Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
login.html

Overview

General Information

Sample Name:login.html
Analysis ID:876180
MD5:daccb43d7df16a5b00d0db1340b979ab
SHA1:ef1e463b2cff4c9b8e5487422ae63ec15083bcbc
SHA256:f0a3bb756492268062c421579e4115d2764a713e5b7cd2fc95a89c94814e6fc2
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Suspicious Javascript code found in HTML file
HTML document with suspicious name
HTML body contains password input but no form action
HTML body with high number of large embedded background images detected
IP address seen in connection with other malware

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 3564 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\login.html MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 6928 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1776,i,3959098085490163762,14531336400767641844,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: login.htmlHTTP Parser: new blob(
Source: login.htmlHTTP Parser: url.createobjecturl
Source: file:///C:/Users/user/Desktop/login.htmlHTTP Parser: <input type="password" .../> found but no <form action="...
Source: login.htmlHTTP Parser: Total embedded background img size: 475993
Source: file:///C:/Users/user/Desktop/login.htmlHTTP Parser: Total embedded background img size: 861218
Source: file:///C:/Users/user/Desktop/login.htmlHTTP Parser: <input type="password" .../> found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: chrome.exeMemory has grown: Private usage: 1MB later: 44MB
Source: Joe Sandbox ViewIP Address: 239.255.255.250 239.255.255.250
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.102Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: login.htmlString found in binary or memory: http://underscorejs.org/LICENSE
Source: login.htmlString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: login.htmlString found in binary or memory: http://www.broofa.com
Source: login.htmlString found in binary or memory: https://angular.io/
Source: login.htmlString found in binary or memory: https://angular.io/api/core/Component#animations).
Source: login.htmlString found in binary or memory: https://angular.io/errors/$
Source: login.htmlString found in binary or memory: https://angular.io/license
Source: login.htmlString found in binary or memory: https://g.co/ng/security#xss)
Source: login.htmlString found in binary or memory: https://github.com/dcodeIO/bytebuffer.js
Source: login.htmlString found in binary or memory: https://github.com/dcodeIO/long.js
Source: login.htmlString found in binary or memory: https://github.com/dcodeIO/protobuf.js
Source: login.htmlString found in binary or memory: https://jquery.com/
Source: login.htmlString found in binary or memory: https://jquery.org/license
Source: login.htmlString found in binary or memory: https://js.foundation/
Source: login.htmlString found in binary or memory: https://lodash.com/
Source: login.htmlString found in binary or memory: https://lodash.com/license
Source: login.htmlString found in binary or memory: https://openjsf.org/
Source: login.htmlString found in binary or memory: https://sizzlejs.com/
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+620; __Secure-ENID=6.SE=cJKCBuSaL1dV3R8z2Y2al7-m2m5bGA74lqbYYkqC3uy-NtZ1f6n_bCBr25tlnnjvdmLpGQ81ZKzP3Te5vVjpSQjYWCwvlOMApK7tmZNWcORu0p4wniPJGQfTslQNnpQWhG9qkwkEgy49-6UG3UQ1eiUyFolJZWLeUM1p4KvjM9E

System Summary

barindex
Source: Name includes: login.htmlInitial sample: login
Source: classification engineClassification label: mal48.phis.winHTML@24/0@6/7
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\login.html
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1776,i,3959098085490163762,14531336400767641844,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1776,i,3959098085490163762,14531336400767641844,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: login.htmlStatic file information: File size 5877035 > 1048576
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
Extra Window Memory Injection
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://www.broofa.com0%URL Reputationsafe
http://www.broofa.com0%URL Reputationsafe
https://openjsf.org/0%URL Reputationsafe
https://js.foundation/0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
216.58.212.173
truefalse
    high
    www.google.com
    142.250.181.228
    truefalse
      high
      clients.l.google.com
      142.250.186.174
      truefalse
        high
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          file:///C:/Users/user/Desktop/login.htmltrue
            low
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                high
                NameSourceMaliciousAntivirus DetectionReputation
                http://underscorejs.org/LICENSElogin.htmlfalse
                  high
                  http://www.apache.org/licenses/LICENSE-2.0login.htmlfalse
                    high
                    https://jquery.org/licenselogin.htmlfalse
                      high
                      https://g.co/ng/security#xss)login.htmlfalse
                        high
                        http://www.broofa.comlogin.htmlfalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://github.com/dcodeIO/long.jslogin.htmlfalse
                          high
                          https://github.com/dcodeIO/protobuf.jslogin.htmlfalse
                            high
                            https://jquery.com/login.htmlfalse
                              high
                              https://angular.io/api/core/Component#animations).login.htmlfalse
                                high
                                https://angular.io/errors/$login.htmlfalse
                                  high
                                  https://angular.io/login.htmlfalse
                                    high
                                    https://lodash.com/login.htmlfalse
                                      high
                                      https://github.com/dcodeIO/bytebuffer.jslogin.htmlfalse
                                        high
                                        https://lodash.com/licenselogin.htmlfalse
                                          high
                                          https://angular.io/licenselogin.htmlfalse
                                            high
                                            https://openjsf.org/login.htmlfalse
                                            • URL Reputation: safe
                                            unknown
                                            https://sizzlejs.com/login.htmlfalse
                                              high
                                              https://js.foundation/login.htmlfalse
                                              • URL Reputation: safe
                                              unknown
                                              • No. of IPs < 25%
                                              • 25% < No. of IPs < 50%
                                              • 50% < No. of IPs < 75%
                                              • 75% < No. of IPs
                                              IPDomainCountryFlagASNASN NameMalicious
                                              239.255.255.250
                                              unknownReserved
                                              unknownunknownfalse
                                              142.250.181.228
                                              www.google.comUnited States
                                              15169GOOGLEUSfalse
                                              142.250.186.174
                                              clients.l.google.comUnited States
                                              15169GOOGLEUSfalse
                                              142.250.186.164
                                              unknownUnited States
                                              15169GOOGLEUSfalse
                                              216.58.212.173
                                              accounts.google.comUnited States
                                              15169GOOGLEUSfalse
                                              IP
                                              192.168.2.1
                                              192.168.8.1
                                              Joe Sandbox Version:37.1.0 Beryl
                                              Analysis ID:876180
                                              Start date and time:2023-05-26 13:07:21 +02:00
                                              Joe Sandbox Product:CloudBasic
                                              Overall analysis duration:0h 4m 14s
                                              Hypervisor based Inspection enabled:false
                                              Report type:full
                                              Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                              Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                                              Number of analysed new started processes analysed:3
                                              Number of new started drivers analysed:0
                                              Number of existing processes analysed:0
                                              Number of existing drivers analysed:0
                                              Number of injected processes analysed:0
                                              Technologies:
                                              • HCA enabled
                                              • EGA enabled
                                              • HDC enabled
                                              • AMSI enabled
                                              Analysis Mode:default
                                              Analysis stop reason:Timeout
                                              Sample file name:login.html
                                              Detection:MAL
                                              Classification:mal48.phis.winHTML@24/0@6/7
                                              EGA Information:Failed
                                              HDC Information:Failed
                                              HCA Information:
                                              • Successful, ratio: 100%
                                              • Number of executed functions: 0
                                              • Number of non-executed functions: 0
                                              Cookbook Comments:
                                              • Found application associated with file extension: .html
                                              • Exclude process from analysis (whitelisted): svchost.exe
                                              • Excluded IPs from analysis (whitelisted): 142.250.185.99, 34.104.35.123
                                              • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, login.live.com, update.googleapis.com, clientservices.googleapis.com
                                              • Not all processes where analyzed, report is missing behavior information
                                              No simulations
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              239.255.255.250login.htmlGet hashmaliciousUnknownBrowse
                                                https://rollins-mkt-prod1.campaign.adobe.com/rln/getImage.jssp?m=ebe0a673-b585-4d5f-8b02-173d6da0ca15&e=boss&l=brandlogo&i=https%3A%2F%2Fstn7ny.codesandbox.io?pop=someone.else%40somewhere.comGet hashmaliciousHTMLPhisherBrowse
                                                  iata-25May2023.shtmlGet hashmaliciousUnknownBrowse
                                                    https://s3.amazonaws.com/v5c323s5fg7hnj-794372450934/tv.htmlGet hashmaliciousUnknownBrowse
                                                      25 May 2023-9706 PM-GTT4FIWVGZ.htmGet hashmaliciousHTMLPhisherBrowse
                                                        https://269.bowwordon.live/fxddhqsm/?u=3w8p605&o=pn1kfzq&f=1&sid=t2~hckuzwxtbpsvmcpf30ztc331&fp=FvEsrkTArOgrxzhB2zExAA2IZuNTD8%2Fd9njv3jvDDOYnVROoSzmzg9nW12cfMdaHPT88q85r2inPkFCSbWgnzkfJFZZA3Mrzk%2F75MnETRxlcbvcR%2BeCurFnWMWd%2Fga7euAPm2FuOzEEhPFPKB9BvYYMpUxFP0z7K9pb7kfgbNf7SPRnAgQYfnloabfpuR%2BvXfyPOArMa%2B%2FuoZCunaXhl0et9vEushY7p%2FHvZJdO3bDfSLkShHDI5ukbNxghFhqsVSdcuoNPFbXVxUMFSYBPgTzlZOfrmXROiGBlvljFG6fsmagUS%2FcuqeVrqE60PwBTm3%2Fi07AuZFW5fp%2FVgaJ6PbiRsnFEiC40thM192GKHQmbP7RKplWwBB8%2B8V9R2MWg%2FLK44BnmLVLfMpK%2FaPUB4ZbPCt%2B1mkosN9tSoNyEbMODuLao0Z7nZzXzxHsVCzILD9XrGiz4%2BbS2yy4q2xExA%2FoVYHMdITtz12kRrUwM13QZcFjcbuNxO6UPZKT9ClRRrlg0lIkw74ioZ2xrB9aRabwONkY0LAtlodraoxsFw%2Frjld227l0ZlFzSfF7ItEflen4OWRtOFW9Wrsiz2kpJPf5oRAHrdZUkN3qG%2F15O3V44Vu5%2BpENw113oXAb%2B5jOBgRRW6I1X0bf8cLxhowerhiMxt50rO8mBdxAQdPHCn0gH0ebxDhuaS%2FLYgUGT1lau3HqE%2F1rCwqxjZHIo6t3aqvc2Hjj%2FENuGU9F8qLn%2F4HSsiaC3Sukth29CJ%2FIfm0DoG%2FPOpXcim37L%2BRGwafmRwN%2B34IPmlvf26KZfI8wQs9UXMmntP2FJP%2FEplJo%2FEuXUDDhLf4tdAg9dU6tbD8htpv%2FZ56%2BEYQ04G6xmNAeWyyYRYW%2BqH6QVG4vuesnwHsUFVE4r7Q4bD2AxRlxgBllMZb9xzCLFetaycJDSQe4RdWGHJtZe55ya806yBuHB3UEIOGCumNPnid8l%2BBkBxT47OXgjG0nQdZNEGlEbG8iU48EiFS%2BfynKs4mEnSwTUQwhNu%2BWoLCLWmr%2BaOWmLkzxkAF6DlCu5U4PEwv0kXLndfcSaUEdYFF1tSL6RjTjR%2F4%2FserlCJRcSC0A70S6zmMbbOJuTCTkFyZCbqppDwf3nbJIzemAl%2FNrhVTetxsOmVhtlYVIdWuIJsMR7pYLYn5O%2BJmmh84Qc78kaOcsh9IKStCc4s7wELskCRSZWlSlVcYTDe1y3u0Azm2jzKUoABLHZ9Gayot1pMs7Ezn44LtE0hIh6os5pialL6zko4EYcZwfFiJSo0zoKsO7C11hQRmWGjq9ZhzS17zVB68Uew11CRT2etioyLsWm0CulA60Qgl1Q3FhL2R0KGQ%2BVqJEQkT54SLGekGCD7A5m%2FAvJh2LOBlQo9XASyku5u4rhmSkHKP7PsYZvvAU38BIRQiJ%2FsNWG97AjUQfgHYLSFjuf9WfC6MGAL3akp5hbpczWPA5%2F0Kqh0QufsQ3FKt8oJHOgjavhW377FPwjPWPquNEQqJfXXFzbCLuu5Fo9dMm97xDMH9KJJNgJOg9VKpdhs0QZHZcHCZgzxR2RTrOotCmAA8xftgXFNd9%2BWk5tunEAteh6V5ByAox3YaUW4P%2FsPW2zAZ5eIXD7IFBnSN%2Bh1mwjkvV0iOw1pqDjahnAaTIBcM75Gcrjj5BZxbXdLsLKiEkjv30wyXvFmgAvISyDbT1JhfC7vxYw9wbQjxQte1G0Z0jdM3wY4NkW2GxS%2F0Yz5hdfDx8oVuW4axhzLyucNXmnWtXmSEilV7dOPCPAD%2BY%2B2Gb1jSwmVdZJy3ND9Get hashmaliciousUnknownBrowse
                                                          _V2.HtMLGet hashmaliciousHTMLPhisherBrowse
                                                            https://www.pdfhubonline.com/install-appGet hashmaliciousUnknownBrowse
                                                              https://rollins-mkt-prod1.campaign.adobe.com/rln/getImage.jssp?m=ebe0a673-b585-4d5f-8b02-173d6da0ca15&e=boss&l=brandlogo&i=http%3A%2F%2Fnorthcape.com.au.CBS4.ya2.design?anVsaWUua29yb3dlQG5vcnRoY2FwZS5jb20uYXU=Get hashmaliciousUnknownBrowse
                                                                https://download.zotero.org/client/release/6.0.26/Zotero-6.0.26_setup.exeGet hashmaliciousUnknownBrowse
                                                                  https://bs.serving-sys.com/Serving/adServer.bs?cn=brd&PluID=0&Pos=20&EyeblasterID=1086486580&clk=1&ctick=00484900&rtu=https%3A%2F%2F4bdp40.codesandbox.io?pop=kkronberg%40whitehouseleisure.co.ukGet hashmaliciousHTMLPhisherBrowse
                                                                    https://rollins-mkt-prod1.campaign.adobe.com/rln/getImage.jssp?m=ebe0a673-b585-4d5f-8b02-173d6da0ca15&e=boss&l=brandlogo&i=http%3A%2F%2Fpaul-lueftung.de.N9bB.dedelices.fr?dGhvbWFzLmxpbmtAcGF1bC1sdWVmdHVuZy5kZQ==Get hashmaliciousUnknownBrowse
                                                                      https://fukutex.net/uqe/Get hashmaliciousUnknownBrowse
                                                                        https://dweb.link/ipfs/Qmew7ZLgFqtcKTFisSkxDT1NYpeFLqjQwaQXaJgoyccdnt?filename=Qmew7ZLgFqtcKTFisSkxDT1NYpeFLqjQwaQXaJgoyccdnt#reservation@anaintercontinental-tokyo.jpGet hashmaliciousUnknownBrowse
                                                                          https://www.bing.com/ck/a?!&&p=3b853cb72f7f4f36JmltdHM9MTY4MjU1MzYwMCZpZ3VpZD0wNDVjZTI0Ny0wZGFkLTY5YTktMmI1ZS1mMGI0MGMyNjY4YjEmaW5zaWQ9NTIyNQ&ptn=3&hsh=3&fclid=045ce247-0dad-69a9-2b5e-f0b40c2668b1&u=a1aHR0cHM6Ly90cGFhZHZpc29ycy5jb20vMjAyMS8xMS8wNS9sZXNzb25zLWxlYXJuZWQtZnJvbS10aGUtcGFuZGVtaWMtaXMtaXQtdGltZS10by1jb25zaWRlci1vdXRzb3VyY2luZy8Get hashmaliciousUnknownBrowse
                                                                            https://rollins-mkt-prod1.campaign.adobe.com/rln/getImage.jssp?m=ebe0a673-b585-4d5f-8b02-173d6da0ca15&e=boss&l=brandlogo&i=https%3A%2F%2Fintertecqatar.com%2Fcss%2Fjs%2Fsiasia%2Fgemseducation.com%2F%2F%2F%2F%2Fa3Jpc2huYW4uZ29waUBnZW1zZWR1Y2F0aW9uLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                                                              https://Microsoft.at-au.therelayservice.com/service/7LUXeQqjd17vo49IsAc8GADu_LekAgG1aVTFnqdMYtDLfTFLPvQWEMt9fDjvKVni5W-yJnMqg27g4rC600BfcvzHAEaiihjRriLQjI7UwaqQvp1964V5aKS3r9aGzZAPDiMEAL5ibWWjdYuQrqgUReb0tFbGH12RdE489hF5B5lgWuSsYmPxEa1BqLD4DeccCctAmlkNy_e9FeaEDvviF5_6-mZPj_iRBX6S_SoW9a-bl2y76_62J07NSaQ8CitaBgct_1DnkFMpMPCjyhAzRxiWVI7P3gROldun_tl39TrpJb2gX9x03zaHCRGAV1kSo8TjC8uFQtvPIMW08902PAsSJpNQgPXnGuB3cjfKaPXaHCOyE6hfhsesk0pmRkF8j7o4bK2fhpiYihPnRnJ3tgGet hashmaliciousUnknownBrowse
                                                                                https://slickdeals.net/?adobeRef=4796c816dd6211edbcf236987a0a01ff0000&sdtid=16572596&sdpid=162856616&sdfid=30&lno=3&trd=https%20go%20redirectinga%20wbr%20t%20com%20&pv&au&u2=https%3A%2F%2F3byx7k.codesandbox.io%2F%3Fmandate=YWVsbHN3b3J0aEBiaWdnZS5jb20=Get hashmaliciousHTMLPhisherBrowse
                                                                                  https://slickdeals.net/?adobeRef=4796c816dd6211edbcf236987a0a01ff0000&sdtid=16572596&sdpid=162856616&sdfid=30&lno=3&trd=https%20go%20redirectinga%20wbr%20t%20com%20&pv&au&u2=https%3A%2F%2F3byx7k.codesandbox.io%2F%3Fmandate=dGhhcnR1bmdAZW5uZWFkLmNvbQ==Get hashmaliciousUnknownBrowse
                                                                                    beneficient-25May2023.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                      No context
                                                                                      No context
                                                                                      No context
                                                                                      No context
                                                                                      No created / dropped files found
                                                                                      File type:HTML document, Unicode text, UTF-8 text, with very long lines (7825)
                                                                                      Entropy (8bit):5.840089611320105
                                                                                      TrID:
                                                                                      • Atom web feed (35501/1) 20.76%
                                                                                      • HyperText Markup Language XML (18501/1) 10.82%
                                                                                      • Scalable Vector Graphics (18501/1) 10.82%
                                                                                      • Artificial Intelligence Markup Language (14501/1) 8.48%
                                                                                      • Mathematical Markup Language (13501/1) 7.89%
                                                                                      File name:login.html
                                                                                      File size:5877035
                                                                                      MD5:daccb43d7df16a5b00d0db1340b979ab
                                                                                      SHA1:ef1e463b2cff4c9b8e5487422ae63ec15083bcbc
                                                                                      SHA256:f0a3bb756492268062c421579e4115d2764a713e5b7cd2fc95a89c94814e6fc2
                                                                                      SHA512:c310eee3cab573e728387b3a7a698e36e36ae3ba26c37d85961cd0d7dd96e1e312eb88a9fb014b8099e821b14c0b3b51653e5aed269503f00f261d05b8fe14a0
                                                                                      SSDEEP:49152:2brAJ6aVxCVUuabZ2LTR17ATlxqiCLX8tfMEvCewKyZlUX7+dZdabAhawsKpg6za:JwwrctOT
                                                                                      TLSH:1F466B737981247243A686E990EF1285BF3C3347D0054628F36CD9EE5BE9984D1A7BBC
                                                                                      File Content Preview:<!doctype html> [if lt IE 7]>.<html class="no-js lt-ie9 lt-ie8 lt-ie7" lang="en"> <![endif]--> [if IE 7]>.<html class="no-js lt-ie9 lt-ie8" lang="en"> <![endif]--> [if IE 8]>.<html class="no-js lt-ie9" lang="en"> <![endif]--> [if gt IE 8]>
                                                                                      Icon Hash:0f3149cc4c490307
                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                      May 26, 2023 13:07:51.400619030 CEST49748443192.168.2.3142.250.186.174
                                                                                      May 26, 2023 13:07:51.400693893 CEST44349748142.250.186.174192.168.2.3
                                                                                      May 26, 2023 13:07:51.400814056 CEST49748443192.168.2.3142.250.186.174
                                                                                      May 26, 2023 13:07:51.418652058 CEST49748443192.168.2.3142.250.186.174
                                                                                      May 26, 2023 13:07:51.418724060 CEST44349748142.250.186.174192.168.2.3
                                                                                      May 26, 2023 13:07:51.420115948 CEST49750443192.168.2.3216.58.212.173
                                                                                      May 26, 2023 13:07:51.420186996 CEST44349750216.58.212.173192.168.2.3
                                                                                      May 26, 2023 13:07:51.420300961 CEST49750443192.168.2.3216.58.212.173
                                                                                      May 26, 2023 13:07:51.420504093 CEST49750443192.168.2.3216.58.212.173
                                                                                      May 26, 2023 13:07:51.420535088 CEST44349750216.58.212.173192.168.2.3
                                                                                      May 26, 2023 13:07:51.533128023 CEST44349748142.250.186.174192.168.2.3
                                                                                      May 26, 2023 13:07:51.538477898 CEST49748443192.168.2.3142.250.186.174
                                                                                      May 26, 2023 13:07:51.538520098 CEST44349748142.250.186.174192.168.2.3
                                                                                      May 26, 2023 13:07:51.539134979 CEST44349748142.250.186.174192.168.2.3
                                                                                      May 26, 2023 13:07:51.539259911 CEST49748443192.168.2.3142.250.186.174
                                                                                      May 26, 2023 13:07:51.539940119 CEST44349748142.250.186.174192.168.2.3
                                                                                      May 26, 2023 13:07:51.540055990 CEST49748443192.168.2.3142.250.186.174
                                                                                      May 26, 2023 13:07:51.567812920 CEST44349750216.58.212.173192.168.2.3
                                                                                      May 26, 2023 13:07:51.612163067 CEST49750443192.168.2.3216.58.212.173
                                                                                      May 26, 2023 13:07:51.696618080 CEST49750443192.168.2.3216.58.212.173
                                                                                      May 26, 2023 13:07:51.696655035 CEST44349750216.58.212.173192.168.2.3
                                                                                      May 26, 2023 13:07:51.701330900 CEST44349750216.58.212.173192.168.2.3
                                                                                      May 26, 2023 13:07:51.701463938 CEST49750443192.168.2.3216.58.212.173
                                                                                      May 26, 2023 13:07:51.849123001 CEST49750443192.168.2.3216.58.212.173
                                                                                      May 26, 2023 13:07:51.849514961 CEST44349750216.58.212.173192.168.2.3
                                                                                      May 26, 2023 13:07:51.850357056 CEST49750443192.168.2.3216.58.212.173
                                                                                      May 26, 2023 13:07:51.850421906 CEST44349750216.58.212.173192.168.2.3
                                                                                      May 26, 2023 13:07:51.851481915 CEST49748443192.168.2.3142.250.186.174
                                                                                      May 26, 2023 13:07:51.851681948 CEST49748443192.168.2.3142.250.186.174
                                                                                      May 26, 2023 13:07:51.851706982 CEST44349748142.250.186.174192.168.2.3
                                                                                      May 26, 2023 13:07:51.851874113 CEST44349748142.250.186.174192.168.2.3
                                                                                      May 26, 2023 13:07:51.883640051 CEST44349748142.250.186.174192.168.2.3
                                                                                      May 26, 2023 13:07:51.883748055 CEST49748443192.168.2.3142.250.186.174
                                                                                      May 26, 2023 13:07:51.883790016 CEST44349748142.250.186.174192.168.2.3
                                                                                      May 26, 2023 13:07:51.883934975 CEST44349748142.250.186.174192.168.2.3
                                                                                      May 26, 2023 13:07:51.884023905 CEST49748443192.168.2.3142.250.186.174
                                                                                      May 26, 2023 13:07:51.884881020 CEST49748443192.168.2.3142.250.186.174
                                                                                      May 26, 2023 13:07:51.884927034 CEST44349748142.250.186.174192.168.2.3
                                                                                      May 26, 2023 13:07:51.891083002 CEST49750443192.168.2.3216.58.212.173
                                                                                      May 26, 2023 13:07:51.906132936 CEST44349750216.58.212.173192.168.2.3
                                                                                      May 26, 2023 13:07:51.906229019 CEST49750443192.168.2.3216.58.212.173
                                                                                      May 26, 2023 13:07:51.906285048 CEST44349750216.58.212.173192.168.2.3
                                                                                      May 26, 2023 13:07:51.906548023 CEST44349750216.58.212.173192.168.2.3
                                                                                      May 26, 2023 13:07:51.906622887 CEST49750443192.168.2.3216.58.212.173
                                                                                      May 26, 2023 13:07:51.907476902 CEST49750443192.168.2.3216.58.212.173
                                                                                      May 26, 2023 13:07:51.907510996 CEST44349750216.58.212.173192.168.2.3
                                                                                      May 26, 2023 13:07:55.313117981 CEST49752443192.168.2.3142.250.181.228
                                                                                      May 26, 2023 13:07:55.313199043 CEST44349752142.250.181.228192.168.2.3
                                                                                      May 26, 2023 13:07:55.313313007 CEST49752443192.168.2.3142.250.181.228
                                                                                      May 26, 2023 13:07:55.313735962 CEST49752443192.168.2.3142.250.181.228
                                                                                      May 26, 2023 13:07:55.313774109 CEST44349752142.250.181.228192.168.2.3
                                                                                      May 26, 2023 13:07:55.386934996 CEST44349752142.250.181.228192.168.2.3
                                                                                      May 26, 2023 13:07:55.387664080 CEST49752443192.168.2.3142.250.181.228
                                                                                      May 26, 2023 13:07:55.387727976 CEST44349752142.250.181.228192.168.2.3
                                                                                      May 26, 2023 13:07:55.388981104 CEST44349752142.250.181.228192.168.2.3
                                                                                      May 26, 2023 13:07:55.389168978 CEST49752443192.168.2.3142.250.181.228
                                                                                      May 26, 2023 13:07:55.391175032 CEST49752443192.168.2.3142.250.181.228
                                                                                      May 26, 2023 13:07:55.391391039 CEST44349752142.250.181.228192.168.2.3
                                                                                      May 26, 2023 13:07:55.573523998 CEST49752443192.168.2.3142.250.181.228
                                                                                      May 26, 2023 13:07:55.573576927 CEST44349752142.250.181.228192.168.2.3
                                                                                      May 26, 2023 13:07:55.674484015 CEST49752443192.168.2.3142.250.181.228
                                                                                      May 26, 2023 13:08:05.358793974 CEST44349752142.250.181.228192.168.2.3
                                                                                      May 26, 2023 13:08:05.358985901 CEST44349752142.250.181.228192.168.2.3
                                                                                      May 26, 2023 13:08:05.359230042 CEST49752443192.168.2.3142.250.181.228
                                                                                      May 26, 2023 13:08:06.161745071 CEST49752443192.168.2.3142.250.181.228
                                                                                      May 26, 2023 13:08:06.161793947 CEST44349752142.250.181.228192.168.2.3
                                                                                      May 26, 2023 13:08:35.555830002 CEST49755443192.168.2.3192.168.8.1
                                                                                      May 26, 2023 13:08:35.555891037 CEST44349755192.168.8.1192.168.2.3
                                                                                      May 26, 2023 13:08:35.556015015 CEST49755443192.168.2.3192.168.8.1
                                                                                      May 26, 2023 13:08:35.568034887 CEST49755443192.168.2.3192.168.8.1
                                                                                      May 26, 2023 13:08:35.568068981 CEST44349755192.168.8.1192.168.2.3
                                                                                      May 26, 2023 13:08:35.568293095 CEST44349755192.168.8.1192.168.2.3
                                                                                      May 26, 2023 13:08:42.017419100 CEST49756443192.168.2.3192.168.8.1
                                                                                      May 26, 2023 13:08:42.017508984 CEST44349756192.168.8.1192.168.2.3
                                                                                      May 26, 2023 13:08:42.017800093 CEST49756443192.168.2.3192.168.8.1
                                                                                      May 26, 2023 13:08:42.018251896 CEST49756443192.168.2.3192.168.8.1
                                                                                      May 26, 2023 13:08:42.018287897 CEST44349756192.168.8.1192.168.2.3
                                                                                      May 26, 2023 13:08:55.361479998 CEST49759443192.168.2.3142.250.186.164
                                                                                      May 26, 2023 13:08:55.361551046 CEST44349759142.250.186.164192.168.2.3
                                                                                      May 26, 2023 13:08:55.361722946 CEST49759443192.168.2.3142.250.186.164
                                                                                      May 26, 2023 13:08:55.362885952 CEST49759443192.168.2.3142.250.186.164
                                                                                      May 26, 2023 13:08:55.362922907 CEST44349759142.250.186.164192.168.2.3
                                                                                      May 26, 2023 13:08:55.422955990 CEST44349759142.250.186.164192.168.2.3
                                                                                      May 26, 2023 13:08:55.423672915 CEST49759443192.168.2.3142.250.186.164
                                                                                      May 26, 2023 13:08:55.423738003 CEST44349759142.250.186.164192.168.2.3
                                                                                      May 26, 2023 13:08:55.424434900 CEST44349759142.250.186.164192.168.2.3
                                                                                      May 26, 2023 13:08:55.425582886 CEST49759443192.168.2.3142.250.186.164
                                                                                      May 26, 2023 13:08:55.425769091 CEST44349759142.250.186.164192.168.2.3
                                                                                      May 26, 2023 13:08:55.466732979 CEST49759443192.168.2.3142.250.186.164
                                                                                      May 26, 2023 13:09:05.423384905 CEST44349759142.250.186.164192.168.2.3
                                                                                      May 26, 2023 13:09:05.423553944 CEST44349759142.250.186.164192.168.2.3
                                                                                      May 26, 2023 13:09:05.423917055 CEST49759443192.168.2.3142.250.186.164
                                                                                      May 26, 2023 13:09:06.164712906 CEST49759443192.168.2.3142.250.186.164
                                                                                      May 26, 2023 13:09:06.164767027 CEST44349759142.250.186.164192.168.2.3
                                                                                      May 26, 2023 13:09:12.021434069 CEST49756443192.168.2.3192.168.8.1
                                                                                      May 26, 2023 13:09:12.062843084 CEST44349756192.168.8.1192.168.2.3
                                                                                      May 26, 2023 13:09:57.067023039 CEST49756443192.168.2.3192.168.8.1
                                                                                      May 26, 2023 13:09:57.067087889 CEST44349756192.168.8.1192.168.2.3
                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                      May 26, 2023 13:07:51.363832951 CEST5731953192.168.2.31.1.1.1
                                                                                      May 26, 2023 13:07:51.364128113 CEST6067153192.168.2.31.1.1.1
                                                                                      May 26, 2023 13:07:51.380985975 CEST53573191.1.1.1192.168.2.3
                                                                                      May 26, 2023 13:07:51.381026983 CEST53606711.1.1.1192.168.2.3
                                                                                      May 26, 2023 13:07:55.273209095 CEST5160153192.168.2.31.1.1.1
                                                                                      May 26, 2023 13:07:55.290276051 CEST53516011.1.1.1192.168.2.3
                                                                                      May 26, 2023 13:07:55.293823957 CEST5824253192.168.2.31.1.1.1
                                                                                      May 26, 2023 13:07:55.310697079 CEST53582421.1.1.1192.168.2.3
                                                                                      May 26, 2023 13:08:55.321634054 CEST5892153192.168.2.31.1.1.1
                                                                                      May 26, 2023 13:08:55.338728905 CEST53589211.1.1.1192.168.2.3
                                                                                      May 26, 2023 13:08:55.342730045 CEST6029853192.168.2.31.1.1.1
                                                                                      May 26, 2023 13:08:55.359709024 CEST53602981.1.1.1192.168.2.3
                                                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                      May 26, 2023 13:07:51.363832951 CEST192.168.2.31.1.1.10x3006Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                                                                      May 26, 2023 13:07:51.364128113 CEST192.168.2.31.1.1.10xdb94Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                                                                      May 26, 2023 13:07:55.273209095 CEST192.168.2.31.1.1.10xe925Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                      May 26, 2023 13:07:55.293823957 CEST192.168.2.31.1.1.10x1322Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                      May 26, 2023 13:08:55.321634054 CEST192.168.2.31.1.1.10xcbeeStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                      May 26, 2023 13:08:55.342730045 CEST192.168.2.31.1.1.10x4804Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                      May 26, 2023 13:07:51.380985975 CEST1.1.1.1192.168.2.30x3006No error (0)accounts.google.com216.58.212.173A (IP address)IN (0x0001)false
                                                                                      May 26, 2023 13:07:51.381026983 CEST1.1.1.1192.168.2.30xdb94No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                      May 26, 2023 13:07:51.381026983 CEST1.1.1.1192.168.2.30xdb94No error (0)clients.l.google.com142.250.186.174A (IP address)IN (0x0001)false
                                                                                      May 26, 2023 13:07:55.290276051 CEST1.1.1.1192.168.2.30xe925No error (0)www.google.com142.250.181.228A (IP address)IN (0x0001)false
                                                                                      May 26, 2023 13:07:55.310697079 CEST1.1.1.1192.168.2.30x1322No error (0)www.google.com142.250.181.228A (IP address)IN (0x0001)false
                                                                                      May 26, 2023 13:08:55.338728905 CEST1.1.1.1192.168.2.30xcbeeNo error (0)www.google.com142.250.184.196A (IP address)IN (0x0001)false
                                                                                      May 26, 2023 13:08:55.359709024 CEST1.1.1.1192.168.2.30x4804No error (0)www.google.com142.250.186.164A (IP address)IN (0x0001)false
                                                                                      • accounts.google.com
                                                                                      • clients2.google.com
                                                                                      Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                      0192.168.2.349750216.58.212.173443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                      TimestampkBytes transferredDirectionData


                                                                                      Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                      1192.168.2.349748142.250.186.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                      TimestampkBytes transferredDirectionData


                                                                                      Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                      2192.168.2.349755192.168.8.1443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                      TimestampkBytes transferredDirectionData
                                                                                      May 26, 2023 13:08:35.568034887 CEST505OUTOPTIONS /VersionRequest HTTP/1.1
                                                                                      Host: 192.168.8.1:443
                                                                                      Connection: keep-alive
                                                                                      Accept: */*
                                                                                      Access-Control-Request-Method: POST
                                                                                      Access-Control-Request-Headers: content-type,x-requested-with
                                                                                      Origin: null
                                                                                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                                                                      Sec-Fetch-Mode: cors
                                                                                      Accept-Encoding: gzip, deflate
                                                                                      Accept-Language: en-US,en;q=0.9


                                                                                      Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                      0192.168.2.349750216.58.212.173443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                      TimestampkBytes transferredDirectionData
                                                                                      2023-05-26 11:07:51 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                                                                                      Host: accounts.google.com
                                                                                      Connection: keep-alive
                                                                                      Content-Length: 1
                                                                                      Origin: https://www.google.com
                                                                                      Content-Type: application/x-www-form-urlencoded
                                                                                      Sec-Fetch-Site: none
                                                                                      Sec-Fetch-Mode: no-cors
                                                                                      Sec-Fetch-Dest: empty
                                                                                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                                                                      Accept-Encoding: gzip, deflate, br
                                                                                      Accept-Language: en-US,en;q=0.9
                                                                                      Cookie: CONSENT=PENDING+620; __Secure-ENID=6.SE=cJKCBuSaL1dV3R8z2Y2al7-m2m5bGA74lqbYYkqC3uy-NtZ1f6n_bCBr25tlnnjvdmLpGQ81ZKzP3Te5vVjpSQjYWCwvlOMApK7tmZNWcORu0p4wniPJGQfTslQNnpQWhG9qkwkEgy49-6UG3UQ1eiUyFolJZWLeUM1p4KvjM9E
                                                                                      2023-05-26 11:07:51 UTC0OUTData Raw: 20
                                                                                      Data Ascii:
                                                                                      2023-05-26 11:07:51 UTC2INHTTP/1.1 200 OK
                                                                                      Content-Type: application/json; charset=utf-8
                                                                                      Access-Control-Allow-Origin: https://www.google.com
                                                                                      Access-Control-Allow-Credentials: true
                                                                                      X-Content-Type-Options: nosniff
                                                                                      Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                                                                      Pragma: no-cache
                                                                                      Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                                                                      Date: Fri, 26 May 2023 11:07:51 GMT
                                                                                      Strict-Transport-Security: max-age=31536000; includeSubDomains
                                                                                      Cross-Origin-Opener-Policy: same-origin
                                                                                      Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                                                                                      Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                                                                      Content-Security-Policy: script-src 'report-sample' 'nonce-obfGz705sOAA5WxrSp3x8g' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                                                                                      Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                                                                                      Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                                                                                      Server: ESF
                                                                                      X-XSS-Protection: 0
                                                                                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                      Accept-Ranges: none
                                                                                      Vary: Accept-Encoding
                                                                                      Connection: close
                                                                                      Transfer-Encoding: chunked
                                                                                      2023-05-26 11:07:51 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                                                                                      Data Ascii: 11["gaia.l.a.r",[]]
                                                                                      2023-05-26 11:07:51 UTC4INData Raw: 30 0d 0a 0d 0a
                                                                                      Data Ascii: 0


                                                                                      Session IDSource IPSource PortDestination IPDestination PortProcess
                                                                                      1192.168.2.349748142.250.186.174443C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                      TimestampkBytes transferredDirectionData
                                                                                      2023-05-26 11:07:51 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                                                                                      Host: clients2.google.com
                                                                                      Connection: keep-alive
                                                                                      X-Goog-Update-Interactivity: fg
                                                                                      X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                                                                                      X-Goog-Update-Updater: chromecrx-104.0.5112.102
                                                                                      Sec-Fetch-Site: none
                                                                                      Sec-Fetch-Mode: no-cors
                                                                                      Sec-Fetch-Dest: empty
                                                                                      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
                                                                                      Accept-Encoding: gzip, deflate, br
                                                                                      Accept-Language: en-US,en;q=0.9
                                                                                      2023-05-26 11:07:51 UTC1INHTTP/1.1 200 OK
                                                                                      Content-Security-Policy: script-src 'report-sample' 'nonce-5_zJDAHytnN6orshg5LahA' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                                                                                      Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                                                                      Pragma: no-cache
                                                                                      Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                                                                      Date: Fri, 26 May 2023 11:07:51 GMT
                                                                                      Content-Type: text/xml; charset=UTF-8
                                                                                      X-Daynum: 5989
                                                                                      X-Daystart: 14871
                                                                                      X-Content-Type-Options: nosniff
                                                                                      X-Frame-Options: SAMEORIGIN
                                                                                      X-XSS-Protection: 1; mode=block
                                                                                      Server: GSE
                                                                                      Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                                                                      Accept-Ranges: none
                                                                                      Vary: Accept-Encoding
                                                                                      Connection: close
                                                                                      Transfer-Encoding: chunked
                                                                                      2023-05-26 11:07:51 UTC2INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 38 39 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 31 34 38 37 31 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                                                                                      Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5989" elapsed_seconds="14871"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                                                                                      2023-05-26 11:07:51 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                                                                                      Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                                                                                      2023-05-26 11:07:51 UTC2INData Raw: 30 0d 0a 0d 0a
                                                                                      Data Ascii: 0


                                                                                      Click to jump to process

                                                                                      Click to jump to process

                                                                                      Click to jump to process

                                                                                      Target ID:0
                                                                                      Start time:13:07:48
                                                                                      Start date:26/05/2023
                                                                                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                      Wow64 process (32bit):false
                                                                                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\login.html
                                                                                      Imagebase:0x7ff70f0c0000
                                                                                      File size:2852640 bytes
                                                                                      MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                                                                                      Has elevated privileges:true
                                                                                      Has administrator privileges:true
                                                                                      Programmed in:C, C++ or other language
                                                                                      Reputation:high

                                                                                      Target ID:1
                                                                                      Start time:13:07:49
                                                                                      Start date:26/05/2023
                                                                                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                      Wow64 process (32bit):false
                                                                                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1776,i,3959098085490163762,14531336400767641844,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                                                                      Imagebase:0x7ff70f0c0000
                                                                                      File size:2852640 bytes
                                                                                      MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                                                                                      Has elevated privileges:true
                                                                                      Has administrator privileges:true
                                                                                      Programmed in:C, C++ or other language
                                                                                      Reputation:high

                                                                                      No disassembly