Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://5.255.255.77

Overview

General Information

Sample URL:http://5.255.255.77
Analysis ID:839706
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2828 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 2216 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1820 --field-trial-handle=1776,i,10677625577141423757,11535006987579640493,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 4888 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://5.255.255.77 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: 5.255.255.77Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49693
Source: unknownNetwork traffic detected: HTTP traffic on port 49693 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49690
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49690 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownTCP traffic detected without corresponding DNS query: 5.255.255.77
Source: unknownTCP traffic detected without corresponding DNS query: 5.255.255.77
Source: unknownTCP traffic detected without corresponding DNS query: 5.255.255.77
Source: unknownTCP traffic detected without corresponding DNS query: 5.255.255.77
Source: unknownTCP traffic detected without corresponding DNS query: 5.255.255.77
Source: unknownTCP traffic detected without corresponding DNS query: 5.255.255.77
Source: unknownTCP traffic detected without corresponding DNS query: 5.255.255.77
Source: unknownTCP traffic detected without corresponding DNS query: 5.255.255.77
Source: unknownTCP traffic detected without corresponding DNS query: 5.255.255.77
Source: unknownTCP traffic detected without corresponding DNS query: 5.255.255.77
Source: classification engineClassification label: clean0.win@25/0@4/8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1820 --field-trial-handle=1776,i,10677625577141423757,11535006987579640493,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://5.255.255.77
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1820 --field-trial-handle=1776,i,10677625577141423757,11535006987579640493,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://5.255.255.773%VirustotalBrowse
http://5.255.255.770%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://5.255.255.77/0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
172.217.16.173
truefalse
    high
    www.google.com
    172.217.16.164
    truefalse
      high
      clients.l.google.com
      142.251.36.174
      truefalse
        high
        windowsupdatebg.s.llnwi.net
        95.140.230.128
        truefalse
          unknown
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                http://5.255.255.77/false
                • Avira URL Cloud: safe
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                5.255.255.77
                unknownRussian Federation
                13238YANDEXRUfalse
                172.217.16.173
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                142.251.36.174
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                172.217.16.164
                www.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.1
                192.168.2.4
                127.0.0.1
                Joe Sandbox Version:37.0.0 Beryl
                Analysis ID:839706
                Start date and time:2023-04-03 07:42:37 +02:00
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 5m 12s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:http://5.255.255.77
                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                Number of analysed new started processes analysed:11
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • HDC enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean0.win@25/0@4/8
                EGA Information:Failed
                HDC Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 204.79.197.200, 13.107.21.200, 93.184.221.240, 172.217.16.163, 34.104.35.123
                • Excluded domains from analysis (whitelisted): www.bing.com, fs.microsoft.com, dual-a-0001.a-msedge.net, wu.ec.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, www-www.bing.com.trafficmanager.net, wu-bg-shim.trafficmanager.net, wu.azureedge.net, edgedl.me.gvt1.com, www-bing-com.dual-a-0001.a-msedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, hlb.apr-52dd2-0.edgecastdns.net, update.googleapis.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtWriteVirtualMemory calls found.
                No simulations
                No context
                No context
                No context
                No context
                No context
                No created / dropped files found
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Apr 3, 2023 07:43:36.504511118 CEST4968880192.168.2.75.255.255.77
                Apr 3, 2023 07:43:36.504844904 CEST4968980192.168.2.75.255.255.77
                Apr 3, 2023 07:43:36.527674913 CEST49690443192.168.2.7142.251.36.174
                Apr 3, 2023 07:43:36.527748108 CEST44349690142.251.36.174192.168.2.7
                Apr 3, 2023 07:43:36.527853012 CEST49690443192.168.2.7142.251.36.174
                Apr 3, 2023 07:43:36.528609991 CEST49690443192.168.2.7142.251.36.174
                Apr 3, 2023 07:43:36.528651953 CEST44349690142.251.36.174192.168.2.7
                Apr 3, 2023 07:43:36.561676979 CEST80496895.255.255.77192.168.2.7
                Apr 3, 2023 07:43:36.561991930 CEST4968980192.168.2.75.255.255.77
                Apr 3, 2023 07:43:36.562833071 CEST80496885.255.255.77192.168.2.7
                Apr 3, 2023 07:43:36.562961102 CEST4968880192.168.2.75.255.255.77
                Apr 3, 2023 07:43:36.592345953 CEST49693443192.168.2.7172.217.16.173
                Apr 3, 2023 07:43:36.592434883 CEST44349693172.217.16.173192.168.2.7
                Apr 3, 2023 07:43:36.592551947 CEST49693443192.168.2.7172.217.16.173
                Apr 3, 2023 07:43:36.592915058 CEST49693443192.168.2.7172.217.16.173
                Apr 3, 2023 07:43:36.592946053 CEST44349693172.217.16.173192.168.2.7
                Apr 3, 2023 07:43:36.644561052 CEST44349690142.251.36.174192.168.2.7
                Apr 3, 2023 07:43:36.691051960 CEST49690443192.168.2.7142.251.36.174
                Apr 3, 2023 07:43:36.691101074 CEST44349690142.251.36.174192.168.2.7
                Apr 3, 2023 07:43:36.691802025 CEST44349690142.251.36.174192.168.2.7
                Apr 3, 2023 07:43:36.691910028 CEST49690443192.168.2.7142.251.36.174
                Apr 3, 2023 07:43:36.692208052 CEST44349693172.217.16.173192.168.2.7
                Apr 3, 2023 07:43:36.692879915 CEST49693443192.168.2.7172.217.16.173
                Apr 3, 2023 07:43:36.692939043 CEST44349693172.217.16.173192.168.2.7
                Apr 3, 2023 07:43:36.693346024 CEST44349690142.251.36.174192.168.2.7
                Apr 3, 2023 07:43:36.693430901 CEST49690443192.168.2.7142.251.36.174
                Apr 3, 2023 07:43:36.694592953 CEST44349693172.217.16.173192.168.2.7
                Apr 3, 2023 07:43:36.694715023 CEST49693443192.168.2.7172.217.16.173
                Apr 3, 2023 07:43:38.181889057 CEST49693443192.168.2.7172.217.16.173
                Apr 3, 2023 07:43:38.181941986 CEST44349693172.217.16.173192.168.2.7
                Apr 3, 2023 07:43:38.182296038 CEST44349693172.217.16.173192.168.2.7
                Apr 3, 2023 07:43:38.183285952 CEST4968880192.168.2.75.255.255.77
                Apr 3, 2023 07:43:38.189827919 CEST49690443192.168.2.7142.251.36.174
                Apr 3, 2023 07:43:38.189888000 CEST44349690142.251.36.174192.168.2.7
                Apr 3, 2023 07:43:38.190186977 CEST49693443192.168.2.7172.217.16.173
                Apr 3, 2023 07:43:38.190265894 CEST44349690142.251.36.174192.168.2.7
                Apr 3, 2023 07:43:38.190277100 CEST44349693172.217.16.173192.168.2.7
                Apr 3, 2023 07:43:38.190629005 CEST49690443192.168.2.7142.251.36.174
                Apr 3, 2023 07:43:38.190665960 CEST44349690142.251.36.174192.168.2.7
                Apr 3, 2023 07:43:38.225663900 CEST44349690142.251.36.174192.168.2.7
                Apr 3, 2023 07:43:38.225758076 CEST49690443192.168.2.7142.251.36.174
                Apr 3, 2023 07:43:38.225797892 CEST44349690142.251.36.174192.168.2.7
                Apr 3, 2023 07:43:38.225999117 CEST44349690142.251.36.174192.168.2.7
                Apr 3, 2023 07:43:38.226087093 CEST49690443192.168.2.7142.251.36.174
                Apr 3, 2023 07:43:38.228110075 CEST49690443192.168.2.7142.251.36.174
                Apr 3, 2023 07:43:38.228152990 CEST44349690142.251.36.174192.168.2.7
                Apr 3, 2023 07:43:38.240968943 CEST80496885.255.255.77192.168.2.7
                Apr 3, 2023 07:43:38.241121054 CEST80496885.255.255.77192.168.2.7
                Apr 3, 2023 07:43:38.241137028 CEST80496885.255.255.77192.168.2.7
                Apr 3, 2023 07:43:38.241235971 CEST4968880192.168.2.75.255.255.77
                Apr 3, 2023 07:43:38.241935968 CEST44349693172.217.16.173192.168.2.7
                Apr 3, 2023 07:43:38.242023945 CEST49693443192.168.2.7172.217.16.173
                Apr 3, 2023 07:43:38.242058992 CEST44349693172.217.16.173192.168.2.7
                Apr 3, 2023 07:43:38.242127895 CEST44349693172.217.16.173192.168.2.7
                Apr 3, 2023 07:43:38.242193937 CEST49693443192.168.2.7172.217.16.173
                Apr 3, 2023 07:43:38.244100094 CEST49693443192.168.2.7172.217.16.173
                Apr 3, 2023 07:43:38.244138956 CEST44349693172.217.16.173192.168.2.7
                Apr 3, 2023 07:43:38.344631910 CEST4968880192.168.2.75.255.255.77
                Apr 3, 2023 07:43:38.402715921 CEST80496885.255.255.77192.168.2.7
                Apr 3, 2023 07:43:38.773614883 CEST49695443192.168.2.7172.217.16.164
                Apr 3, 2023 07:43:38.773695946 CEST44349695172.217.16.164192.168.2.7
                Apr 3, 2023 07:43:38.773838997 CEST49695443192.168.2.7172.217.16.164
                Apr 3, 2023 07:43:38.774135113 CEST49695443192.168.2.7172.217.16.164
                Apr 3, 2023 07:43:38.774163008 CEST44349695172.217.16.164192.168.2.7
                Apr 3, 2023 07:43:38.832628965 CEST44349695172.217.16.164192.168.2.7
                Apr 3, 2023 07:43:38.833117962 CEST49695443192.168.2.7172.217.16.164
                Apr 3, 2023 07:43:38.833163977 CEST44349695172.217.16.164192.168.2.7
                Apr 3, 2023 07:43:38.834510088 CEST44349695172.217.16.164192.168.2.7
                Apr 3, 2023 07:43:38.834603071 CEST49695443192.168.2.7172.217.16.164
                Apr 3, 2023 07:43:38.837152958 CEST49695443192.168.2.7172.217.16.164
                Apr 3, 2023 07:43:38.837188005 CEST44349695172.217.16.164192.168.2.7
                Apr 3, 2023 07:43:38.837320089 CEST44349695172.217.16.164192.168.2.7
                Apr 3, 2023 07:43:38.897373915 CEST49695443192.168.2.7172.217.16.164
                Apr 3, 2023 07:43:38.897433043 CEST44349695172.217.16.164192.168.2.7
                Apr 3, 2023 07:43:39.106633902 CEST49695443192.168.2.7172.217.16.164
                Apr 3, 2023 07:43:48.856435061 CEST44349695172.217.16.164192.168.2.7
                Apr 3, 2023 07:43:48.856602907 CEST44349695172.217.16.164192.168.2.7
                Apr 3, 2023 07:43:48.856684923 CEST49695443192.168.2.7172.217.16.164
                Apr 3, 2023 07:43:50.882736921 CEST49695443192.168.2.7172.217.16.164
                Apr 3, 2023 07:43:50.882787943 CEST44349695172.217.16.164192.168.2.7
                Apr 3, 2023 07:44:21.577230930 CEST4968980192.168.2.75.255.255.77
                Apr 3, 2023 07:44:21.633488894 CEST80496895.255.255.77192.168.2.7
                Apr 3, 2023 07:44:38.930136919 CEST4968980192.168.2.75.255.255.77
                Apr 3, 2023 07:44:38.930793047 CEST49724443192.168.2.7172.217.16.164
                Apr 3, 2023 07:44:38.930874109 CEST44349724172.217.16.164192.168.2.7
                Apr 3, 2023 07:44:38.930958033 CEST49724443192.168.2.7172.217.16.164
                Apr 3, 2023 07:44:38.934111118 CEST49724443192.168.2.7172.217.16.164
                Apr 3, 2023 07:44:38.934148073 CEST44349724172.217.16.164192.168.2.7
                Apr 3, 2023 07:44:38.986877918 CEST80496895.255.255.77192.168.2.7
                Apr 3, 2023 07:44:38.987072945 CEST4968980192.168.2.75.255.255.77
                Apr 3, 2023 07:44:39.001791000 CEST44349724172.217.16.164192.168.2.7
                Apr 3, 2023 07:44:39.032965899 CEST49724443192.168.2.7172.217.16.164
                Apr 3, 2023 07:44:39.033039093 CEST44349724172.217.16.164192.168.2.7
                Apr 3, 2023 07:44:39.033979893 CEST44349724172.217.16.164192.168.2.7
                Apr 3, 2023 07:44:39.036174059 CEST49724443192.168.2.7172.217.16.164
                Apr 3, 2023 07:44:39.036207914 CEST44349724172.217.16.164192.168.2.7
                Apr 3, 2023 07:44:39.036410093 CEST44349724172.217.16.164192.168.2.7
                Apr 3, 2023 07:44:39.084362984 CEST49724443192.168.2.7172.217.16.164
                Apr 3, 2023 07:44:49.051224947 CEST44349724172.217.16.164192.168.2.7
                Apr 3, 2023 07:44:49.051323891 CEST44349724172.217.16.164192.168.2.7
                Apr 3, 2023 07:44:49.051379919 CEST49724443192.168.2.7172.217.16.164
                TimestampSource PortDest PortSource IPDest IP
                Apr 3, 2023 07:43:36.298712015 CEST5905853192.168.2.78.8.8.8
                Apr 3, 2023 07:43:36.301018953 CEST5487553192.168.2.78.8.8.8
                Apr 3, 2023 07:43:36.332266092 CEST53590588.8.8.8192.168.2.7
                Apr 3, 2023 07:43:36.335376978 CEST53548758.8.8.8192.168.2.7
                Apr 3, 2023 07:43:38.706007004 CEST5575253192.168.2.78.8.8.8
                Apr 3, 2023 07:43:38.726665974 CEST53557528.8.8.8192.168.2.7
                Apr 3, 2023 07:44:38.854979038 CEST5900653192.168.2.78.8.8.8
                Apr 3, 2023 07:44:38.875437021 CEST53590068.8.8.8192.168.2.7
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 3, 2023 07:43:36.298712015 CEST192.168.2.78.8.8.80x1203Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Apr 3, 2023 07:43:36.301018953 CEST192.168.2.78.8.8.80x860aStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Apr 3, 2023 07:43:38.706007004 CEST192.168.2.78.8.8.80xfc56Standard query (0)www.google.comA (IP address)IN (0x0001)false
                Apr 3, 2023 07:44:38.854979038 CEST192.168.2.78.8.8.80x4aafStandard query (0)www.google.comA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 3, 2023 07:43:27.407504082 CEST8.8.8.8192.168.2.70x1bb0No error (0)windowsupdatebg.s.llnwi.net95.140.230.128A (IP address)IN (0x0001)false
                Apr 3, 2023 07:43:27.407504082 CEST8.8.8.8192.168.2.70x1bb0No error (0)windowsupdatebg.s.llnwi.net178.79.225.128A (IP address)IN (0x0001)false
                Apr 3, 2023 07:43:36.332266092 CEST8.8.8.8192.168.2.70x1203No error (0)accounts.google.com172.217.16.173A (IP address)IN (0x0001)false
                Apr 3, 2023 07:43:36.335376978 CEST8.8.8.8192.168.2.70x860aNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Apr 3, 2023 07:43:36.335376978 CEST8.8.8.8192.168.2.70x860aNo error (0)clients.l.google.com142.251.36.174A (IP address)IN (0x0001)false
                Apr 3, 2023 07:43:38.726665974 CEST8.8.8.8192.168.2.70xfc56No error (0)www.google.com172.217.16.164A (IP address)IN (0x0001)false
                Apr 3, 2023 07:44:38.875437021 CEST8.8.8.8192.168.2.70x4aafNo error (0)www.google.com172.217.16.164A (IP address)IN (0x0001)false
                • clients2.google.com
                • accounts.google.com
                • 5.255.255.77
                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.749690142.251.36.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.749693172.217.16.173443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData


                Session IDSource IPSource PortDestination IPDestination PortProcess
                2192.168.2.7496885.255.255.7780C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Apr 3, 2023 07:43:38.183285952 CEST233OUTGET / HTTP/1.1
                Host: 5.255.255.77
                Connection: keep-alive
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
                Accept-Encoding: gzip, deflate
                Accept-Language: en-US,en;q=0.9
                Apr 3, 2023 07:43:38.241121054 CEST238INHTTP/1.1 406 Not acceptable
                Accept-CH: Sec-CH-UA-Platform-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA, Sec-CH-UA-Full-Version-List, Sec-CH-UA-WoW64, Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Platform, Sec-CH-UA-Full-Version, Viewport-Width, DPR, Device-Memory, RTT, Downlink, ECT
                Connection: Close
                Content-Length: 0
                NEL: {"report_to": "network-errors", "max_age": 100, "success_fraction": 0.001, "failure_fraction": 0.1}
                Report-To: { "group": "network-errors", "max_age": 100, "endpoints": [{"url": "https://dr.yandex.net/nel", "priority": 1}, {"url": "https://dr2.yandex.net/nel", "priority": 2}]}
                X-Content-Type-Options: nosniff
                X-Yandex-Req-Id: 1680500618210949-596957874466284545-balancer-l7leveler-kubr-yp-vla-9-BAL


                Session IDSource IPSource PortDestination IPDestination PortProcess
                3192.168.2.7496895.255.255.7780C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                Apr 3, 2023 07:44:21.577230930 CEST603OUTData Raw: 00
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortProcess
                0192.168.2.749690142.251.36.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-04-03 05:43:38 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                Host: clients2.google.com
                Connection: keep-alive
                X-Goog-Update-Interactivity: fg
                X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                X-Goog-Update-Updater: chromecrx-104.0.5112.81
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2023-04-03 05:43:38 UTC1INHTTP/1.1 200 OK
                Content-Security-Policy: script-src 'report-sample' 'nonce-icWu_Ik4yt9lzI0KRh9r0w' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Mon, 03 Apr 2023 05:43:38 GMT
                Content-Type: text/xml; charset=UTF-8
                X-Daynum: 5935
                X-Daystart: 81818
                X-Content-Type-Options: nosniff
                X-Frame-Options: SAMEORIGIN
                X-XSS-Protection: 1; mode=block
                Server: GSE
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2023-04-03 05:43:38 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 33 35 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 38 31 38 31 38 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5935" elapsed_seconds="81818"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                2023-04-03 05:43:38 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                2023-04-03 05:43:38 UTC2INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Session IDSource IPSource PortDestination IPDestination PortProcess
                1192.168.2.749693172.217.16.173443C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampkBytes transferredDirectionData
                2023-04-03 05:43:38 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                Host: accounts.google.com
                Connection: keep-alive
                Content-Length: 1
                Origin: https://www.google.com
                Content-Type: application/x-www-form-urlencoded
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: empty
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2023-04-03 05:43:38 UTC1OUTData Raw: 20
                Data Ascii:
                2023-04-03 05:43:38 UTC2INHTTP/1.1 200 OK
                Content-Type: application/json; charset=utf-8
                Access-Control-Allow-Origin: https://www.google.com
                Access-Control-Allow-Credentials: true
                X-Content-Type-Options: nosniff
                Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                Pragma: no-cache
                Expires: Mon, 01 Jan 1990 00:00:00 GMT
                Date: Mon, 03 Apr 2023 05:43:38 GMT
                Strict-Transport-Security: max-age=31536000; includeSubDomains
                Cross-Origin-Opener-Policy: same-origin
                Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                Content-Security-Policy: script-src 'report-sample' 'nonce-eF-uUXBS5yK-l58UTk7DXQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
                Server: ESF
                X-XSS-Protection: 0
                Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                Accept-Ranges: none
                Vary: Accept-Encoding
                Connection: close
                Transfer-Encoding: chunked
                2023-04-03 05:43:38 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                Data Ascii: 11["gaia.l.a.r",[]]
                2023-04-03 05:43:38 UTC4INData Raw: 30 0d 0a 0d 0a
                Data Ascii: 0


                Click to jump to process

                Click to jump to process

                Click to dive into process behavior distribution

                Click to jump to process

                Target ID:0
                Start time:07:43:31
                Start date:03/04/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff7c2920000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                Target ID:1
                Start time:07:43:33
                Start date:03/04/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1820 --field-trial-handle=1776,i,10677625577141423757,11535006987579640493,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff7c2920000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                Target ID:2
                Start time:07:43:34
                Start date:03/04/2023
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://5.255.255.77
                Imagebase:0x7ff7c2920000
                File size:2851656 bytes
                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low

                No disassembly