Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://url7700.sugarwish.com/wf/open?upn=u001.xPKdG7DIDBRNWMoHAlI-2F9w-2BL0mz-2F-2B7nzUKMxCUcVPh0sm-2Bt6QBVj4HRDbUSeK95ZOZkhwOQ66hq6Y-2FSiZvX2SPxbhF9aQfNXHuF3wwfNJG48vKmZPxEA43n817ElrV1J5tWcQjvpIeDTe5WGdHPj8Bu8rMnfxYNCU2mfFRm-2BYRFyvN8Nf96DVgYAvGR-2FH-2F9jpWcCpdtSx3qCvIelB9I2LUDWux4RvO4gLO3wUwXoFzBI

Overview

General Information

Sample URL:http://url7700.sugarwish.com/wf/open?upn=u001.xPKdG7DIDBRNWMoHAlI-2F9w-2BL0mz-2F-2B7nzUKMxCUcVPh0sm-2Bt6QBVj4HRDbUSeK95ZOZkhwOQ66hq6Y-2FSiZvX2SPxbhF9aQfNXHuF3wwfNJG48vKmZPxEA43n817ElrV1J5tWcQjvpIeDTe5
Analysis ID:1580419
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4836 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 1460 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2232 --field-trial-handle=2164,i,11409191433582876295,12870069023951760183,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 5084 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://url7700.sugarwish.com/wf/open?upn=u001.xPKdG7DIDBRNWMoHAlI-2F9w-2BL0mz-2F-2B7nzUKMxCUcVPh0sm-2Bt6QBVj4HRDbUSeK95ZOZkhwOQ66hq6Y-2FSiZvX2SPxbhF9aQfNXHuF3wwfNJG48vKmZPxEA43n817ElrV1J5tWcQjvpIeDTe5WGdHPj8Bu8rMnfxYNCU2mfFRm-2BYRFyvN8Nf96DVgYAvGR-2FH-2F9jpWcCpdtSx3qCvIelB9I2LUDWux4RvO4gLO3wUwXoFzBI6sgiMltNv1hr8KIqmtJy" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: http://url7700.sugarwish.com/wf/open?upn=u001.xPKdG7DIDBRNWMoHAlI-2F9w-2BL0mz-2F-2B7nzUKMxCUcVPh0sm-2Bt6QBVj4HRDbUSeK95ZOZkhwOQ66hq6Y-2FSiZvX2SPxbhF9aQfNXHuF3wwfNJG48vKmZPxEA43n817ElrV1J5tWcQjvpIeDTe5WGdHPj8Bu8rMnfxYNCU2mfFRm-2BYRFyvN8Nf96DVgYAvGR-2FH-2F9jpWcCpdtSx3qCvIelB9I2LUDWux4RvO4gLO3wUwXoFzBI6sgiMltNv1hr8KIqmtJyHTTP Parser: No favicon
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 40.81.94.65
Source: global trafficHTTP traffic detected: GET /wf/open?upn=u001.xPKdG7DIDBRNWMoHAlI-2F9w-2BL0mz-2F-2B7nzUKMxCUcVPh0sm-2Bt6QBVj4HRDbUSeK95ZOZkhwOQ66hq6Y-2FSiZvX2SPxbhF9aQfNXHuF3wwfNJG48vKmZPxEA43n817ElrV1J5tWcQjvpIeDTe5WGdHPj8Bu8rMnfxYNCU2mfFRm-2BYRFyvN8Nf96DVgYAvGR-2FH-2F9jpWcCpdtSx3qCvIelB9I2LUDWux4RvO4gLO3wUwXoFzBI6sgiMltNv1hr8KIqmtJy HTTP/1.1Host: url7700.sugarwish.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: url7700.sugarwish.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://url7700.sugarwish.com/wf/open?upn=u001.xPKdG7DIDBRNWMoHAlI-2F9w-2BL0mz-2F-2B7nzUKMxCUcVPh0sm-2Bt6QBVj4HRDbUSeK95ZOZkhwOQ66hq6Y-2FSiZvX2SPxbhF9aQfNXHuF3wwfNJG48vKmZPxEA43n817ElrV1J5tWcQjvpIeDTe5WGdHPj8Bu8rMnfxYNCU2mfFRm-2BYRFyvN8Nf96DVgYAvGR-2FH-2F9jpWcCpdtSx3qCvIelB9I2LUDWux4RvO4gLO3wUwXoFzBI6sgiMltNv1hr8KIqmtJyAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: url7700.sugarwish.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 24 Dec 2024 13:02:45 GMTContent-Type: text/htmlContent-Length: 564Connection: keep-aliveData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a Data Ascii: <html><head><title>404 Not Found</title></head><body bgcolor="white"><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page --><!-- a padding to disable MSIE and Chrome friendly error page -->
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
Source: classification engineClassification label: clean0.win@16/2@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2232 --field-trial-handle=2164,i,11409191433582876295,12870069023951760183,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://url7700.sugarwish.com/wf/open?upn=u001.xPKdG7DIDBRNWMoHAlI-2F9w-2BL0mz-2F-2B7nzUKMxCUcVPh0sm-2Bt6QBVj4HRDbUSeK95ZOZkhwOQ66hq6Y-2FSiZvX2SPxbhF9aQfNXHuF3wwfNJG48vKmZPxEA43n817ElrV1J5tWcQjvpIeDTe5WGdHPj8Bu8rMnfxYNCU2mfFRm-2BYRFyvN8Nf96DVgYAvGR-2FH-2F9jpWcCpdtSx3qCvIelB9I2LUDWux4RvO4gLO3wUwXoFzBI6sgiMltNv1hr8KIqmtJy"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2232 --field-trial-handle=2164,i,11409191433582876295,12870069023951760183,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://url7700.sugarwish.com/wf/open?upn=u001.xPKdG7DIDBRNWMoHAlI-2F9w-2BL0mz-2F-2B7nzUKMxCUcVPh0sm-2Bt6QBVj4HRDbUSeK95ZOZkhwOQ66hq6Y-2FSiZvX2SPxbhF9aQfNXHuF3wwfNJG48vKmZPxEA43n817ElrV1J5tWcQjvpIeDTe5WGdHPj8Bu8rMnfxYNCU2mfFRm-2BYRFyvN8Nf96DVgYAvGR-2FH-2F9jpWcCpdtSx3qCvIelB9I2LUDWux4RvO4gLO3wUwXoFzBI6sgiMltNv1hr8KIqmtJy0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://url7700.sugarwish.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
sendgrid.net
167.89.115.150
truefalse
    high
    www.google.com
    142.250.181.68
    truefalse
      high
      url7700.sugarwish.com
      unknown
      unknownfalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://url7700.sugarwish.com/favicon.icofalse
        • Avira URL Cloud: safe
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        142.250.181.68
        www.google.comUnited States
        15169GOOGLEUSfalse
        167.89.115.150
        sendgrid.netUnited States
        11377SENDGRIDUSfalse
        IP
        192.168.2.7
        Joe Sandbox version:41.0.0 Charoite
        Analysis ID:1580419
        Start date and time:2024-12-24 14:01:42 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 51s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://url7700.sugarwish.com/wf/open?upn=u001.xPKdG7DIDBRNWMoHAlI-2F9w-2BL0mz-2F-2B7nzUKMxCUcVPh0sm-2Bt6QBVj4HRDbUSeK95ZOZkhwOQ66hq6Y-2FSiZvX2SPxbhF9aQfNXHuF3wwfNJG48vKmZPxEA43n817ElrV1J5tWcQjvpIeDTe5WGdHPj8Bu8rMnfxYNCU2mfFRm-2BYRFyvN8Nf96DVgYAvGR-2FH-2F9jpWcCpdtSx3qCvIelB9I2LUDWux4RvO4gLO3wUwXoFzBI6sgiMltNv1hr8KIqmtJy
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:14
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean0.win@16/2@4/4
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 172.217.21.35, 142.250.181.142, 173.194.220.84, 199.232.210.172, 172.217.17.46, 172.217.17.35, 13.107.246.63, 23.218.208.109, 4.175.87.197
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, time.windows.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
        • Not all processes where analyzed, report is missing behavior information
        • VT rate limit hit for: http://url7700.sugarwish.com/wf/open?upn=u001.xPKdG7DIDBRNWMoHAlI-2F9w-2BL0mz-2F-2B7nzUKMxCUcVPh0sm-2Bt6QBVj4HRDbUSeK95ZOZkhwOQ66hq6Y-2FSiZvX2SPxbhF9aQfNXHuF3wwfNJG48vKmZPxEA43n817ElrV1J5tWcQjvpIeDTe5WGdHPj8Bu8rMnfxYNCU2mfFRm-2BYRFyvN8Nf96DVgYAvGR-2FH-2F9jpWcCpdtSx3qCvIelB9I2LUDWux4RvO4gLO3wUwXoFzBI6sgiMltNv1hr8KIqmtJy
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text, with CRLF line terminators
        Category:downloaded
        Size (bytes):564
        Entropy (8bit):4.72971822420855
        Encrypted:false
        SSDEEP:12:TjeRHdHiHZdtklI5r8INGlTF5TF5TF5TF5TF5TFK:neRH988DTPTPTPTPTPTc
        MD5:8E325DC2FEA7C8900FC6C4B8C6C394FE
        SHA1:1B3291D4EEA179C84145B2814CB53E6A506EC201
        SHA-256:0B52C5338AF355699530A47683420E48C7344E779D3E815FF9943CBFDC153CF2
        SHA-512:084C608F1F860FB08EF03B155658EA9988B3628D3C0F0E9561FDFF930E5912004CDDBCC43B1FA90C21FE7F5A481AC47C64B8CAA066C2BDF3CF533E152BF96C14
        Malicious:false
        Reputation:low
        URL:http://url7700.sugarwish.com/favicon.ico
        Preview:<html>..<head><title>404 Not Found</title></head>..<body bgcolor="white">..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Dec 24, 2024 14:02:29.336725950 CET49671443192.168.2.7204.79.197.203
        Dec 24, 2024 14:02:29.648937941 CET49671443192.168.2.7204.79.197.203
        Dec 24, 2024 14:02:30.258200884 CET49671443192.168.2.7204.79.197.203
        Dec 24, 2024 14:02:30.586390972 CET49674443192.168.2.7104.98.116.138
        Dec 24, 2024 14:02:30.586422920 CET49675443192.168.2.7104.98.116.138
        Dec 24, 2024 14:02:30.695713043 CET49672443192.168.2.7104.98.116.138
        Dec 24, 2024 14:02:31.461347103 CET49671443192.168.2.7204.79.197.203
        Dec 24, 2024 14:02:33.867566109 CET49671443192.168.2.7204.79.197.203
        Dec 24, 2024 14:02:37.886853933 CET49677443192.168.2.720.50.201.200
        Dec 24, 2024 14:02:38.383279085 CET49677443192.168.2.720.50.201.200
        Dec 24, 2024 14:02:38.804869890 CET49671443192.168.2.7204.79.197.203
        Dec 24, 2024 14:02:39.179836988 CET49677443192.168.2.720.50.201.200
        Dec 24, 2024 14:02:40.304689884 CET49672443192.168.2.7104.98.116.138
        Dec 24, 2024 14:02:40.382781982 CET49674443192.168.2.7104.98.116.138
        Dec 24, 2024 14:02:40.382853031 CET49675443192.168.2.7104.98.116.138
        Dec 24, 2024 14:02:40.679651976 CET49677443192.168.2.720.50.201.200
        Dec 24, 2024 14:02:41.756954908 CET49706443192.168.2.7142.250.181.68
        Dec 24, 2024 14:02:41.757004023 CET44349706142.250.181.68192.168.2.7
        Dec 24, 2024 14:02:41.757077932 CET49706443192.168.2.7142.250.181.68
        Dec 24, 2024 14:02:41.757308006 CET49706443192.168.2.7142.250.181.68
        Dec 24, 2024 14:02:41.757325888 CET44349706142.250.181.68192.168.2.7
        Dec 24, 2024 14:02:43.345237017 CET44349698104.98.116.138192.168.2.7
        Dec 24, 2024 14:02:43.345441103 CET49698443192.168.2.7104.98.116.138
        Dec 24, 2024 14:02:43.452928066 CET44349706142.250.181.68192.168.2.7
        Dec 24, 2024 14:02:43.453224897 CET49706443192.168.2.7142.250.181.68
        Dec 24, 2024 14:02:43.453264952 CET44349706142.250.181.68192.168.2.7
        Dec 24, 2024 14:02:43.454251051 CET44349706142.250.181.68192.168.2.7
        Dec 24, 2024 14:02:43.454336882 CET49706443192.168.2.7142.250.181.68
        Dec 24, 2024 14:02:43.456315994 CET49706443192.168.2.7142.250.181.68
        Dec 24, 2024 14:02:43.456399918 CET44349706142.250.181.68192.168.2.7
        Dec 24, 2024 14:02:43.498337984 CET49706443192.168.2.7142.250.181.68
        Dec 24, 2024 14:02:43.498374939 CET44349706142.250.181.68192.168.2.7
        Dec 24, 2024 14:02:43.550956964 CET49706443192.168.2.7142.250.181.68
        Dec 24, 2024 14:02:43.667733908 CET49677443192.168.2.720.50.201.200
        Dec 24, 2024 14:02:43.941145897 CET4970980192.168.2.7167.89.115.150
        Dec 24, 2024 14:02:43.941862106 CET4971080192.168.2.7167.89.115.150
        Dec 24, 2024 14:02:44.064106941 CET8049709167.89.115.150192.168.2.7
        Dec 24, 2024 14:02:44.064246893 CET4970980192.168.2.7167.89.115.150
        Dec 24, 2024 14:02:44.064429998 CET4970980192.168.2.7167.89.115.150
        Dec 24, 2024 14:02:44.064793110 CET8049710167.89.115.150192.168.2.7
        Dec 24, 2024 14:02:44.064856052 CET4971080192.168.2.7167.89.115.150
        Dec 24, 2024 14:02:44.183877945 CET8049709167.89.115.150192.168.2.7
        Dec 24, 2024 14:02:45.160794973 CET8049709167.89.115.150192.168.2.7
        Dec 24, 2024 14:02:45.206201077 CET4970980192.168.2.7167.89.115.150
        Dec 24, 2024 14:02:45.358460903 CET4970980192.168.2.7167.89.115.150
        Dec 24, 2024 14:02:45.478009939 CET8049709167.89.115.150192.168.2.7
        Dec 24, 2024 14:02:45.677285910 CET8049709167.89.115.150192.168.2.7
        Dec 24, 2024 14:02:45.742904902 CET4970980192.168.2.7167.89.115.150
        Dec 24, 2024 14:02:48.414963007 CET49671443192.168.2.7204.79.197.203
        Dec 24, 2024 14:02:49.633588076 CET49677443192.168.2.720.50.201.200
        Dec 24, 2024 14:02:51.200113058 CET49698443192.168.2.7104.98.116.138
        Dec 24, 2024 14:02:51.200789928 CET49729443192.168.2.7104.98.116.138
        Dec 24, 2024 14:02:51.200800896 CET44349729104.98.116.138192.168.2.7
        Dec 24, 2024 14:02:51.200860977 CET49729443192.168.2.7104.98.116.138
        Dec 24, 2024 14:02:51.201520920 CET49729443192.168.2.7104.98.116.138
        Dec 24, 2024 14:02:51.201529026 CET44349729104.98.116.138192.168.2.7
        Dec 24, 2024 14:02:51.319591999 CET44349698104.98.116.138192.168.2.7
        Dec 24, 2024 14:02:53.145520926 CET44349706142.250.181.68192.168.2.7
        Dec 24, 2024 14:02:53.145586014 CET44349706142.250.181.68192.168.2.7
        Dec 24, 2024 14:02:53.145701885 CET49706443192.168.2.7142.250.181.68
        Dec 24, 2024 14:02:53.931842089 CET49706443192.168.2.7142.250.181.68
        Dec 24, 2024 14:02:53.931859016 CET44349706142.250.181.68192.168.2.7
        Dec 24, 2024 14:03:01.539803982 CET49677443192.168.2.720.50.201.200
        Dec 24, 2024 14:03:29.071727991 CET4971080192.168.2.7167.89.115.150
        Dec 24, 2024 14:03:29.191464901 CET8049710167.89.115.150192.168.2.7
        Dec 24, 2024 14:03:30.681071043 CET4970980192.168.2.7167.89.115.150
        Dec 24, 2024 14:03:30.800962925 CET8049709167.89.115.150192.168.2.7
        Dec 24, 2024 14:03:35.253420115 CET44349729104.98.116.138192.168.2.7
        Dec 24, 2024 14:03:35.253551960 CET49729443192.168.2.7104.98.116.138
        Dec 24, 2024 14:03:41.682214022 CET49846443192.168.2.7142.250.181.68
        Dec 24, 2024 14:03:41.682252884 CET44349846142.250.181.68192.168.2.7
        Dec 24, 2024 14:03:41.682357073 CET49846443192.168.2.7142.250.181.68
        Dec 24, 2024 14:03:41.682606936 CET49846443192.168.2.7142.250.181.68
        Dec 24, 2024 14:03:41.682616949 CET44349846142.250.181.68192.168.2.7
        Dec 24, 2024 14:03:43.370814085 CET44349846142.250.181.68192.168.2.7
        Dec 24, 2024 14:03:43.371195078 CET49846443192.168.2.7142.250.181.68
        Dec 24, 2024 14:03:43.371207952 CET44349846142.250.181.68192.168.2.7
        Dec 24, 2024 14:03:43.371484995 CET44349846142.250.181.68192.168.2.7
        Dec 24, 2024 14:03:43.371978998 CET49846443192.168.2.7142.250.181.68
        Dec 24, 2024 14:03:43.372025013 CET44349846142.250.181.68192.168.2.7
        Dec 24, 2024 14:03:43.415014982 CET49846443192.168.2.7142.250.181.68
        Dec 24, 2024 14:03:44.967901945 CET8049710167.89.115.150192.168.2.7
        Dec 24, 2024 14:03:44.967988014 CET4971080192.168.2.7167.89.115.150
        Dec 24, 2024 14:03:45.936028004 CET4971080192.168.2.7167.89.115.150
        Dec 24, 2024 14:03:46.055496931 CET8049710167.89.115.150192.168.2.7
        Dec 24, 2024 14:03:50.681595087 CET8049709167.89.115.150192.168.2.7
        Dec 24, 2024 14:03:50.685338974 CET4970980192.168.2.7167.89.115.150
        Dec 24, 2024 14:03:51.935118914 CET4970980192.168.2.7167.89.115.150
        Dec 24, 2024 14:03:52.054600954 CET8049709167.89.115.150192.168.2.7
        Dec 24, 2024 14:03:53.079123020 CET44349846142.250.181.68192.168.2.7
        Dec 24, 2024 14:03:53.079224110 CET44349846142.250.181.68192.168.2.7
        Dec 24, 2024 14:03:53.079272985 CET49846443192.168.2.7142.250.181.68
        Dec 24, 2024 14:03:53.934542894 CET49846443192.168.2.7142.250.181.68
        Dec 24, 2024 14:03:53.934575081 CET44349846142.250.181.68192.168.2.7
        TimestampSource PortDest PortSource IPDest IP
        Dec 24, 2024 14:02:37.848670006 CET53492951.1.1.1192.168.2.7
        Dec 24, 2024 14:02:37.852089882 CET53569421.1.1.1192.168.2.7
        Dec 24, 2024 14:02:40.612484932 CET53492741.1.1.1192.168.2.7
        Dec 24, 2024 14:02:41.618238926 CET5956153192.168.2.71.1.1.1
        Dec 24, 2024 14:02:41.618380070 CET5572853192.168.2.71.1.1.1
        Dec 24, 2024 14:02:41.754971981 CET53557281.1.1.1192.168.2.7
        Dec 24, 2024 14:02:41.756007910 CET53595611.1.1.1192.168.2.7
        Dec 24, 2024 14:02:43.528254986 CET6412453192.168.2.71.1.1.1
        Dec 24, 2024 14:02:43.528656960 CET6451053192.168.2.71.1.1.1
        Dec 24, 2024 14:02:43.939919949 CET53641241.1.1.1192.168.2.7
        Dec 24, 2024 14:02:43.940114021 CET53645101.1.1.1192.168.2.7
        Dec 24, 2024 14:02:44.265763998 CET123123192.168.2.740.81.94.65
        Dec 24, 2024 14:02:45.597064018 CET12312340.81.94.65192.168.2.7
        Dec 24, 2024 14:02:57.759130001 CET53654761.1.1.1192.168.2.7
        Dec 24, 2024 14:03:16.428932905 CET53519151.1.1.1192.168.2.7
        Dec 24, 2024 14:03:37.387294054 CET53505851.1.1.1192.168.2.7
        Dec 24, 2024 14:03:38.373924971 CET138138192.168.2.7192.168.2.255
        Dec 24, 2024 14:03:38.834450960 CET53516041.1.1.1192.168.2.7
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Dec 24, 2024 14:02:41.618238926 CET192.168.2.71.1.1.10xf088Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:41.618380070 CET192.168.2.71.1.1.10x91bdStandard query (0)www.google.com65IN (0x0001)false
        Dec 24, 2024 14:02:43.528254986 CET192.168.2.71.1.1.10xf56fStandard query (0)url7700.sugarwish.comA (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.528656960 CET192.168.2.71.1.1.10xb89dStandard query (0)url7700.sugarwish.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Dec 24, 2024 14:02:41.754971981 CET1.1.1.1192.168.2.70x91bdNo error (0)www.google.com65IN (0x0001)false
        Dec 24, 2024 14:02:41.756007910 CET1.1.1.1192.168.2.70xf088No error (0)www.google.com142.250.181.68A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)url7700.sugarwish.comsendgrid.netCNAME (Canonical name)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.115.150A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.118.128A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.115.52A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.118.62A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.115.56A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.118.52A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.115.77A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.118.95A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.115.120A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.115.78A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.118.61A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.115.61A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.118.83A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.115.28A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.118.109A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.939919949 CET1.1.1.1192.168.2.70xf56fNo error (0)sendgrid.net167.89.118.120A (IP address)IN (0x0001)false
        Dec 24, 2024 14:02:43.940114021 CET1.1.1.1192.168.2.70xb89dNo error (0)url7700.sugarwish.comsendgrid.netCNAME (Canonical name)IN (0x0001)false
        • url7700.sugarwish.com
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.749709167.89.115.150801460C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Dec 24, 2024 14:02:44.064429998 CET727OUTGET /wf/open?upn=u001.xPKdG7DIDBRNWMoHAlI-2F9w-2BL0mz-2F-2B7nzUKMxCUcVPh0sm-2Bt6QBVj4HRDbUSeK95ZOZkhwOQ66hq6Y-2FSiZvX2SPxbhF9aQfNXHuF3wwfNJG48vKmZPxEA43n817ElrV1J5tWcQjvpIeDTe5WGdHPj8Bu8rMnfxYNCU2mfFRm-2BYRFyvN8Nf96DVgYAvGR-2FH-2F9jpWcCpdtSx3qCvIelB9I2LUDWux4RvO4gLO3wUwXoFzBI6sgiMltNv1hr8KIqmtJy HTTP/1.1
        Host: url7700.sugarwish.com
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Dec 24, 2024 14:02:45.160794973 CET335INHTTP/1.1 200 OK
        Server: nginx
        Date: Tue, 24 Dec 2024 13:02:45 GMT
        Content-Type: image/gif
        Content-Length: 43
        Connection: keep-alive
        Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
        Expires: Sat, 15 Jul 2000 05:00:00 GMT
        X-Robots-Tag: noindex, nofollow
        Data Raw: 47 49 46 38 39 61 01 00 01 00 80 00 00 ff ff ff 00 00 00 21 f9 04 01 00 00 00 00 2c 00 00 00 00 01 00 01 00 00 02 02 44 01 00 3b
        Data Ascii: GIF89a!,D;
        Dec 24, 2024 14:02:45.358460903 CET677OUTGET /favicon.ico HTTP/1.1
        Host: url7700.sugarwish.com
        Connection: keep-alive
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Referer: http://url7700.sugarwish.com/wf/open?upn=u001.xPKdG7DIDBRNWMoHAlI-2F9w-2BL0mz-2F-2B7nzUKMxCUcVPh0sm-2Bt6QBVj4HRDbUSeK95ZOZkhwOQ66hq6Y-2FSiZvX2SPxbhF9aQfNXHuF3wwfNJG48vKmZPxEA43n817ElrV1J5tWcQjvpIeDTe5WGdHPj8Bu8rMnfxYNCU2mfFRm-2BYRFyvN8Nf96DVgYAvGR-2FH-2F9jpWcCpdtSx3qCvIelB9I2LUDWux4RvO4gLO3wUwXoFzBI6sgiMltNv1hr8KIqmtJy
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        Dec 24, 2024 14:02:45.677285910 CET712INHTTP/1.1 404 Not Found
        Server: nginx
        Date: Tue, 24 Dec 2024 13:02:45 GMT
        Content-Type: text/html
        Content-Length: 564
        Connection: keep-alive
        Data Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 20 62 67 63 6f 6c 6f 72 3d 22 77 68 69 74 65 22 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 [TRUNCATED]
        Data Ascii: <html><head><title>404 Not Found</title></head><body bgcolor="white"><center><h1>404 Not Found</h1></center><hr><center>nginx</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and Chrome friendly error page -->
        Dec 24, 2024 14:03:30.681071043 CET6OUTData Raw: 00
        Data Ascii:


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.749710167.89.115.150801460C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        Dec 24, 2024 14:03:29.071727991 CET6OUTData Raw: 00
        Data Ascii:


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:08:02:32
        Start date:24/12/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff6c4390000
        File size:3'242'272 bytes
        MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:08:02:36
        Start date:24/12/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2232 --field-trial-handle=2164,i,11409191433582876295,12870069023951760183,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff6c4390000
        File size:3'242'272 bytes
        MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:9
        Start time:08:02:42
        Start date:24/12/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://url7700.sugarwish.com/wf/open?upn=u001.xPKdG7DIDBRNWMoHAlI-2F9w-2BL0mz-2F-2B7nzUKMxCUcVPh0sm-2Bt6QBVj4HRDbUSeK95ZOZkhwOQ66hq6Y-2FSiZvX2SPxbhF9aQfNXHuF3wwfNJG48vKmZPxEA43n817ElrV1J5tWcQjvpIeDTe5WGdHPj8Bu8rMnfxYNCU2mfFRm-2BYRFyvN8Nf96DVgYAvGR-2FH-2F9jpWcCpdtSx3qCvIelB9I2LUDWux4RvO4gLO3wUwXoFzBI6sgiMltNv1hr8KIqmtJy"
        Imagebase:0x7ff6c4390000
        File size:3'242'272 bytes
        MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly