Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://com-trackehk.top

Overview

General Information

Sample URL:http://com-trackehk.top
Analysis ID:1543820
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2908 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1608 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2284 --field-trial-handle=2024,i,13833328681594894192,7522541735868610036,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6320 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://com-trackehk.top" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: com-trackehk.top
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: unknown0.win@20/0@17/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2284 --field-trial-handle=2024,i,13833328681594894192,7522541735868610036,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://com-trackehk.top"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2284 --field-trial-handle=2024,i,13833328681594894192,7522541735868610036,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    google.com
    142.250.186.46
    truefalse
      unknown
      www.google.com
      142.250.184.196
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          com-trackehk.top
          unknown
          unknownfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.184.196
            www.google.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1543820
            Start date and time:2024-10-28 14:19:20 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 1s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://com-trackehk.top
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@20/0@17/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.184.195, 142.250.110.84, 142.250.185.238, 34.104.35.123, 184.28.90.27, 20.12.23.50, 199.232.214.172, 192.229.221.95, 20.3.187.198
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://com-trackehk.top
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 28, 2024 14:20:08.673247099 CET49675443192.168.2.4173.222.162.32
            Oct 28, 2024 14:20:18.281634092 CET49675443192.168.2.4173.222.162.32
            Oct 28, 2024 14:20:22.335988045 CET49737443192.168.2.4142.250.184.196
            Oct 28, 2024 14:20:22.336108923 CET44349737142.250.184.196192.168.2.4
            Oct 28, 2024 14:20:22.336215019 CET49737443192.168.2.4142.250.184.196
            Oct 28, 2024 14:20:22.336719990 CET49737443192.168.2.4142.250.184.196
            Oct 28, 2024 14:20:22.336755991 CET44349737142.250.184.196192.168.2.4
            Oct 28, 2024 14:20:23.199995995 CET44349737142.250.184.196192.168.2.4
            Oct 28, 2024 14:20:23.200282097 CET49737443192.168.2.4142.250.184.196
            Oct 28, 2024 14:20:23.200325966 CET44349737142.250.184.196192.168.2.4
            Oct 28, 2024 14:20:23.201879978 CET44349737142.250.184.196192.168.2.4
            Oct 28, 2024 14:20:23.201946974 CET49737443192.168.2.4142.250.184.196
            Oct 28, 2024 14:20:23.353439093 CET49737443192.168.2.4142.250.184.196
            Oct 28, 2024 14:20:23.353640079 CET44349737142.250.184.196192.168.2.4
            Oct 28, 2024 14:20:23.407397985 CET49737443192.168.2.4142.250.184.196
            Oct 28, 2024 14:20:23.407423973 CET44349737142.250.184.196192.168.2.4
            Oct 28, 2024 14:20:23.454271078 CET49737443192.168.2.4142.250.184.196
            Oct 28, 2024 14:20:33.198421001 CET44349737142.250.184.196192.168.2.4
            Oct 28, 2024 14:20:33.198507071 CET44349737142.250.184.196192.168.2.4
            Oct 28, 2024 14:20:33.198723078 CET49737443192.168.2.4142.250.184.196
            Oct 28, 2024 14:20:34.082696915 CET49737443192.168.2.4142.250.184.196
            Oct 28, 2024 14:20:34.082729101 CET44349737142.250.184.196192.168.2.4
            Oct 28, 2024 14:20:34.326126099 CET4972380192.168.2.493.184.221.240
            Oct 28, 2024 14:20:34.332128048 CET804972393.184.221.240192.168.2.4
            Oct 28, 2024 14:20:34.332211018 CET4972380192.168.2.493.184.221.240
            TimestampSource PortDest PortSource IPDest IP
            Oct 28, 2024 14:20:17.881782055 CET53510861.1.1.1192.168.2.4
            Oct 28, 2024 14:20:17.895843029 CET53612841.1.1.1192.168.2.4
            Oct 28, 2024 14:20:19.127860069 CET53530731.1.1.1192.168.2.4
            Oct 28, 2024 14:20:19.145847082 CET5976353192.168.2.41.1.1.1
            Oct 28, 2024 14:20:19.146526098 CET5022853192.168.2.41.1.1.1
            Oct 28, 2024 14:20:19.235883951 CET53502281.1.1.1192.168.2.4
            Oct 28, 2024 14:20:19.239247084 CET53597631.1.1.1192.168.2.4
            Oct 28, 2024 14:20:19.239999056 CET5993853192.168.2.41.1.1.1
            Oct 28, 2024 14:20:19.332293987 CET53599381.1.1.1192.168.2.4
            Oct 28, 2024 14:20:19.358043909 CET5740653192.168.2.48.8.8.8
            Oct 28, 2024 14:20:19.358463049 CET5264853192.168.2.41.1.1.1
            Oct 28, 2024 14:20:19.365789890 CET53526481.1.1.1192.168.2.4
            Oct 28, 2024 14:20:19.366107941 CET53574068.8.8.8192.168.2.4
            Oct 28, 2024 14:20:20.376543999 CET6454753192.168.2.41.1.1.1
            Oct 28, 2024 14:20:20.376869917 CET5482253192.168.2.41.1.1.1
            Oct 28, 2024 14:20:20.470784903 CET53548221.1.1.1192.168.2.4
            Oct 28, 2024 14:20:20.470957994 CET53645471.1.1.1192.168.2.4
            Oct 28, 2024 14:20:22.233302116 CET5831953192.168.2.41.1.1.1
            Oct 28, 2024 14:20:22.233820915 CET6432453192.168.2.41.1.1.1
            Oct 28, 2024 14:20:22.332798958 CET53643241.1.1.1192.168.2.4
            Oct 28, 2024 14:20:22.333014965 CET53583191.1.1.1192.168.2.4
            Oct 28, 2024 14:20:25.493334055 CET6077153192.168.2.41.1.1.1
            Oct 28, 2024 14:20:25.493522882 CET5892553192.168.2.41.1.1.1
            Oct 28, 2024 14:20:25.815855980 CET53607711.1.1.1192.168.2.4
            Oct 28, 2024 14:20:25.827215910 CET53589251.1.1.1192.168.2.4
            Oct 28, 2024 14:20:25.828046083 CET6125853192.168.2.41.1.1.1
            Oct 28, 2024 14:20:25.918808937 CET53612581.1.1.1192.168.2.4
            Oct 28, 2024 14:20:31.703195095 CET5302553192.168.2.41.1.1.1
            Oct 28, 2024 14:20:31.703459024 CET5587453192.168.2.41.1.1.1
            Oct 28, 2024 14:20:31.796384096 CET53530251.1.1.1192.168.2.4
            Oct 28, 2024 14:20:31.818808079 CET6056453192.168.2.41.1.1.1
            Oct 28, 2024 14:20:31.919889927 CET53558741.1.1.1192.168.2.4
            Oct 28, 2024 14:20:32.365169048 CET53605641.1.1.1192.168.2.4
            Oct 28, 2024 14:20:32.385256052 CET6404653192.168.2.41.1.1.1
            Oct 28, 2024 14:20:32.386606932 CET5101753192.168.2.48.8.8.8
            Oct 28, 2024 14:20:32.394903898 CET53640461.1.1.1192.168.2.4
            Oct 28, 2024 14:20:32.395766020 CET53510178.8.8.8192.168.2.4
            Oct 28, 2024 14:20:34.647839069 CET138138192.168.2.4192.168.2.255
            Oct 28, 2024 14:20:36.360683918 CET53492641.1.1.1192.168.2.4
            TimestampSource IPDest IPChecksumCodeType
            Oct 28, 2024 14:20:31.919960022 CET192.168.2.41.1.1.1c22c(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 28, 2024 14:20:19.145847082 CET192.168.2.41.1.1.10x1149Standard query (0)com-trackehk.topA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:19.146526098 CET192.168.2.41.1.1.10xb093Standard query (0)com-trackehk.top65IN (0x0001)false
            Oct 28, 2024 14:20:19.239999056 CET192.168.2.41.1.1.10x73cStandard query (0)com-trackehk.topA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:19.358043909 CET192.168.2.48.8.8.80x3ce2Standard query (0)google.comA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:19.358463049 CET192.168.2.41.1.1.10x6091Standard query (0)google.comA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:20.376543999 CET192.168.2.41.1.1.10xd26bStandard query (0)com-trackehk.topA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:20.376869917 CET192.168.2.41.1.1.10xae76Standard query (0)com-trackehk.top65IN (0x0001)false
            Oct 28, 2024 14:20:22.233302116 CET192.168.2.41.1.1.10x80cfStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:22.233820915 CET192.168.2.41.1.1.10xd589Standard query (0)www.google.com65IN (0x0001)false
            Oct 28, 2024 14:20:25.493334055 CET192.168.2.41.1.1.10xf8b5Standard query (0)com-trackehk.topA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:25.493522882 CET192.168.2.41.1.1.10x2528Standard query (0)com-trackehk.top65IN (0x0001)false
            Oct 28, 2024 14:20:25.828046083 CET192.168.2.41.1.1.10x3469Standard query (0)com-trackehk.topA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:31.703195095 CET192.168.2.41.1.1.10xec59Standard query (0)com-trackehk.topA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:31.703459024 CET192.168.2.41.1.1.10xe890Standard query (0)com-trackehk.top65IN (0x0001)false
            Oct 28, 2024 14:20:31.818808079 CET192.168.2.41.1.1.10xb3f7Standard query (0)com-trackehk.topA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:32.385256052 CET192.168.2.41.1.1.10x6689Standard query (0)google.comA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:32.386606932 CET192.168.2.48.8.8.80x3715Standard query (0)google.comA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 28, 2024 14:20:19.235883951 CET1.1.1.1192.168.2.40xb093Name error (3)com-trackehk.topnonenone65IN (0x0001)false
            Oct 28, 2024 14:20:19.239247084 CET1.1.1.1192.168.2.40x1149Name error (3)com-trackehk.topnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:19.332293987 CET1.1.1.1192.168.2.40x73cName error (3)com-trackehk.topnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:19.365789890 CET1.1.1.1192.168.2.40x6091No error (0)google.com142.250.186.46A (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:19.366107941 CET8.8.8.8192.168.2.40x3ce2No error (0)google.com142.250.184.238A (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:20.470784903 CET1.1.1.1192.168.2.40xae76Name error (3)com-trackehk.topnonenone65IN (0x0001)false
            Oct 28, 2024 14:20:20.470957994 CET1.1.1.1192.168.2.40xd26bName error (3)com-trackehk.topnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:22.332798958 CET1.1.1.1192.168.2.40xd589No error (0)www.google.com65IN (0x0001)false
            Oct 28, 2024 14:20:22.333014965 CET1.1.1.1192.168.2.40x80cfNo error (0)www.google.com142.250.184.196A (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:25.815855980 CET1.1.1.1192.168.2.40xf8b5Name error (3)com-trackehk.topnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:25.827215910 CET1.1.1.1192.168.2.40x2528Name error (3)com-trackehk.topnonenone65IN (0x0001)false
            Oct 28, 2024 14:20:25.918808937 CET1.1.1.1192.168.2.40x3469Name error (3)com-trackehk.topnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:31.279870987 CET1.1.1.1192.168.2.40x23c5No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:31.279870987 CET1.1.1.1192.168.2.40x23c5No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:31.796384096 CET1.1.1.1192.168.2.40xec59Name error (3)com-trackehk.topnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:31.919889927 CET1.1.1.1192.168.2.40xe890Name error (3)com-trackehk.topnonenone65IN (0x0001)false
            Oct 28, 2024 14:20:32.365169048 CET1.1.1.1192.168.2.40xb3f7Name error (3)com-trackehk.topnonenoneA (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:32.394903898 CET1.1.1.1192.168.2.40x6689No error (0)google.com142.250.186.78A (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:32.395766020 CET8.8.8.8192.168.2.40x3715No error (0)google.com142.250.186.78A (IP address)IN (0x0001)false
            Oct 28, 2024 14:20:33.028348923 CET1.1.1.1192.168.2.40x6175No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 28, 2024 14:20:33.028348923 CET1.1.1.1192.168.2.40x6175No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false

            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:09:20:12
            Start date:28/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:09:20:16
            Start date:28/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2284 --field-trial-handle=2024,i,13833328681594894192,7522541735868610036,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:09:20:18
            Start date:28/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://com-trackehk.top"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly