Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://dataservice.protection.outlook.com

Overview

General Information

Sample URL:http://dataservice.protection.outlook.com
Analysis ID:1544063
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2688 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4904 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2112 --field-trial-handle=1980,i,12897951742911303431,16248922528316802725,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6276 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://dataservice.protection.outlook.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 87.248.204.0
Source: unknownTCP traffic detected without corresponding DNS query: 87.248.204.0
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: dataservice.protection.outlook.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: dataservice.protection.outlook.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: dataservice.protection.outlook.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: unknown0.win@18/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2112 --field-trial-handle=1980,i,12897951742911303431,16248922528316802725,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://dataservice.protection.outlook.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2112 --field-trial-handle=1980,i,12897951742911303431,16248922528316802725,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
global.dataservice.eop-tm2.outlook.com
104.47.18.208
truefalse
    unknown
    www.google.com
    142.250.185.228
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        dataservice.protection.outlook.com
        unknown
        unknownfalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          http://dataservice.protection.outlook.com/false
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            104.47.18.208
            global.dataservice.eop-tm2.outlook.comUnited States
            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
            142.250.185.228
            www.google.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1544063
            Start date and time:2024-10-28 19:20:17 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 1m 59s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://dataservice.protection.outlook.com
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@18/0@4/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 216.58.206.67, 172.217.18.110, 64.233.167.84, 34.104.35.123, 184.28.90.27, 4.175.87.197, 93.184.221.240, 192.229.221.95, 52.165.164.15, 13.95.31.18
            • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://dataservice.protection.outlook.com
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 28, 2024 19:21:12.226891994 CET49675443192.168.2.4173.222.162.32
            Oct 28, 2024 19:21:15.211930037 CET4973580192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:15.212060928 CET4973680192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:15.217510939 CET8049735104.47.18.208192.168.2.4
            Oct 28, 2024 19:21:15.217530966 CET8049736104.47.18.208192.168.2.4
            Oct 28, 2024 19:21:15.217628002 CET4973580192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:15.217835903 CET4973680192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:15.217839956 CET4973580192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:15.223160028 CET8049735104.47.18.208192.168.2.4
            Oct 28, 2024 19:21:17.747319937 CET49739443192.168.2.4142.250.185.228
            Oct 28, 2024 19:21:17.747368097 CET44349739142.250.185.228192.168.2.4
            Oct 28, 2024 19:21:17.747531891 CET49739443192.168.2.4142.250.185.228
            Oct 28, 2024 19:21:17.748861074 CET49739443192.168.2.4142.250.185.228
            Oct 28, 2024 19:21:17.748874903 CET44349739142.250.185.228192.168.2.4
            Oct 28, 2024 19:21:18.605092049 CET44349739142.250.185.228192.168.2.4
            Oct 28, 2024 19:21:18.605643988 CET49739443192.168.2.4142.250.185.228
            Oct 28, 2024 19:21:18.605660915 CET44349739142.250.185.228192.168.2.4
            Oct 28, 2024 19:21:18.607362986 CET44349739142.250.185.228192.168.2.4
            Oct 28, 2024 19:21:18.608436108 CET49739443192.168.2.4142.250.185.228
            Oct 28, 2024 19:21:18.609595060 CET49739443192.168.2.4142.250.185.228
            Oct 28, 2024 19:21:18.609679937 CET44349739142.250.185.228192.168.2.4
            Oct 28, 2024 19:21:18.664869070 CET49739443192.168.2.4142.250.185.228
            Oct 28, 2024 19:21:18.664891005 CET44349739142.250.185.228192.168.2.4
            Oct 28, 2024 19:21:18.710001945 CET49739443192.168.2.4142.250.185.228
            Oct 28, 2024 19:21:23.694224119 CET8049735104.47.18.208192.168.2.4
            Oct 28, 2024 19:21:23.694317102 CET4973580192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:23.701033115 CET4973580192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:23.705923080 CET8049736104.47.18.208192.168.2.4
            Oct 28, 2024 19:21:23.706043959 CET4973680192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:23.706307888 CET8049735104.47.18.208192.168.2.4
            Oct 28, 2024 19:21:23.762923002 CET4973680192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:23.768376112 CET8049736104.47.18.208192.168.2.4
            Oct 28, 2024 19:21:24.799472094 CET4974280192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:24.799474001 CET4974380192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:24.805063963 CET8049742104.47.18.208192.168.2.4
            Oct 28, 2024 19:21:24.805108070 CET8049743104.47.18.208192.168.2.4
            Oct 28, 2024 19:21:24.805217028 CET4974280192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:24.805239916 CET4974380192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:24.810959101 CET4974380192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:24.816319942 CET8049743104.47.18.208192.168.2.4
            Oct 28, 2024 19:21:28.841491938 CET44349739142.250.185.228192.168.2.4
            Oct 28, 2024 19:21:28.841665030 CET44349739142.250.185.228192.168.2.4
            Oct 28, 2024 19:21:28.841744900 CET49739443192.168.2.4142.250.185.228
            Oct 28, 2024 19:21:29.773029089 CET804972387.248.204.0192.168.2.4
            Oct 28, 2024 19:21:29.773962975 CET4972380192.168.2.487.248.204.0
            Oct 28, 2024 19:21:29.774317026 CET4972380192.168.2.487.248.204.0
            Oct 28, 2024 19:21:29.779741049 CET804972387.248.204.0192.168.2.4
            Oct 28, 2024 19:21:30.446738005 CET49739443192.168.2.4142.250.185.228
            Oct 28, 2024 19:21:30.446825981 CET44349739142.250.185.228192.168.2.4
            Oct 28, 2024 19:21:33.300862074 CET8049743104.47.18.208192.168.2.4
            Oct 28, 2024 19:21:33.300945044 CET4974380192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:33.301069021 CET8049742104.47.18.208192.168.2.4
            Oct 28, 2024 19:21:33.301198959 CET4974280192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:33.304809093 CET4974380192.168.2.4104.47.18.208
            Oct 28, 2024 19:21:33.310233116 CET8049743104.47.18.208192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Oct 28, 2024 19:21:14.217751026 CET53555101.1.1.1192.168.2.4
            Oct 28, 2024 19:21:14.225720882 CET53588871.1.1.1192.168.2.4
            Oct 28, 2024 19:21:15.197463036 CET5101553192.168.2.41.1.1.1
            Oct 28, 2024 19:21:15.197647095 CET5676653192.168.2.41.1.1.1
            Oct 28, 2024 19:21:15.205547094 CET53567661.1.1.1192.168.2.4
            Oct 28, 2024 19:21:15.207372904 CET53510151.1.1.1192.168.2.4
            Oct 28, 2024 19:21:15.543230057 CET53545131.1.1.1192.168.2.4
            Oct 28, 2024 19:21:17.736236095 CET6493453192.168.2.41.1.1.1
            Oct 28, 2024 19:21:17.736574888 CET5285953192.168.2.41.1.1.1
            Oct 28, 2024 19:21:17.745521069 CET53528591.1.1.1192.168.2.4
            Oct 28, 2024 19:21:17.745620012 CET53649341.1.1.1192.168.2.4
            Oct 28, 2024 19:21:30.192090034 CET138138192.168.2.4192.168.2.255
            Oct 28, 2024 19:21:32.596651077 CET53557011.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 28, 2024 19:21:15.197463036 CET192.168.2.41.1.1.10x82bbStandard query (0)dataservice.protection.outlook.comA (IP address)IN (0x0001)false
            Oct 28, 2024 19:21:15.197647095 CET192.168.2.41.1.1.10xb5daStandard query (0)dataservice.protection.outlook.com65IN (0x0001)false
            Oct 28, 2024 19:21:17.736236095 CET192.168.2.41.1.1.10x580bStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 28, 2024 19:21:17.736574888 CET192.168.2.41.1.1.10xdc70Standard query (0)www.google.com65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 28, 2024 19:21:15.205547094 CET1.1.1.1192.168.2.40xb5daNo error (0)dataservice.protection.outlook.comglobal.dataservice.eop-tm2.outlook.comCNAME (Canonical name)IN (0x0001)false
            Oct 28, 2024 19:21:15.207372904 CET1.1.1.1192.168.2.40x82bbNo error (0)dataservice.protection.outlook.comglobal.dataservice.eop-tm2.outlook.comCNAME (Canonical name)IN (0x0001)false
            Oct 28, 2024 19:21:15.207372904 CET1.1.1.1192.168.2.40x82bbNo error (0)global.dataservice.eop-tm2.outlook.com104.47.18.208A (IP address)IN (0x0001)false
            Oct 28, 2024 19:21:15.207372904 CET1.1.1.1192.168.2.40x82bbNo error (0)global.dataservice.eop-tm2.outlook.com104.47.18.144A (IP address)IN (0x0001)false
            Oct 28, 2024 19:21:15.207372904 CET1.1.1.1192.168.2.40x82bbNo error (0)global.dataservice.eop-tm2.outlook.com104.47.22.144A (IP address)IN (0x0001)false
            Oct 28, 2024 19:21:17.745521069 CET1.1.1.1192.168.2.40xdc70No error (0)www.google.com65IN (0x0001)false
            Oct 28, 2024 19:21:17.745620012 CET1.1.1.1192.168.2.40x580bNo error (0)www.google.com142.250.185.228A (IP address)IN (0x0001)false
            Oct 28, 2024 19:21:28.969744921 CET1.1.1.1192.168.2.40x5b53No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 28, 2024 19:21:28.969744921 CET1.1.1.1192.168.2.40x5b53No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
            • dataservice.protection.outlook.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.449735104.47.18.208804904C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 28, 2024 19:21:15.217839956 CET449OUTGET / HTTP/1.1
            Host: dataservice.protection.outlook.com
            Connection: keep-alive
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.449743104.47.18.208804904C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            Oct 28, 2024 19:21:24.810959101 CET475OUTGET / HTTP/1.1
            Host: dataservice.protection.outlook.com
            Connection: keep-alive
            Cache-Control: max-age=0
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Accept-Encoding: gzip, deflate
            Accept-Language: en-US,en;q=0.9


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:14:21:07
            Start date:28/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:14:21:12
            Start date:28/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2112 --field-trial-handle=1980,i,12897951742911303431,16248922528316802725,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:14:21:14
            Start date:28/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://dataservice.protection.outlook.com"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly