Pop: ZRH50-C1
                  X-Amz-Cf-Id: Lfn8PxLCtfWE5m-zh1aznTdBjSEIGFc8BqI0RxmBicKdILuVpTKB_A==
                  Feb 7, 2023 18:20:50.989067078 CET555OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.549698216.58.209.45443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-02-07 17:20:06 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                  Host: accounts.google.com
                  Connection: keep-alive
                  Content-Length: 1
                  Origin: https://www.google.com
                  Content-Type: application/x-www-form-urlencoded
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2023-02-07 17:20:06 UTC0OUTData Raw: 20
                  Data Ascii:
                  2023-02-07 17:20:06 UTC2INHTTP/1.1 200 OK
                  Content-Type: application/json; charset=utf-8
                  Access-Control-Allow-Origin: https://www.google.com
                  Access-Control-Allow-Credentials: true
                  X-Content-Type-Options: nosniff
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Tue, 07 Feb 2023 17:20:06 GMT
                  Strict-Transport-Security: max-age=31536000; includeSubDomains
                  Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                  Report-To: {"group":"IdentityListAccountsHttp","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external"}]}
                  Content-Security-Policy: script-src 'report-sample' 'nonce-reiNpvXXodXhCxiYFFgn7Q' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                  Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                  Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                  Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                  Cross-Origin-Opener-Policy: same-origin; report-to="IdentityListAccountsHttp"
                  Server: ESF
                  X-XSS-Protection: 0
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-02-07 17:20:06 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                  Data Ascii: 11["gaia.l.a.r",[]]
                  2023-02-07 17:20:06 UTC4INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  1192.168.2.549701142.250.180.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampkBytes transferredDirectionData
                  2023-02-07 17:20:06 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                  Host: clients2.google.com
                  Connection: keep-alive
                  X-Goog-Update-Interactivity: fg
                  X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                  X-Goog-Update-Updater: chromecrx-104.0.5112.81
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: empty
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2023-02-07 17:20:06 UTC1INHTTP/1.1 200 OK
                  Content-Security-Policy: script-src 'report-sample' 'nonce-9oBKZ8UPinJywXnpba0-5A' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                  Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                  Pragma: no-cache
                  Expires: Mon, 01 Jan 1990 00:00:00 GMT
                  Date: Tue, 07 Feb 2023 17:20:06 GMT
                  Content-Type: text/xml; charset=UTF-8
                  X-Daynum: 5881
                  X-Daystart: 33606
                  X-Content-Type-Options: nosniff
                  X-Frame-Options: SAMEORIGIN
                  X-XSS-Protection: 1; mode=block
                  Server: GSE
                  Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                  Accept-Ranges: none
                  Vary: Accept-Encoding
                  Connection: close
                  Transfer-Encoding: chunked
                  2023-02-07 17:20:06 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 38 38 31 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 33 36 30 36 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                  Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5881" elapsed_seconds="33606"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                  2023-02-07 17:20:06 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                  Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                  2023-02-07 17:20:06 UTC2INData Raw: 30 0d 0a 0d 0a
                  Data Ascii: 0


                  Click to jump to process

                  Click to jump to process

                  Click to dive into process behavior distribution

                  Click to jump to process

                  Target ID:0
                  Start time:18:20:00
                  Start date:07/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:1
                  Start time:18:20:02
                  Start date:07/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1944 --field-trial-handle=1748,i,13924636935230247093,10287414604649073630,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:2
                  Start time:18:20:03
                  Start date:07/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://sb.scorecardresearch.com/b?c1=2&c2=6402952&c3=&c4=&c5=&c6=&c15=&ns__t=1675295934629&ns_c=UTF-8&c7=https://www.linkedin.com/in/ritu-sharma-9318a61b1/&c9=
                  Imagebase:0x7ff7d31b0000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  No disassembly