Edit tour

Windows Analysis Report
http://faceliker.com

Overview

General Information

Sample URL:http://faceliker.com
Analysis ID:1649423
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Confidence:60%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5452 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 3796 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2308,i,4183497678686017889,15892254238914863444,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2328 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 1876 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://faceliker.com" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 142.251.40.228:443 -> 192.168.2.4:49728 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: faceliker.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownHTTPS traffic detected: 142.251.40.228:443 -> 192.168.2.4:49728 version: TLS 1.2
Source: classification engineClassification label: unknown0.win@22/0@21/2
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2308,i,4183497678686017889,15892254238914863444,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2328 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://faceliker.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2308,i,4183497678686017889,15892254238914863444,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2328 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1649423 URL: http://faceliker.com Startdate: 26/03/2025 Architecture: WINDOWS Score: 0 14 faceliker.com 2->14 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 16 192.168.2.4, 443, 49635, 49668 unknown unknown 6->16 11 chrome.exe 6->11         started        process5 dnsIp6 18 www.google.com 142.251.40.228, 443, 49728 GOOGLEUS United States 11->18 20 google.com 11->20 22 faceliker.com 11->22

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://faceliker.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.80.14
truefalse
    high
    www.google.com
    142.251.40.228
    truefalse
      high
      faceliker.com
      unknown
      unknownfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        142.251.40.228
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1649423
        Start date and time:2025-03-26 19:16:51 +01:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 11s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://faceliker.com
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:18
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:UNKNOWN
        Classification:unknown0.win@22/0@21/2
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): audiodg.exe, sppsvc.exe, RuntimeBroker.exe, ShellExperienceHost.exe, SIHClient.exe, SgrmBroker.exe, backgroundTaskHost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 23.9.183.29, 142.250.80.35, 142.250.81.238, 142.251.167.84, 142.251.40.142, 20.12.23.50
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, clientservices.googleapis.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, fe3cr.delivery.mp.microsoft.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtOpenFile calls found.
        • VT rate limit hit for: http://faceliker.com
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info

        Download Network PCAP: filteredfull

        • Total Packets: 40
        • 443 (HTTPS)
        • 80 (HTTP)
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Mar 26, 2025 19:17:58.098784924 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 19:17:58.410854101 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 19:17:58.676496029 CET49671443192.168.2.4204.79.197.203
        Mar 26, 2025 19:17:59.020226002 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 19:18:00.223372936 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 19:18:02.332763910 CET4968180192.168.2.42.17.190.73
        Mar 26, 2025 19:18:02.645292044 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 19:18:02.817168951 CET49680443192.168.2.4204.79.197.222
        Mar 26, 2025 19:18:07.484621048 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 19:18:08.347645998 CET49671443192.168.2.4204.79.197.203
        Mar 26, 2025 19:18:09.591434956 CET49728443192.168.2.4142.251.40.228
        Mar 26, 2025 19:18:09.591473103 CET44349728142.251.40.228192.168.2.4
        Mar 26, 2025 19:18:09.591811895 CET49728443192.168.2.4142.251.40.228
        Mar 26, 2025 19:18:09.592019081 CET49728443192.168.2.4142.251.40.228
        Mar 26, 2025 19:18:09.592030048 CET44349728142.251.40.228192.168.2.4
        Mar 26, 2025 19:18:09.786057949 CET44349728142.251.40.228192.168.2.4
        Mar 26, 2025 19:18:09.792293072 CET44349728142.251.40.228192.168.2.4
        Mar 26, 2025 19:18:09.795092106 CET49728443192.168.2.4142.251.40.228
        Mar 26, 2025 19:18:09.796341896 CET49728443192.168.2.4142.251.40.228
        Mar 26, 2025 19:18:09.796351910 CET44349728142.251.40.228192.168.2.4
        Mar 26, 2025 19:18:09.796660900 CET44349728142.251.40.228192.168.2.4
        Mar 26, 2025 19:18:09.838888884 CET49728443192.168.2.4142.251.40.228
        Mar 26, 2025 19:18:17.093326092 CET49678443192.168.2.420.189.173.27
        Mar 26, 2025 19:18:19.822134972 CET44349728142.251.40.228192.168.2.4
        Mar 26, 2025 19:18:19.822200060 CET44349728142.251.40.228192.168.2.4
        Mar 26, 2025 19:18:19.822571993 CET49728443192.168.2.4142.251.40.228
        Mar 26, 2025 19:18:21.647207022 CET49728443192.168.2.4142.251.40.228
        Mar 26, 2025 19:18:21.647259951 CET44349728142.251.40.228192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Mar 26, 2025 19:18:05.678553104 CET53519381.1.1.1192.168.2.4
        Mar 26, 2025 19:18:05.680917978 CET53513711.1.1.1192.168.2.4
        Mar 26, 2025 19:18:06.253761053 CET53502191.1.1.1192.168.2.4
        Mar 26, 2025 19:18:06.441565990 CET53647191.1.1.1192.168.2.4
        Mar 26, 2025 19:18:09.500991106 CET5736053192.168.2.41.1.1.1
        Mar 26, 2025 19:18:09.501338005 CET5677953192.168.2.41.1.1.1
        Mar 26, 2025 19:18:09.589281082 CET53573601.1.1.1192.168.2.4
        Mar 26, 2025 19:18:09.589358091 CET53567791.1.1.1192.168.2.4
        Mar 26, 2025 19:18:11.516356945 CET5374853192.168.2.41.1.1.1
        Mar 26, 2025 19:18:11.516496897 CET6321553192.168.2.41.1.1.1
        Mar 26, 2025 19:18:11.606498003 CET53632151.1.1.1192.168.2.4
        Mar 26, 2025 19:18:11.606517076 CET53537481.1.1.1192.168.2.4
        Mar 26, 2025 19:18:11.804817915 CET6445653192.168.2.41.1.1.1
        Mar 26, 2025 19:18:11.810583115 CET5967853192.168.2.41.1.1.1
        Mar 26, 2025 19:18:11.810874939 CET5786053192.168.2.41.1.1.1
        Mar 26, 2025 19:18:11.893246889 CET53644561.1.1.1192.168.2.4
        Mar 26, 2025 19:18:11.898741961 CET53596781.1.1.1192.168.2.4
        Mar 26, 2025 19:18:11.932889938 CET6431853192.168.2.41.1.1.1
        Mar 26, 2025 19:18:11.933048964 CET6331253192.168.2.41.1.1.1
        Mar 26, 2025 19:18:11.942478895 CET53578601.1.1.1192.168.2.4
        Mar 26, 2025 19:18:12.023941040 CET53643181.1.1.1192.168.2.4
        Mar 26, 2025 19:18:12.023966074 CET53633121.1.1.1192.168.2.4
        Mar 26, 2025 19:18:12.054266930 CET5488053192.168.2.48.8.8.8
        Mar 26, 2025 19:18:12.054534912 CET5844553192.168.2.41.1.1.1
        Mar 26, 2025 19:18:12.143459082 CET53548808.8.8.8192.168.2.4
        Mar 26, 2025 19:18:12.143496990 CET53584451.1.1.1192.168.2.4
        Mar 26, 2025 19:18:13.074085951 CET6461953192.168.2.41.1.1.1
        Mar 26, 2025 19:18:13.085541964 CET6376253192.168.2.41.1.1.1
        Mar 26, 2025 19:18:13.162763119 CET53646191.1.1.1192.168.2.4
        Mar 26, 2025 19:18:13.173832893 CET53637621.1.1.1192.168.2.4
        Mar 26, 2025 19:18:18.238383055 CET5542953192.168.2.41.1.1.1
        Mar 26, 2025 19:18:18.238383055 CET4963553192.168.2.41.1.1.1
        Mar 26, 2025 19:18:18.328049898 CET53554291.1.1.1192.168.2.4
        Mar 26, 2025 19:18:18.328079939 CET53496351.1.1.1192.168.2.4
        Mar 26, 2025 19:18:18.329289913 CET5863753192.168.2.41.1.1.1
        Mar 26, 2025 19:18:18.417682886 CET53586371.1.1.1192.168.2.4
        Mar 26, 2025 19:18:23.453438044 CET53545181.1.1.1192.168.2.4
        Mar 26, 2025 19:18:24.341444016 CET5328153192.168.2.41.1.1.1
        Mar 26, 2025 19:18:24.341623068 CET5765153192.168.2.41.1.1.1
        Mar 26, 2025 19:18:24.430604935 CET53532811.1.1.1192.168.2.4
        Mar 26, 2025 19:18:24.430624962 CET53576511.1.1.1192.168.2.4
        Mar 26, 2025 19:18:24.431948900 CET6382953192.168.2.41.1.1.1
        Mar 26, 2025 19:18:24.520284891 CET53638291.1.1.1192.168.2.4
        Mar 26, 2025 19:18:24.533768892 CET5826953192.168.2.41.1.1.1
        Mar 26, 2025 19:18:24.533860922 CET4966853192.168.2.48.8.8.8
        Mar 26, 2025 19:18:24.621855021 CET53582691.1.1.1192.168.2.4
        Mar 26, 2025 19:18:24.621911049 CET53496688.8.8.8192.168.2.4
        TimestampSource IPDest IPChecksumCodeType
        Mar 26, 2025 19:18:11.942544937 CET192.168.2.41.1.1.1c22c(Port unreachable)Destination Unreachable
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Mar 26, 2025 19:18:09.500991106 CET192.168.2.41.1.1.10x98d7Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:09.501338005 CET192.168.2.41.1.1.10xb3e8Standard query (0)www.google.com65IN (0x0001)false
        Mar 26, 2025 19:18:11.516356945 CET192.168.2.41.1.1.10x8699Standard query (0)faceliker.comA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:11.516496897 CET192.168.2.41.1.1.10x5beaStandard query (0)faceliker.com65IN (0x0001)false
        Mar 26, 2025 19:18:11.804817915 CET192.168.2.41.1.1.10x6858Standard query (0)faceliker.comA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:11.810583115 CET192.168.2.41.1.1.10x836dStandard query (0)faceliker.comA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:11.810874939 CET192.168.2.41.1.1.10x33feStandard query (0)faceliker.com65IN (0x0001)false
        Mar 26, 2025 19:18:11.932889938 CET192.168.2.41.1.1.10x6e6eStandard query (0)faceliker.comA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:11.933048964 CET192.168.2.41.1.1.10x1ad3Standard query (0)faceliker.com65IN (0x0001)false
        Mar 26, 2025 19:18:12.054266930 CET192.168.2.48.8.8.80x7480Standard query (0)google.comA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:12.054534912 CET192.168.2.41.1.1.10xd078Standard query (0)google.comA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:13.074085951 CET192.168.2.41.1.1.10x918eStandard query (0)faceliker.comA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:13.085541964 CET192.168.2.41.1.1.10x27ceStandard query (0)faceliker.com65IN (0x0001)false
        Mar 26, 2025 19:18:18.238383055 CET192.168.2.41.1.1.10xc33eStandard query (0)faceliker.comA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:18.238383055 CET192.168.2.41.1.1.10x641aStandard query (0)faceliker.com65IN (0x0001)false
        Mar 26, 2025 19:18:18.329289913 CET192.168.2.41.1.1.10x5dbfStandard query (0)faceliker.comA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:24.341444016 CET192.168.2.41.1.1.10xdf77Standard query (0)faceliker.comA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:24.341623068 CET192.168.2.41.1.1.10x83f0Standard query (0)faceliker.com65IN (0x0001)false
        Mar 26, 2025 19:18:24.431948900 CET192.168.2.41.1.1.10x847bStandard query (0)faceliker.comA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:24.533768892 CET192.168.2.41.1.1.10xef52Standard query (0)google.comA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:24.533860922 CET192.168.2.48.8.8.80xa4ddStandard query (0)google.comA (IP address)IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Mar 26, 2025 19:18:09.589281082 CET1.1.1.1192.168.2.40x98d7No error (0)www.google.com142.251.40.228A (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:09.589358091 CET1.1.1.1192.168.2.40xb3e8No error (0)www.google.com65IN (0x0001)false
        Mar 26, 2025 19:18:11.606498003 CET1.1.1.1192.168.2.40x5beaName error (3)faceliker.comnonenone65IN (0x0001)false
        Mar 26, 2025 19:18:11.606517076 CET1.1.1.1192.168.2.40x8699Name error (3)faceliker.comnonenoneA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:11.893246889 CET1.1.1.1192.168.2.40x6858Name error (3)faceliker.comnonenoneA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:11.898741961 CET1.1.1.1192.168.2.40x836dName error (3)faceliker.comnonenoneA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:11.942478895 CET1.1.1.1192.168.2.40x33feName error (3)faceliker.comnonenone65IN (0x0001)false
        Mar 26, 2025 19:18:12.023941040 CET1.1.1.1192.168.2.40x6e6eName error (3)faceliker.comnonenoneA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:12.023966074 CET1.1.1.1192.168.2.40x1ad3Name error (3)faceliker.comnonenone65IN (0x0001)false
        Mar 26, 2025 19:18:12.143459082 CET8.8.8.8192.168.2.40x7480No error (0)google.com142.250.80.14A (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:12.143496990 CET1.1.1.1192.168.2.40xd078No error (0)google.com142.250.80.14A (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:13.162763119 CET1.1.1.1192.168.2.40x918eName error (3)faceliker.comnonenoneA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:13.173832893 CET1.1.1.1192.168.2.40x27ceName error (3)faceliker.comnonenone65IN (0x0001)false
        Mar 26, 2025 19:18:18.328049898 CET1.1.1.1192.168.2.40xc33eName error (3)faceliker.comnonenoneA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:18.328079939 CET1.1.1.1192.168.2.40x641aName error (3)faceliker.comnonenone65IN (0x0001)false
        Mar 26, 2025 19:18:18.417682886 CET1.1.1.1192.168.2.40x5dbfName error (3)faceliker.comnonenoneA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:24.430604935 CET1.1.1.1192.168.2.40xdf77Name error (3)faceliker.comnonenoneA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:24.430624962 CET1.1.1.1192.168.2.40x83f0Name error (3)faceliker.comnonenone65IN (0x0001)false
        Mar 26, 2025 19:18:24.520284891 CET1.1.1.1192.168.2.40x847bName error (3)faceliker.comnonenoneA (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:24.621855021 CET1.1.1.1192.168.2.40xef52No error (0)google.com142.250.80.14A (IP address)IN (0x0001)false
        Mar 26, 2025 19:18:24.621911049 CET8.8.8.8192.168.2.40xa4ddNo error (0)google.com142.250.80.14A (IP address)IN (0x0001)false
        01020s020406080100

        Click to jump to process

        01020s0.0050100MB

        Click to jump to process

        Target ID:4
        Start time:14:17:58
        Start date:26/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:5
        Start time:14:18:04
        Start date:26/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2308,i,4183497678686017889,15892254238914863444,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2328 /prefetch:3
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:16
        Start time:14:18:10
        Start date:26/03/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://faceliker.com"
        Imagebase:0x7ff786830000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

        No disassembly