Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://volmar.sinformations.cfd

Overview

General Information

Sample URL:http://volmar.sinformations.cfd
Analysis ID:1581493
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 2344 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1360 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2004,i,15814095141836103454,17948706345906513014,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6476 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://volmar.sinformations.cfd" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://volmar.sinformations.cfdAvira URL Cloud: detection malicious, Label: malware
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: volmar.sinformations.cfd
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: mal48.win@20/0@16/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2004,i,15814095141836103454,17948706345906513014,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://volmar.sinformations.cfd"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2004,i,15814095141836103454,17948706345906513014,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://volmar.sinformations.cfd100%Avira URL Cloudmalware
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.181.110
truefalse
    high
    www.google.com
    142.250.181.68
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        high
        volmar.sinformations.cfd
        unknown
        unknownfalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          142.250.181.68
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.4
          Joe Sandbox version:41.0.0 Charoite
          Analysis ID:1581493
          Start date and time:2024-12-27 22:25:28 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 1m 48s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://volmar.sinformations.cfd
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:7
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:MAL
          Classification:mal48.win@20/0@16/3
          Cookbook Comments:
          • URL browsing timeout or error
          • URL not reachable
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 172.217.21.35, 64.233.161.84, 142.250.181.142, 172.217.17.46, 217.20.58.100, 192.229.221.95, 23.218.208.109, 20.109.210.53
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, ocsp.digicert.com, slscr.update.microsoft.com, ocsp.edge.digicert.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • VT rate limit hit for: http://volmar.sinformations.cfd
          No simulations
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Dec 27, 2024 22:26:19.739339113 CET49675443192.168.2.4173.222.162.32
          Dec 27, 2024 22:26:29.347172022 CET49675443192.168.2.4173.222.162.32
          Dec 27, 2024 22:26:32.129277945 CET49737443192.168.2.4142.250.181.68
          Dec 27, 2024 22:26:32.129331112 CET44349737142.250.181.68192.168.2.4
          Dec 27, 2024 22:26:32.129410028 CET49737443192.168.2.4142.250.181.68
          Dec 27, 2024 22:26:32.129587889 CET49737443192.168.2.4142.250.181.68
          Dec 27, 2024 22:26:32.129607916 CET44349737142.250.181.68192.168.2.4
          Dec 27, 2024 22:26:33.878825903 CET44349737142.250.181.68192.168.2.4
          Dec 27, 2024 22:26:33.885435104 CET49737443192.168.2.4142.250.181.68
          Dec 27, 2024 22:26:33.885456085 CET44349737142.250.181.68192.168.2.4
          Dec 27, 2024 22:26:33.887418985 CET44349737142.250.181.68192.168.2.4
          Dec 27, 2024 22:26:33.887475967 CET49737443192.168.2.4142.250.181.68
          Dec 27, 2024 22:26:33.889419079 CET49737443192.168.2.4142.250.181.68
          Dec 27, 2024 22:26:33.889508963 CET44349737142.250.181.68192.168.2.4
          Dec 27, 2024 22:26:33.929897070 CET49737443192.168.2.4142.250.181.68
          Dec 27, 2024 22:26:33.929918051 CET44349737142.250.181.68192.168.2.4
          Dec 27, 2024 22:26:33.975796938 CET49737443192.168.2.4142.250.181.68
          Dec 27, 2024 22:26:43.572465897 CET44349737142.250.181.68192.168.2.4
          Dec 27, 2024 22:26:43.572530031 CET44349737142.250.181.68192.168.2.4
          Dec 27, 2024 22:26:43.572597980 CET49737443192.168.2.4142.250.181.68
          Dec 27, 2024 22:26:43.990564108 CET49737443192.168.2.4142.250.181.68
          Dec 27, 2024 22:26:43.990578890 CET44349737142.250.181.68192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          Dec 27, 2024 22:26:27.710948944 CET53632701.1.1.1192.168.2.4
          Dec 27, 2024 22:26:27.716217041 CET53549901.1.1.1192.168.2.4
          Dec 27, 2024 22:26:30.433131933 CET53563251.1.1.1192.168.2.4
          Dec 27, 2024 22:26:31.990226030 CET5119753192.168.2.41.1.1.1
          Dec 27, 2024 22:26:31.991167068 CET5902153192.168.2.41.1.1.1
          Dec 27, 2024 22:26:32.128020048 CET53511971.1.1.1192.168.2.4
          Dec 27, 2024 22:26:32.128070116 CET53590211.1.1.1192.168.2.4
          Dec 27, 2024 22:26:33.077845097 CET6521053192.168.2.41.1.1.1
          Dec 27, 2024 22:26:33.094306946 CET6107253192.168.2.41.1.1.1
          Dec 27, 2024 22:26:33.386565924 CET53652101.1.1.1192.168.2.4
          Dec 27, 2024 22:26:33.386903048 CET53610721.1.1.1192.168.2.4
          Dec 27, 2024 22:26:33.387856960 CET5653053192.168.2.41.1.1.1
          Dec 27, 2024 22:26:33.524900913 CET53565301.1.1.1192.168.2.4
          Dec 27, 2024 22:26:33.689052105 CET5427953192.168.2.48.8.8.8
          Dec 27, 2024 22:26:33.689477921 CET6055553192.168.2.41.1.1.1
          Dec 27, 2024 22:26:33.823020935 CET53542798.8.8.8192.168.2.4
          Dec 27, 2024 22:26:33.827270031 CET53605551.1.1.1192.168.2.4
          Dec 27, 2024 22:26:34.735610008 CET6098153192.168.2.41.1.1.1
          Dec 27, 2024 22:26:34.735826969 CET5788053192.168.2.41.1.1.1
          Dec 27, 2024 22:26:34.873543024 CET53609811.1.1.1192.168.2.4
          Dec 27, 2024 22:26:34.875354052 CET53578801.1.1.1192.168.2.4
          Dec 27, 2024 22:26:39.914233923 CET6481953192.168.2.41.1.1.1
          Dec 27, 2024 22:26:39.914357901 CET5786453192.168.2.41.1.1.1
          Dec 27, 2024 22:26:40.057276011 CET53648191.1.1.1192.168.2.4
          Dec 27, 2024 22:26:40.063625097 CET53578641.1.1.1192.168.2.4
          Dec 27, 2024 22:26:40.064444065 CET5075353192.168.2.41.1.1.1
          Dec 27, 2024 22:26:40.202265978 CET53507531.1.1.1192.168.2.4
          Dec 27, 2024 22:26:40.722978115 CET6451553192.168.2.41.1.1.1
          Dec 27, 2024 22:26:40.723258018 CET5007753192.168.2.41.1.1.1
          Dec 27, 2024 22:26:40.860732079 CET53645151.1.1.1192.168.2.4
          Dec 27, 2024 22:26:40.862034082 CET53500771.1.1.1192.168.2.4
          Dec 27, 2024 22:26:40.882513046 CET5783453192.168.2.41.1.1.1
          Dec 27, 2024 22:26:40.883768082 CET6000053192.168.2.48.8.8.8
          Dec 27, 2024 22:26:41.018512011 CET53600008.8.8.8192.168.2.4
          Dec 27, 2024 22:26:41.019856930 CET53578341.1.1.1192.168.2.4
          Dec 27, 2024 22:26:41.388462067 CET138138192.168.2.4192.168.2.255
          Dec 27, 2024 22:26:47.484658957 CET53515391.1.1.1192.168.2.4
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Dec 27, 2024 22:26:31.990226030 CET192.168.2.41.1.1.10x38aeStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:31.991167068 CET192.168.2.41.1.1.10x2e1aStandard query (0)www.google.com65IN (0x0001)false
          Dec 27, 2024 22:26:33.077845097 CET192.168.2.41.1.1.10x4ce8Standard query (0)volmar.sinformations.cfdA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:33.094306946 CET192.168.2.41.1.1.10xf759Standard query (0)volmar.sinformations.cfd65IN (0x0001)false
          Dec 27, 2024 22:26:33.387856960 CET192.168.2.41.1.1.10x7325Standard query (0)volmar.sinformations.cfdA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:33.689052105 CET192.168.2.48.8.8.80x3d1dStandard query (0)google.comA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:33.689477921 CET192.168.2.41.1.1.10xcafdStandard query (0)google.comA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:34.735610008 CET192.168.2.41.1.1.10x5804Standard query (0)volmar.sinformations.cfdA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:34.735826969 CET192.168.2.41.1.1.10x688bStandard query (0)volmar.sinformations.cfd65IN (0x0001)false
          Dec 27, 2024 22:26:39.914233923 CET192.168.2.41.1.1.10x5252Standard query (0)volmar.sinformations.cfdA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:39.914357901 CET192.168.2.41.1.1.10xd222Standard query (0)volmar.sinformations.cfd65IN (0x0001)false
          Dec 27, 2024 22:26:40.064444065 CET192.168.2.41.1.1.10xee17Standard query (0)volmar.sinformations.cfdA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:40.722978115 CET192.168.2.41.1.1.10xfc0bStandard query (0)volmar.sinformations.cfdA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:40.723258018 CET192.168.2.41.1.1.10x6a3fStandard query (0)volmar.sinformations.cfd65IN (0x0001)false
          Dec 27, 2024 22:26:40.882513046 CET192.168.2.41.1.1.10x405fStandard query (0)google.comA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:40.883768082 CET192.168.2.48.8.8.80x2609Standard query (0)google.comA (IP address)IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Dec 27, 2024 22:26:32.128020048 CET1.1.1.1192.168.2.40x38aeNo error (0)www.google.com142.250.181.68A (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:32.128070116 CET1.1.1.1192.168.2.40x2e1aNo error (0)www.google.com65IN (0x0001)false
          Dec 27, 2024 22:26:33.386565924 CET1.1.1.1192.168.2.40x4ce8Name error (3)volmar.sinformations.cfdnonenoneA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:33.386903048 CET1.1.1.1192.168.2.40xf759Name error (3)volmar.sinformations.cfdnonenone65IN (0x0001)false
          Dec 27, 2024 22:26:33.524900913 CET1.1.1.1192.168.2.40x7325Name error (3)volmar.sinformations.cfdnonenoneA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:33.823020935 CET8.8.8.8192.168.2.40x3d1dNo error (0)google.com142.250.181.110A (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:33.827270031 CET1.1.1.1192.168.2.40xcafdNo error (0)google.com172.217.17.46A (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:34.873543024 CET1.1.1.1192.168.2.40x5804Name error (3)volmar.sinformations.cfdnonenoneA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:34.875354052 CET1.1.1.1192.168.2.40x688bName error (3)volmar.sinformations.cfdnonenone65IN (0x0001)false
          Dec 27, 2024 22:26:40.057276011 CET1.1.1.1192.168.2.40x5252Name error (3)volmar.sinformations.cfdnonenoneA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:40.063625097 CET1.1.1.1192.168.2.40xd222Name error (3)volmar.sinformations.cfdnonenone65IN (0x0001)false
          Dec 27, 2024 22:26:40.202265978 CET1.1.1.1192.168.2.40xee17Name error (3)volmar.sinformations.cfdnonenoneA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:40.860732079 CET1.1.1.1192.168.2.40xfc0bName error (3)volmar.sinformations.cfdnonenoneA (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:40.862034082 CET1.1.1.1192.168.2.40x6a3fName error (3)volmar.sinformations.cfdnonenone65IN (0x0001)false
          Dec 27, 2024 22:26:41.018512011 CET8.8.8.8192.168.2.40x2609No error (0)google.com142.250.181.110A (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:41.019856930 CET1.1.1.1192.168.2.40x405fNo error (0)google.com172.217.17.46A (IP address)IN (0x0001)false
          Dec 27, 2024 22:26:48.304214954 CET1.1.1.1192.168.2.40xbd00No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Dec 27, 2024 22:26:48.304214954 CET1.1.1.1192.168.2.40xbd00No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false

          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:16:26:24
          Start date:27/12/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:16:26:26
          Start date:27/12/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2004,i,15814095141836103454,17948706345906513014,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:16:26:32
          Start date:27/12/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://volmar.sinformations.cfd"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly