Edit tour

Windows Analysis Report
http://uodrle.com

Overview

General Information

Sample URL:http://uodrle.com
Analysis ID:1378871
Infos:
Errors
  • URL not reachable

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Snort IDS alert for network traffic

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 1620 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4944 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=2244,i,6226501050019006142,7998128323453965157,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6484 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://uodrle.com MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
Timestamp:1.1.1.1192.168.2.453550602811577 01/22/24-16:49:46.933180
SID:2811577
Source Port:53
Destination Port:55060
Protocol:UDP
Classtype:A Network Trojan was detected

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://uodrle.comAvira URL Cloud: detection malicious, Label: phishing
Source: http://uodrle.comSlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering

Networking

barindex
Source: TrafficSnort IDS: 2811577 ETPRO TROJAN Possible Virut DGA NXDOMAIN Responses (com) 1.1.1.1:53 -> 192.168.2.4:55060
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: classification engineClassification label: mal56.win@19/0@16/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=2244,i,6226501050019006142,7998128323453965157,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://uodrle.com
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=2244,i,6226501050019006142,7998128323453965157,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
Domain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Data Encrypted for ImpactDNS ServerEmail Addresses
Local AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureTraffic Duplication1
Ingress Tool Transfer
Data DestructionVirtual Private ServerEmployee Names
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1378871 URL: http://uodrle.com Startdate: 22/01/2024 Architecture: WINDOWS Score: 56 15 uodrle.com 2->15 17 fp2e7a.wpc.phicdn.net 2->17 19 fp2e7a.wpc.2be4.phicdn.net 2->19 33 Snort IDS alert for network traffic 2->33 35 Antivirus / Scanner detection for submitted sample 2->35 7 chrome.exe 2->7         started        10 chrome.exe 2->10         started        signatures3 process4 dnsIp5 21 192.168.2.4, 138, 443, 49730 unknown unknown 7->21 23 192.168.2.16 unknown unknown 7->23 25 239.255.255.250 unknown Reserved 7->25 12 chrome.exe 7->12         started        process6 dnsIp7 27 accounts.google.com 142.250.105.84, 443, 49730 GOOGLEUS United States 12->27 29 www.google.com 142.250.9.147, 443, 49736 GOOGLEUS United States 12->29 31 4 other IPs or domains 12->31

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://uodrle.com100%Avira URL Cloudphishing
http://uodrle.com100%SlashNextCredential Stealing type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
google.com
172.253.126.113
truefalse
    high
    accounts.google.com
    142.250.105.84
    truefalse
      high
      www.google.com
      142.250.9.147
      truefalse
        high
        clients.l.google.com
        64.233.185.139
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            clients2.google.com
            unknown
            unknownfalse
              high
              uodrle.com
              unknown
              unknownfalse
                unknown
                NameMaliciousAntivirus DetectionReputation
                https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
                  high
                  https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    142.250.105.84
                    accounts.google.comUnited States
                    15169GOOGLEUSfalse
                    142.250.9.147
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    64.233.185.139
                    clients.l.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.16
                    192.168.2.4
                    Joe Sandbox version:38.0.0 Ammolite
                    Analysis ID:1378871
                    Start date and time:2024-01-22 16:48:46 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 1m 58s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://uodrle.com
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:7
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:MAL
                    Classification:mal56.win@19/0@16/6
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    Cookbook Comments:
                    • URL browsing timeout or error
                    • URL not reachable
                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 142.251.15.94, 34.104.35.123, 23.208.128.100, 40.68.123.157, 72.21.81.240, 192.229.211.108, 13.95.31.18
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    • VT rate limit hit for: http://uodrle.com
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    No created / dropped files found
                    No static file info

                    Download Network PCAP: filteredfull

                    TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                    1.1.1.1192.168.2.453550602811577 01/22/24-16:49:46.933180UDP2811577ETPRO TROJAN Possible Virut DGA NXDOMAIN Responses (com)53550601.1.1.1192.168.2.4
                    • Total Packets: 49
                    • 443 (HTTPS)
                    • 53 (DNS)
                    TimestampSource PortDest PortSource IPDest IP
                    Jan 22, 2024 16:49:36.551909924 CET49675443192.168.2.4173.222.162.32
                    Jan 22, 2024 16:49:44.383436918 CET49730443192.168.2.4142.250.105.84
                    Jan 22, 2024 16:49:44.383483887 CET44349730142.250.105.84192.168.2.4
                    Jan 22, 2024 16:49:44.383538008 CET49730443192.168.2.4142.250.105.84
                    Jan 22, 2024 16:49:44.383965015 CET49731443192.168.2.464.233.185.139
                    Jan 22, 2024 16:49:44.384027004 CET4434973164.233.185.139192.168.2.4
                    Jan 22, 2024 16:49:44.384102106 CET49731443192.168.2.464.233.185.139
                    Jan 22, 2024 16:49:44.384382963 CET49730443192.168.2.4142.250.105.84
                    Jan 22, 2024 16:49:44.384401083 CET44349730142.250.105.84192.168.2.4
                    Jan 22, 2024 16:49:44.384639978 CET49731443192.168.2.464.233.185.139
                    Jan 22, 2024 16:49:44.384671926 CET4434973164.233.185.139192.168.2.4
                    Jan 22, 2024 16:49:44.626471996 CET4434973164.233.185.139192.168.2.4
                    Jan 22, 2024 16:49:44.627054930 CET49731443192.168.2.464.233.185.139
                    Jan 22, 2024 16:49:44.627073050 CET4434973164.233.185.139192.168.2.4
                    Jan 22, 2024 16:49:44.627778053 CET4434973164.233.185.139192.168.2.4
                    Jan 22, 2024 16:49:44.627836943 CET49731443192.168.2.464.233.185.139
                    Jan 22, 2024 16:49:44.629414082 CET4434973164.233.185.139192.168.2.4
                    Jan 22, 2024 16:49:44.629463911 CET49731443192.168.2.464.233.185.139
                    Jan 22, 2024 16:49:44.632193089 CET49731443192.168.2.464.233.185.139
                    Jan 22, 2024 16:49:44.632277012 CET4434973164.233.185.139192.168.2.4
                    Jan 22, 2024 16:49:44.632463932 CET49731443192.168.2.464.233.185.139
                    Jan 22, 2024 16:49:44.632472038 CET4434973164.233.185.139192.168.2.4
                    Jan 22, 2024 16:49:44.634443045 CET44349730142.250.105.84192.168.2.4
                    Jan 22, 2024 16:49:44.634659052 CET49730443192.168.2.4142.250.105.84
                    Jan 22, 2024 16:49:44.634675980 CET44349730142.250.105.84192.168.2.4
                    Jan 22, 2024 16:49:44.636924982 CET44349730142.250.105.84192.168.2.4
                    Jan 22, 2024 16:49:44.636985064 CET49730443192.168.2.4142.250.105.84
                    Jan 22, 2024 16:49:44.638834000 CET49730443192.168.2.4142.250.105.84
                    Jan 22, 2024 16:49:44.638926983 CET44349730142.250.105.84192.168.2.4
                    Jan 22, 2024 16:49:44.639141083 CET49730443192.168.2.4142.250.105.84
                    Jan 22, 2024 16:49:44.639151096 CET44349730142.250.105.84192.168.2.4
                    Jan 22, 2024 16:49:44.676084995 CET49731443192.168.2.464.233.185.139
                    Jan 22, 2024 16:49:44.696722031 CET49730443192.168.2.4142.250.105.84
                    Jan 22, 2024 16:49:44.832408905 CET4434973164.233.185.139192.168.2.4
                    Jan 22, 2024 16:49:44.832601070 CET4434973164.233.185.139192.168.2.4
                    Jan 22, 2024 16:49:44.832654953 CET49731443192.168.2.464.233.185.139
                    Jan 22, 2024 16:49:44.833702087 CET49731443192.168.2.464.233.185.139
                    Jan 22, 2024 16:49:44.833719969 CET4434973164.233.185.139192.168.2.4
                    Jan 22, 2024 16:49:44.862270117 CET44349730142.250.105.84192.168.2.4
                    Jan 22, 2024 16:49:44.862464905 CET44349730142.250.105.84192.168.2.4
                    Jan 22, 2024 16:49:44.862534046 CET49730443192.168.2.4142.250.105.84
                    Jan 22, 2024 16:49:44.864475965 CET49730443192.168.2.4142.250.105.84
                    Jan 22, 2024 16:49:44.864497900 CET44349730142.250.105.84192.168.2.4
                    Jan 22, 2024 16:49:46.165116072 CET49675443192.168.2.4173.222.162.32
                    Jan 22, 2024 16:49:48.818511963 CET49736443192.168.2.4142.250.9.147
                    Jan 22, 2024 16:49:48.818592072 CET44349736142.250.9.147192.168.2.4
                    Jan 22, 2024 16:49:48.818752050 CET49736443192.168.2.4142.250.9.147
                    Jan 22, 2024 16:49:48.819014072 CET49736443192.168.2.4142.250.9.147
                    Jan 22, 2024 16:49:48.819051027 CET44349736142.250.9.147192.168.2.4
                    Jan 22, 2024 16:49:49.043873072 CET44349736142.250.9.147192.168.2.4
                    Jan 22, 2024 16:49:49.044482946 CET49736443192.168.2.4142.250.9.147
                    Jan 22, 2024 16:49:49.044512033 CET44349736142.250.9.147192.168.2.4
                    Jan 22, 2024 16:49:49.046231985 CET44349736142.250.9.147192.168.2.4
                    Jan 22, 2024 16:49:49.046303034 CET49736443192.168.2.4142.250.9.147
                    Jan 22, 2024 16:49:49.048513889 CET49736443192.168.2.4142.250.9.147
                    Jan 22, 2024 16:49:49.048610926 CET44349736142.250.9.147192.168.2.4
                    Jan 22, 2024 16:49:49.097533941 CET49736443192.168.2.4142.250.9.147
                    Jan 22, 2024 16:49:49.097553015 CET44349736142.250.9.147192.168.2.4
                    Jan 22, 2024 16:49:49.144437075 CET49736443192.168.2.4142.250.9.147
                    Jan 22, 2024 16:49:59.044182062 CET44349736142.250.9.147192.168.2.4
                    Jan 22, 2024 16:49:59.044255018 CET44349736142.250.9.147192.168.2.4
                    Jan 22, 2024 16:49:59.044337034 CET49736443192.168.2.4142.250.9.147
                    Jan 22, 2024 16:50:00.553324938 CET49736443192.168.2.4142.250.9.147
                    Jan 22, 2024 16:50:00.553343058 CET44349736142.250.9.147192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Jan 22, 2024 16:49:44.241630077 CET6085453192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:44.241849899 CET5568053192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:44.242345095 CET5402253192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:44.242626905 CET5828453192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:44.360471964 CET53608541.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:44.360841036 CET53556801.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:44.360896111 CET53540221.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:44.361121893 CET53582841.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:45.011296988 CET53629151.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:45.454186916 CET5808553192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:45.454615116 CET6413253192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:45.575177908 CET53641321.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:45.624063969 CET53580851.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:45.624882936 CET5650853192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:45.744004011 CET53565081.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:45.776913881 CET5702753192.168.2.48.8.8.8
                    Jan 22, 2024 16:49:45.777340889 CET5561353192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:45.881915092 CET53570278.8.8.8192.168.2.4
                    Jan 22, 2024 16:49:45.896146059 CET53556131.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:46.793548107 CET5321553192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:46.793932915 CET5506053192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:46.925869942 CET53532151.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:46.933180094 CET53550601.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:48.408912897 CET5787353192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:48.409354925 CET5635853192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:48.527170897 CET53578731.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:48.528027058 CET53563581.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:52.018455982 CET6252453192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:52.020193100 CET5403053192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:52.150669098 CET53625241.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:52.152406931 CET53540301.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:52.153023958 CET5163153192.168.2.41.1.1.1
                    Jan 22, 2024 16:49:52.274625063 CET53516311.1.1.1192.168.2.4
                    Jan 22, 2024 16:49:59.017364025 CET138138192.168.2.4192.168.2.255
                    Jan 22, 2024 16:50:02.155875921 CET53617081.1.1.1192.168.2.4
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Jan 22, 2024 16:49:44.241630077 CET192.168.2.41.1.1.10x36ffStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:44.241849899 CET192.168.2.41.1.1.10x4ae6Standard query (0)clients2.google.com65IN (0x0001)false
                    Jan 22, 2024 16:49:44.242345095 CET192.168.2.41.1.1.10x3740Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:44.242626905 CET192.168.2.41.1.1.10x2d32Standard query (0)accounts.google.com65IN (0x0001)false
                    Jan 22, 2024 16:49:45.454186916 CET192.168.2.41.1.1.10x51c8Standard query (0)uodrle.comA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.454615116 CET192.168.2.41.1.1.10xf27Standard query (0)uodrle.com65IN (0x0001)false
                    Jan 22, 2024 16:49:45.624882936 CET192.168.2.41.1.1.10xbd49Standard query (0)uodrle.comA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.776913881 CET192.168.2.48.8.8.80x888cStandard query (0)google.comA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.777340889 CET192.168.2.41.1.1.10x335aStandard query (0)google.comA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:46.793548107 CET192.168.2.41.1.1.10x5bfStandard query (0)uodrle.comA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:46.793932915 CET192.168.2.41.1.1.10x7136Standard query (0)uodrle.com65IN (0x0001)false
                    Jan 22, 2024 16:49:48.408912897 CET192.168.2.41.1.1.10x181Standard query (0)www.google.comA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:48.409354925 CET192.168.2.41.1.1.10x5502Standard query (0)www.google.com65IN (0x0001)false
                    Jan 22, 2024 16:49:52.018455982 CET192.168.2.41.1.1.10xa0b3Standard query (0)uodrle.comA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:52.020193100 CET192.168.2.41.1.1.10x4650Standard query (0)uodrle.com65IN (0x0001)false
                    Jan 22, 2024 16:49:52.153023958 CET192.168.2.41.1.1.10x2e8bStandard query (0)uodrle.comA (IP address)IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Jan 22, 2024 16:49:44.360471964 CET1.1.1.1192.168.2.40x36ffNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Jan 22, 2024 16:49:44.360471964 CET1.1.1.1192.168.2.40x36ffNo error (0)clients.l.google.com64.233.185.139A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:44.360471964 CET1.1.1.1192.168.2.40x36ffNo error (0)clients.l.google.com64.233.185.101A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:44.360471964 CET1.1.1.1192.168.2.40x36ffNo error (0)clients.l.google.com64.233.185.100A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:44.360471964 CET1.1.1.1192.168.2.40x36ffNo error (0)clients.l.google.com64.233.185.138A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:44.360471964 CET1.1.1.1192.168.2.40x36ffNo error (0)clients.l.google.com64.233.185.113A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:44.360471964 CET1.1.1.1192.168.2.40x36ffNo error (0)clients.l.google.com64.233.185.102A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:44.360841036 CET1.1.1.1192.168.2.40x4ae6No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Jan 22, 2024 16:49:44.360896111 CET1.1.1.1192.168.2.40x3740No error (0)accounts.google.com142.250.105.84A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.575177908 CET1.1.1.1192.168.2.40xf27Name error (3)uodrle.comnonenone65IN (0x0001)false
                    Jan 22, 2024 16:49:45.624063969 CET1.1.1.1192.168.2.40x51c8Name error (3)uodrle.comnonenoneA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.744004011 CET1.1.1.1192.168.2.40xbd49Name error (3)uodrle.comnonenoneA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.881915092 CET8.8.8.8192.168.2.40x888cNo error (0)google.com172.253.126.113A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.881915092 CET8.8.8.8192.168.2.40x888cNo error (0)google.com172.253.126.138A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.881915092 CET8.8.8.8192.168.2.40x888cNo error (0)google.com172.253.126.139A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.881915092 CET8.8.8.8192.168.2.40x888cNo error (0)google.com172.253.126.102A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.881915092 CET8.8.8.8192.168.2.40x888cNo error (0)google.com172.253.126.101A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.881915092 CET8.8.8.8192.168.2.40x888cNo error (0)google.com172.253.126.100A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.896146059 CET1.1.1.1192.168.2.40x335aNo error (0)google.com64.233.185.138A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.896146059 CET1.1.1.1192.168.2.40x335aNo error (0)google.com64.233.185.102A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.896146059 CET1.1.1.1192.168.2.40x335aNo error (0)google.com64.233.185.113A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.896146059 CET1.1.1.1192.168.2.40x335aNo error (0)google.com64.233.185.100A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.896146059 CET1.1.1.1192.168.2.40x335aNo error (0)google.com64.233.185.139A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:45.896146059 CET1.1.1.1192.168.2.40x335aNo error (0)google.com64.233.185.101A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:46.925869942 CET1.1.1.1192.168.2.40x5bfName error (3)uodrle.comnonenoneA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:46.933180094 CET1.1.1.1192.168.2.40x7136Name error (3)uodrle.comnonenone65IN (0x0001)false
                    Jan 22, 2024 16:49:48.527170897 CET1.1.1.1192.168.2.40x181No error (0)www.google.com142.250.9.147A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:48.527170897 CET1.1.1.1192.168.2.40x181No error (0)www.google.com142.250.9.105A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:48.527170897 CET1.1.1.1192.168.2.40x181No error (0)www.google.com142.250.9.104A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:48.527170897 CET1.1.1.1192.168.2.40x181No error (0)www.google.com142.250.9.103A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:48.527170897 CET1.1.1.1192.168.2.40x181No error (0)www.google.com142.250.9.106A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:48.527170897 CET1.1.1.1192.168.2.40x181No error (0)www.google.com142.250.9.99A (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:48.528027058 CET1.1.1.1192.168.2.40x5502No error (0)www.google.com65IN (0x0001)false
                    Jan 22, 2024 16:49:52.150669098 CET1.1.1.1192.168.2.40xa0b3Name error (3)uodrle.comnonenoneA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:49:52.152406931 CET1.1.1.1192.168.2.40x4650Name error (3)uodrle.comnonenone65IN (0x0001)false
                    Jan 22, 2024 16:49:52.274625063 CET1.1.1.1192.168.2.40x2e8bName error (3)uodrle.comnonenoneA (IP address)IN (0x0001)false
                    Jan 22, 2024 16:50:01.569595098 CET1.1.1.1192.168.2.40xcf49No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Jan 22, 2024 16:50:01.569595098 CET1.1.1.1192.168.2.40xcf49No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    • clients2.google.com
                    • accounts.google.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.44973164.233.185.1394434944C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-01-22 15:49:44 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                    Host: clients2.google.com
                    Connection: keep-alive
                    X-Goog-Update-Interactivity: fg
                    X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                    X-Goog-Update-Updater: chromecrx-117.0.5938.132
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-01-22 15:49:44 UTC732INHTTP/1.1 200 OK
                    Content-Security-Policy: script-src 'report-sample' 'nonce-bhGpYuTA_4rPWohtakNKsw' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Mon, 22 Jan 2024 15:49:44 GMT
                    Content-Type: text/xml; charset=UTF-8
                    X-Daynum: 6230
                    X-Daystart: 28184
                    X-Content-Type-Options: nosniff
                    X-Frame-Options: SAMEORIGIN
                    X-XSS-Protection: 1; mode=block
                    Server: GSE
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2024-01-22 15:49:44 UTC520INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 32 33 30 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 32 38 31 38 34 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                    Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6230" elapsed_seconds="28184"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                    2024-01-22 15:49:44 UTC200INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                    Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                    2024-01-22 15:49:44 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.449730142.250.105.844434944C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-01-22 15:49:44 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                    Host: accounts.google.com
                    Connection: keep-alive
                    Content-Length: 1
                    Origin: https://www.google.com
                    Content-Type: application/x-www-form-urlencoded
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
                    2024-01-22 15:49:44 UTC1OUTData Raw: 20
                    Data Ascii:
                    2024-01-22 15:49:44 UTC1627INHTTP/1.1 200 OK
                    Content-Type: application/json; charset=utf-8
                    Access-Control-Allow-Origin: https://www.google.com
                    Access-Control-Allow-Credentials: true
                    X-Content-Type-Options: nosniff
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Mon, 22 Jan 2024 15:49:44 GMT
                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                    Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                    Content-Security-Policy: script-src 'report-sample' 'nonce-uwgTBJ6MNmJ47xleuco8sQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                    Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                    Cross-Origin-Opener-Policy: same-origin
                    Server: ESF
                    X-XSS-Protection: 0
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2024-01-22 15:49:44 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                    Data Ascii: 11["gaia.l.a.r",[]]
                    2024-01-22 15:49:44 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    05101520s020406080100

                    Click to jump to process

                    05101520s0.0020406080100MB

                    Click to jump to process

                    Target ID:0
                    Start time:16:49:39
                    Start date:22/01/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:16:49:42
                    Start date:22/01/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=2244,i,6226501050019006142,7998128323453965157,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:16:49:44
                    Start date:22/01/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://uodrle.com
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                    There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                    No disassembly