Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://biruuq.com/f.php?e=br2PMEkzX4etGTJQWDungH49fmtueHVYY3lUMlNtQmowN3Y4WGd6LzdFUVB6dUZXNllHUE1NQndDaEdlcTJURC9qQ1R0VHBHWWIxY2R4UHlwWXNCcmhRQVcyalQ3K0VFWFU4RUtsaHluWE9kYnc1U0MwYVdLOHVsZ2NvWDNnV21rM3BNVFJVekpEdTh3NjFBbXhQMVExKzA3dytjcHJEcVpRTCsrcEM3UUozNXdPSXl2dUZ3OEpXZXFpMUNSaXdsdFE2TjYxR2x1NVZpe

Overview

General Information

Sample URL:https://biruuq.com/f.php?e=br2PMEkzX4etGTJQWDungH49fmtueHVYY3lUMlNtQmowN3Y4WGd6LzdFUVB6dUZXNllHUE1NQndDaEdlcTJURC9qQ1R0VHBHWWIxY2R4UHlwWXNCcmhRQVcyalQ3K0VFWFU4RUtsaHluWE9kYnc1U0MwYVdLOHVsZ2NvWDNnV21rM
Analysis ID:1542423
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

  • System is w7x64
  • chrome.exe (PID: 2424 cmdline: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: FFA2B8E17F645BCC20F0E0201FEF83ED)
    • chrome.exe (PID: 1224 cmdline: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1460 --field-trial-handle=1264,i,6515938508693869711,13721224092671204226,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: FFA2B8E17F645BCC20F0E0201FEF83ED)
  • chrome.exe (PID: 240 cmdline: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "https://biruuq.com/f.php?e=br2PMEkzX4etGTJQWDungH49fmtueHVYY3lUMlNtQmowN3Y4WGd6LzdFUVB6dUZXNllHUE1NQndDaEdlcTJURC9qQ1R0VHBHWWIxY2R4UHlwWXNCcmhRQVcyalQ3K0VFWFU4RUtsaHluWE9kYnc1U0MwYVdLOHVsZ2NvWDNnV21rM3BNVFJVekpEdTh3NjFBbXhQMVExKzA3dytjcHJEcVpRTCsrcEM3UUozNXdPSXl2dUZ3OEpXZXFpMUNSaXdsdFE2TjYxR2x1NVZpeWhNbmYxblg3amM1WTFlUEZIVmRTaHQ2YkdvZFhTYld3MWRSN3JxNkw2U1FkRHNGTFpIMzkyb2I0WDROWm1taERuNHlhZWRlemZQT0pIVFZYb2lVUGhTOU9qNmJSNXhrTEVURXAxSVlEblRXQTFaYjdGUVlyOVNaa3ZGS3h1eERKMzNiMk1vRkdyUkFPTmNyc1hqV092MCtEak1oK01OblNZdmNCSHRkWFVtdWVjTXFUUHE4MjdZa0pIdVdGaDUyQkJnbmtJdVJDYVgxczdod0FkWFlIUmxFTTdsUzJYSHdtWEFRU1JYM0tzangyOHlOb0c3bE1YWFNuWkJYWm1hS29tQjkxUjBFbXBzbktsbXp6VGh0VVU5M0ZjVnMvaVBoZFEySGF5eitQd3ZPdUMzMkVmalZDN0dtVW96MEZTdXloT0g0RDFJQ3Z6bFpVWVl3NUV1QmRxS0p2WHJxcVY2WkVqck54NGEzV3hRUFlraXdCK09uZzlTaXVKWmdYQ2pZT0ZsWUZJVjBwb2VLNjMrQ0JKbjQxMXh0RUcvVVB4M1VGSzlWMnhLYlUraXdaYXgvTFRmSHgwUG5Id1BTZEEyUXJJS2lHdmZaRTRGUTZHVVhuUUR3ZHJFeXJKUmdqc0crck4rTUdUdWh1N3krYVR0QldXQU4rSGRBS0Z2L0N3RitlTjh0a09YNzBranUyQ1Z0QXB3QU1mNzdjWE1nQnNJWkw2N3lKK1d3MXRLQmZuTnpCalVwZG1jai81YXBEMlFwVmhSRDFoZmlaMS8vRU9TaXREUGRHNitQUXBlVDhMa3lZK0tsZk1OL2NaRXdSSWU5eklCOHFjcnRsdk9rYVpkdVduY1lmRHd3bm5PN1FZSkNtREFZcjRnZjRBanFSN1hTWHlKcEQ0SWpKeVh5M2x0Y2pWcTMyUGlYTjZwRWdoZXp0ejFOS2I0OXNmSHErTnJSY1UyK21ld29vNlBzdVRhNi9sQnZsZEJUQWQrZnN2bmliMlBNNGtRWGYzL3AvVmdQa1g0YWZtTXZSdkRLTHZEUC92TDhNZlkrVTRWYlE9PQ%3D%3D&fp=3f9689c9c10f3e5af454abad6931a2b8" MD5: FFA2B8E17F645BCC20F0E0201FEF83ED)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\GoogleJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_2424_1607448395Jump to behavior
Source: global trafficHTTP traffic detected: GET /f.php?e=br2PMEkzX4etGTJQWDungH49fmtueHVYY3lUMlNtQmowN3Y4WGd6LzdFUVB6dUZXNllHUE1NQndDaEdlcTJURC9qQ1R0VHBHWWIxY2R4UHlwWXNCcmhRQVcyalQ3K0VFWFU4RUtsaHluWE9kYnc1U0MwYVdLOHVsZ2NvWDNnV21rM3BNVFJVekpEdTh3NjFBbXhQMVExKzA3dytjcHJEcVpRTCsrcEM3UUozNXdPSXl2dUZ3OEpXZXFpMUNSaXdsdFE2TjYxR2x1NVZpeWhNbmYxblg3amM1WTFlUEZIVmRTaHQ2YkdvZFhTYld3MWRSN3JxNkw2U1FkRHNGTFpIMzkyb2I0WDROWm1taERuNHlhZWRlemZQT0pIVFZYb2lVUGhTOU9qNmJSNXhrTEVURXAxSVlEblRXQTFaYjdGUVlyOVNaa3ZGS3h1eERKMzNiMk1vRkdyUkFPTmNyc1hqV092MCtEak1oK01OblNZdmNCSHRkWFVtdWVjTXFUUHE4MjdZa0pIdVdGaDUyQkJnbmtJdVJDYVgxczdod0FkWFlIUmxFTTdsUzJYSHdtWEFRU1JYM0tzangyOHlOb0c3bE1YWFNuWkJYWm1hS29tQjkxUjBFbXBzbktsbXp6VGh0VVU5M0ZjVnMvaVBoZFEySGF5eitQd3ZPdUMzMkVmalZDN0dtVW96MEZTdXloT0g0RDFJQ3Z6bFpVWVl3NUV1QmRxS0p2WHJxcVY2WkVqck54NGEzV3hRUFlraXdCK09uZzlTaXVKWmdYQ2pZT0ZsWUZJVjBwb2VLNjMrQ0JKbjQxMXh0RUcvVVB4M1VGSzlWMnhLYlUraXdaYXgvTFRmSHgwUG5Id1BTZEEyUXJJS2lHdmZaRTRGUTZHVVhuUUR3ZHJFeXJKUmdqc0crck4rTUdUdWh1N3krYVR0QldXQU4rSGRBS0Z2L0N3RitlTjh0a09YNzBranUyQ1Z0QXB3QU1mNzdjWE1nQnNJWkw2N3lKK1d3MXRLQmZuTnpCalVwZG1jai81YXBEMlFwVmhSRDFoZmlaMS8vRU9TaXREUGRHNitQUXBlVDhMa3lZK0tsZk1OL2NaRXdSSWU5eklCOHFjcnRsdk9rYVpkdVduY1lmRHd3bm5PN1FZSkNtREFZcjRnZjRBanFSN1hTWHlKcEQ0SWpKeVh5M2x0Y2pWcTMyUGlYTjZwRWdoZXp0ejFOS2I0OXNmSHErTnJSY1UyK21ld29vNlBzdVRhNi9sQnZsZEJUQWQrZnN2bmliMlBNNGtRWGYzL3AvVmdQa1g0YWZtTXZSdkRLTHZEUC92TDhNZlkrVTRWYlE9PQ%3D%3D&fp=3f9689c9c10f3e5af454abad6931a2b8 HTTP/1.1Host: biruuq.comConnection: keep-alivesec-ch-ua: "Not_A Brand";v="99", "Google Chrome";v="109", "Chromium";v="109"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: biruuq.comConnection: keep-alivesec-ch-ua: "Not_A Brand";v="99", "Google Chrome";v="109", "Chromium";v="109"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://biruuq.com/f.php?e=br2PMEkzX4etGTJQWDungH49fmtueHVYY3lUMlNtQmowN3Y4WGd6LzdFUVB6dUZXNllHUE1NQndDaEdlcTJURC9qQ1R0VHBHWWIxY2R4UHlwWXNCcmhRQVcyalQ3K0VFWFU4RUtsaHluWE9kYnc1U0MwYVdLOHVsZ2NvWDNnV21rM3BNVFJVekpEdTh3NjFBbXhQMVExKzA3dytjcHJEcVpRTCsrcEM3UUozNXdPSXl2dUZ3OEpXZXFpMUNSaXdsdFE2TjYxR2x1NVZpeWhNbmYxblg3amM1WTFlUEZIVmRTaHQ2YkdvZFhTYld3MWRSN3JxNkw2U1FkRHNGTFpIMzkyb2I0WDROWm1taERuNHlhZWRlemZQT0pIVFZYb2lVUGhTOU9qNmJSNXhrTEVURXAxSVlEblRXQTFaYjdGUVlyOVNaa3ZGS3h1eERKMzNiMk1vRkdyUkFPTmNyc1hqV092MCtEak1oK01OblNZdmNCSHRkWFVtdWVjTXFUUHE4MjdZa0pIdVdGaDUyQkJnbmtJdVJDYVgxczdod0FkWFlIUmxFTTdsUzJYSHdtWEFRU1JYM0tzangyOHlOb0c3bE1YWFNuWkJYWm1hS29tQjkxUjBFbXBzbktsbXp6VGh0VVU5M0ZjVnMvaVBoZFEySGF5eitQd3ZPdUMzMkVmalZDN0dtVW96MEZTdXloT0g0RDFJQ3Z6bFpVWVl3NUV1QmRxS0p2WHJxcVY2WkVqck54NGEzV3hRUFlraXdCK09uZzlTaXVKWmdYQ2pZT0ZsWUZJVjBwb2VLNjMrQ0JKbjQxMXh0RUcvVVB4M1VGSzlWMnhLYlUraXdaYXgvTFRmSHgwUG5Id1BTZEEyUXJJS2lHdmZaRTRGUTZHVVhuUUR3ZHJFeXJKUmdqc0crck4rTUdUdWh1N3krYVR0QldXQU4rSGRBS0Z2L0N3RitlTjh0a09YNzBranUyQ1Z0QXB3QU1mNzdjWE1nQnNJWkw2N3lKK1d3MXRLQmZuTnpCalVwZG1jai81YXBEMlFwVmhSRDFoZmlaMS8vRU9TaXREUGRHNitQUXBlVDhMa3lZK0tsZk1OL2NaRXdSSWU5eklCOHFjcnRsdk9rYVpkdVduY1lmRHd3bm5PN1FZSkNtREFZcjRnZjRBanFSN1hTWHlKcEQ0SWpKeVh5M2x0Y2pWcTMyUGlYTjZwRWdoZXp0ejFOS2I0OXNmSHErTnJSY1UyK21ld29vNlBzdVRhNi9sQnZsZEJUQWQrZnN2bmliMlBNNGtRWGYzL3AvVmdQa1g0YWZtTXZSdkRLTHZEUC92TDhNZlkrVTRWYlE9PQ%3D%3D&fp=3f9689c9c10f3e5af454abad6931a2b8Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: biruuq.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49169
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49167
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49166
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49171
Source: unknownNetwork traffic detected: HTTP traffic on port 49169 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49167 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49171 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49166 -> 443
Source: classification engineClassification label: clean0.win@18/4@4/3
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\GoogleJump to behavior
Source: unknownProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1460 --field-trial-handle=1264,i,6515938508693869711,13721224092671204226,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "https://biruuq.com/f.php?e=br2PMEkzX4etGTJQWDungH49fmtueHVYY3lUMlNtQmowN3Y4WGd6LzdFUVB6dUZXNllHUE1NQndDaEdlcTJURC9qQ1R0VHBHWWIxY2R4UHlwWXNCcmhRQVcyalQ3K0VFWFU4RUtsaHluWE9kYnc1U0MwYVdLOHVsZ2NvWDNnV21rM3BNVFJVekpEdTh3NjFBbXhQMVExKzA3dytjcHJEcVpRTCsrcEM3UUozNXdPSXl2dUZ3OEpXZXFpMUNSaXdsdFE2TjYxR2x1NVZpeWhNbmYxblg3amM1WTFlUEZIVmRTaHQ2YkdvZFhTYld3MWRSN3JxNkw2U1FkRHNGTFpIMzkyb2I0WDROWm1taERuNHlhZWRlemZQT0pIVFZYb2lVUGhTOU9qNmJSNXhrTEVURXAxSVlEblRXQTFaYjdGUVlyOVNaa3ZGS3h1eERKMzNiMk1vRkdyUkFPTmNyc1hqV092MCtEak1oK01OblNZdmNCSHRkWFVtdWVjTXFUUHE4MjdZa0pIdVdGaDUyQkJnbmtJdVJDYVgxczdod0FkWFlIUmxFTTdsUzJYSHdtWEFRU1JYM0tzangyOHlOb0c3bE1YWFNuWkJYWm1hS29tQjkxUjBFbXBzbktsbXp6VGh0VVU5M0ZjVnMvaVBoZFEySGF5eitQd3ZPdUMzMkVmalZDN0dtVW96MEZTdXloT0g0RDFJQ3Z6bFpVWVl3NUV1QmRxS0p2WHJxcVY2WkVqck54NGEzV3hRUFlraXdCK09uZzlTaXVKWmdYQ2pZT0ZsWUZJVjBwb2VLNjMrQ0JKbjQxMXh0RUcvVVB4M1VGSzlWMnhLYlUraXdaYXgvTFRmSHgwUG5Id1BTZEEyUXJJS2lHdmZaRTRGUTZHVVhuUUR3ZHJFeXJKUmdqc0crck4rTUdUdWh1N3krYVR0QldXQU4rSGRBS0Z2L0N3RitlTjh0a09YNzBranUyQ1Z0QXB3QU1mNzdjWE1nQnNJWkw2N3lKK1d3MXRLQmZuTnpCalVwZG1jai81YXBEMlFwVmhSRDFoZmlaMS8vRU9TaXREUGRHNitQUXBlVDhMa3lZK0tsZk1OL2NaRXdSSWU5eklCOHFjcnRsdk9rYVpkdVduY1lmRHd3bm5PN1FZSkNtREFZcjRnZjRBanFSN1hTWHlKcEQ0SWpKeVh5M2x0Y2pWcTMyUGlYTjZwRWdoZXp0ejFOS2I0OXNmSHErTnJSY1UyK21ld29vNlBzdVRhNi9sQnZsZEJUQWQrZnN2bmliMlBNNGtRWGYzL3AvVmdQa1g0YWZtTXZSdkRLTHZEUC92TDhNZlkrVTRWYlE9PQ%3D%3D&fp=3f9689c9c10f3e5af454abad6931a2b8"
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1460 --field-trial-handle=1264,i,6515938508693869711,13721224092671204226,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\GoogleJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\chrome_BITS_2424_1607448395Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
172.217.18.4
truefalse
    unknown
    biruuq.com
    103.224.182.206
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      https://biruuq.com/favicon.icofalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        103.224.182.206
        biruuq.comAustralia
        133618TRELLIAN-AS-APTrellianPtyLimitedAUfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        172.217.18.4
        www.google.comUnited States
        15169GOOGLEUSfalse
        Joe Sandbox version:41.0.0 Charoite
        Analysis ID:1542423
        Start date and time:2024-10-25 22:28:38 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 55s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://biruuq.com/f.php?e=br2PMEkzX4etGTJQWDungH49fmtueHVYY3lUMlNtQmowN3Y4WGd6LzdFUVB6dUZXNllHUE1NQndDaEdlcTJURC9qQ1R0VHBHWWIxY2R4UHlwWXNCcmhRQVcyalQ3K0VFWFU4RUtsaHluWE9kYnc1U0MwYVdLOHVsZ2NvWDNnV21rM3BNVFJVekpEdTh3NjFBbXhQMVExKzA3dytjcHJEcVpRTCsrcEM3UUozNXdPSXl2dUZ3OEpXZXFpMUNSaXdsdFE2TjYxR2x1NVZpeWhNbmYxblg3amM1WTFlUEZIVmRTaHQ2YkdvZFhTYld3MWRSN3JxNkw2U1FkRHNGTFpIMzkyb2I0WDROWm1taERuNHlhZWRlemZQT0pIVFZYb2lVUGhTOU9qNmJSNXhrTEVURXAxSVlEblRXQTFaYjdGUVlyOVNaa3ZGS3h1eERKMzNiMk1vRkdyUkFPTmNyc1hqV092MCtEak1oK01OblNZdmNCSHRkWFVtdWVjTXFUUHE4MjdZa0pIdVdGaDUyQkJnbmtJdVJDYVgxczdod0FkWFlIUmxFTTdsUzJYSHdtWEFRU1JYM0tzangyOHlOb0c3bE1YWFNuWkJYWm1hS29tQjkxUjBFbXBzbktsbXp6VGh0VVU5M0ZjVnMvaVBoZFEySGF5eitQd3ZPdUMzMkVmalZDN0dtVW96MEZTdXloT0g0RDFJQ3Z6bFpVWVl3NUV1QmRxS0p2WHJxcVY2WkVqck54NGEzV3hRUFlraXdCK09uZzlTaXVKWmdYQ2pZT0ZsWUZJVjBwb2VLNjMrQ0JKbjQxMXh0RUcvVVB4M1VGSzlWMnhLYlUraXdaYXgvTFRmSHgwUG5Id1BTZEEyUXJJS2lHdmZaRTRGUTZHVVhuUUR3ZHJFeXJKUmdqc0crck4rTUdUdWh1N3krYVR0QldXQU4rSGRBS0Z2L0N3RitlTjh0a09YNzBranUyQ1Z0QXB3QU1mNzdjWE1nQnNJWkw2N3lKK1d3MXRLQmZuTnpCalVwZG1jai81YXBEMlFwVmhSRDFoZmlaMS8vRU9TaXREUGRHNitQUXBlVDhMa3lZK0tsZk1OL2NaRXdSSWU5eklCOHFjcnRsdk9rYVpkdVduY1lmRHd3bm5PN1FZSkNtREFZcjRnZjRBanFSN1hTWHlKcEQ0SWpKeVh5M2x0Y2pWcTMyUGlYTjZwRWdoZXp0ejFOS2I0OXNmSHErTnJSY1UyK21ld29vNlBzdVRhNi9sQnZsZEJUQWQrZnN2bmliMlBNNGtRWGYzL3AvVmdQa1g0YWZtTXZSdkRLTHZEUC92TDhNZlkrVTRWYlE9PQ%3D%3D&fp=3f9689c9c10f3e5af454abad6931a2b8
        Analysis system description:Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
        Number of analysed new started processes analysed:3
        Number of new started drivers analysed:2
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean0.win@18/4@4/3
        • Exclude process from analysis (whitelisted): vga.dll
        • Excluded IPs from analysis (whitelisted): 142.250.184.195, 142.250.185.78, 172.217.218.84, 34.104.35.123, 142.250.185.131
        • Excluded domains from analysis (whitelisted): clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, update.googleapis.com, clientservices.googleapis.com, clients.l.google.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        • VT rate limit hit for: https://biruuq.com/f.php?e=br2PMEkzX4etGTJQWDungH49fmtueHVYY3lUMlNtQmowN3Y4WGd6LzdFUVB6dUZXNllHUE1NQndDaEdlcTJURC9qQ1R0VHBHWWIxY2R4UHlwWXNCcmhRQVcyalQ3K0VFWFU4RUtsaHluWE9kYnc1U0MwYVdLOHVsZ2NvWDNnV21rM3BNVFJVekpEdTh3NjFBbXhQMVExKzA3dytjcHJEcVpRTCsrcEM3UUozNXdPSXl2dUZ3OEpXZXFpMUNSaXdsdFE2TjYxR2x1NVZpeWhNbmYxblg3amM1WTFlUEZIVmRTaHQ2YkdvZFhTYld3MWRSN3JxNkw2U1FkRHNGTFpIMzkyb2I0WDROWm1taERuNHlhZWRlemZQT0pIVFZYb2lVUGhTOU9qNmJSNXhrTEVURXAxSVlEblRXQTFaYjdGUVlyOVNaa3ZGS3h1eERKMzNiMk1vRkdyUkFPTmNyc1hqV092MCtEak1oK01OblNZdmNCSHRkWFVtdWVjTXFUUHE4MjdZa0pIdVdGaDUyQkJnbmtJdVJDYVgxczdod0FkWFlIUmxFTTdsUzJYSHdtWEFRU1JYM0tzangyOHlOb0c3bE1YWFNuWkJYWm1hS29tQjkxUjBFbXBzbktsbXp6VGh0VVU5M0ZjVnMvaVBoZFEySGF5eitQd3ZPdUMzMkVmalZDN0dtVW96MEZTdXloT0g0RDFJQ3Z6bFpVWVl3NUV1QmRxS0p2WHJxcVY2WkVqck54NGEzV3hRUFlraXdCK09uZzlTaXVKWmdYQ2pZT0ZsWUZJVjBwb2VLNjMrQ0JKbjQxMXh0RUcvVVB4M1VGSzlWMnhLYlUraXdaYXgvTFRmSHgwUG5Id1BTZEEyUXJJS2lHdmZaRTRGUTZHVVhuUUR3ZHJFeXJKUmdqc0crck4rTUdUdWh1N3krYVR0QldXQU4rSGRBS0Z2L0N3RitlTjh0a09YNzBranUyQ
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text
        Category:downloaded
        Size (bytes):94
        Entropy (8bit):4.648751656165808
        Encrypted:false
        SSDEEP:3:qVZqcMsMgs0UL3AE+FoJRx+QVBK3z:qzsgs0HE+2XVBmz
        MD5:E96DDCEB1C305B9AD21EAAE42522C26F
        SHA1:AD08AE39A71ED5BA992B8B5DABC450D046354696
        SHA-256:9221CFEDFC5E03790F46C7890BCA21FCC47C5788D89DAB0AA0799C492B6AE78A
        SHA-512:1CC850F76467645447E9935F4DE13EDE698727B4FB598C7BD36DE2779596D8B5A85CB94B0CF1FB2259AD1D988F1F199E3F4C310DFDC22FCDD378B8E773F0DBD5
        Malicious:false
        Reputation:low
        URL:https://biruuq.com/favicon.ico
        Preview:<html><body><h1>403 Forbidden</h1>.Request forbidden by administrative rules..</body></html>..
        Process:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
        File Type:ASCII text, with CRLF line terminators
        Category:downloaded
        Size (bytes):2
        Entropy (8bit):1.0
        Encrypted:false
        SSDEEP:3:y:y
        MD5:81051BCC2CF1BEDF378224B0A93E2877
        SHA1:BA8AB5A0280B953AA97435FF8946CBCBB2755A27
        SHA-256:7EB70257593DA06F682A3DDDA54A9D260D4FC514F645237F5CA74B08F8DA61A6
        SHA-512:1B302A2F1E624A5FB5AD94DDC4E5F8BFD74D26FA37512D0E5FACE303D8C40EEE0D0FFA3649F5DA43F439914D128166CB6C4774A7CAA3B174D7535451EB697B5D
        Malicious:false
        Reputation:low
        URL:https://biruuq.com/f.php?e=br2PMEkzX4etGTJQWDungH49fmtueHVYY3lUMlNtQmowN3Y4WGd6LzdFUVB6dUZXNllHUE1NQndDaEdlcTJURC9qQ1R0VHBHWWIxY2R4UHlwWXNCcmhRQVcyalQ3K0VFWFU4RUtsaHluWE9kYnc1U0MwYVdLOHVsZ2NvWDNnV21rM3BNVFJVekpEdTh3NjFBbXhQMVExKzA3dytjcHJEcVpRTCsrcEM3UUozNXdPSXl2dUZ3OEpXZXFpMUNSaXdsdFE2TjYxR2x1NVZpeWhNbmYxblg3amM1WTFlUEZIVmRTaHQ2YkdvZFhTYld3MWRSN3JxNkw2U1FkRHNGTFpIMzkyb2I0WDROWm1taERuNHlhZWRlemZQT0pIVFZYb2lVUGhTOU9qNmJSNXhrTEVURXAxSVlEblRXQTFaYjdGUVlyOVNaa3ZGS3h1eERKMzNiMk1vRkdyUkFPTmNyc1hqV092MCtEak1oK01OblNZdmNCSHRkWFVtdWVjTXFUUHE4MjdZa0pIdVdGaDUyQkJnbmtJdVJDYVgxczdod0FkWFlIUmxFTTdsUzJYSHdtWEFRU1JYM0tzangyOHlOb0c3bE1YWFNuWkJYWm1hS29tQjkxUjBFbXBzbktsbXp6VGh0VVU5M0ZjVnMvaVBoZFEySGF5eitQd3ZPdUMzMkVmalZDN0dtVW96MEZTdXloT0g0RDFJQ3Z6bFpVWVl3NUV1QmRxS0p2WHJxcVY2WkVqck54NGEzV3hRUFlraXdCK09uZzlTaXVKWmdYQ2pZT0ZsWUZJVjBwb2VLNjMrQ0JKbjQxMXh0RUcvVVB4M1VGSzlWMnhLYlUraXdaYXgvTFRmSHgwUG5Id1BTZEEyUXJJS2lHdmZaRTRGUTZHVVhuUUR3ZHJFeXJKUmdqc0crck4rTUdUdWh1N3krYVR0QldXQU4rSGRBS0Z2L0N3RitlTjh0a09YNzBranUyQ1Z0QXB3QU1mNzdjWE1nQnNJWkw2N3lKK1d3MXRLQmZuTnpCalVwZG1jai81YXBEMlFwVmhSRDFoZmlaMS8vRU9TaXREUGRHNitQUXBlVDhMa3lZK0tsZk1OL2NaRXdSSWU5eklCOHFjcnRsdk9rYVpkdVduY1lmRHd3bm5PN1FZSkNtREFZcjRnZjRBanFSN1hTWHlKcEQ0SWpKeVh5M2x0Y2pWcTMyUGlYTjZwRWdoZXp0ejFOS2I0OXNmSHErTnJSY1UyK21ld29vNlBzdVRhNi9sQnZsZEJUQWQrZnN2bmliMlBNNGtRWGYzL3AvVmdQa1g0YWZtTXZSdkRLTHZEUC92TDhNZlkrVTRWYlE9PQ%3D%3D&fp=3f9689c9c10f3e5af454abad6931a2b8
        Preview:..
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Oct 25, 2024 22:29:37.302093029 CEST49166443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:37.302139044 CEST44349166103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:37.302257061 CEST49166443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:37.302711010 CEST49167443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:37.302766085 CEST44349167103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:37.302814007 CEST49167443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:37.302994967 CEST49166443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:37.303004980 CEST44349166103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:37.303107977 CEST49167443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:37.303126097 CEST44349167103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:37.998868942 CEST44349166103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:37.999341965 CEST49166443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:37.999350071 CEST44349166103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:37.999720097 CEST44349166103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:37.999772072 CEST49166443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:38.000360966 CEST44349166103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:38.001677990 CEST49166443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:38.001727104 CEST44349166103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:38.002036095 CEST49166443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:38.002043962 CEST44349166103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:38.011168003 CEST44349167103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:38.011404991 CEST49167443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:38.011425018 CEST44349167103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:38.012368917 CEST44349167103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:38.012420893 CEST49167443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:38.013390064 CEST44349167103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:38.014800072 CEST49167443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:38.014887094 CEST44349167103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:38.166234970 CEST44349166103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:38.166286945 CEST49166443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:38.172446966 CEST49166443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:38.172465086 CEST44349166103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:38.210397959 CEST49167443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:38.210448027 CEST44349167103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:38.217489958 CEST49169443192.168.2.22172.217.18.4
        Oct 25, 2024 22:29:38.217540026 CEST44349169172.217.18.4192.168.2.22
        Oct 25, 2024 22:29:38.217590094 CEST49169443192.168.2.22172.217.18.4
        Oct 25, 2024 22:29:38.218633890 CEST49169443192.168.2.22172.217.18.4
        Oct 25, 2024 22:29:38.218651056 CEST44349169172.217.18.4192.168.2.22
        Oct 25, 2024 22:29:38.365525961 CEST44349167103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:38.365592003 CEST49167443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:38.367131948 CEST49167443192.168.2.22103.224.182.206
        Oct 25, 2024 22:29:38.367150068 CEST44349167103.224.182.206192.168.2.22
        Oct 25, 2024 22:29:39.104154110 CEST44349169172.217.18.4192.168.2.22
        Oct 25, 2024 22:29:39.105230093 CEST49169443192.168.2.22172.217.18.4
        Oct 25, 2024 22:29:39.105264902 CEST44349169172.217.18.4192.168.2.22
        Oct 25, 2024 22:29:39.106347084 CEST44349169172.217.18.4192.168.2.22
        Oct 25, 2024 22:29:39.106398106 CEST49169443192.168.2.22172.217.18.4
        Oct 25, 2024 22:29:39.108935118 CEST49169443192.168.2.22172.217.18.4
        Oct 25, 2024 22:29:39.108994961 CEST44349169172.217.18.4192.168.2.22
        Oct 25, 2024 22:29:39.315334082 CEST44349169172.217.18.4192.168.2.22
        Oct 25, 2024 22:29:39.315391064 CEST49169443192.168.2.22172.217.18.4
        Oct 25, 2024 22:29:49.126473904 CEST44349169172.217.18.4192.168.2.22
        Oct 25, 2024 22:29:49.126576900 CEST44349169172.217.18.4192.168.2.22
        Oct 25, 2024 22:29:49.126724958 CEST49169443192.168.2.22172.217.18.4
        Oct 25, 2024 22:29:49.588785887 CEST49169443192.168.2.22172.217.18.4
        Oct 25, 2024 22:29:49.588845015 CEST44349169172.217.18.4192.168.2.22
        Oct 25, 2024 22:30:38.244529963 CEST49171443192.168.2.22172.217.18.4
        Oct 25, 2024 22:30:38.244627953 CEST44349171172.217.18.4192.168.2.22
        Oct 25, 2024 22:30:38.244718075 CEST49171443192.168.2.22172.217.18.4
        Oct 25, 2024 22:30:38.245357990 CEST49171443192.168.2.22172.217.18.4
        Oct 25, 2024 22:30:38.245407104 CEST44349171172.217.18.4192.168.2.22
        Oct 25, 2024 22:30:39.099430084 CEST44349171172.217.18.4192.168.2.22
        Oct 25, 2024 22:30:39.099848986 CEST49171443192.168.2.22172.217.18.4
        Oct 25, 2024 22:30:39.099910021 CEST44349171172.217.18.4192.168.2.22
        Oct 25, 2024 22:30:39.100404024 CEST44349171172.217.18.4192.168.2.22
        Oct 25, 2024 22:30:39.101865053 CEST49171443192.168.2.22172.217.18.4
        Oct 25, 2024 22:30:39.101975918 CEST44349171172.217.18.4192.168.2.22
        Oct 25, 2024 22:30:39.307339907 CEST44349171172.217.18.4192.168.2.22
        Oct 25, 2024 22:30:39.307411909 CEST49171443192.168.2.22172.217.18.4
        Oct 25, 2024 22:30:39.307450056 CEST49171443192.168.2.22172.217.18.4
        Oct 25, 2024 22:30:49.109021902 CEST44349171172.217.18.4192.168.2.22
        Oct 25, 2024 22:30:49.109101057 CEST44349171172.217.18.4192.168.2.22
        Oct 25, 2024 22:30:49.109178066 CEST49171443192.168.2.22172.217.18.4
        Oct 25, 2024 22:30:49.591197968 CEST49171443192.168.2.22172.217.18.4
        Oct 25, 2024 22:30:49.591236115 CEST44349171172.217.18.4192.168.2.22
        TimestampSource PortDest PortSource IPDest IP
        Oct 25, 2024 22:29:33.627043962 CEST53548218.8.8.8192.168.2.22
        Oct 25, 2024 22:29:33.655059099 CEST53527818.8.8.8192.168.2.22
        Oct 25, 2024 22:29:36.038156033 CEST53626728.8.8.8192.168.2.22
        Oct 25, 2024 22:29:37.139062881 CEST5484253192.168.2.228.8.8.8
        Oct 25, 2024 22:29:37.141573906 CEST5810553192.168.2.228.8.8.8
        Oct 25, 2024 22:29:37.300045013 CEST53548428.8.8.8192.168.2.22
        Oct 25, 2024 22:29:37.301495075 CEST53581058.8.8.8192.168.2.22
        Oct 25, 2024 22:29:38.207077026 CEST5739053192.168.2.228.8.8.8
        Oct 25, 2024 22:29:38.208774090 CEST5809553192.168.2.228.8.8.8
        Oct 25, 2024 22:29:38.214225054 CEST53573908.8.8.8192.168.2.22
        Oct 25, 2024 22:29:38.215859890 CEST53580958.8.8.8192.168.2.22
        Oct 25, 2024 22:29:53.025768995 CEST53520748.8.8.8192.168.2.22
        Oct 25, 2024 22:29:59.722368002 CEST53518288.8.8.8192.168.2.22
        Oct 25, 2024 22:30:10.002083063 CEST53646878.8.8.8192.168.2.22
        Oct 25, 2024 22:30:28.833165884 CEST53582578.8.8.8192.168.2.22
        Oct 25, 2024 22:30:33.528127909 CEST53492268.8.8.8192.168.2.22
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Oct 25, 2024 22:29:37.139062881 CEST192.168.2.228.8.8.80xd4a8Standard query (0)biruuq.comA (IP address)IN (0x0001)false
        Oct 25, 2024 22:29:37.141573906 CEST192.168.2.228.8.8.80xc64cStandard query (0)biruuq.com65IN (0x0001)false
        Oct 25, 2024 22:29:38.207077026 CEST192.168.2.228.8.8.80x3a4fStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Oct 25, 2024 22:29:38.208774090 CEST192.168.2.228.8.8.80x8467Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Oct 25, 2024 22:29:37.300045013 CEST8.8.8.8192.168.2.220xd4a8No error (0)biruuq.com103.224.182.206A (IP address)IN (0x0001)false
        Oct 25, 2024 22:29:38.214225054 CEST8.8.8.8192.168.2.220x3a4fNo error (0)www.google.com172.217.18.4A (IP address)IN (0x0001)false
        Oct 25, 2024 22:29:38.215859890 CEST8.8.8.8192.168.2.220x8467No error (0)www.google.com65IN (0x0001)false
        • biruuq.com
        • https:
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.2249166103.224.182.2064431224C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2024-10-25 20:29:37 UTC2042OUTGET /f.php?e=br2PMEkzX4etGTJQWDungH49fmtueHVYY3lUMlNtQmowN3Y4WGd6LzdFUVB6dUZXNllHUE1NQndDaEdlcTJURC9qQ1R0VHBHWWIxY2R4UHlwWXNCcmhRQVcyalQ3K0VFWFU4RUtsaHluWE9kYnc1U0MwYVdLOHVsZ2NvWDNnV21rM3BNVFJVekpEdTh3NjFBbXhQMVExKzA3dytjcHJEcVpRTCsrcEM3UUozNXdPSXl2dUZ3OEpXZXFpMUNSaXdsdFE2TjYxR2x1NVZpeWhNbmYxblg3amM1WTFlUEZIVmRTaHQ2YkdvZFhTYld3MWRSN3JxNkw2U1FkRHNGTFpIMzkyb2I0WDROWm1taERuNHlhZWRlemZQT0pIVFZYb2lVUGhTOU9qNmJSNXhrTEVURXAxSVlEblRXQTFaYjdGUVlyOVNaa3ZGS3h1eERKMzNiMk1vRkdyUkFPTmNyc1hqV092MCtEak1oK01OblNZdmNCSHRkWFVtdWVjTXFUUHE4MjdZa0pIdVdGaDUyQkJnbmtJdVJDYVgxczdod0FkWFlIUmxFTTdsUzJYSHdtWEFRU1JYM0tzangyOHlOb0c3bE1YWFNuWkJYWm1hS29tQjkxUjBFbXBzbktsbXp6VGh0VVU5M0ZjVnMvaVBoZFEySGF5eitQd3ZPdUMzMkVmalZDN0dtVW96MEZTdXloT0g0RDFJQ3Z6bFpVWVl3NUV1QmRxS0p2WHJxcVY2WkVqck54NGEzV3hRUFlraXdCK09uZzlTaXVKWmdYQ2pZT0ZsWUZJVjBwb2VLNjMrQ0JKbjQxMXh0RUcvVVB4M1VGSzlWMnhLYlUraXdaYXgvTFRmSHgwUG5Id1BTZEEyUXJJS2lHdmZaRTRGUTZHVVhuUUR3ZHJFeXJKUmdqc0crck4rTUdUdWh1N3krYVR0QldXQU4rSGRBS0Z2L0N3RitlTjh0a09YNzBranUyQ1Z0QXB3QU1mNzdjWE1nQnNJWkw2N3lKK1d3MXR [TRUNCATED]
        Host: biruuq.com
        Connection: keep-alive
        sec-ch-ua: "Not_A Brand";v="99", "Google Chrome";v="109", "Chromium";v="109"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2024-10-25 20:29:38 UTC150INHTTP/1.1 200 OK
        date: Fri, 25 Oct 2024 20:29:38 GMT
        server: Apache
        content-length: 2
        content-type: text/html; charset=UTF-8
        connection: close
        2024-10-25 20:29:38 UTC2INData Raw: 0d 0a
        Data Ascii:


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.2249167103.224.182.2064431224C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2024-10-25 20:29:38 UTC1965OUTGET /favicon.ico HTTP/1.1
        Host: biruuq.com
        Connection: keep-alive
        sec-ch-ua: "Not_A Brand";v="99", "Google Chrome";v="109", "Chromium";v="109"
        sec-ch-ua-mobile: ?0
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
        sec-ch-ua-platform: "Windows"
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://biruuq.com/f.php?e=br2PMEkzX4etGTJQWDungH49fmtueHVYY3lUMlNtQmowN3Y4WGd6LzdFUVB6dUZXNllHUE1NQndDaEdlcTJURC9qQ1R0VHBHWWIxY2R4UHlwWXNCcmhRQVcyalQ3K0VFWFU4RUtsaHluWE9kYnc1U0MwYVdLOHVsZ2NvWDNnV21rM3BNVFJVekpEdTh3NjFBbXhQMVExKzA3dytjcHJEcVpRTCsrcEM3UUozNXdPSXl2dUZ3OEpXZXFpMUNSaXdsdFE2TjYxR2x1NVZpeWhNbmYxblg3amM1WTFlUEZIVmRTaHQ2YkdvZFhTYld3MWRSN3JxNkw2U1FkRHNGTFpIMzkyb2I0WDROWm1taERuNHlhZWRlemZQT0pIVFZYb2lVUGhTOU9qNmJSNXhrTEVURXAxSVlEblRXQTFaYjdGUVlyOVNaa3ZGS3h1eERKMzNiMk1vRkdyUkFPTmNyc1hqV092MCtEak1oK01OblNZdmNCSHRkWFVtdWVjTXFUUHE4MjdZa0pIdVdGaDUyQkJnbmtJdVJDYVgxczdod0FkWFlIUmxFTTdsUzJYSHdtWEFRU1JYM0tzangyOHlOb0c3bE1YWFNuWkJYWm1hS29tQjkxUjBFbXBzbktsbXp6VGh0VVU5M0ZjVnMvaVBoZFEySGF5eitQd3ZPdUMzMkVmalZDN0dtVW96MEZTdXloT0g0RDFJQ3Z6bFpVWVl3NUV1QmRxS0p2WHJxcVY2WkVqck54NGEzV3hRUFlraXdCK09uZzlTaXVKWmdYQ2pZT0ZsWUZJVjBwb2VLNjMrQ0JKbjQxMXh0RUcvVVB4M1VGSzlWMnhLYlUraXdaYXgvTFRmSHgwUG5Id1BTZEEyUXJJS2lHdmZaRTRGUTZHVVhuUUR3ZHJFeXJKUmdqc0crck4rTUdUdWh1N3krYVR0QldXQU4rSGRBS0Z2L0N3RitlTjh0a09YNzBranUyQ1Z0QXB3QU1mNzdj [TRUNCATED]
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2024-10-25 20:29:38 UTC76INData Raw: 48 54 54 50 2f 31 2e 30 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 63 61 63 68 65 2d 63 6f 6e 74 72 6f 6c 3a 20 6e 6f 2d 63 61 63 68 65 0d 0a 63 6f 6e 74 65 6e 74 2d 74 79 70 65 3a 20 74 65 78 74 2f 68 74 6d 6c 0d 0a 0d 0a
        Data Ascii: HTTP/1.0 403 Forbiddencache-control: no-cachecontent-type: text/html
        2024-10-25 20:29:38 UTC94INData Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 52 65 71 75 65 73 74 20 66 6f 72 62 69 64 64 65 6e 20 62 79 20 61 64 6d 69 6e 69 73 74 72 61 74 69 76 65 20 72 75 6c 65 73 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a 0a
        Data Ascii: <html><body><h1>403 Forbidden</h1>Request forbidden by administrative rules.</body></html>


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:16:29:31
        Start date:25/10/2024
        Path:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x13f500000
        File size:3'151'128 bytes
        MD5 hash:FFA2B8E17F645BCC20F0E0201FEF83ED
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:1
        Start time:16:29:32
        Start date:25/10/2024
        Path:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1460 --field-trial-handle=1264,i,6515938508693869711,13721224092671204226,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x13f500000
        File size:3'151'128 bytes
        MD5 hash:FFA2B8E17F645BCC20F0E0201FEF83ED
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:4
        Start time:16:29:36
        Start date:25/10/2024
        Path:C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "https://biruuq.com/f.php?e=br2PMEkzX4etGTJQWDungH49fmtueHVYY3lUMlNtQmowN3Y4WGd6LzdFUVB6dUZXNllHUE1NQndDaEdlcTJURC9qQ1R0VHBHWWIxY2R4UHlwWXNCcmhRQVcyalQ3K0VFWFU4RUtsaHluWE9kYnc1U0MwYVdLOHVsZ2NvWDNnV21rM3BNVFJVekpEdTh3NjFBbXhQMVExKzA3dytjcHJEcVpRTCsrcEM3UUozNXdPSXl2dUZ3OEpXZXFpMUNSaXdsdFE2TjYxR2x1NVZpeWhNbmYxblg3amM1WTFlUEZIVmRTaHQ2YkdvZFhTYld3MWRSN3JxNkw2U1FkRHNGTFpIMzkyb2I0WDROWm1taERuNHlhZWRlemZQT0pIVFZYb2lVUGhTOU9qNmJSNXhrTEVURXAxSVlEblRXQTFaYjdGUVlyOVNaa3ZGS3h1eERKMzNiMk1vRkdyUkFPTmNyc1hqV092MCtEak1oK01OblNZdmNCSHRkWFVtdWVjTXFUUHE4MjdZa0pIdVdGaDUyQkJnbmtJdVJDYVgxczdod0FkWFlIUmxFTTdsUzJYSHdtWEFRU1JYM0tzangyOHlOb0c3bE1YWFNuWkJYWm1hS29tQjkxUjBFbXBzbktsbXp6VGh0VVU5M0ZjVnMvaVBoZFEySGF5eitQd3ZPdUMzMkVmalZDN0dtVW96MEZTdXloT0g0RDFJQ3Z6bFpVWVl3NUV1QmRxS0p2WHJxcVY2WkVqck54NGEzV3hRUFlraXdCK09uZzlTaXVKWmdYQ2pZT0ZsWUZJVjBwb2VLNjMrQ0JKbjQxMXh0RUcvVVB4M1VGSzlWMnhLYlUraXdaYXgvTFRmSHgwUG5Id1BTZEEyUXJJS2lHdmZaRTRGUTZHVVhuUUR3ZHJFeXJKUmdqc0crck4rTUdUdWh1N3krYVR0QldXQU4rSGRBS0Z2L0N3RitlTjh0a09YNzBranUyQ1Z0QXB3QU1mNzdjWE1nQnNJWkw2N3lKK1d3MXRLQmZuTnpCalVwZG1jai81YXBEMlFwVmhSRDFoZmlaMS8vRU9TaXREUGRHNitQUXBlVDhMa3lZK0tsZk1OL2NaRXdSSWU5eklCOHFjcnRsdk9rYVpkdVduY1lmRHd3bm5PN1FZSkNtREFZcjRnZjRBanFSN1hTWHlKcEQ0SWpKeVh5M2x0Y2pWcTMyUGlYTjZwRWdoZXp0ejFOS2I0OXNmSHErTnJSY1UyK21ld29vNlBzdVRhNi9sQnZsZEJUQWQrZnN2bmliMlBNNGtRWGYzL3AvVmdQa1g0YWZtTXZSdkRLTHZEUC92TDhNZlkrVTRWYlE9PQ%3D%3D&fp=3f9689c9c10f3e5af454abad6931a2b8"
        Imagebase:0x13f500000
        File size:3'151'128 bytes
        MD5 hash:FFA2B8E17F645BCC20F0E0201FEF83ED
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly