Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://renovaserv.bio

Overview

General Information

Sample URL:http://renovaserv.bio
Analysis ID:1544576
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3940 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4136 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2304 --field-trial-handle=2212,i,3695921414161726884,12419819560418100838,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6272 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://renovaserv.bio" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: renovaserv.bio
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: unknown0.win@20/0@19/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2304 --field-trial-handle=2212,i,3695921414161726884,12419819560418100838,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://renovaserv.bio"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2304 --field-trial-handle=2212,i,3695921414161726884,12419819560418100838,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1544576 URL: http://renovaserv.bio Startdate: 29/10/2024 Architecture: WINDOWS Score: 0 14 renovaserv.bio 2->14 16 fp2e7a.wpc.phicdn.net 2->16 18 fp2e7a.wpc.2be4.phicdn.net 2->18 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 20 192.168.2.4, 138, 443, 49569 unknown unknown 6->20 22 239.255.255.250 unknown Reserved 6->22 11 chrome.exe 6->11         started        process5 dnsIp6 24 www.google.com 142.250.184.196, 443, 49737 GOOGLEUS United States 11->24 26 renovaserv.bio 11->26 28 google.com 11->28

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.184.238
truefalse
    unknown
    www.google.com
    142.250.184.196
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        renovaserv.bio
        unknown
        unknownfalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          142.250.184.196
          www.google.comUnited States
          15169GOOGLEUSfalse
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          IP
          192.168.2.4
          Joe Sandbox version:41.0.0 Charoite
          Analysis ID:1544576
          Start date and time:2024-10-29 15:41:13 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 1m 59s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://renovaserv.bio
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:7
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:UNKNOWN
          Classification:unknown0.win@20/0@19/3
          Cookbook Comments:
          • URL browsing timeout or error
          • URL not reachable
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.250.186.174, 74.125.71.84, 142.250.186.67, 34.104.35.123, 184.28.90.27, 20.109.210.53, 93.184.221.240, 192.229.221.95, 13.85.23.206
          • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          • VT rate limit hit for: http://renovaserv.bio
          No simulations
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Oct 29, 2024 15:41:59.228571892 CET49675443192.168.2.4173.222.162.32
          Oct 29, 2024 15:42:08.829469919 CET49675443192.168.2.4173.222.162.32
          Oct 29, 2024 15:42:12.841558933 CET49737443192.168.2.4142.250.184.196
          Oct 29, 2024 15:42:12.841603041 CET44349737142.250.184.196192.168.2.4
          Oct 29, 2024 15:42:12.845017910 CET49737443192.168.2.4142.250.184.196
          Oct 29, 2024 15:42:12.845330000 CET49737443192.168.2.4142.250.184.196
          Oct 29, 2024 15:42:12.845350027 CET44349737142.250.184.196192.168.2.4
          Oct 29, 2024 15:42:13.712707996 CET44349737142.250.184.196192.168.2.4
          Oct 29, 2024 15:42:13.713613033 CET49737443192.168.2.4142.250.184.196
          Oct 29, 2024 15:42:13.713675976 CET44349737142.250.184.196192.168.2.4
          Oct 29, 2024 15:42:13.715095997 CET44349737142.250.184.196192.168.2.4
          Oct 29, 2024 15:42:13.715182066 CET49737443192.168.2.4142.250.184.196
          Oct 29, 2024 15:42:14.115000963 CET49737443192.168.2.4142.250.184.196
          Oct 29, 2024 15:42:14.115427017 CET44349737142.250.184.196192.168.2.4
          Oct 29, 2024 15:42:14.168240070 CET49737443192.168.2.4142.250.184.196
          Oct 29, 2024 15:42:14.168284893 CET44349737142.250.184.196192.168.2.4
          Oct 29, 2024 15:42:14.215133905 CET49737443192.168.2.4142.250.184.196
          Oct 29, 2024 15:42:23.728806019 CET44349737142.250.184.196192.168.2.4
          Oct 29, 2024 15:42:23.728976965 CET44349737142.250.184.196192.168.2.4
          Oct 29, 2024 15:42:23.729034901 CET49737443192.168.2.4142.250.184.196
          Oct 29, 2024 15:42:25.167891026 CET49737443192.168.2.4142.250.184.196
          Oct 29, 2024 15:42:25.167927980 CET44349737142.250.184.196192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          Oct 29, 2024 15:42:08.804809093 CET53538431.1.1.1192.168.2.4
          Oct 29, 2024 15:42:08.806899071 CET53569441.1.1.1192.168.2.4
          Oct 29, 2024 15:42:10.248152971 CET4956953192.168.2.41.1.1.1
          Oct 29, 2024 15:42:10.248352051 CET5560453192.168.2.41.1.1.1
          Oct 29, 2024 15:42:10.273768902 CET53556041.1.1.1192.168.2.4
          Oct 29, 2024 15:42:10.275186062 CET53495691.1.1.1192.168.2.4
          Oct 29, 2024 15:42:10.275770903 CET5697153192.168.2.41.1.1.1
          Oct 29, 2024 15:42:10.280308962 CET53638021.1.1.1192.168.2.4
          Oct 29, 2024 15:42:10.302901030 CET53569711.1.1.1192.168.2.4
          Oct 29, 2024 15:42:10.361126900 CET5899153192.168.2.48.8.8.8
          Oct 29, 2024 15:42:10.361596107 CET5648253192.168.2.41.1.1.1
          Oct 29, 2024 15:42:10.369344950 CET53589918.8.8.8192.168.2.4
          Oct 29, 2024 15:42:10.369440079 CET53564821.1.1.1192.168.2.4
          Oct 29, 2024 15:42:11.366549015 CET6073553192.168.2.41.1.1.1
          Oct 29, 2024 15:42:11.368361950 CET5884353192.168.2.41.1.1.1
          Oct 29, 2024 15:42:11.387352943 CET53607351.1.1.1192.168.2.4
          Oct 29, 2024 15:42:11.394103050 CET53588431.1.1.1192.168.2.4
          Oct 29, 2024 15:42:11.407047987 CET5796753192.168.2.41.1.1.1
          Oct 29, 2024 15:42:11.407202005 CET5746653192.168.2.41.1.1.1
          Oct 29, 2024 15:42:11.427223921 CET53579671.1.1.1192.168.2.4
          Oct 29, 2024 15:42:11.430921078 CET53574661.1.1.1192.168.2.4
          Oct 29, 2024 15:42:12.809660912 CET5242953192.168.2.41.1.1.1
          Oct 29, 2024 15:42:12.817147970 CET53524291.1.1.1192.168.2.4
          Oct 29, 2024 15:42:12.823381901 CET6501653192.168.2.41.1.1.1
          Oct 29, 2024 15:42:12.830816984 CET53650161.1.1.1192.168.2.4
          Oct 29, 2024 15:42:16.487361908 CET6365853192.168.2.41.1.1.1
          Oct 29, 2024 15:42:16.487699986 CET5604753192.168.2.41.1.1.1
          Oct 29, 2024 15:42:16.495387077 CET53560471.1.1.1192.168.2.4
          Oct 29, 2024 15:42:16.496567965 CET53636581.1.1.1192.168.2.4
          Oct 29, 2024 15:42:16.498733044 CET5770553192.168.2.41.1.1.1
          Oct 29, 2024 15:42:16.508687973 CET53577051.1.1.1192.168.2.4
          Oct 29, 2024 15:42:22.678800106 CET5974553192.168.2.41.1.1.1
          Oct 29, 2024 15:42:22.678920984 CET5744353192.168.2.41.1.1.1
          Oct 29, 2024 15:42:22.701055050 CET53597451.1.1.1192.168.2.4
          Oct 29, 2024 15:42:22.709183931 CET53574431.1.1.1192.168.2.4
          Oct 29, 2024 15:42:22.709733963 CET6011353192.168.2.41.1.1.1
          Oct 29, 2024 15:42:22.741167068 CET53601131.1.1.1192.168.2.4
          Oct 29, 2024 15:42:22.751931906 CET6122653192.168.2.41.1.1.1
          Oct 29, 2024 15:42:22.752249002 CET5058853192.168.2.48.8.8.8
          Oct 29, 2024 15:42:22.759356022 CET53612261.1.1.1192.168.2.4
          Oct 29, 2024 15:42:22.760370016 CET53505888.8.8.8192.168.2.4
          Oct 29, 2024 15:42:26.631098986 CET138138192.168.2.4192.168.2.255
          Oct 29, 2024 15:42:27.332120895 CET53640691.1.1.1192.168.2.4
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Oct 29, 2024 15:42:10.248152971 CET192.168.2.41.1.1.10x3ba5Standard query (0)renovaserv.bioA (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:10.248352051 CET192.168.2.41.1.1.10xd59bStandard query (0)renovaserv.bio65IN (0x0001)false
          Oct 29, 2024 15:42:10.275770903 CET192.168.2.41.1.1.10x5ddbStandard query (0)renovaserv.bioA (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:10.361126900 CET192.168.2.48.8.8.80xa79bStandard query (0)google.comA (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:10.361596107 CET192.168.2.41.1.1.10xaf27Standard query (0)google.comA (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:11.366549015 CET192.168.2.41.1.1.10x205cStandard query (0)renovaserv.bioA (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:11.368361950 CET192.168.2.41.1.1.10xa783Standard query (0)renovaserv.bio65IN (0x0001)false
          Oct 29, 2024 15:42:11.407047987 CET192.168.2.41.1.1.10x98b1Standard query (0)renovaserv.bioA (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:11.407202005 CET192.168.2.41.1.1.10x776eStandard query (0)renovaserv.bio65IN (0x0001)false
          Oct 29, 2024 15:42:12.809660912 CET192.168.2.41.1.1.10x393aStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:12.823381901 CET192.168.2.41.1.1.10x9c11Standard query (0)www.google.com65IN (0x0001)false
          Oct 29, 2024 15:42:16.487361908 CET192.168.2.41.1.1.10xc352Standard query (0)renovaserv.bioA (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:16.487699986 CET192.168.2.41.1.1.10x152fStandard query (0)renovaserv.bio65IN (0x0001)false
          Oct 29, 2024 15:42:16.498733044 CET192.168.2.41.1.1.10xb527Standard query (0)renovaserv.bioA (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:22.678800106 CET192.168.2.41.1.1.10xe7afStandard query (0)renovaserv.bioA (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:22.678920984 CET192.168.2.41.1.1.10x473bStandard query (0)renovaserv.bio65IN (0x0001)false
          Oct 29, 2024 15:42:22.709733963 CET192.168.2.41.1.1.10x30d5Standard query (0)renovaserv.bioA (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:22.751931906 CET192.168.2.41.1.1.10x22baStandard query (0)google.comA (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:22.752249002 CET192.168.2.48.8.8.80xa1a6Standard query (0)google.comA (IP address)IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Oct 29, 2024 15:42:10.369344950 CET8.8.8.8192.168.2.40xa79bNo error (0)google.com142.250.184.238A (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:10.369440079 CET1.1.1.1192.168.2.40xaf27No error (0)google.com142.250.186.110A (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:12.817147970 CET1.1.1.1192.168.2.40x393aNo error (0)www.google.com142.250.184.196A (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:12.830816984 CET1.1.1.1192.168.2.40x9c11No error (0)www.google.com65IN (0x0001)false
          Oct 29, 2024 15:42:22.759356022 CET1.1.1.1192.168.2.40x22baNo error (0)google.com142.250.186.174A (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:22.760370016 CET8.8.8.8192.168.2.40xa1a6No error (0)google.com142.250.184.238A (IP address)IN (0x0001)false
          Oct 29, 2024 15:42:23.335494041 CET1.1.1.1192.168.2.40xd243No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Oct 29, 2024 15:42:23.335494041 CET1.1.1.1192.168.2.40xd243No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false

          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:10:42:02
          Start date:29/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:10:42:06
          Start date:29/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2304 --field-trial-handle=2212,i,3695921414161726884,12419819560418100838,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:10:42:08
          Start date:29/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://renovaserv.bio"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly