Edit tour

Windows Analysis Report
https://lrp.omeclk.com/portal/wts/ug^cncmcEvybaMAPbte^6cjy2y8Aa8eDjj8q88hszErEGlGla

Overview

General Information

Sample URL:https://lrp.omeclk.com/portal/wts/ug^cncmcEvybaMAPbte^6cjy2y8Aa8eDjj8q88hszErEGlGla
Analysis ID:1671099
Infos:

Detection

Score:0
Range:0 - 100
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6832 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6140 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2144,i,17823587456219845118,8708141082104404739,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2216 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 5568 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2144,i,17823587456219845118,8708141082104404739,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=4732 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7260 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lrp.omeclk.com/portal/wts/ug%5EcncmcEvybaMAPbte%5E6cjy2y8Aa8eDjj8q88hszErEGlGla" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.5:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 205.162.42.171:443 -> 192.168.2.5:49704 version: TLS 1.2
Source: unknownHTTPS traffic detected: 205.162.42.171:443 -> 192.168.2.5:49705 version: TLS 1.2
Source: unknownHTTPS traffic detected: 150.171.28.254:443 -> 192.168.2.5:49709 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.28.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.28.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.28.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.28.254
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /portal/wts/ug%5EcncmcEvybaMAPbte%5E6cjy2y8Aa8eDjj8q88hszErEGlGla HTTP/1.1Host: lrp.omeclk.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: lrp.omeclk.com
Source: global trafficDNS traffic detected: DNS query: www.linkedin.cohttps
Source: global trafficDNS traffic detected: DNS query: google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49675
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.5:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 205.162.42.171:443 -> 192.168.2.5:49704 version: TLS 1.2
Source: unknownHTTPS traffic detected: 205.162.42.171:443 -> 192.168.2.5:49705 version: TLS 1.2
Source: unknownHTTPS traffic detected: 150.171.28.254:443 -> 192.168.2.5:49709 version: TLS 1.2
Source: classification engineClassification label: clean0.win@29/0@29/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2144,i,17823587456219845118,8708141082104404739,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2216 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2144,i,17823587456219845118,8708141082104404739,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=4732 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lrp.omeclk.com/portal/wts/ug%5EcncmcEvybaMAPbte%5E6cjy2y8Aa8eDjj8q88hszErEGlGla"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2144,i,17823587456219845118,8708141082104404739,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2216 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2144,i,17823587456219845118,8708141082104404739,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=4732 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1671099 URL: https://lrp.omeclk.com/port... Startdate: 22/04/2025 Architecture: WINDOWS Score: 0 16 www.linkedin.cohttps 2->16 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 18 192.168.2.5, 138, 443, 49160 unknown unknown 6->18 11 chrome.exe 6->11         started        14 chrome.exe 6->14         started        process5 dnsIp6 20 lrp.omeclk.com 205.162.42.171, 443, 49704, 49705 QTS-ASUS United States 11->20 22 www.google.com 142.250.69.4, 443, 49703, 49714 GOOGLEUS United States 11->22 24 2 other IPs or domains 11->24

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://lrp.omeclk.com/portal/wts/ug%5EcncmcEvybaMAPbte%5E6cjy2y8Aa8eDjj8q88hszErEGlGla0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.68.238
truefalse
    high
    lrp.omeclk.com
    205.162.42.171
    truefalse
      unknown
      www.google.com
      142.250.69.4
      truefalse
        high
        www.linkedin.cohttps
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://lrp.omeclk.com/portal/wts/ug%5EcncmcEvybaMAPbte%5E6cjy2y8Aa8eDjj8q88hszErEGlGlafalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.69.4
            www.google.comUnited States
            15169GOOGLEUSfalse
            205.162.42.171
            lrp.omeclk.comUnited States
            53866QTS-ASUSfalse
            IP
            192.168.2.5
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1671099
            Start date and time:2025-04-22 16:31:15 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 46s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://lrp.omeclk.com/portal/wts/ug^cncmcEvybaMAPbte^6cjy2y8Aa8eDjj8q88hszErEGlGla
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:15
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@29/0@29/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.68.227, 142.250.69.14, 142.250.141.84, 142.250.68.238, 199.232.210.172, 192.178.49.195, 142.250.69.3, 184.29.183.29, 20.12.23.50
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, c2a9c95e369881c67228a6591cac2686.clo.footprintdns.com, ax-ring.msedge.net, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, c.pki.goog
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtOpenFile calls found.
            • VT rate limit hit for: https://lrp.omeclk.com/portal/wts/ug%5EcncmcEvybaMAPbte%5E6cjy2y8Aa8eDjj8q88hszErEGlGla
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info

            Download Network PCAP: filteredfull

            • Total Packets: 78
            • 443 (HTTPS)
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Apr 22, 2025 16:31:57.675911903 CEST49672443192.168.2.5204.79.197.203
            Apr 22, 2025 16:31:58.879070044 CEST49672443192.168.2.5204.79.197.203
            Apr 22, 2025 16:32:01.285305977 CEST49672443192.168.2.5204.79.197.203
            Apr 22, 2025 16:32:05.994260073 CEST49676443192.168.2.520.189.173.14
            Apr 22, 2025 16:32:06.229726076 CEST49672443192.168.2.5204.79.197.203
            Apr 22, 2025 16:32:06.300951004 CEST49676443192.168.2.520.189.173.14
            Apr 22, 2025 16:32:06.910326958 CEST49676443192.168.2.520.189.173.14
            Apr 22, 2025 16:32:08.113192081 CEST49676443192.168.2.520.189.173.14
            Apr 22, 2025 16:32:10.520257950 CEST49676443192.168.2.520.189.173.14
            Apr 22, 2025 16:32:11.584820986 CEST49703443192.168.2.5142.250.69.4
            Apr 22, 2025 16:32:11.584882975 CEST44349703142.250.69.4192.168.2.5
            Apr 22, 2025 16:32:11.585207939 CEST49703443192.168.2.5142.250.69.4
            Apr 22, 2025 16:32:11.585422993 CEST49703443192.168.2.5142.250.69.4
            Apr 22, 2025 16:32:11.585445881 CEST44349703142.250.69.4192.168.2.5
            Apr 22, 2025 16:32:11.904869080 CEST44349703142.250.69.4192.168.2.5
            Apr 22, 2025 16:32:11.905059099 CEST49703443192.168.2.5142.250.69.4
            Apr 22, 2025 16:32:11.906266928 CEST49703443192.168.2.5142.250.69.4
            Apr 22, 2025 16:32:11.906286001 CEST44349703142.250.69.4192.168.2.5
            Apr 22, 2025 16:32:11.906543970 CEST44349703142.250.69.4192.168.2.5
            Apr 22, 2025 16:32:11.957453012 CEST49703443192.168.2.5142.250.69.4
            Apr 22, 2025 16:32:13.182982922 CEST49704443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.183048964 CEST44349704205.162.42.171192.168.2.5
            Apr 22, 2025 16:32:13.183192968 CEST49704443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.183414936 CEST49704443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.183439970 CEST44349704205.162.42.171192.168.2.5
            Apr 22, 2025 16:32:13.193542957 CEST49705443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.193593025 CEST44349705205.162.42.171192.168.2.5
            Apr 22, 2025 16:32:13.194444895 CEST49705443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.195452929 CEST49705443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.195468903 CEST44349705205.162.42.171192.168.2.5
            Apr 22, 2025 16:32:13.753184080 CEST44349704205.162.42.171192.168.2.5
            Apr 22, 2025 16:32:13.753406048 CEST49704443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.754277945 CEST49704443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.754292011 CEST44349704205.162.42.171192.168.2.5
            Apr 22, 2025 16:32:13.754515886 CEST44349704205.162.42.171192.168.2.5
            Apr 22, 2025 16:32:13.754868984 CEST49704443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.762131929 CEST44349705205.162.42.171192.168.2.5
            Apr 22, 2025 16:32:13.762367010 CEST49705443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.762579918 CEST49705443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.762593985 CEST44349705205.162.42.171192.168.2.5
            Apr 22, 2025 16:32:13.762799025 CEST44349705205.162.42.171192.168.2.5
            Apr 22, 2025 16:32:13.800268888 CEST44349704205.162.42.171192.168.2.5
            Apr 22, 2025 16:32:13.818427086 CEST49705443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.943532944 CEST44349704205.162.42.171192.168.2.5
            Apr 22, 2025 16:32:13.943675995 CEST44349704205.162.42.171192.168.2.5
            Apr 22, 2025 16:32:13.944041967 CEST49704443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.944041967 CEST49704443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:13.944134951 CEST49704443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:15.330780029 CEST49676443192.168.2.520.189.173.14
            Apr 22, 2025 16:32:15.833369970 CEST49672443192.168.2.5204.79.197.203
            Apr 22, 2025 16:32:21.888925076 CEST44349703142.250.69.4192.168.2.5
            Apr 22, 2025 16:32:21.888998985 CEST44349703142.250.69.4192.168.2.5
            Apr 22, 2025 16:32:21.889133930 CEST49703443192.168.2.5142.250.69.4
            Apr 22, 2025 16:32:22.444370031 CEST49703443192.168.2.5142.250.69.4
            Apr 22, 2025 16:32:22.444395065 CEST44349703142.250.69.4192.168.2.5
            Apr 22, 2025 16:32:23.143455029 CEST49675443192.168.2.52.23.227.208
            Apr 22, 2025 16:32:23.143487930 CEST443496752.23.227.208192.168.2.5
            Apr 22, 2025 16:32:23.503225088 CEST49709443192.168.2.5150.171.28.254
            Apr 22, 2025 16:32:23.503263950 CEST44349709150.171.28.254192.168.2.5
            Apr 22, 2025 16:32:23.503353119 CEST49709443192.168.2.5150.171.28.254
            Apr 22, 2025 16:32:23.503622055 CEST49709443192.168.2.5150.171.28.254
            Apr 22, 2025 16:32:23.503635883 CEST44349709150.171.28.254192.168.2.5
            Apr 22, 2025 16:32:23.946259975 CEST44349709150.171.28.254192.168.2.5
            Apr 22, 2025 16:32:23.946338892 CEST49709443192.168.2.5150.171.28.254
            Apr 22, 2025 16:32:24.942207098 CEST49676443192.168.2.520.189.173.14
            Apr 22, 2025 16:32:58.770142078 CEST49705443192.168.2.5205.162.42.171
            Apr 22, 2025 16:32:58.770169973 CEST44349705205.162.42.171192.168.2.5
            Apr 22, 2025 16:33:11.505198002 CEST49714443192.168.2.5142.250.69.4
            Apr 22, 2025 16:33:11.505233049 CEST44349714142.250.69.4192.168.2.5
            Apr 22, 2025 16:33:11.505297899 CEST49714443192.168.2.5142.250.69.4
            Apr 22, 2025 16:33:11.505511999 CEST49714443192.168.2.5142.250.69.4
            Apr 22, 2025 16:33:11.505527973 CEST44349714142.250.69.4192.168.2.5
            Apr 22, 2025 16:33:11.818927050 CEST44349714142.250.69.4192.168.2.5
            Apr 22, 2025 16:33:11.819231033 CEST49714443192.168.2.5142.250.69.4
            Apr 22, 2025 16:33:11.819256067 CEST44349714142.250.69.4192.168.2.5
            Apr 22, 2025 16:33:14.444092035 CEST49705443192.168.2.5205.162.42.171
            Apr 22, 2025 16:33:14.444220066 CEST44349705205.162.42.171192.168.2.5
            Apr 22, 2025 16:33:14.444283009 CEST49705443192.168.2.5205.162.42.171
            Apr 22, 2025 16:33:21.814239979 CEST44349714142.250.69.4192.168.2.5
            Apr 22, 2025 16:33:21.814306974 CEST44349714142.250.69.4192.168.2.5
            Apr 22, 2025 16:33:21.814368963 CEST49714443192.168.2.5142.250.69.4
            Apr 22, 2025 16:33:22.444142103 CEST49714443192.168.2.5142.250.69.4
            Apr 22, 2025 16:33:22.444161892 CEST44349714142.250.69.4192.168.2.5
            TimestampSource PortDest PortSource IPDest IP
            Apr 22, 2025 16:32:07.358998060 CEST53599561.1.1.1192.168.2.5
            Apr 22, 2025 16:32:07.411832094 CEST53593451.1.1.1192.168.2.5
            Apr 22, 2025 16:32:08.673276901 CEST53581751.1.1.1192.168.2.5
            Apr 22, 2025 16:32:08.809187889 CEST53561611.1.1.1192.168.2.5
            Apr 22, 2025 16:32:11.442961931 CEST6536053192.168.2.51.1.1.1
            Apr 22, 2025 16:32:11.443320036 CEST5427953192.168.2.51.1.1.1
            Apr 22, 2025 16:32:11.583272934 CEST53653601.1.1.1192.168.2.5
            Apr 22, 2025 16:32:11.583421946 CEST53542791.1.1.1192.168.2.5
            Apr 22, 2025 16:32:13.017205000 CEST5046353192.168.2.51.1.1.1
            Apr 22, 2025 16:32:13.022145987 CEST5382053192.168.2.51.1.1.1
            Apr 22, 2025 16:32:13.169800997 CEST53504631.1.1.1192.168.2.5
            Apr 22, 2025 16:32:13.182111979 CEST53538201.1.1.1192.168.2.5
            Apr 22, 2025 16:32:13.946103096 CEST6421353192.168.2.51.1.1.1
            Apr 22, 2025 16:32:13.946279049 CEST6392753192.168.2.51.1.1.1
            Apr 22, 2025 16:32:14.113593102 CEST53639271.1.1.1192.168.2.5
            Apr 22, 2025 16:32:14.115144014 CEST53642131.1.1.1192.168.2.5
            Apr 22, 2025 16:32:14.115761042 CEST6195053192.168.2.51.1.1.1
            Apr 22, 2025 16:32:14.260935068 CEST53619501.1.1.1192.168.2.5
            Apr 22, 2025 16:32:14.310273886 CEST6287853192.168.2.58.8.8.8
            Apr 22, 2025 16:32:14.310975075 CEST6090353192.168.2.51.1.1.1
            Apr 22, 2025 16:32:14.453275919 CEST53609031.1.1.1192.168.2.5
            Apr 22, 2025 16:32:14.460731983 CEST53628788.8.8.8192.168.2.5
            Apr 22, 2025 16:32:15.312694073 CEST5218653192.168.2.51.1.1.1
            Apr 22, 2025 16:32:15.312998056 CEST5145153192.168.2.51.1.1.1
            Apr 22, 2025 16:32:15.454822063 CEST53521861.1.1.1192.168.2.5
            Apr 22, 2025 16:32:15.459368944 CEST53514511.1.1.1192.168.2.5
            Apr 22, 2025 16:32:20.480475903 CEST6126053192.168.2.51.1.1.1
            Apr 22, 2025 16:32:20.480618000 CEST6059153192.168.2.51.1.1.1
            Apr 22, 2025 16:32:20.632102966 CEST53612601.1.1.1192.168.2.5
            Apr 22, 2025 16:32:20.636699915 CEST53605911.1.1.1192.168.2.5
            Apr 22, 2025 16:32:20.637275934 CEST5964753192.168.2.51.1.1.1
            Apr 22, 2025 16:32:20.814418077 CEST53596471.1.1.1192.168.2.5
            Apr 22, 2025 16:32:25.824078083 CEST53557201.1.1.1192.168.2.5
            Apr 22, 2025 16:32:29.843565941 CEST6279253192.168.2.51.1.1.1
            Apr 22, 2025 16:32:29.844472885 CEST5682653192.168.2.51.1.1.1
            Apr 22, 2025 16:32:29.985572100 CEST53568261.1.1.1192.168.2.5
            Apr 22, 2025 16:32:30.002912045 CEST53627921.1.1.1192.168.2.5
            Apr 22, 2025 16:32:30.003607035 CEST6015153192.168.2.51.1.1.1
            Apr 22, 2025 16:32:30.145029068 CEST53601511.1.1.1192.168.2.5
            Apr 22, 2025 16:32:30.156434059 CEST5414053192.168.2.51.1.1.1
            Apr 22, 2025 16:32:30.157074928 CEST5947153192.168.2.58.8.8.8
            Apr 22, 2025 16:32:30.297820091 CEST53541401.1.1.1192.168.2.5
            Apr 22, 2025 16:32:30.315126896 CEST53594718.8.8.8192.168.2.5
            Apr 22, 2025 16:32:44.661266088 CEST53534381.1.1.1192.168.2.5
            Apr 22, 2025 16:32:59.616511106 CEST5394653192.168.2.51.1.1.1
            Apr 22, 2025 16:32:59.759601116 CEST53539461.1.1.1192.168.2.5
            Apr 22, 2025 16:33:00.172019958 CEST5738453192.168.2.51.1.1.1
            Apr 22, 2025 16:33:00.172389030 CEST5808053192.168.2.51.1.1.1
            Apr 22, 2025 16:33:00.313168049 CEST53580801.1.1.1192.168.2.5
            Apr 22, 2025 16:33:00.331290960 CEST53573841.1.1.1192.168.2.5
            Apr 22, 2025 16:33:00.332143068 CEST5644353192.168.2.51.1.1.1
            Apr 22, 2025 16:33:00.474286079 CEST53564431.1.1.1192.168.2.5
            Apr 22, 2025 16:33:06.499510050 CEST5064353192.168.2.51.1.1.1
            Apr 22, 2025 16:33:06.499672890 CEST4916053192.168.2.51.1.1.1
            Apr 22, 2025 16:33:06.650264978 CEST53491601.1.1.1192.168.2.5
            Apr 22, 2025 16:33:06.660438061 CEST53506431.1.1.1192.168.2.5
            Apr 22, 2025 16:33:06.660983086 CEST5692053192.168.2.51.1.1.1
            Apr 22, 2025 16:33:06.811278105 CEST53569201.1.1.1192.168.2.5
            Apr 22, 2025 16:33:06.826420069 CEST5095353192.168.2.51.1.1.1
            Apr 22, 2025 16:33:06.826708078 CEST6187553192.168.2.58.8.8.8
            Apr 22, 2025 16:33:06.915893078 CEST53564371.1.1.1192.168.2.5
            Apr 22, 2025 16:33:06.966511965 CEST53509531.1.1.1192.168.2.5
            Apr 22, 2025 16:33:06.975588083 CEST53618758.8.8.8192.168.2.5
            Apr 22, 2025 16:33:07.427304983 CEST53546011.1.1.1192.168.2.5
            Apr 22, 2025 16:33:08.401102066 CEST138138192.168.2.5192.168.2.255
            Apr 22, 2025 16:33:10.020661116 CEST53633461.1.1.1192.168.2.5
            Apr 22, 2025 16:33:19.818341017 CEST6371553192.168.2.51.1.1.1
            Apr 22, 2025 16:33:19.973370075 CEST53637151.1.1.1192.168.2.5
            TimestampSource IPDest IPChecksumCodeType
            Apr 22, 2025 16:32:08.673302889 CEST192.168.2.51.1.1.1c1fa(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 22, 2025 16:32:11.442961931 CEST192.168.2.51.1.1.10x7426Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:11.443320036 CEST192.168.2.51.1.1.10xd7eeStandard query (0)www.google.com65IN (0x0001)false
            Apr 22, 2025 16:32:13.017205000 CEST192.168.2.51.1.1.10x3f33Standard query (0)lrp.omeclk.comA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:13.022145987 CEST192.168.2.51.1.1.10x3b85Standard query (0)lrp.omeclk.com65IN (0x0001)false
            Apr 22, 2025 16:32:13.946103096 CEST192.168.2.51.1.1.10x1f8fStandard query (0)www.linkedin.cohttpsA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:13.946279049 CEST192.168.2.51.1.1.10x99bfStandard query (0)www.linkedin.cohttps65IN (0x0001)false
            Apr 22, 2025 16:32:14.115761042 CEST192.168.2.51.1.1.10x1158Standard query (0)www.linkedin.cohttpsA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:14.310273886 CEST192.168.2.58.8.8.80x134aStandard query (0)google.comA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:14.310975075 CEST192.168.2.51.1.1.10xfad2Standard query (0)google.comA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:15.312694073 CEST192.168.2.51.1.1.10xaa7Standard query (0)www.linkedin.cohttpsA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:15.312998056 CEST192.168.2.51.1.1.10x4375Standard query (0)www.linkedin.cohttps65IN (0x0001)false
            Apr 22, 2025 16:32:20.480475903 CEST192.168.2.51.1.1.10xcdc0Standard query (0)www.linkedin.cohttpsA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:20.480618000 CEST192.168.2.51.1.1.10xbb30Standard query (0)www.linkedin.cohttps65IN (0x0001)false
            Apr 22, 2025 16:32:20.637275934 CEST192.168.2.51.1.1.10x7415Standard query (0)www.linkedin.cohttpsA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:29.843565941 CEST192.168.2.51.1.1.10xc78eStandard query (0)www.linkedin.cohttpsA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:29.844472885 CEST192.168.2.51.1.1.10xa202Standard query (0)www.linkedin.cohttps65IN (0x0001)false
            Apr 22, 2025 16:32:30.003607035 CEST192.168.2.51.1.1.10xa3c7Standard query (0)www.linkedin.cohttpsA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:30.156434059 CEST192.168.2.51.1.1.10x639aStandard query (0)google.comA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:30.157074928 CEST192.168.2.58.8.8.80x5690Standard query (0)google.comA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:59.616511106 CEST192.168.2.51.1.1.10x3a67Standard query (0)www.linkedin.cohttpsA (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:00.172019958 CEST192.168.2.51.1.1.10x25d8Standard query (0)www.linkedin.cohttpsA (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:00.172389030 CEST192.168.2.51.1.1.10x79dStandard query (0)www.linkedin.cohttps65IN (0x0001)false
            Apr 22, 2025 16:33:00.332143068 CEST192.168.2.51.1.1.10xc89eStandard query (0)www.linkedin.cohttpsA (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:06.499510050 CEST192.168.2.51.1.1.10xc3e2Standard query (0)www.linkedin.cohttpsA (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:06.499672890 CEST192.168.2.51.1.1.10x9ac8Standard query (0)www.linkedin.cohttps65IN (0x0001)false
            Apr 22, 2025 16:33:06.660983086 CEST192.168.2.51.1.1.10x594fStandard query (0)www.linkedin.cohttpsA (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:06.826420069 CEST192.168.2.51.1.1.10xa177Standard query (0)google.comA (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:06.826708078 CEST192.168.2.58.8.8.80x535cStandard query (0)google.comA (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:19.818341017 CEST192.168.2.51.1.1.10xc70dStandard query (0)www.linkedin.cohttpsA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 22, 2025 16:32:11.583272934 CEST1.1.1.1192.168.2.50x7426No error (0)www.google.com142.250.69.4A (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:11.583421946 CEST1.1.1.1192.168.2.50xd7eeNo error (0)www.google.com65IN (0x0001)false
            Apr 22, 2025 16:32:13.169800997 CEST1.1.1.1192.168.2.50x3f33No error (0)lrp.omeclk.com205.162.42.171A (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:14.113593102 CEST1.1.1.1192.168.2.50x99bfName error (3)www.linkedin.cohttpsnonenone65IN (0x0001)false
            Apr 22, 2025 16:32:14.115144014 CEST1.1.1.1192.168.2.50x1f8fName error (3)www.linkedin.cohttpsnonenoneA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:14.260935068 CEST1.1.1.1192.168.2.50x1158Name error (3)www.linkedin.cohttpsnonenoneA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:14.453275919 CEST1.1.1.1192.168.2.50xfad2No error (0)google.com142.250.68.238A (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:14.460731983 CEST8.8.8.8192.168.2.50x134aNo error (0)google.com142.250.72.142A (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:15.454822063 CEST1.1.1.1192.168.2.50xaa7Name error (3)www.linkedin.cohttpsnonenoneA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:15.459368944 CEST1.1.1.1192.168.2.50x4375Name error (3)www.linkedin.cohttpsnonenone65IN (0x0001)false
            Apr 22, 2025 16:32:20.632102966 CEST1.1.1.1192.168.2.50xcdc0Name error (3)www.linkedin.cohttpsnonenoneA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:20.636699915 CEST1.1.1.1192.168.2.50xbb30Name error (3)www.linkedin.cohttpsnonenone65IN (0x0001)false
            Apr 22, 2025 16:32:20.814418077 CEST1.1.1.1192.168.2.50x7415Name error (3)www.linkedin.cohttpsnonenoneA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:29.985572100 CEST1.1.1.1192.168.2.50xa202Name error (3)www.linkedin.cohttpsnonenone65IN (0x0001)false
            Apr 22, 2025 16:32:30.002912045 CEST1.1.1.1192.168.2.50xc78eName error (3)www.linkedin.cohttpsnonenoneA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:30.145029068 CEST1.1.1.1192.168.2.50xa3c7Name error (3)www.linkedin.cohttpsnonenoneA (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:30.297820091 CEST1.1.1.1192.168.2.50x639aNo error (0)google.com142.250.68.238A (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:30.315126896 CEST8.8.8.8192.168.2.50x5690No error (0)google.com142.250.72.142A (IP address)IN (0x0001)false
            Apr 22, 2025 16:32:59.759601116 CEST1.1.1.1192.168.2.50x3a67Name error (3)www.linkedin.cohttpsnonenoneA (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:00.313168049 CEST1.1.1.1192.168.2.50x79dName error (3)www.linkedin.cohttpsnonenone65IN (0x0001)false
            Apr 22, 2025 16:33:00.331290960 CEST1.1.1.1192.168.2.50x25d8Name error (3)www.linkedin.cohttpsnonenoneA (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:00.474286079 CEST1.1.1.1192.168.2.50xc89eName error (3)www.linkedin.cohttpsnonenoneA (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:06.650264978 CEST1.1.1.1192.168.2.50x9ac8Name error (3)www.linkedin.cohttpsnonenone65IN (0x0001)false
            Apr 22, 2025 16:33:06.660438061 CEST1.1.1.1192.168.2.50xc3e2Name error (3)www.linkedin.cohttpsnonenoneA (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:06.811278105 CEST1.1.1.1192.168.2.50x594fName error (3)www.linkedin.cohttpsnonenoneA (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:06.966511965 CEST1.1.1.1192.168.2.50xa177No error (0)google.com142.250.68.238A (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:06.975588083 CEST8.8.8.8192.168.2.50x535cNo error (0)google.com142.250.72.142A (IP address)IN (0x0001)false
            Apr 22, 2025 16:33:19.973370075 CEST1.1.1.1192.168.2.50xc70dName error (3)www.linkedin.cohttpsnonenoneA (IP address)IN (0x0001)false
            • lrp.omeclk.com
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.549704205.162.42.1714436140C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-04-22 14:32:13 UTC728OUTGET /portal/wts/ug%5EcncmcEvybaMAPbte%5E6cjy2y8Aa8eDjj8q88hszErEGlGla HTTP/1.1
            Host: lrp.omeclk.com
            Connection: keep-alive
            sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br, zstd
            Accept-Language: en-US,en;q=0.9
            2025-04-22 14:32:13 UTC436INHTTP/1.1 302
            X-Frame-Options: SAMEORIGIN
            X-Content-Type-Options: nosniff
            Location: https://www.linkedin.cohttps://www.linkedin.com/company/university-business-magazine/m/company/human-resource-executive-magazine/?viewAsMember=true&utm_source=omeda&utm_medium=email&utm_campaign=Newsletter-20250422&om_id=1101713878&om_eid=7910I5583589B9B
            Content-Length: 0
            Date: Tue, 22 Apr 2025 14:32:13 GMT
            Server: Apache
            Connection: close


            020406080s020406080100

            Click to jump to process

            020406080s0.0050100MB

            Click to jump to process

            Target ID:1
            Start time:10:32:01
            Start date:22/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff6a2540000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:4
            Start time:10:32:05
            Start date:22/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2144,i,17823587456219845118,8708141082104404739,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2216 /prefetch:3
            Imagebase:0x7ff6a2540000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:8
            Start time:10:32:08
            Start date:22/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2144,i,17823587456219845118,8708141082104404739,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=4732 /prefetch:8
            Imagebase:0x7ff7c3fa0000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:11
            Start time:10:32:11
            Start date:22/04/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://lrp.omeclk.com/portal/wts/ug%5EcncmcEvybaMAPbte%5E6cjy2y8Aa8eDjj8q88hszErEGlGla"
            Imagebase:0x7ff6a2540000
            File size:3'388'000 bytes
            MD5 hash:E81F54E6C1129887AEA47E7D092680BF
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
            There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

            No disassembly