Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://t1vil-telegram.org/login/index.html

Overview

General Information

Sample URL:https://t1vil-telegram.org/login/index.html
Analysis ID:1591437
Infos:
Errors
  • URL not reachable

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
AI detected suspicious URL
Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 1780 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5580 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1988,i,9257619110126995060,5718316809822774828,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6528 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://t1vil-telegram.org/login/index.html" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://t1vil-telegram.org/login/index.htmlAvira URL Cloud: detection malicious, Label: phishing

Phishing

barindex
Source: URLJoe Sandbox AI: AI detected Brand spoofing attempt in URL: https://t1vil-telegram.org
Source: URLJoe Sandbox AI: AI detected Typosquatting in URL: https://t1vil-telegram.org
Source: global trafficTCP traffic: 192.168.2.4:49731 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.168.102
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.168.102
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: t1vil-telegram.org
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: classification engineClassification label: mal52.win@20/0@19/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1988,i,9257619110126995060,5718316809822774828,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://t1vil-telegram.org/login/index.html"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1988,i,9257619110126995060,5718316809822774828,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://t1vil-telegram.org/login/index.html100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.186.46
truefalse
    high
    www.google.com
    142.250.185.228
    truefalse
      high
      t1vil-telegram.org
      unknown
      unknownfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        142.250.185.228
        www.google.comUnited States
        15169GOOGLEUSfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        IP
        192.168.2.4
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1591437
        Start date and time:2025-01-15 00:42:32 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 0s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://t1vil-telegram.org/login/index.html
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:7
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal52.win@20/0@19/3
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.184.195, 142.250.185.238, 142.251.16.84, 142.250.184.206, 142.250.185.206, 142.250.186.78, 217.20.57.36, 2.23.77.188, 142.250.181.238, 142.250.186.110, 2.23.242.162, 20.109.210.53
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, ocsp.digicert.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
        • Not all processes where analyzed, report is missing behavior information
        • VT rate limit hit for: https://t1vil-telegram.org/login/index.html
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Jan 15, 2025 00:43:28.808015108 CET4973153192.168.2.41.1.1.1
        Jan 15, 2025 00:43:28.813196898 CET53497311.1.1.1192.168.2.4
        Jan 15, 2025 00:43:28.813265085 CET4973153192.168.2.41.1.1.1
        Jan 15, 2025 00:43:28.813463926 CET4973153192.168.2.41.1.1.1
        Jan 15, 2025 00:43:28.813493967 CET4973153192.168.2.41.1.1.1
        Jan 15, 2025 00:43:28.819164038 CET53497311.1.1.1192.168.2.4
        Jan 15, 2025 00:43:28.819175959 CET53497311.1.1.1192.168.2.4
        Jan 15, 2025 00:43:29.259330034 CET53497311.1.1.1192.168.2.4
        Jan 15, 2025 00:43:29.259978056 CET4973153192.168.2.41.1.1.1
        Jan 15, 2025 00:43:29.265902996 CET53497311.1.1.1192.168.2.4
        Jan 15, 2025 00:43:29.265949011 CET4973153192.168.2.41.1.1.1
        Jan 15, 2025 00:43:32.514353991 CET49738443192.168.2.4142.250.185.228
        Jan 15, 2025 00:43:32.514390945 CET44349738142.250.185.228192.168.2.4
        Jan 15, 2025 00:43:32.515348911 CET49738443192.168.2.4142.250.185.228
        Jan 15, 2025 00:43:32.515348911 CET49738443192.168.2.4142.250.185.228
        Jan 15, 2025 00:43:32.515383005 CET44349738142.250.185.228192.168.2.4
        Jan 15, 2025 00:43:33.148464918 CET44349738142.250.185.228192.168.2.4
        Jan 15, 2025 00:43:33.148823977 CET49738443192.168.2.4142.250.185.228
        Jan 15, 2025 00:43:33.148839951 CET44349738142.250.185.228192.168.2.4
        Jan 15, 2025 00:43:33.149826050 CET44349738142.250.185.228192.168.2.4
        Jan 15, 2025 00:43:33.149893999 CET49738443192.168.2.4142.250.185.228
        Jan 15, 2025 00:43:33.151156902 CET49738443192.168.2.4142.250.185.228
        Jan 15, 2025 00:43:33.151216984 CET44349738142.250.185.228192.168.2.4
        Jan 15, 2025 00:43:33.191843033 CET49738443192.168.2.4142.250.185.228
        Jan 15, 2025 00:43:33.191852093 CET44349738142.250.185.228192.168.2.4
        Jan 15, 2025 00:43:33.238811970 CET49738443192.168.2.4142.250.185.228
        Jan 15, 2025 00:43:43.058043003 CET44349738142.250.185.228192.168.2.4
        Jan 15, 2025 00:43:43.058114052 CET44349738142.250.185.228192.168.2.4
        Jan 15, 2025 00:43:43.058156967 CET49738443192.168.2.4142.250.185.228
        Jan 15, 2025 00:43:43.192507982 CET49738443192.168.2.4142.250.185.228
        Jan 15, 2025 00:43:43.192531109 CET44349738142.250.185.228192.168.2.4
        Jan 15, 2025 00:43:44.821196079 CET4972380192.168.2.42.16.168.102
        Jan 15, 2025 00:43:44.826390028 CET80497232.16.168.102192.168.2.4
        Jan 15, 2025 00:43:44.826457977 CET4972380192.168.2.42.16.168.102
        TimestampSource PortDest PortSource IPDest IP
        Jan 15, 2025 00:43:28.526820898 CET53587051.1.1.1192.168.2.4
        Jan 15, 2025 00:43:28.725744963 CET53580951.1.1.1192.168.2.4
        Jan 15, 2025 00:43:28.725944042 CET53545131.1.1.1192.168.2.4
        Jan 15, 2025 00:43:29.911362886 CET53641071.1.1.1192.168.2.4
        Jan 15, 2025 00:43:32.503660917 CET5925753192.168.2.41.1.1.1
        Jan 15, 2025 00:43:32.503798962 CET5001353192.168.2.41.1.1.1
        Jan 15, 2025 00:43:32.512295961 CET53592571.1.1.1192.168.2.4
        Jan 15, 2025 00:43:32.513380051 CET53500131.1.1.1192.168.2.4
        Jan 15, 2025 00:43:33.985559940 CET5075753192.168.2.41.1.1.1
        Jan 15, 2025 00:43:33.985730886 CET5886453192.168.2.41.1.1.1
        Jan 15, 2025 00:43:34.000241041 CET53588641.1.1.1192.168.2.4
        Jan 15, 2025 00:43:34.001019955 CET53507571.1.1.1192.168.2.4
        Jan 15, 2025 00:43:34.001950026 CET6431453192.168.2.41.1.1.1
        Jan 15, 2025 00:43:34.119754076 CET53643141.1.1.1192.168.2.4
        Jan 15, 2025 00:43:34.179522038 CET5440253192.168.2.48.8.8.8
        Jan 15, 2025 00:43:34.180421114 CET6274553192.168.2.41.1.1.1
        Jan 15, 2025 00:43:34.186851978 CET53627451.1.1.1192.168.2.4
        Jan 15, 2025 00:43:34.194503069 CET53544028.8.8.8192.168.2.4
        Jan 15, 2025 00:43:35.310952902 CET5731353192.168.2.41.1.1.1
        Jan 15, 2025 00:43:35.311151028 CET6381653192.168.2.41.1.1.1
        Jan 15, 2025 00:43:35.318636894 CET53573131.1.1.1192.168.2.4
        Jan 15, 2025 00:43:35.325277090 CET53638161.1.1.1192.168.2.4
        Jan 15, 2025 00:43:35.351849079 CET6460153192.168.2.41.1.1.1
        Jan 15, 2025 00:43:35.351985931 CET6306253192.168.2.41.1.1.1
        Jan 15, 2025 00:43:35.366204977 CET53630621.1.1.1192.168.2.4
        Jan 15, 2025 00:43:35.366961956 CET53646011.1.1.1192.168.2.4
        Jan 15, 2025 00:43:40.387187004 CET6006353192.168.2.41.1.1.1
        Jan 15, 2025 00:43:40.387293100 CET5031053192.168.2.41.1.1.1
        Jan 15, 2025 00:43:40.402400970 CET53503101.1.1.1192.168.2.4
        Jan 15, 2025 00:43:40.404205084 CET53600631.1.1.1192.168.2.4
        Jan 15, 2025 00:43:40.404963970 CET5396953192.168.2.41.1.1.1
        Jan 15, 2025 00:43:40.420500994 CET53539691.1.1.1192.168.2.4
        Jan 15, 2025 00:43:45.118738890 CET138138192.168.2.4192.168.2.255
        Jan 15, 2025 00:43:46.903908014 CET53496231.1.1.1192.168.2.4
        Jan 15, 2025 00:43:49.702805996 CET6425353192.168.2.41.1.1.1
        Jan 15, 2025 00:43:49.702920914 CET6006553192.168.2.41.1.1.1
        Jan 15, 2025 00:43:49.717509031 CET53642531.1.1.1192.168.2.4
        Jan 15, 2025 00:43:49.717931986 CET53600651.1.1.1192.168.2.4
        Jan 15, 2025 00:43:49.718754053 CET6528853192.168.2.41.1.1.1
        Jan 15, 2025 00:43:49.734863997 CET53652881.1.1.1192.168.2.4
        Jan 15, 2025 00:43:49.745594025 CET6324953192.168.2.41.1.1.1
        Jan 15, 2025 00:43:49.745919943 CET5358153192.168.2.48.8.8.8
        Jan 15, 2025 00:43:49.754158974 CET53632491.1.1.1192.168.2.4
        Jan 15, 2025 00:43:49.758286953 CET53535818.8.8.8192.168.2.4
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Jan 15, 2025 00:43:32.503660917 CET192.168.2.41.1.1.10xfd6bStandard query (0)www.google.comA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:32.503798962 CET192.168.2.41.1.1.10x8584Standard query (0)www.google.com65IN (0x0001)false
        Jan 15, 2025 00:43:33.985559940 CET192.168.2.41.1.1.10xf9beStandard query (0)t1vil-telegram.orgA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:33.985730886 CET192.168.2.41.1.1.10x679dStandard query (0)t1vil-telegram.org65IN (0x0001)false
        Jan 15, 2025 00:43:34.001950026 CET192.168.2.41.1.1.10xb6bdStandard query (0)t1vil-telegram.orgA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:34.179522038 CET192.168.2.48.8.8.80xb1ecStandard query (0)google.comA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:34.180421114 CET192.168.2.41.1.1.10x3e9Standard query (0)google.comA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:35.310952902 CET192.168.2.41.1.1.10x41beStandard query (0)t1vil-telegram.orgA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:35.311151028 CET192.168.2.41.1.1.10xa339Standard query (0)t1vil-telegram.org65IN (0x0001)false
        Jan 15, 2025 00:43:35.351849079 CET192.168.2.41.1.1.10x168fStandard query (0)t1vil-telegram.orgA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:35.351985931 CET192.168.2.41.1.1.10xbb12Standard query (0)t1vil-telegram.org65IN (0x0001)false
        Jan 15, 2025 00:43:40.387187004 CET192.168.2.41.1.1.10x6d73Standard query (0)t1vil-telegram.orgA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:40.387293100 CET192.168.2.41.1.1.10x9bf4Standard query (0)t1vil-telegram.org65IN (0x0001)false
        Jan 15, 2025 00:43:40.404963970 CET192.168.2.41.1.1.10xae71Standard query (0)t1vil-telegram.orgA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:49.702805996 CET192.168.2.41.1.1.10x65b1Standard query (0)t1vil-telegram.orgA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:49.702920914 CET192.168.2.41.1.1.10x29d2Standard query (0)t1vil-telegram.org65IN (0x0001)false
        Jan 15, 2025 00:43:49.718754053 CET192.168.2.41.1.1.10x42beStandard query (0)t1vil-telegram.orgA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:49.745594025 CET192.168.2.41.1.1.10xe9cfStandard query (0)google.comA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:49.745919943 CET192.168.2.48.8.8.80xb9fcStandard query (0)google.comA (IP address)IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Jan 15, 2025 00:43:32.512295961 CET1.1.1.1192.168.2.40xfd6bNo error (0)www.google.com142.250.185.228A (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:32.513380051 CET1.1.1.1192.168.2.40x8584No error (0)www.google.com65IN (0x0001)false
        Jan 15, 2025 00:43:34.000241041 CET1.1.1.1192.168.2.40x679dName error (3)t1vil-telegram.orgnonenone65IN (0x0001)false
        Jan 15, 2025 00:43:34.001019955 CET1.1.1.1192.168.2.40xf9beName error (3)t1vil-telegram.orgnonenoneA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:34.119754076 CET1.1.1.1192.168.2.40xb6bdName error (3)t1vil-telegram.orgnonenoneA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:34.186851978 CET1.1.1.1192.168.2.40x3e9No error (0)google.com142.250.186.46A (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:34.194503069 CET8.8.8.8192.168.2.40xb1ecNo error (0)google.com142.250.75.238A (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:35.318636894 CET1.1.1.1192.168.2.40x41beName error (3)t1vil-telegram.orgnonenoneA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:35.325277090 CET1.1.1.1192.168.2.40xa339Name error (3)t1vil-telegram.orgnonenone65IN (0x0001)false
        Jan 15, 2025 00:43:35.366204977 CET1.1.1.1192.168.2.40xbb12Name error (3)t1vil-telegram.orgnonenone65IN (0x0001)false
        Jan 15, 2025 00:43:35.366961956 CET1.1.1.1192.168.2.40x168fName error (3)t1vil-telegram.orgnonenoneA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:40.402400970 CET1.1.1.1192.168.2.40x9bf4Name error (3)t1vil-telegram.orgnonenone65IN (0x0001)false
        Jan 15, 2025 00:43:40.404205084 CET1.1.1.1192.168.2.40x6d73Name error (3)t1vil-telegram.orgnonenoneA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:40.420500994 CET1.1.1.1192.168.2.40xae71Name error (3)t1vil-telegram.orgnonenoneA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:49.717509031 CET1.1.1.1192.168.2.40x65b1Name error (3)t1vil-telegram.orgnonenoneA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:49.717931986 CET1.1.1.1192.168.2.40x29d2Name error (3)t1vil-telegram.orgnonenone65IN (0x0001)false
        Jan 15, 2025 00:43:49.734863997 CET1.1.1.1192.168.2.40x42beName error (3)t1vil-telegram.orgnonenoneA (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:49.754158974 CET1.1.1.1192.168.2.40xe9cfNo error (0)google.com216.58.212.174A (IP address)IN (0x0001)false
        Jan 15, 2025 00:43:49.758286953 CET8.8.8.8192.168.2.40xb9fcNo error (0)google.com142.250.75.238A (IP address)IN (0x0001)false

        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:18:43:21
        Start date:14/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:18:43:26
        Start date:14/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1988,i,9257619110126995060,5718316809822774828,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:18:43:33
        Start date:14/01/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://t1vil-telegram.org/login/index.html"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly