Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://xtbvquomsb.me/

Overview

General Information

Sample URL:https://xtbvquomsb.me/
Analysis ID:1589667
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Detected non-DNS traffic on DNS port
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 4436 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5832 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2416 --field-trial-handle=2276,i,8701860816603897792,15822417821152639384,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 5804 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://xtbvquomsb.me/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://xtbvquomsb.me/Avira URL Cloud: detection malicious, Label: phishing
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49720 version: TLS 1.0
Source: global trafficTCP traffic: 192.168.2.5:63355 -> 1.1.1.1:53
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49720 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: xtbvquomsb.me
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: classification engineClassification label: mal48.win@19/6@18/3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2416 --field-trial-handle=2276,i,8701860816603897792,15822417821152639384,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://xtbvquomsb.me/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2416 --field-trial-handle=2276,i,8701860816603897792,15822417821152639384,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://xtbvquomsb.me/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.186.174
truefalse
    high
    edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
    217.20.57.19
    truefalse
      high
      s-part-0017.t-0009.t-msedge.net
      13.107.246.45
      truefalse
        high
        www.google.com
        142.250.185.132
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.221.95
          truefalse
            high
            xtbvquomsb.me
            unknown
            unknownfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              142.250.185.132
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.5
              Joe Sandbox version:42.0.0 Malachite
              Analysis ID:1589667
              Start date and time:2025-01-13 00:51:36 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 1m 58s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://xtbvquomsb.me/
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:6
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:MAL
              Classification:mal48.win@19/6@18/3
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              Cookbook Comments:
              • URL browsing timeout or error
              • URL not reachable
              • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 172.217.18.99, 142.250.74.206, 64.233.167.84, 216.58.206.78, 142.250.181.238, 184.28.90.27, 2.23.242.162, 20.109.210.53, 217.20.57.19, 192.229.221.95, 52.165.164.15, 142.250.186.78, 142.250.184.206, 142.250.80.46, 13.107.246.45
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, otelrules.azureedge.net, otelrules.afd.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, redirector.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, azureedge-t-prod.trafficmanager.net, clients.l.google.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://xtbvquomsb.me/
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Jan 12 22:52:28 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2677
              Entropy (8bit):3.9786398295476477
              Encrypted:false
              SSDEEP:48:8fdITsogHy/WidAKZdA19ehwiZUklqehGy+3:8yPL/8dy
              MD5:DA54A816F5FC679D26269FCA750FA9AF
              SHA1:C1A3CADFFCD1CF2A94C03D512D2F2CD83DB36DC7
              SHA-256:CCDF6580CC4865CEC4DAB8CD956ED7227AB89441D8D861CADAD7E35CB917D4CB
              SHA-512:00F62D15C76D34892A81183A6B2ED6A30FF247B0F9A2C73AF969DBC1765D50F2A08D05337D34993C2E6DED50CB4B5FF60F96293DED796A3B55853EAEE1BC969F
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,....m...Me..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I,Z......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,Z......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V,Z......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V,Z............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V,Z.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............?.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Jan 12 22:52:28 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2679
              Entropy (8bit):3.9942100023921006
              Encrypted:false
              SSDEEP:48:8wdITsogHy/WidAKZdA1weh/iZUkAQkqehNy+2:8TPL/O9QQy
              MD5:AADD7BE2A9F0A0403A1014617F5E68D7
              SHA1:6E605FBCCCF3DCAE411C8D5B80EC258DE39B69B5
              SHA-256:A587DF870CBD94E4F70EA04EB308AB3DD461EF4F6B90CAB2FA451867827E2960
              SHA-512:B1CD773E63FA26992B8B100DF2636955087F16B22906379A49EDC52802F186FAB23C34008DCA84067FB92FB2ECEB3C7BBFDFFFBC21A5E5ABC527AC8ED12AA3DB
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,....T3..Me..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I,Z......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,Z......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V,Z......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V,Z............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V,Z.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............?.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2693
              Entropy (8bit):4.008609120230921
              Encrypted:false
              SSDEEP:48:8xZdITsosHy/WidAKZdA14tseh7sFiZUkmgqeh7sHy+BX:8x8Pf/2nxy
              MD5:05D9F96F77495A9F781A2F67BD96CF27
              SHA1:CBB7B7D069BE8364925DBB4EEDB06BA7293EBD67
              SHA-256:B304BDD969E180EF6FE8DBE7216DCEA8B31DD17DBAA7BBE7CAE3E39EBE346CD8
              SHA-512:19FD5B6810A1FA6BB72CD59C1DD28681DC6938FBFB5887CBDA526D7C6B3607A9B5C2066099389A83CBED8B66F09AF4070909BFF961DE9FCE79927A2BFA149C88
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I,Z......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,Z......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V,Z......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V,Z............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............?.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Jan 12 22:52:28 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2681
              Entropy (8bit):3.992511408390583
              Encrypted:false
              SSDEEP:48:8+dITsogHy/WidAKZdA1vehDiZUkwqehJy+R:8hPL/Vfy
              MD5:C945D2BB5C1E52AEE12DA5A6CC797EC8
              SHA1:DBD113A88C3E749F4CFF948569CA0B87102AA4F5
              SHA-256:E4F28ECB63FF96BC166A8D9C7DCB6B5C1356776C11D42C2F5B7E50DBC555D8D2
              SHA-512:EA1C8AA96EC8B7E67867D49321625415630FC41F8216C52FDD9FF4F51269C9A5435028D3E62D3A35D7C96CE291933F553D06C4E1F6DC78B627B2371833B71547
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,.....n..Me..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I,Z......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,Z......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V,Z......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V,Z............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V,Z.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............?.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Jan 12 22:52:28 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2681
              Entropy (8bit):3.9830659167195046
              Encrypted:false
              SSDEEP:48:8zdITsogHy/WidAKZdA1hehBiZUk1W1qehLy+C:8uPL/F9ry
              MD5:39F8CD7FCE2F615BF3E292F8647B26A0
              SHA1:6763678E6095473EAF4B4C1EBCF99A9588B08F50
              SHA-256:73A4FFD6C41996389987A41BB1C01AAFF2A3379F42E0751898A25AFEAA71D892
              SHA-512:57387642C726A9E3F0983213C11099776F12EB9234A48B00E03BC0C2623649E576E971C0B870CA5B2EF2B0E92FA9635B103247875301A7F3E3085770020C7C6B
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,........Me..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I,Z......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,Z......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V,Z......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V,Z............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V,Z.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............?.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Jan 12 22:52:28 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
              Category:dropped
              Size (bytes):2683
              Entropy (8bit):3.99545670546549
              Encrypted:false
              SSDEEP:48:80VdITsogHy/WidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbxy+yT+:89PL/ZT/TbxWOvTbxy7T
              MD5:969D3CBAC37AC67D293087FF0D9F78E8
              SHA1:455285B2C4ABDDDA1E47F51CA78CF217E57AC006
              SHA-256:890B4D97264F7D982EF5A035DD8CA0E64F6D6013EE361D79B9B2268ACBD90C80
              SHA-512:14102B4B4C306CE1656EBED6C4645CBB755280753136615E2453AB37FDA513EAA295F3108765D5F26C78C11388C455B5F3D7D270E6CA6F888AC97C354C0891B9
              Malicious:false
              Reputation:low
              Preview:L..................F.@.. ...$+.,........Me..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I,Z......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,Z......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V,Z......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V,Z............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V,Z.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............?.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Jan 13, 2025 00:52:21.490214109 CET49674443192.168.2.523.1.237.91
              Jan 13, 2025 00:52:21.490216970 CET49675443192.168.2.523.1.237.91
              Jan 13, 2025 00:52:21.615003109 CET49673443192.168.2.523.1.237.91
              Jan 13, 2025 00:52:31.096415043 CET49674443192.168.2.523.1.237.91
              Jan 13, 2025 00:52:31.096440077 CET49675443192.168.2.523.1.237.91
              Jan 13, 2025 00:52:31.221410990 CET49673443192.168.2.523.1.237.91
              Jan 13, 2025 00:52:32.464898109 CET49711443192.168.2.5142.250.185.132
              Jan 13, 2025 00:52:32.464945078 CET44349711142.250.185.132192.168.2.5
              Jan 13, 2025 00:52:32.465006113 CET49711443192.168.2.5142.250.185.132
              Jan 13, 2025 00:52:32.467194080 CET49711443192.168.2.5142.250.185.132
              Jan 13, 2025 00:52:32.467207909 CET44349711142.250.185.132192.168.2.5
              Jan 13, 2025 00:52:32.920347929 CET4434970323.1.237.91192.168.2.5
              Jan 13, 2025 00:52:32.920507908 CET49703443192.168.2.523.1.237.91
              Jan 13, 2025 00:52:33.115494967 CET44349711142.250.185.132192.168.2.5
              Jan 13, 2025 00:52:33.116766930 CET49711443192.168.2.5142.250.185.132
              Jan 13, 2025 00:52:33.116786003 CET44349711142.250.185.132192.168.2.5
              Jan 13, 2025 00:52:33.117908955 CET44349711142.250.185.132192.168.2.5
              Jan 13, 2025 00:52:33.118045092 CET49711443192.168.2.5142.250.185.132
              Jan 13, 2025 00:52:33.121212006 CET49711443192.168.2.5142.250.185.132
              Jan 13, 2025 00:52:33.121298075 CET44349711142.250.185.132192.168.2.5
              Jan 13, 2025 00:52:33.161618948 CET49711443192.168.2.5142.250.185.132
              Jan 13, 2025 00:52:33.161624908 CET44349711142.250.185.132192.168.2.5
              Jan 13, 2025 00:52:33.208492041 CET49711443192.168.2.5142.250.185.132
              Jan 13, 2025 00:52:43.049140930 CET44349711142.250.185.132192.168.2.5
              Jan 13, 2025 00:52:43.049220085 CET44349711142.250.185.132192.168.2.5
              Jan 13, 2025 00:52:43.049407005 CET49711443192.168.2.5142.250.185.132
              Jan 13, 2025 00:52:43.948859930 CET49703443192.168.2.523.1.237.91
              Jan 13, 2025 00:52:43.949398994 CET49703443192.168.2.523.1.237.91
              Jan 13, 2025 00:52:43.950570107 CET49720443192.168.2.523.1.237.91
              Jan 13, 2025 00:52:43.950607061 CET4434972023.1.237.91192.168.2.5
              Jan 13, 2025 00:52:43.950716972 CET49720443192.168.2.523.1.237.91
              Jan 13, 2025 00:52:43.951703072 CET49720443192.168.2.523.1.237.91
              Jan 13, 2025 00:52:43.951714039 CET4434972023.1.237.91192.168.2.5
              Jan 13, 2025 00:52:43.953737020 CET4434970323.1.237.91192.168.2.5
              Jan 13, 2025 00:52:43.954183102 CET4434970323.1.237.91192.168.2.5
              Jan 13, 2025 00:52:44.484424114 CET49711443192.168.2.5142.250.185.132
              Jan 13, 2025 00:52:44.484467030 CET44349711142.250.185.132192.168.2.5
              Jan 13, 2025 00:52:44.582819939 CET4434972023.1.237.91192.168.2.5
              Jan 13, 2025 00:52:44.583055973 CET49720443192.168.2.523.1.237.91
              Jan 13, 2025 00:52:51.445971012 CET6335553192.168.2.51.1.1.1
              Jan 13, 2025 00:52:51.450815916 CET53633551.1.1.1192.168.2.5
              Jan 13, 2025 00:52:51.450912952 CET6335553192.168.2.51.1.1.1
              Jan 13, 2025 00:52:51.450912952 CET6335553192.168.2.51.1.1.1
              Jan 13, 2025 00:52:51.455668926 CET53633551.1.1.1192.168.2.5
              Jan 13, 2025 00:52:51.962408066 CET53633551.1.1.1192.168.2.5
              Jan 13, 2025 00:52:51.962842941 CET6335553192.168.2.51.1.1.1
              Jan 13, 2025 00:52:51.967896938 CET53633551.1.1.1192.168.2.5
              Jan 13, 2025 00:52:51.968039989 CET6335553192.168.2.51.1.1.1
              TimestampSource PortDest PortSource IPDest IP
              Jan 13, 2025 00:52:27.757138968 CET53567021.1.1.1192.168.2.5
              Jan 13, 2025 00:52:27.803962946 CET53493101.1.1.1192.168.2.5
              Jan 13, 2025 00:52:28.789100885 CET53522541.1.1.1192.168.2.5
              Jan 13, 2025 00:52:32.380227089 CET5814253192.168.2.51.1.1.1
              Jan 13, 2025 00:52:32.381069899 CET6028953192.168.2.51.1.1.1
              Jan 13, 2025 00:52:32.387485027 CET53581421.1.1.1192.168.2.5
              Jan 13, 2025 00:52:32.387758017 CET53602891.1.1.1192.168.2.5
              Jan 13, 2025 00:52:33.768357992 CET5779253192.168.2.51.1.1.1
              Jan 13, 2025 00:52:33.768697977 CET5617253192.168.2.51.1.1.1
              Jan 13, 2025 00:52:33.776631117 CET53577921.1.1.1192.168.2.5
              Jan 13, 2025 00:52:33.776650906 CET53561721.1.1.1192.168.2.5
              Jan 13, 2025 00:52:33.777945995 CET6250553192.168.2.51.1.1.1
              Jan 13, 2025 00:52:33.786653042 CET53625051.1.1.1192.168.2.5
              Jan 13, 2025 00:52:33.809813023 CET4976153192.168.2.51.1.1.1
              Jan 13, 2025 00:52:33.810545921 CET5875353192.168.2.51.1.1.1
              Jan 13, 2025 00:52:33.817811966 CET53497611.1.1.1192.168.2.5
              Jan 13, 2025 00:52:33.818924904 CET53587531.1.1.1192.168.2.5
              Jan 13, 2025 00:52:34.662132025 CET5094553192.168.2.58.8.8.8
              Jan 13, 2025 00:52:34.662133932 CET5592653192.168.2.51.1.1.1
              Jan 13, 2025 00:52:34.668930054 CET53559261.1.1.1192.168.2.5
              Jan 13, 2025 00:52:34.676887989 CET53509458.8.8.8192.168.2.5
              Jan 13, 2025 00:52:35.499450922 CET6426153192.168.2.51.1.1.1
              Jan 13, 2025 00:52:35.499639034 CET6499053192.168.2.51.1.1.1
              Jan 13, 2025 00:52:35.507525921 CET53642611.1.1.1192.168.2.5
              Jan 13, 2025 00:52:35.507966995 CET53649901.1.1.1192.168.2.5
              Jan 13, 2025 00:52:35.821388006 CET4972453192.168.2.51.1.1.1
              Jan 13, 2025 00:52:35.822093010 CET5198653192.168.2.51.1.1.1
              Jan 13, 2025 00:52:35.830233097 CET53497241.1.1.1192.168.2.5
              Jan 13, 2025 00:52:35.830840111 CET53519861.1.1.1192.168.2.5
              Jan 13, 2025 00:52:41.069233894 CET5299553192.168.2.51.1.1.1
              Jan 13, 2025 00:52:41.069725037 CET5829453192.168.2.51.1.1.1
              Jan 13, 2025 00:52:41.078094006 CET53582941.1.1.1192.168.2.5
              Jan 13, 2025 00:52:41.083818913 CET53529951.1.1.1192.168.2.5
              Jan 13, 2025 00:52:41.088855028 CET5493453192.168.2.51.1.1.1
              Jan 13, 2025 00:52:41.096380949 CET53549341.1.1.1192.168.2.5
              Jan 13, 2025 00:52:41.118863106 CET5684653192.168.2.51.1.1.1
              Jan 13, 2025 00:52:41.119007111 CET5083453192.168.2.51.1.1.1
              Jan 13, 2025 00:52:41.127196074 CET53508341.1.1.1192.168.2.5
              Jan 13, 2025 00:52:41.133187056 CET53568461.1.1.1192.168.2.5
              Jan 13, 2025 00:52:46.400407076 CET53544731.1.1.1192.168.2.5
              Jan 13, 2025 00:52:51.445586920 CET53654781.1.1.1192.168.2.5
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Jan 13, 2025 00:52:32.380227089 CET192.168.2.51.1.1.10x414fStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:32.381069899 CET192.168.2.51.1.1.10x8e4cStandard query (0)www.google.com65IN (0x0001)false
              Jan 13, 2025 00:52:33.768357992 CET192.168.2.51.1.1.10xec58Standard query (0)xtbvquomsb.meA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:33.768697977 CET192.168.2.51.1.1.10xe43bStandard query (0)xtbvquomsb.me65IN (0x0001)false
              Jan 13, 2025 00:52:33.777945995 CET192.168.2.51.1.1.10x1ce5Standard query (0)xtbvquomsb.meA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:33.809813023 CET192.168.2.51.1.1.10xda8Standard query (0)xtbvquomsb.meA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:33.810545921 CET192.168.2.51.1.1.10xe785Standard query (0)xtbvquomsb.me65IN (0x0001)false
              Jan 13, 2025 00:52:34.662132025 CET192.168.2.58.8.8.80xb3cdStandard query (0)google.comA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:34.662133932 CET192.168.2.51.1.1.10x70f9Standard query (0)google.comA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:35.499450922 CET192.168.2.51.1.1.10xd954Standard query (0)xtbvquomsb.meA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:35.499639034 CET192.168.2.51.1.1.10xbab8Standard query (0)xtbvquomsb.me65IN (0x0001)false
              Jan 13, 2025 00:52:35.821388006 CET192.168.2.51.1.1.10x4331Standard query (0)xtbvquomsb.meA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:35.822093010 CET192.168.2.51.1.1.10x5e31Standard query (0)xtbvquomsb.me65IN (0x0001)false
              Jan 13, 2025 00:52:41.069233894 CET192.168.2.51.1.1.10x5eb2Standard query (0)xtbvquomsb.meA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:41.069725037 CET192.168.2.51.1.1.10xc18fStandard query (0)xtbvquomsb.me65IN (0x0001)false
              Jan 13, 2025 00:52:41.088855028 CET192.168.2.51.1.1.10xcb19Standard query (0)xtbvquomsb.meA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:41.118863106 CET192.168.2.51.1.1.10x71a7Standard query (0)xtbvquomsb.meA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:41.119007111 CET192.168.2.51.1.1.10x8fdaStandard query (0)xtbvquomsb.me65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Jan 13, 2025 00:52:32.387485027 CET1.1.1.1192.168.2.50x414fNo error (0)www.google.com142.250.185.132A (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:32.387758017 CET1.1.1.1192.168.2.50x8e4cNo error (0)www.google.com65IN (0x0001)false
              Jan 13, 2025 00:52:33.776631117 CET1.1.1.1192.168.2.50xec58Name error (3)xtbvquomsb.menonenoneA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:33.776650906 CET1.1.1.1192.168.2.50xe43bName error (3)xtbvquomsb.menonenone65IN (0x0001)false
              Jan 13, 2025 00:52:33.786653042 CET1.1.1.1192.168.2.50x1ce5Name error (3)xtbvquomsb.menonenoneA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:33.817811966 CET1.1.1.1192.168.2.50xda8Name error (3)xtbvquomsb.menonenoneA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:33.818924904 CET1.1.1.1192.168.2.50xe785Name error (3)xtbvquomsb.menonenone65IN (0x0001)false
              Jan 13, 2025 00:52:34.668930054 CET1.1.1.1192.168.2.50x70f9No error (0)google.com142.250.186.174A (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:34.676887989 CET8.8.8.8192.168.2.50xb3cdNo error (0)google.com142.251.37.14A (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:35.507525921 CET1.1.1.1192.168.2.50xd954Name error (3)xtbvquomsb.menonenoneA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:35.507966995 CET1.1.1.1192.168.2.50xbab8Name error (3)xtbvquomsb.menonenone65IN (0x0001)false
              Jan 13, 2025 00:52:35.830233097 CET1.1.1.1192.168.2.50x4331Name error (3)xtbvquomsb.menonenoneA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:35.830840111 CET1.1.1.1192.168.2.50x5e31Name error (3)xtbvquomsb.menonenone65IN (0x0001)false
              Jan 13, 2025 00:52:41.078094006 CET1.1.1.1192.168.2.50xc18fName error (3)xtbvquomsb.menonenone65IN (0x0001)false
              Jan 13, 2025 00:52:41.083818913 CET1.1.1.1192.168.2.50x5eb2Name error (3)xtbvquomsb.menonenoneA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:41.096380949 CET1.1.1.1192.168.2.50xcb19Name error (3)xtbvquomsb.menonenoneA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:41.127196074 CET1.1.1.1192.168.2.50x8fdaName error (3)xtbvquomsb.menonenone65IN (0x0001)false
              Jan 13, 2025 00:52:41.133187056 CET1.1.1.1192.168.2.50x71a7Name error (3)xtbvquomsb.menonenoneA (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:42.279773951 CET1.1.1.1192.168.2.50x9a46No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.19A (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:42.279773951 CET1.1.1.1192.168.2.50x9a46No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.18A (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:42.279773951 CET1.1.1.1192.168.2.50x9a46No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.20A (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:42.279773951 CET1.1.1.1192.168.2.50x9a46No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com84.201.210.39A (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:42.279773951 CET1.1.1.1192.168.2.50x9a46No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com84.201.210.23A (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:42.279773951 CET1.1.1.1192.168.2.50x9a46No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.34A (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:42.279773951 CET1.1.1.1192.168.2.50x9a46No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.36A (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:42.279773951 CET1.1.1.1192.168.2.50x9a46No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.35A (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:43.263386965 CET1.1.1.1192.168.2.50xdb5eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Jan 13, 2025 00:52:43.263386965 CET1.1.1.1192.168.2.50xdb5eNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Jan 13, 2025 00:52:45.053128004 CET1.1.1.1192.168.2.50xe422No error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.nets-part-0017.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
              Jan 13, 2025 00:52:45.053128004 CET1.1.1.1192.168.2.50xe422No error (0)s-part-0017.t-0009.t-msedge.net13.107.246.45A (IP address)IN (0x0001)false

              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:18:52:23
              Start date:12/01/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff715980000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:18:52:26
              Start date:12/01/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2416 --field-trial-handle=2276,i,8701860816603897792,15822417821152639384,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff715980000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:18:52:32
              Start date:12/01/2025
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://xtbvquomsb.me/"
              Imagebase:0x7ff715980000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly