Edit tour

Windows Analysis Report
http://bhpwqtiudzqnz.vip

Overview

General Information

Sample URL:http://bhpwqtiudzqnz.vip
Analysis ID:1675954
Infos:

Detection

Score:0
Range:0 - 100
Confidence:80%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6956 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6408 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2028,i,7869801962805117019,18132110213460785511,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2100 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 7204 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2028,i,7869801962805117019,18132110213460785511,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2816 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7428 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bhpwqtiudzqnz.vip" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.150.203:443 -> 192.168.2.5:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 150.171.28.254:443 -> 192.168.2.5:49706 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.28.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.28.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.28.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.28.254
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: bhpwqtiudzqnz.vipConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: bhpwqtiudzqnz.vipConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://bhpwqtiudzqnz.vip/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: bhpwqtiudzqnz.vip
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Mon, 28 Apr 2025 05:46:29 GMTContent-Type: application/xml; charset=UTF-8Content-Length: 111Connection: closeX-Guploader-Uploadid: AAO2VwqLtfR4C7QpTNrMth0MlxJe8EY4pdmMlGJI5RhNlE4k9zi0AJwrJnGMfX88TPdPZEynzh997wAccess-Control-Allow-Origin: *Expires: Mon, 28 Apr 2025 05:46:29 GMTCache-Control: private, max-age=0Server: cloudflareCf-Cache-Status: DYNAMICCF-RAY: 9374426bbda397fd-PHXalt-svc: h3=":443"; ma=86400
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Mon, 28 Apr 2025 05:46:30 GMTContent-Type: application/xml; charset=UTF-8Content-Length: 111Connection: closeX-Guploader-Uploadid: AAO2VwoCaFMqsBkX6rWX6shvUH0Lg0LaDcWgq-QOw89V04Nu6xt0V6p41oVDnU3_oqFF5RQ7ecICjogAccess-Control-Allow-Origin: *Expires: Mon, 28 Apr 2025 05:46:30 GMTCache-Control: private, max-age=0Server: cloudflareCf-Cache-Status: BYPASSCF-RAY: 937442715d902b8e-LAXalt-svc: h3=":443"; ma=86400
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49675
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.150.203:443 -> 192.168.2.5:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 150.171.28.254:443 -> 192.168.2.5:49706 version: TLS 1.2
Source: classification engineClassification label: clean0.win@24/4@6/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2028,i,7869801962805117019,18132110213460785511,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2100 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2028,i,7869801962805117019,18132110213460785511,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2816 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bhpwqtiudzqnz.vip"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2028,i,7869801962805117019,18132110213460785511,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2100 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2028,i,7869801962805117019,18132110213460785511,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2816 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1675954 URL: http://bhpwqtiudzqnz.vip Startdate: 28/04/2025 Architecture: WINDOWS Score: 0 5 chrome.exe 2 2->5         started        8 chrome.exe 2->8         started        dnsIp3 15 192.168.2.5, 138, 443, 49675 unknown unknown 5->15 10 chrome.exe 5->10         started        13 chrome.exe 5->13         started        process4 dnsIp5 17 www.google.com 192.178.49.196, 443, 49701, 49711 GOOGLEUS United States 10->17 19 bhpwqtiudzqnz.vip 172.67.150.203, 443, 49703, 49704 CLOUDFLARENETUS United States 10->19

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://bhpwqtiudzqnz.vip0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://bhpwqtiudzqnz.vip/favicon.ico0%Avira URL Cloudsafe
https://bhpwqtiudzqnz.vip/0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
192.178.49.196
truefalse
    high
    bhpwqtiudzqnz.vip
    172.67.150.203
    truefalse
      unknown
      NameMaliciousAntivirus DetectionReputation
      http://c.pki.goog/r/r4.crlfalse
        high
        https://bhpwqtiudzqnz.vip/false
        • Avira URL Cloud: safe
        unknown
        https://bhpwqtiudzqnz.vip/favicon.icofalse
        • Avira URL Cloud: safe
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        172.67.150.203
        bhpwqtiudzqnz.vipUnited States
        13335CLOUDFLARENETUSfalse
        192.178.49.196
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.5
        Joe Sandbox version:42.0.0 Malachite
        Analysis ID:1675954
        Start date and time:2025-04-28 07:45:29 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 47s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://bhpwqtiudzqnz.vip
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:14
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:CLEAN
        Classification:clean0.win@24/4@6/3
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 199.232.210.172, 142.250.68.227, 192.178.49.174, 142.250.101.84, 172.217.12.142, 192.178.49.206, 142.250.189.14, 192.178.49.163, 142.250.69.3, 184.29.183.29, 20.12.23.50
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, c2a9c95e369881c67228a6591cac2686.clo.footprintdns.com, ax-ring.msedge.net, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, c.pki.goog
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtOpenFile calls found.
        • VT rate limit hit for: http://bhpwqtiudzqnz.vip
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:XML 1.0 document, ASCII text, with no line terminators
        Category:downloaded
        Size (bytes):111
        Entropy (8bit):4.62062991365628
        Encrypted:false
        SSDEEP:3:vFWWMNCmXyKgCC6beXqZj+PBMkmKqWWU667wtKPU9KgqLn:TM3i0b9ZjZvKtWRbtmBg6n
        MD5:E7A9350210B4DBA641F6020447C96045
        SHA1:581ACCEF4A8B7FBED97291FE7DD4E113F794EC80
        SHA-256:08142330655DEB1526DCC56795C92EB5C13012F75B599D5AC68DB4027953ED80
        SHA-512:2DCB8AD4EAC1B103DA4F806A49D7A0EFCC64D362865A18EFB257B45059BC1453D053136073009929415200F48F47B03F8E19E52A8AF7CB846AD081E0318586A2
        Malicious:false
        Reputation:low
        URL:https://bhpwqtiudzqnz.vip/favicon.ico
        Preview:<?xml version='1.0' encoding='UTF-8'?><Error><Code>AccessDenied</Code><Message>Access denied.</Message></Error>
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:XML 1.0 document, ASCII text, with no line terminators
        Category:downloaded
        Size (bytes):111
        Entropy (8bit):4.62062991365628
        Encrypted:false
        SSDEEP:3:vFWWMNCmXyKgCC6beXqZj+PBMkmKqWWU667wtKPU9KgqLn:TM3i0b9ZjZvKtWRbtmBg6n
        MD5:E7A9350210B4DBA641F6020447C96045
        SHA1:581ACCEF4A8B7FBED97291FE7DD4E113F794EC80
        SHA-256:08142330655DEB1526DCC56795C92EB5C13012F75B599D5AC68DB4027953ED80
        SHA-512:2DCB8AD4EAC1B103DA4F806A49D7A0EFCC64D362865A18EFB257B45059BC1453D053136073009929415200F48F47B03F8E19E52A8AF7CB846AD081E0318586A2
        Malicious:false
        Reputation:low
        URL:https://bhpwqtiudzqnz.vip/
        Preview:<?xml version='1.0' encoding='UTF-8'?><Error><Code>AccessDenied</Code><Message>Access denied.</Message></Error>
        No static file info

        Download Network PCAP: filteredfull

        • Total Packets: 38
        • 443 (HTTPS)
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Apr 28, 2025 07:46:11.854922056 CEST49672443192.168.2.5204.79.197.203
        Apr 28, 2025 07:46:13.058039904 CEST49672443192.168.2.5204.79.197.203
        Apr 28, 2025 07:46:15.464247942 CEST49672443192.168.2.5204.79.197.203
        Apr 28, 2025 07:46:20.276767015 CEST49672443192.168.2.5204.79.197.203
        Apr 28, 2025 07:46:20.882334948 CEST49676443192.168.2.520.189.173.14
        Apr 28, 2025 07:46:21.183005095 CEST49676443192.168.2.520.189.173.14
        Apr 28, 2025 07:46:21.808007956 CEST49676443192.168.2.520.189.173.14
        Apr 28, 2025 07:46:23.011130095 CEST49676443192.168.2.520.189.173.14
        Apr 28, 2025 07:46:24.279798985 CEST4969980192.168.2.5192.178.49.195
        Apr 28, 2025 07:46:24.428591013 CEST8049699192.178.49.195192.168.2.5
        Apr 28, 2025 07:46:24.428678036 CEST4969980192.168.2.5192.178.49.195
        Apr 28, 2025 07:46:24.428847075 CEST4969980192.168.2.5192.178.49.195
        Apr 28, 2025 07:46:24.576889992 CEST8049699192.178.49.195192.168.2.5
        Apr 28, 2025 07:46:24.577241898 CEST8049699192.178.49.195192.168.2.5
        Apr 28, 2025 07:46:24.714378119 CEST4969980192.168.2.5192.178.49.195
        Apr 28, 2025 07:46:25.417536020 CEST49676443192.168.2.520.189.173.14
        Apr 28, 2025 07:46:27.589134932 CEST49701443192.168.2.5192.178.49.196
        Apr 28, 2025 07:46:27.589168072 CEST44349701192.178.49.196192.168.2.5
        Apr 28, 2025 07:46:27.589262009 CEST49701443192.168.2.5192.178.49.196
        Apr 28, 2025 07:46:27.589473963 CEST49701443192.168.2.5192.178.49.196
        Apr 28, 2025 07:46:27.589487076 CEST44349701192.178.49.196192.168.2.5
        Apr 28, 2025 07:46:27.909241915 CEST44349701192.178.49.196192.168.2.5
        Apr 28, 2025 07:46:27.909353971 CEST49701443192.168.2.5192.178.49.196
        Apr 28, 2025 07:46:27.913125038 CEST49701443192.168.2.5192.178.49.196
        Apr 28, 2025 07:46:27.913131952 CEST44349701192.178.49.196192.168.2.5
        Apr 28, 2025 07:46:27.913422108 CEST44349701192.178.49.196192.168.2.5
        Apr 28, 2025 07:46:27.966264963 CEST49701443192.168.2.5192.178.49.196
        Apr 28, 2025 07:46:28.534010887 CEST49703443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:28.534065962 CEST44349703172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:28.534159899 CEST49703443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:28.534394979 CEST49703443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:28.534409046 CEST44349703172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:28.827707052 CEST44349703172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:28.827805042 CEST49703443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:28.829344988 CEST49703443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:28.829355001 CEST44349703172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:28.829598904 CEST44349703172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:28.830173016 CEST49703443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:28.872277975 CEST44349703172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:29.261560917 CEST44349703172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:29.261622906 CEST44349703172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:29.261753082 CEST49703443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:29.294362068 CEST49703443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:29.294399023 CEST44349703172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:29.407632113 CEST49704443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:29.407695055 CEST44349704172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:29.407777071 CEST49704443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:29.408010960 CEST49704443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:29.408027887 CEST44349704172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:29.715398073 CEST44349704172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:29.716615915 CEST49704443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:29.716666937 CEST44349704172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:29.716839075 CEST49704443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:29.716846943 CEST44349704172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:29.882900000 CEST49672443192.168.2.5204.79.197.203
        Apr 28, 2025 07:46:30.144676924 CEST44349704172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:30.144741058 CEST44349704172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:30.144790888 CEST49704443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:30.145771980 CEST49704443192.168.2.5172.67.150.203
        Apr 28, 2025 07:46:30.145797968 CEST44349704172.67.150.203192.168.2.5
        Apr 28, 2025 07:46:30.231467009 CEST49676443192.168.2.520.189.173.14
        Apr 28, 2025 07:46:36.863730907 CEST49675443192.168.2.52.23.227.208
        Apr 28, 2025 07:46:36.863775969 CEST443496752.23.227.208192.168.2.5
        Apr 28, 2025 07:46:37.246335983 CEST49706443192.168.2.5150.171.28.254
        Apr 28, 2025 07:46:37.246383905 CEST44349706150.171.28.254192.168.2.5
        Apr 28, 2025 07:46:37.246460915 CEST49706443192.168.2.5150.171.28.254
        Apr 28, 2025 07:46:37.246808052 CEST49706443192.168.2.5150.171.28.254
        Apr 28, 2025 07:46:37.246822119 CEST44349706150.171.28.254192.168.2.5
        Apr 28, 2025 07:46:37.692424059 CEST44349706150.171.28.254192.168.2.5
        Apr 28, 2025 07:46:37.692507029 CEST49706443192.168.2.5150.171.28.254
        Apr 28, 2025 07:46:37.891369104 CEST44349701192.178.49.196192.168.2.5
        Apr 28, 2025 07:46:37.891433954 CEST44349701192.178.49.196192.168.2.5
        Apr 28, 2025 07:46:37.891499043 CEST49701443192.168.2.5192.178.49.196
        Apr 28, 2025 07:46:37.935220957 CEST49701443192.168.2.5192.178.49.196
        Apr 28, 2025 07:46:37.935239077 CEST44349701192.178.49.196192.168.2.5
        Apr 28, 2025 07:46:39.839766979 CEST49676443192.168.2.520.189.173.14
        Apr 28, 2025 07:47:24.730690002 CEST4969980192.168.2.5192.178.49.195
        Apr 28, 2025 07:47:24.878907919 CEST8049699192.178.49.195192.168.2.5
        Apr 28, 2025 07:47:24.878963947 CEST4969980192.168.2.5192.178.49.195
        Apr 28, 2025 07:47:27.497493982 CEST49711443192.168.2.5192.178.49.196
        Apr 28, 2025 07:47:27.497534037 CEST44349711192.178.49.196192.168.2.5
        Apr 28, 2025 07:47:27.497615099 CEST49711443192.168.2.5192.178.49.196
        Apr 28, 2025 07:47:27.497771025 CEST49711443192.168.2.5192.178.49.196
        Apr 28, 2025 07:47:27.497785091 CEST44349711192.178.49.196192.168.2.5
        Apr 28, 2025 07:47:27.811203957 CEST44349711192.178.49.196192.168.2.5
        Apr 28, 2025 07:47:27.811533928 CEST49711443192.168.2.5192.178.49.196
        Apr 28, 2025 07:47:27.811563969 CEST44349711192.178.49.196192.168.2.5
        Apr 28, 2025 07:47:37.806813955 CEST44349711192.178.49.196192.168.2.5
        Apr 28, 2025 07:47:37.806879044 CEST44349711192.178.49.196192.168.2.5
        Apr 28, 2025 07:47:37.807048082 CEST49711443192.168.2.5192.178.49.196
        Apr 28, 2025 07:47:37.934899092 CEST49711443192.168.2.5192.178.49.196
        Apr 28, 2025 07:47:37.934928894 CEST44349711192.178.49.196192.168.2.5
        TimestampSource PortDest PortSource IPDest IP
        Apr 28, 2025 07:46:23.319246054 CEST53603181.1.1.1192.168.2.5
        Apr 28, 2025 07:46:23.438117981 CEST53626241.1.1.1192.168.2.5
        Apr 28, 2025 07:46:24.730834961 CEST53634541.1.1.1192.168.2.5
        Apr 28, 2025 07:46:27.436222076 CEST6293253192.168.2.51.1.1.1
        Apr 28, 2025 07:46:27.436394930 CEST5659953192.168.2.51.1.1.1
        Apr 28, 2025 07:46:27.576924086 CEST53629321.1.1.1192.168.2.5
        Apr 28, 2025 07:46:27.588141918 CEST53565991.1.1.1192.168.2.5
        Apr 28, 2025 07:46:28.174453020 CEST5647253192.168.2.51.1.1.1
        Apr 28, 2025 07:46:28.178263903 CEST5608953192.168.2.51.1.1.1
        Apr 28, 2025 07:46:28.191143036 CEST5321153192.168.2.51.1.1.1
        Apr 28, 2025 07:46:28.191354036 CEST6541953192.168.2.51.1.1.1
        Apr 28, 2025 07:46:28.344953060 CEST53654191.1.1.1192.168.2.5
        Apr 28, 2025 07:46:28.351865053 CEST53560891.1.1.1192.168.2.5
        Apr 28, 2025 07:46:28.351963043 CEST53564721.1.1.1192.168.2.5
        Apr 28, 2025 07:46:28.533397913 CEST53532111.1.1.1192.168.2.5
        Apr 28, 2025 07:46:41.690855980 CEST53641311.1.1.1192.168.2.5
        Apr 28, 2025 07:47:00.472491026 CEST53596271.1.1.1192.168.2.5
        Apr 28, 2025 07:47:22.580810070 CEST138138192.168.2.5192.168.2.255
        Apr 28, 2025 07:47:22.844825983 CEST53647151.1.1.1192.168.2.5
        Apr 28, 2025 07:47:22.925261021 CEST53653441.1.1.1192.168.2.5
        Apr 28, 2025 07:47:26.090590000 CEST53554091.1.1.1192.168.2.5
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 28, 2025 07:46:27.436222076 CEST192.168.2.51.1.1.10xad22Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 28, 2025 07:46:27.436394930 CEST192.168.2.51.1.1.10xa46Standard query (0)www.google.com65IN (0x0001)false
        Apr 28, 2025 07:46:28.174453020 CEST192.168.2.51.1.1.10xab89Standard query (0)bhpwqtiudzqnz.vipA (IP address)IN (0x0001)false
        Apr 28, 2025 07:46:28.178263903 CEST192.168.2.51.1.1.10xe578Standard query (0)bhpwqtiudzqnz.vip65IN (0x0001)false
        Apr 28, 2025 07:46:28.191143036 CEST192.168.2.51.1.1.10x50deStandard query (0)bhpwqtiudzqnz.vipA (IP address)IN (0x0001)false
        Apr 28, 2025 07:46:28.191354036 CEST192.168.2.51.1.1.10x3bafStandard query (0)bhpwqtiudzqnz.vip65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 28, 2025 07:46:27.576924086 CEST1.1.1.1192.168.2.50xad22No error (0)www.google.com192.178.49.196A (IP address)IN (0x0001)false
        Apr 28, 2025 07:46:27.588141918 CEST1.1.1.1192.168.2.50xa46No error (0)www.google.com65IN (0x0001)false
        Apr 28, 2025 07:46:28.344953060 CEST1.1.1.1192.168.2.50x3bafNo error (0)bhpwqtiudzqnz.vip65IN (0x0001)false
        Apr 28, 2025 07:46:28.351865053 CEST1.1.1.1192.168.2.50xe578No error (0)bhpwqtiudzqnz.vip65IN (0x0001)false
        Apr 28, 2025 07:46:28.351963043 CEST1.1.1.1192.168.2.50xab89No error (0)bhpwqtiudzqnz.vip172.67.150.203A (IP address)IN (0x0001)false
        Apr 28, 2025 07:46:28.351963043 CEST1.1.1.1192.168.2.50xab89No error (0)bhpwqtiudzqnz.vip104.21.0.92A (IP address)IN (0x0001)false
        Apr 28, 2025 07:46:28.533397913 CEST1.1.1.1192.168.2.50x50deNo error (0)bhpwqtiudzqnz.vip172.67.150.203A (IP address)IN (0x0001)false
        Apr 28, 2025 07:46:28.533397913 CEST1.1.1.1192.168.2.50x50deNo error (0)bhpwqtiudzqnz.vip104.21.0.92A (IP address)IN (0x0001)false
        • bhpwqtiudzqnz.vip
        • c.pki.goog
        Session IDSource IPSource PortDestination IPDestination Port
        0192.168.2.549699192.178.49.19580
        TimestampBytes transferredDirectionData
        Apr 28, 2025 07:46:24.428847075 CEST200OUTGET /r/r4.crl HTTP/1.1
        Cache-Control: max-age = 3000
        Connection: Keep-Alive
        Accept: */*
        If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
        User-Agent: Microsoft-CryptoAPI/10.0
        Host: c.pki.goog
        Apr 28, 2025 07:46:24.577241898 CEST1243INHTTP/1.1 200 OK
        Accept-Ranges: bytes
        Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
        Cross-Origin-Resource-Policy: cross-origin
        Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
        Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
        Content-Length: 530
        X-Content-Type-Options: nosniff
        Server: sffe
        X-XSS-Protection: 0
        Date: Mon, 28 Apr 2025 05:00:42 GMT
        Expires: Mon, 28 Apr 2025 05:50:42 GMT
        Cache-Control: public, max-age=3000
        Age: 2742
        Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
        Content-Type: application/pkix-crl
        Vary: Accept-Encoding
        Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
        Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.549703172.67.150.2034436408C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-04-28 05:46:28 UTC667OUTGET / HTTP/1.1
        Host: bhpwqtiudzqnz.vip
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-04-28 05:46:29 UTC464INHTTP/1.1 403 Forbidden
        Date: Mon, 28 Apr 2025 05:46:29 GMT
        Content-Type: application/xml; charset=UTF-8
        Content-Length: 111
        Connection: close
        X-Guploader-Uploadid: AAO2VwqLtfR4C7QpTNrMth0MlxJe8EY4pdmMlGJI5RhNlE4k9zi0AJwrJnGMfX88TPdPZEynzh997w
        Access-Control-Allow-Origin: *
        Expires: Mon, 28 Apr 2025 05:46:29 GMT
        Cache-Control: private, max-age=0
        Server: cloudflare
        Cf-Cache-Status: DYNAMIC
        CF-RAY: 9374426bbda397fd-PHX
        alt-svc: h3=":443"; ma=86400
        2025-04-28 05:46:29 UTC111INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 27 31 2e 30 27 20 65 6e 63 6f 64 69 6e 67 3d 27 55 54 46 2d 38 27 3f 3e 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 64 65 6e 69 65 64 2e 3c 2f 4d 65 73 73 61 67 65 3e 3c 2f 45 72 72 6f 72 3e
        Data Ascii: <?xml version='1.0' encoding='UTF-8'?><Error><Code>AccessDenied</Code><Message>Access denied.</Message></Error>


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.549704172.67.150.2034436408C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2025-04-28 05:46:29 UTC597OUTGET /favicon.ico HTTP/1.1
        Host: bhpwqtiudzqnz.vip
        Connection: keep-alive
        sec-ch-ua-platform: "Windows"
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
        sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
        sec-ch-ua-mobile: ?0
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://bhpwqtiudzqnz.vip/
        Accept-Encoding: gzip, deflate, br, zstd
        Accept-Language: en-US,en;q=0.9
        2025-04-28 05:46:30 UTC464INHTTP/1.1 403 Forbidden
        Date: Mon, 28 Apr 2025 05:46:30 GMT
        Content-Type: application/xml; charset=UTF-8
        Content-Length: 111
        Connection: close
        X-Guploader-Uploadid: AAO2VwoCaFMqsBkX6rWX6shvUH0Lg0LaDcWgq-QOw89V04Nu6xt0V6p41oVDnU3_oqFF5RQ7ecICjog
        Access-Control-Allow-Origin: *
        Expires: Mon, 28 Apr 2025 05:46:30 GMT
        Cache-Control: private, max-age=0
        Server: cloudflare
        Cf-Cache-Status: BYPASS
        CF-RAY: 937442715d902b8e-LAX
        alt-svc: h3=":443"; ma=86400
        2025-04-28 05:46:30 UTC111INData Raw: 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 27 31 2e 30 27 20 65 6e 63 6f 64 69 6e 67 3d 27 55 54 46 2d 38 27 3f 3e 3c 45 72 72 6f 72 3e 3c 43 6f 64 65 3e 41 63 63 65 73 73 44 65 6e 69 65 64 3c 2f 43 6f 64 65 3e 3c 4d 65 73 73 61 67 65 3e 41 63 63 65 73 73 20 64 65 6e 69 65 64 2e 3c 2f 4d 65 73 73 61 67 65 3e 3c 2f 45 72 72 6f 72 3e
        Data Ascii: <?xml version='1.0' encoding='UTF-8'?><Error><Code>AccessDenied</Code><Message>Access denied.</Message></Error>


        020406080s020406080100

        Click to jump to process

        020406080s0.0050100MB

        Click to jump to process

        Target ID:0
        Start time:01:46:16
        Start date:28/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff759990000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:01:46:21
        Start date:28/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2028,i,7869801962805117019,18132110213460785511,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2100 /prefetch:3
        Imagebase:0x7ff759990000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:7
        Start time:01:46:23
        Start date:28/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2028,i,7869801962805117019,18132110213460785511,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2816 /prefetch:8
        Imagebase:0x7ff759990000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:10
        Start time:01:46:26
        Start date:28/04/2025
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bhpwqtiudzqnz.vip"
        Imagebase:0x7ff759990000
        File size:3'388'000 bytes
        MD5 hash:E81F54E6C1129887AEA47E7D092680BF
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
        There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

        No disassembly