Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://api.mappearl.com/plg?u=570412EA-DFDE-5094-AC13-C0B5E1CAF7D3

Overview

General Information

Sample URL:http://api.mappearl.com/plg?u=570412EA-DFDE-5094-AC13-C0B5E1CAF7D3
Analysis ID:1545198
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4812 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3752 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2268 --field-trial-handle=2016,i,2377350547010925657,6958914748394700237,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6308 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://api.mappearl.com/plg?u=570412EA-DFDE-5094-AC13-C0B5E1CAF7D3" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: api.mappearl.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: unknown0.win@20/0@17/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2268 --field-trial-handle=2016,i,2377350547010925657,6958914748394700237,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://api.mappearl.com/plg?u=570412EA-DFDE-5094-AC13-C0B5E1CAF7D3"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2268 --field-trial-handle=2016,i,2377350547010925657,6958914748394700237,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    google.com
    142.250.184.238
    truefalse
      unknown
      www.google.com
      142.250.185.100
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          api.mappearl.com
          unknown
          unknownfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.185.100
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1545198
            Start date and time:2024-10-30 08:27:38 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 2s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://api.mappearl.com/plg?u=570412EA-DFDE-5094-AC13-C0B5E1CAF7D3
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@20/0@17/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.185.195, 216.58.206.78, 108.177.15.84, 34.104.35.123, 184.28.90.27, 4.245.163.56, 199.232.210.172, 192.229.221.95, 20.3.187.198
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://api.mappearl.com/plg?u=570412EA-DFDE-5094-AC13-C0B5E1CAF7D3
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 30, 2024 08:28:35.096857071 CET49675443192.168.2.4173.222.162.32
            Oct 30, 2024 08:28:40.600150108 CET49737443192.168.2.4142.250.185.100
            Oct 30, 2024 08:28:40.600224018 CET44349737142.250.185.100192.168.2.4
            Oct 30, 2024 08:28:40.600291014 CET49737443192.168.2.4142.250.185.100
            Oct 30, 2024 08:28:40.600964069 CET49737443192.168.2.4142.250.185.100
            Oct 30, 2024 08:28:40.600992918 CET44349737142.250.185.100192.168.2.4
            Oct 30, 2024 08:28:41.459253073 CET44349737142.250.185.100192.168.2.4
            Oct 30, 2024 08:28:41.459573030 CET49737443192.168.2.4142.250.185.100
            Oct 30, 2024 08:28:41.459589958 CET44349737142.250.185.100192.168.2.4
            Oct 30, 2024 08:28:41.460683107 CET44349737142.250.185.100192.168.2.4
            Oct 30, 2024 08:28:41.460800886 CET49737443192.168.2.4142.250.185.100
            Oct 30, 2024 08:28:41.463190079 CET49737443192.168.2.4142.250.185.100
            Oct 30, 2024 08:28:41.463255882 CET44349737142.250.185.100192.168.2.4
            Oct 30, 2024 08:28:41.514724970 CET49737443192.168.2.4142.250.185.100
            Oct 30, 2024 08:28:41.514744997 CET44349737142.250.185.100192.168.2.4
            Oct 30, 2024 08:28:41.561542988 CET49737443192.168.2.4142.250.185.100
            Oct 30, 2024 08:28:50.470252991 CET4972380192.168.2.488.221.110.91
            Oct 30, 2024 08:28:50.475984097 CET804972388.221.110.91192.168.2.4
            Oct 30, 2024 08:28:50.476054907 CET4972380192.168.2.488.221.110.91
            Oct 30, 2024 08:28:51.460347891 CET44349737142.250.185.100192.168.2.4
            Oct 30, 2024 08:28:51.460421085 CET44349737142.250.185.100192.168.2.4
            Oct 30, 2024 08:28:51.460479975 CET49737443192.168.2.4142.250.185.100
            Oct 30, 2024 08:28:53.089795113 CET49737443192.168.2.4142.250.185.100
            Oct 30, 2024 08:28:53.089834929 CET44349737142.250.185.100192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Oct 30, 2024 08:28:36.652864933 CET53562391.1.1.1192.168.2.4
            Oct 30, 2024 08:28:36.831399918 CET53588831.1.1.1192.168.2.4
            Oct 30, 2024 08:28:37.852648020 CET6494853192.168.2.41.1.1.1
            Oct 30, 2024 08:28:37.853080034 CET6146953192.168.2.41.1.1.1
            Oct 30, 2024 08:28:37.863447905 CET53649481.1.1.1192.168.2.4
            Oct 30, 2024 08:28:37.878186941 CET4950253192.168.2.41.1.1.1
            Oct 30, 2024 08:28:37.883708954 CET53614691.1.1.1192.168.2.4
            Oct 30, 2024 08:28:37.910563946 CET53495021.1.1.1192.168.2.4
            Oct 30, 2024 08:28:37.961839914 CET6117053192.168.2.48.8.8.8
            Oct 30, 2024 08:28:37.962734938 CET5335653192.168.2.41.1.1.1
            Oct 30, 2024 08:28:37.969563007 CET53611708.8.8.8192.168.2.4
            Oct 30, 2024 08:28:37.970020056 CET53533561.1.1.1192.168.2.4
            Oct 30, 2024 08:28:38.082140923 CET53577941.1.1.1192.168.2.4
            Oct 30, 2024 08:28:39.050208092 CET5805553192.168.2.41.1.1.1
            Oct 30, 2024 08:28:39.050544024 CET5234253192.168.2.41.1.1.1
            Oct 30, 2024 08:28:39.081259966 CET53580551.1.1.1192.168.2.4
            Oct 30, 2024 08:28:39.224093914 CET53523421.1.1.1192.168.2.4
            Oct 30, 2024 08:28:40.555444002 CET5738153192.168.2.41.1.1.1
            Oct 30, 2024 08:28:40.555718899 CET5690853192.168.2.41.1.1.1
            Oct 30, 2024 08:28:40.563040972 CET53569081.1.1.1192.168.2.4
            Oct 30, 2024 08:28:40.563052893 CET53573811.1.1.1192.168.2.4
            Oct 30, 2024 08:28:44.113555908 CET5413253192.168.2.41.1.1.1
            Oct 30, 2024 08:28:44.113989115 CET5586053192.168.2.41.1.1.1
            Oct 30, 2024 08:28:44.121867895 CET53541321.1.1.1192.168.2.4
            Oct 30, 2024 08:28:44.123375893 CET53558601.1.1.1192.168.2.4
            Oct 30, 2024 08:28:44.124557018 CET6167653192.168.2.41.1.1.1
            Oct 30, 2024 08:28:44.134365082 CET53616761.1.1.1192.168.2.4
            Oct 30, 2024 08:28:50.399013996 CET5813753192.168.2.41.1.1.1
            Oct 30, 2024 08:28:50.399179935 CET5608753192.168.2.41.1.1.1
            Oct 30, 2024 08:28:50.430313110 CET53581371.1.1.1192.168.2.4
            Oct 30, 2024 08:28:50.430402040 CET53560871.1.1.1192.168.2.4
            Oct 30, 2024 08:28:50.431334972 CET6478853192.168.2.41.1.1.1
            Oct 30, 2024 08:28:50.597723007 CET53647881.1.1.1192.168.2.4
            Oct 30, 2024 08:28:50.613640070 CET6164353192.168.2.41.1.1.1
            Oct 30, 2024 08:28:50.614115000 CET6330753192.168.2.48.8.8.8
            Oct 30, 2024 08:28:50.621409893 CET53633078.8.8.8192.168.2.4
            Oct 30, 2024 08:28:50.622009993 CET53616431.1.1.1192.168.2.4
            Oct 30, 2024 08:28:50.884056091 CET138138192.168.2.4192.168.2.255
            Oct 30, 2024 08:28:55.232409954 CET53625671.1.1.1192.168.2.4
            TimestampSource IPDest IPChecksumCodeType
            Oct 30, 2024 08:28:37.884042025 CET192.168.2.41.1.1.1c22f(Port unreachable)Destination Unreachable
            Oct 30, 2024 08:28:39.224196911 CET192.168.2.41.1.1.1c22f(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 30, 2024 08:28:37.852648020 CET192.168.2.41.1.1.10x6569Standard query (0)api.mappearl.comA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:37.853080034 CET192.168.2.41.1.1.10x7135Standard query (0)api.mappearl.com65IN (0x0001)false
            Oct 30, 2024 08:28:37.878186941 CET192.168.2.41.1.1.10x955bStandard query (0)api.mappearl.comA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:37.961839914 CET192.168.2.48.8.8.80x7d98Standard query (0)google.comA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:37.962734938 CET192.168.2.41.1.1.10x1415Standard query (0)google.comA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:39.050208092 CET192.168.2.41.1.1.10x213aStandard query (0)api.mappearl.comA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:39.050544024 CET192.168.2.41.1.1.10x7001Standard query (0)api.mappearl.com65IN (0x0001)false
            Oct 30, 2024 08:28:40.555444002 CET192.168.2.41.1.1.10x86b3Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:40.555718899 CET192.168.2.41.1.1.10x6191Standard query (0)www.google.com65IN (0x0001)false
            Oct 30, 2024 08:28:44.113555908 CET192.168.2.41.1.1.10x7a38Standard query (0)api.mappearl.comA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:44.113989115 CET192.168.2.41.1.1.10x2c27Standard query (0)api.mappearl.com65IN (0x0001)false
            Oct 30, 2024 08:28:44.124557018 CET192.168.2.41.1.1.10xb1feStandard query (0)api.mappearl.comA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:50.399013996 CET192.168.2.41.1.1.10xa1a6Standard query (0)api.mappearl.comA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:50.399179935 CET192.168.2.41.1.1.10x3e18Standard query (0)api.mappearl.com65IN (0x0001)false
            Oct 30, 2024 08:28:50.431334972 CET192.168.2.41.1.1.10xe60Standard query (0)api.mappearl.comA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:50.613640070 CET192.168.2.41.1.1.10x894fStandard query (0)google.comA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:50.614115000 CET192.168.2.48.8.8.80xf54dStandard query (0)google.comA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 30, 2024 08:28:37.863447905 CET1.1.1.1192.168.2.40x6569Name error (3)api.mappearl.comnonenoneA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:37.883708954 CET1.1.1.1192.168.2.40x7135Name error (3)api.mappearl.comnonenone65IN (0x0001)false
            Oct 30, 2024 08:28:37.910563946 CET1.1.1.1192.168.2.40x955bName error (3)api.mappearl.comnonenoneA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:37.969563007 CET8.8.8.8192.168.2.40x7d98No error (0)google.com142.250.184.238A (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:37.970020056 CET1.1.1.1192.168.2.40x1415No error (0)google.com142.250.184.238A (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:39.081259966 CET1.1.1.1192.168.2.40x213aName error (3)api.mappearl.comnonenoneA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:39.224093914 CET1.1.1.1192.168.2.40x7001Name error (3)api.mappearl.comnonenone65IN (0x0001)false
            Oct 30, 2024 08:28:40.563040972 CET1.1.1.1192.168.2.40x6191No error (0)www.google.com65IN (0x0001)false
            Oct 30, 2024 08:28:40.563052893 CET1.1.1.1192.168.2.40x86b3No error (0)www.google.com142.250.185.100A (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:44.121867895 CET1.1.1.1192.168.2.40x7a38Name error (3)api.mappearl.comnonenoneA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:44.123375893 CET1.1.1.1192.168.2.40x2c27Name error (3)api.mappearl.comnonenone65IN (0x0001)false
            Oct 30, 2024 08:28:44.134365082 CET1.1.1.1192.168.2.40xb1feName error (3)api.mappearl.comnonenoneA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:49.107469082 CET1.1.1.1192.168.2.40x9bdcNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:49.107469082 CET1.1.1.1192.168.2.40x9bdcNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:50.430313110 CET1.1.1.1192.168.2.40xa1a6Name error (3)api.mappearl.comnonenoneA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:50.430402040 CET1.1.1.1192.168.2.40x3e18Name error (3)api.mappearl.comnonenone65IN (0x0001)false
            Oct 30, 2024 08:28:50.597723007 CET1.1.1.1192.168.2.40xe60Name error (3)api.mappearl.comnonenoneA (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:50.621409893 CET8.8.8.8192.168.2.40xf54dNo error (0)google.com142.250.184.238A (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:50.622009993 CET1.1.1.1192.168.2.40x894fNo error (0)google.com142.250.186.78A (IP address)IN (0x0001)false
            Oct 30, 2024 08:28:50.984865904 CET1.1.1.1192.168.2.40xbebNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 30, 2024 08:28:50.984865904 CET1.1.1.1192.168.2.40xbebNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false

            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:03:28:30
            Start date:30/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:03:28:34
            Start date:30/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2268 --field-trial-handle=2016,i,2377350547010925657,6958914748394700237,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:03:28:37
            Start date:30/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://api.mappearl.com/plg?u=570412EA-DFDE-5094-AC13-C0B5E1CAF7D3"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly