Edit tour

Windows Analysis Report
http://o28sy4q7wu-dsn.algolia.net

Overview

General Information

Sample URL:http://o28sy4q7wu-dsn.algolia.net
Analysis ID:1573478
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5460 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2492 --field-trial-handle=2460,i,7891699012482754450,14498568815434285668,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6476 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://o28sy4q7wu-dsn.algolia.net" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://algolia.net/1/404HTTP Parser: No favicon
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /1/404 HTTP/1.1Host: algolia.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: algolia.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://algolia.net/1/404Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /1/404 HTTP/1.1Host: algolia.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://algolia.net/1/404Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: o28sy4q7wu-dsn.algolia.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: o28sy4q7wu-dsn.algolia.net
Source: global trafficDNS traffic detected: DNS query: algolia.net
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 12 Dec 2024 03:53:12 GMTContent-Type: application/json; charset=UTF-8Content-Length: 164Connection: closeAccess-Control-Allow-Origin: *Timing-Allow-Origin: *X-Content-Type-Options: nosniffStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadContent-Disposition: inline; filename=a.txt
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Thu, 12 Dec 2024 03:53:16 GMTContent-Type: application/json; charset=UTF-8Content-Length: 164Connection: closeAccess-Control-Allow-Origin: *Timing-Allow-Origin: *X-Content-Type-Options: nosniffStrict-Transport-Security: max-age=31536000; includeSubDomains; preloadContent-Disposition: inline; filename=a.txt
Source: chromecache_42.2.drString found in binary or memory: https://www.algolia.com/doc/rest-api/search/
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: classification engineClassification label: clean0.win@17/2@6/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2492 --field-trial-handle=2460,i,7891699012482754450,14498568815434285668,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://o28sy4q7wu-dsn.algolia.net"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2492 --field-trial-handle=2460,i,7891699012482754450,14498568815434285668,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1573478 URL: http://o28sy4q7wu-dsn.algolia.net Startdate: 12/12/2024 Architecture: WINDOWS Score: 0 5 chrome.exe 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.4, 138, 443, 49588 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 algolia.net 149.202.84.123, 443, 49743, 49744 OVHFR France 10->17 19 d124-use-1.algolia.net 207.244.74.97, 49740, 49741, 80 LEASEWEB-USA-WDCUS United States 10->19 21 3 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://o28sy4q7wu-dsn.algolia.net0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.181.132
truefalse
    high
    algolia.net
    149.202.84.123
    truefalse
      high
      d124-use-1.algolia.net
      207.244.74.97
      truefalse
        unknown
        o28sy4q7wu-dsn.algolia.net
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          http://o28sy4q7wu-dsn.algolia.net/false
            high
            https://algolia.net/1/404false
              high
              https://algolia.net/favicon.icofalse
                high
                NameSourceMaliciousAntivirus DetectionReputation
                https://www.algolia.com/doc/rest-api/search/chromecache_42.2.drfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  207.244.74.97
                  d124-use-1.algolia.netUnited States
                  30633LEASEWEB-USA-WDCUSfalse
                  149.202.84.123
                  algolia.netFrance
                  16276OVHFRfalse
                  142.250.181.132
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.4
                  Joe Sandbox version:41.0.0 Charoite
                  Analysis ID:1573478
                  Start date and time:2024-12-12 04:52:08 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 4m 0s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:browseurl.jbs
                  Sample URL:http://o28sy4q7wu-dsn.algolia.net
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:8
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@17/2@6/5
                  EGA Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                  • Excluded IPs from analysis (whitelisted): 172.217.19.227, 172.217.17.78, 64.233.163.84, 172.217.17.46, 199.232.210.172, 192.229.221.95, 172.217.17.35, 23.35.236.109, 20.109.210.53, 13.107.246.63
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
                  • Not all processes where analyzed, report is missing behavior information
                  • VT rate limit hit for: http://o28sy4q7wu-dsn.algolia.net
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:JSON data
                  Category:downloaded
                  Size (bytes):164
                  Entropy (8bit):4.765689469062448
                  Encrypted:false
                  SSDEEP:3:YIzVErxKBiAIFkMKJMsMzEWAqA6NurSLHKCELKdXAEiBQST2DqJMzdkgHJ2ybL+n:YIh6LeMSM2WNuGLfEmdXMBQkCigp2cL+
                  MD5:BFED3480E14E9AF6C6921AE50973BC20
                  SHA1:D057F00DD0AA2FFCF743292D7313B665ABC971D9
                  SHA-256:81A1AC294C869F14D7EB4ABB5135E55DAFC98D938BE17536146C469AFE88D18D
                  SHA-512:8C95C435A1C69BA190B22EA0DBEAABA1235A19B083709BABD6A3B824A71340A929D29EA3E35869B10D9BFA6C4799104D4C07725A6C720A0969D47EE5789066F1
                  Malicious:false
                  Reputation:low
                  URL:https://algolia.net/1/404
                  Preview:{"message":"Path not supported by Algolia REST API. Please have a look at https://www.algolia.com/doc/rest-api/search/ for the list of valid commands","status":404}
                  No static file info

                  Download Network PCAP: filteredfull

                  • Total Packets: 71
                  • 443 (HTTPS)
                  • 80 (HTTP)
                  • 53 (DNS)
                  TimestampSource PortDest PortSource IPDest IP
                  Dec 12, 2024 04:53:04.138881922 CET49675443192.168.2.4173.222.162.32
                  Dec 12, 2024 04:53:07.854211092 CET49738443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:53:07.854301929 CET44349738142.250.181.132192.168.2.4
                  Dec 12, 2024 04:53:07.854399920 CET49738443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:53:07.854573011 CET49738443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:53:07.854590893 CET44349738142.250.181.132192.168.2.4
                  Dec 12, 2024 04:53:09.147577047 CET4974080192.168.2.4207.244.74.97
                  Dec 12, 2024 04:53:09.148314953 CET4974180192.168.2.4207.244.74.97
                  Dec 12, 2024 04:53:09.267030001 CET8049740207.244.74.97192.168.2.4
                  Dec 12, 2024 04:53:09.267613888 CET8049741207.244.74.97192.168.2.4
                  Dec 12, 2024 04:53:09.267709017 CET4974080192.168.2.4207.244.74.97
                  Dec 12, 2024 04:53:09.267868996 CET4974180192.168.2.4207.244.74.97
                  Dec 12, 2024 04:53:09.273303986 CET4974180192.168.2.4207.244.74.97
                  Dec 12, 2024 04:53:09.392678976 CET8049741207.244.74.97192.168.2.4
                  Dec 12, 2024 04:53:09.557706118 CET44349738142.250.181.132192.168.2.4
                  Dec 12, 2024 04:53:09.557965994 CET49738443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:53:09.557986021 CET44349738142.250.181.132192.168.2.4
                  Dec 12, 2024 04:53:09.559643984 CET44349738142.250.181.132192.168.2.4
                  Dec 12, 2024 04:53:09.559709072 CET49738443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:53:09.563901901 CET49738443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:53:09.563990116 CET44349738142.250.181.132192.168.2.4
                  Dec 12, 2024 04:53:09.607161999 CET49738443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:53:09.607180119 CET44349738142.250.181.132192.168.2.4
                  Dec 12, 2024 04:53:09.653062105 CET49738443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:53:10.364619017 CET8049741207.244.74.97192.168.2.4
                  Dec 12, 2024 04:53:10.415992022 CET4974180192.168.2.4207.244.74.97
                  Dec 12, 2024 04:53:10.583458900 CET49743443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:10.583559990 CET44349743149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:10.583657026 CET49743443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:10.583822966 CET49743443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:10.583842993 CET44349743149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:11.958812952 CET44349743149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:11.959100008 CET49743443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:11.959165096 CET44349743149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:11.960711956 CET44349743149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:11.960782051 CET49743443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:11.961644888 CET49743443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:11.961734056 CET44349743149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:11.961838961 CET49743443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:11.961857080 CET44349743149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:12.010070086 CET49743443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:12.462152004 CET44349743149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:12.462254047 CET44349743149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:12.462445974 CET49743443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:12.462949991 CET49743443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:12.462994099 CET44349743149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:12.511626959 CET49744443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:12.511719942 CET44349744149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:12.511842012 CET49744443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:12.512017012 CET49744443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:12.512036085 CET44349744149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:13.877748966 CET44349744149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:13.878038883 CET49744443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:13.878063917 CET44349744149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:13.878398895 CET44349744149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:13.878912926 CET49744443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:13.878954887 CET49744443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:13.879014969 CET44349744149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:13.934190989 CET49744443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:14.387969017 CET44349744149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:14.388039112 CET44349744149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:14.388086081 CET49744443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:14.388396025 CET49744443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:14.388416052 CET44349744149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:14.388428926 CET49744443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:14.388463974 CET49744443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:14.389945984 CET49745443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:14.390042067 CET44349745149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:14.390120029 CET49745443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:14.390316963 CET49745443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:14.390341043 CET44349745149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:15.772850037 CET44349745149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:15.773205996 CET49745443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:15.773271084 CET44349745149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:15.774446964 CET44349745149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:15.774749041 CET49745443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:15.774848938 CET49745443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:15.774861097 CET44349745149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:15.774928093 CET44349745149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:15.825470924 CET49745443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:16.288273096 CET44349745149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:16.288460016 CET44349745149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:16.288551092 CET49745443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:16.290072918 CET49745443192.168.2.4149.202.84.123
                  Dec 12, 2024 04:53:16.290116072 CET44349745149.202.84.123192.168.2.4
                  Dec 12, 2024 04:53:19.241300106 CET44349738142.250.181.132192.168.2.4
                  Dec 12, 2024 04:53:19.241436005 CET44349738142.250.181.132192.168.2.4
                  Dec 12, 2024 04:53:19.241488934 CET49738443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:53:19.608861923 CET49738443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:53:19.608891964 CET44349738142.250.181.132192.168.2.4
                  Dec 12, 2024 04:53:22.271606922 CET4972380192.168.2.4199.232.214.172
                  Dec 12, 2024 04:53:22.391282082 CET8049723199.232.214.172192.168.2.4
                  Dec 12, 2024 04:53:22.391347885 CET4972380192.168.2.4199.232.214.172
                  Dec 12, 2024 04:53:54.278752089 CET4974080192.168.2.4207.244.74.97
                  Dec 12, 2024 04:53:54.398524046 CET8049740207.244.74.97192.168.2.4
                  Dec 12, 2024 04:53:55.371629953 CET4974180192.168.2.4207.244.74.97
                  Dec 12, 2024 04:53:55.491627932 CET8049741207.244.74.97192.168.2.4
                  Dec 12, 2024 04:54:07.780014038 CET49770443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:54:07.780116081 CET44349770142.250.181.132192.168.2.4
                  Dec 12, 2024 04:54:07.780230999 CET49770443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:54:07.780847073 CET49770443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:54:07.780884981 CET44349770142.250.181.132192.168.2.4
                  Dec 12, 2024 04:54:09.474009037 CET44349770142.250.181.132192.168.2.4
                  Dec 12, 2024 04:54:09.474239111 CET49770443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:54:09.474262953 CET44349770142.250.181.132192.168.2.4
                  Dec 12, 2024 04:54:09.474778891 CET44349770142.250.181.132192.168.2.4
                  Dec 12, 2024 04:54:09.475254059 CET49770443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:54:09.475352049 CET44349770142.250.181.132192.168.2.4
                  Dec 12, 2024 04:54:09.528454065 CET49770443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:54:09.608134031 CET4974080192.168.2.4207.244.74.97
                  Dec 12, 2024 04:54:09.728102922 CET8049740207.244.74.97192.168.2.4
                  Dec 12, 2024 04:54:09.728442907 CET4974080192.168.2.4207.244.74.97
                  Dec 12, 2024 04:54:10.481762886 CET4972480192.168.2.4199.232.214.172
                  Dec 12, 2024 04:54:10.601670027 CET8049724199.232.214.172192.168.2.4
                  Dec 12, 2024 04:54:10.601859093 CET4972480192.168.2.4199.232.214.172
                  Dec 12, 2024 04:54:19.214559078 CET44349770142.250.181.132192.168.2.4
                  Dec 12, 2024 04:54:19.214689970 CET44349770142.250.181.132192.168.2.4
                  Dec 12, 2024 04:54:19.215018034 CET49770443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:54:19.607619047 CET49770443192.168.2.4142.250.181.132
                  Dec 12, 2024 04:54:19.607636929 CET44349770142.250.181.132192.168.2.4
                  Dec 12, 2024 04:54:25.378915071 CET8049741207.244.74.97192.168.2.4
                  Dec 12, 2024 04:54:25.378981113 CET4974180192.168.2.4207.244.74.97
                  Dec 12, 2024 04:54:25.607928991 CET4974180192.168.2.4207.244.74.97
                  Dec 12, 2024 04:54:25.727236032 CET8049741207.244.74.97192.168.2.4
                  TimestampSource PortDest PortSource IPDest IP
                  Dec 12, 2024 04:53:03.490278959 CET53523451.1.1.1192.168.2.4
                  Dec 12, 2024 04:53:03.571724892 CET53592781.1.1.1192.168.2.4
                  Dec 12, 2024 04:53:06.470397949 CET53525201.1.1.1192.168.2.4
                  Dec 12, 2024 04:53:07.716320992 CET5933253192.168.2.41.1.1.1
                  Dec 12, 2024 04:53:07.716423988 CET5531953192.168.2.41.1.1.1
                  Dec 12, 2024 04:53:07.853198051 CET53593321.1.1.1192.168.2.4
                  Dec 12, 2024 04:53:07.853389978 CET53553191.1.1.1192.168.2.4
                  Dec 12, 2024 04:53:08.787101984 CET5788653192.168.2.41.1.1.1
                  Dec 12, 2024 04:53:08.787218094 CET5325253192.168.2.41.1.1.1
                  Dec 12, 2024 04:53:09.133395910 CET53532521.1.1.1192.168.2.4
                  Dec 12, 2024 04:53:09.141046047 CET53578861.1.1.1192.168.2.4
                  Dec 12, 2024 04:53:10.367439985 CET5070753192.168.2.41.1.1.1
                  Dec 12, 2024 04:53:10.367439985 CET4958853192.168.2.41.1.1.1
                  Dec 12, 2024 04:53:10.582510948 CET53507071.1.1.1192.168.2.4
                  Dec 12, 2024 04:53:10.582829952 CET53495881.1.1.1192.168.2.4
                  Dec 12, 2024 04:53:22.066168070 CET138138192.168.2.4192.168.2.255
                  Dec 12, 2024 04:53:23.292663097 CET53587471.1.1.1192.168.2.4
                  Dec 12, 2024 04:53:42.073038101 CET53629531.1.1.1192.168.2.4
                  Dec 12, 2024 04:54:03.233366966 CET53582921.1.1.1192.168.2.4
                  Dec 12, 2024 04:54:04.375552893 CET53536031.1.1.1192.168.2.4
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Dec 12, 2024 04:53:07.716320992 CET192.168.2.41.1.1.10x9a9fStandard query (0)www.google.comA (IP address)IN (0x0001)false
                  Dec 12, 2024 04:53:07.716423988 CET192.168.2.41.1.1.10x9e99Standard query (0)www.google.com65IN (0x0001)false
                  Dec 12, 2024 04:53:08.787101984 CET192.168.2.41.1.1.10x527eStandard query (0)o28sy4q7wu-dsn.algolia.netA (IP address)IN (0x0001)false
                  Dec 12, 2024 04:53:08.787218094 CET192.168.2.41.1.1.10x59b9Standard query (0)o28sy4q7wu-dsn.algolia.net65IN (0x0001)false
                  Dec 12, 2024 04:53:10.367439985 CET192.168.2.41.1.1.10x316bStandard query (0)algolia.netA (IP address)IN (0x0001)false
                  Dec 12, 2024 04:53:10.367439985 CET192.168.2.41.1.1.10xcc53Standard query (0)algolia.net65IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Dec 12, 2024 04:53:07.853198051 CET1.1.1.1192.168.2.40x9a9fNo error (0)www.google.com142.250.181.132A (IP address)IN (0x0001)false
                  Dec 12, 2024 04:53:07.853389978 CET1.1.1.1192.168.2.40x9e99No error (0)www.google.com65IN (0x0001)false
                  Dec 12, 2024 04:53:09.133395910 CET1.1.1.1192.168.2.40x59b9No error (0)o28sy4q7wu-dsn.algolia.netdsn.o28sy4q7wu.api.algolia.netCNAME (Canonical name)IN (0x0001)false
                  Dec 12, 2024 04:53:09.133395910 CET1.1.1.1192.168.2.40x59b9No error (0)dsn.o28sy4q7wu.api.algolia.netd124-use-2.algolia.netCNAME (Canonical name)IN (0x0001)false
                  Dec 12, 2024 04:53:09.141046047 CET1.1.1.1192.168.2.40x527eNo error (0)o28sy4q7wu-dsn.algolia.netdsn.o28sy4q7wu.api.algolia.netCNAME (Canonical name)IN (0x0001)false
                  Dec 12, 2024 04:53:09.141046047 CET1.1.1.1192.168.2.40x527eNo error (0)dsn.o28sy4q7wu.api.algolia.netd124-use-1.algolia.netCNAME (Canonical name)IN (0x0001)false
                  Dec 12, 2024 04:53:09.141046047 CET1.1.1.1192.168.2.40x527eNo error (0)d124-use-1.algolia.net207.244.74.97A (IP address)IN (0x0001)false
                  Dec 12, 2024 04:53:10.582510948 CET1.1.1.1192.168.2.40x316bNo error (0)algolia.net149.202.84.123A (IP address)IN (0x0001)false
                  Dec 12, 2024 04:53:10.582510948 CET1.1.1.1192.168.2.40x316bNo error (0)algolia.net91.109.20.242A (IP address)IN (0x0001)false
                  Dec 12, 2024 04:53:10.582510948 CET1.1.1.1192.168.2.40x316bNo error (0)algolia.net103.254.154.6A (IP address)IN (0x0001)false
                  • algolia.net
                  • https:
                  • o28sy4q7wu-dsn.algolia.net
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.449741207.244.74.97802416C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Dec 12, 2024 04:53:09.273303986 CET441OUTGET / HTTP/1.1
                  Host: o28sy4q7wu-dsn.algolia.net
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Accept-Encoding: gzip, deflate
                  Accept-Language: en-US,en;q=0.9
                  Dec 12, 2024 04:53:10.364619017 CET517INHTTP/1.1 301 Moved Permanently
                  Server: nginx
                  Date: Thu, 12 Dec 2024 03:53:10 GMT
                  Content-Type: text/html
                  Content-Length: 162
                  Connection: keep-alive
                  Location: https://algolia.net/1/404
                  Access-Control-Allow-Origin: *
                  Timing-Allow-Origin: *
                  X-Content-Type-Options: nosniff
                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                  Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                  Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx</center></body></html>
                  Dec 12, 2024 04:53:55.371629953 CET6OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.449740207.244.74.97802416C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  Dec 12, 2024 04:53:54.278752089 CET6OUTData Raw: 00
                  Data Ascii:


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.449743149.202.84.1234432416C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-12-12 03:53:11 UTC659OUTGET /1/404 HTTP/1.1
                  Host: algolia.net
                  Connection: keep-alive
                  Upgrade-Insecure-Requests: 1
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                  Sec-Fetch-Site: none
                  Sec-Fetch-Mode: navigate
                  Sec-Fetch-User: ?1
                  Sec-Fetch-Dest: document
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  sec-ch-ua-platform: "Windows"
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-12-12 03:53:12 UTC372INHTTP/1.1 404 Not Found
                  Server: nginx
                  Date: Thu, 12 Dec 2024 03:53:12 GMT
                  Content-Type: application/json; charset=UTF-8
                  Content-Length: 164
                  Connection: close
                  Access-Control-Allow-Origin: *
                  Timing-Allow-Origin: *
                  X-Content-Type-Options: nosniff
                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                  Content-Disposition: inline; filename=a.txt
                  2024-12-12 03:53:12 UTC164INData Raw: 7b 22 6d 65 73 73 61 67 65 22 3a 22 50 61 74 68 20 6e 6f 74 20 73 75 70 70 6f 72 74 65 64 20 62 79 20 41 6c 67 6f 6c 69 61 20 52 45 53 54 20 41 50 49 2e 20 50 6c 65 61 73 65 20 68 61 76 65 20 61 20 6c 6f 6f 6b 20 61 74 20 68 74 74 70 73 3a 2f 2f 77 77 77 2e 61 6c 67 6f 6c 69 61 2e 63 6f 6d 2f 64 6f 63 2f 72 65 73 74 2d 61 70 69 2f 73 65 61 72 63 68 2f 20 66 6f 72 20 74 68 65 20 6c 69 73 74 20 6f 66 20 76 61 6c 69 64 20 63 6f 6d 6d 61 6e 64 73 22 2c 22 73 74 61 74 75 73 22 3a 34 30 34 7d
                  Data Ascii: {"message":"Path not supported by Algolia REST API. Please have a look at https://www.algolia.com/doc/rest-api/search/ for the list of valid commands","status":404}


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.449744149.202.84.1234432416C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-12-12 03:53:13 UTC583OUTGET /favicon.ico HTTP/1.1
                  Host: algolia.net
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  sec-ch-ua-platform: "Windows"
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://algolia.net/1/404
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-12-12 03:53:14 UTC350INHTTP/1.1 301 Moved Permanently
                  Server: nginx
                  Date: Thu, 12 Dec 2024 03:53:14 GMT
                  Content-Type: text/html
                  Content-Length: 162
                  Connection: close
                  Location: https://algolia.net/1/404
                  Access-Control-Allow-Origin: *
                  Timing-Allow-Origin: *
                  X-Content-Type-Options: nosniff
                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                  2024-12-12 03:53:14 UTC162INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 33 30 31 20 4d 6f 76 65 64 20 50 65 72 6d 61 6e 65 6e 74 6c 79 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a
                  Data Ascii: <html><head><title>301 Moved Permanently</title></head><body><center><h1>301 Moved Permanently</h1></center><hr><center>nginx</center></body></html>


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.449745149.202.84.1234432416C:\Program Files\Google\Chrome\Application\chrome.exe
                  TimestampBytes transferredDirectionData
                  2024-12-12 03:53:15 UTC577OUTGET /1/404 HTTP/1.1
                  Host: algolia.net
                  Connection: keep-alive
                  sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                  sec-ch-ua-mobile: ?0
                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                  sec-ch-ua-platform: "Windows"
                  Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                  Sec-Fetch-Site: same-origin
                  Sec-Fetch-Mode: no-cors
                  Sec-Fetch-Dest: image
                  Referer: https://algolia.net/1/404
                  Accept-Encoding: gzip, deflate, br
                  Accept-Language: en-US,en;q=0.9
                  2024-12-12 03:53:16 UTC372INHTTP/1.1 404 Not Found
                  Server: nginx
                  Date: Thu, 12 Dec 2024 03:53:16 GMT
                  Content-Type: application/json; charset=UTF-8
                  Content-Length: 164
                  Connection: close
                  Access-Control-Allow-Origin: *
                  Timing-Allow-Origin: *
                  X-Content-Type-Options: nosniff
                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                  Content-Disposition: inline; filename=a.txt
                  2024-12-12 03:53:16 UTC164INData Raw: 7b 22 6d 65 73 73 61 67 65 22 3a 22 50 61 74 68 20 6e 6f 74 20 73 75 70 70 6f 72 74 65 64 20 62 79 20 41 6c 67 6f 6c 69 61 20 52 45 53 54 20 41 50 49 2e 20 50 6c 65 61 73 65 20 68 61 76 65 20 61 20 6c 6f 6f 6b 20 61 74 20 68 74 74 70 73 3a 2f 2f 77 77 77 2e 61 6c 67 6f 6c 69 61 2e 63 6f 6d 2f 64 6f 63 2f 72 65 73 74 2d 61 70 69 2f 73 65 61 72 63 68 2f 20 66 6f 72 20 74 68 65 20 6c 69 73 74 20 6f 66 20 76 61 6c 69 64 20 63 6f 6d 6d 61 6e 64 73 22 2c 22 73 74 61 74 75 73 22 3a 34 30 34 7d
                  Data Ascii: {"message":"Path not supported by Algolia REST API. Please have a look at https://www.algolia.com/doc/rest-api/search/ for the list of valid commands","status":404}


                  020406080s020406080100

                  Click to jump to process

                  020406080s0.0020406080100MB

                  Click to jump to process

                  Target ID:0
                  Start time:22:52:59
                  Start date:11/12/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:22:53:02
                  Start date:11/12/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2492 --field-trial-handle=2460,i,7891699012482754450,14498568815434285668,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:false

                  Target ID:3
                  Start time:22:53:08
                  Start date:11/12/2024
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://o28sy4q7wu-dsn.algolia.net"
                  Imagebase:0x7ff76e190000
                  File size:3'242'272 bytes
                  MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low
                  Has exited:true
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
                  There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

                  No disassembly