Edit tour

Windows Analysis Report
http://coaufu.com/xr.php

Overview

General Information

Sample URL:http://coaufu.com/xr.php
Analysis ID:1676316
Infos:

Detection

Score:56
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 6372 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6508 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2076,i,9472488879478441467,1154831689453066924,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2112 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 1988 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2076,i,9472488879478441467,1154831689453066924,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5012 /prefetch:8 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 7276 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://coaufu.com/xr.php" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://coaufu.com/xr.phpAvira URL Cloud: detection malicious, Label: phishing
Source: https://coaufu.com/favicon.icoAvira URL Cloud: Label: phishing
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 103.224.182.206:443 -> 192.168.2.5:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 150.171.27.254:443 -> 192.168.2.5:49709 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.27.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.27.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.27.254
Source: unknownTCP traffic detected without corresponding DNS query: 150.171.27.254
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /xr.php HTTP/1.1Host: coaufu.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: coaufu.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://coaufu.com/xr.phpAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: coaufu.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49675
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.5:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 103.224.182.206:443 -> 192.168.2.5:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 150.171.27.254:443 -> 192.168.2.5:49709 version: TLS 1.2
Source: classification engineClassification label: mal56.win@24/2@6/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2076,i,9472488879478441467,1154831689453066924,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2112 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2076,i,9472488879478441467,1154831689453066924,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5012 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://coaufu.com/xr.php"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2076,i,9472488879478441467,1154831689453066924,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2112 /prefetch:3Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2076,i,9472488879478441467,1154831689453066924,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5012 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1676316 URL: http://coaufu.com/xr.php Startdate: 28/04/2025 Architecture: WINDOWS Score: 56 22 Antivirus detection for URL or domain 2->22 24 Antivirus / Scanner detection for submitted sample 2->24 6 chrome.exe 2 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 16 192.168.2.5, 138, 443, 49365 unknown unknown 6->16 11 chrome.exe 6->11         started        14 chrome.exe 6->14         started        process5 dnsIp6 18 coaufu.com 103.224.182.206, 443, 49703, 49704 TRELLIAN-AS-APTrellianPtyLimitedAU Australia 11->18 20 www.google.com 142.250.69.4, 443, 49701, 49714 GOOGLEUS United States 11->20

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://coaufu.com/xr.php100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://coaufu.com/favicon.ico100%Avira URL Cloudphishing

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
coaufu.com
103.224.182.206
truefalse
    high
    www.google.com
    142.250.69.4
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      https://coaufu.com/favicon.icofalse
      • Avira URL Cloud: phishing
      unknown
      http://c.pki.goog/r/r4.crlfalse
        high
        https://coaufu.com/xr.phpfalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          103.224.182.206
          coaufu.comAustralia
          133618TRELLIAN-AS-APTrellianPtyLimitedAUfalse
          142.250.69.4
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.5
          Joe Sandbox version:42.0.0 Malachite
          Analysis ID:1676316
          Start date and time:2025-04-28 16:07:18 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 2m 57s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://coaufu.com/xr.php
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:9
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:MAL
          Classification:mal56.win@24/2@6/3
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 199.232.210.172, 142.250.69.3, 142.250.68.238, 142.250.141.84, 192.178.49.206, 192.178.49.163, 142.250.68.227, 184.29.183.29, 4.175.87.197
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, c2a9c95e369881c67228a6591cac2686.clo.footprintdns.com, ax-ring.msedge.net, clients2.google.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com, c.pki.goog
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtOpenFile calls found.
          • VT rate limit hit for: http://coaufu.com/xr.php
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:HTML document, ASCII text
          Category:downloaded
          Size (bytes):94
          Entropy (8bit):4.648751656165808
          Encrypted:false
          SSDEEP:3:qVZqcMsMgs0UL3AE+FoJRx+QVBK3z:qzsgs0HE+2XVBmz
          MD5:E96DDCEB1C305B9AD21EAAE42522C26F
          SHA1:AD08AE39A71ED5BA992B8B5DABC450D046354696
          SHA-256:9221CFEDFC5E03790F46C7890BCA21FCC47C5788D89DAB0AA0799C492B6AE78A
          SHA-512:1CC850F76467645447E9935F4DE13EDE698727B4FB598C7BD36DE2779596D8B5A85CB94B0CF1FB2259AD1D988F1F199E3F4C310DFDC22FCDD378B8E773F0DBD5
          Malicious:false
          Reputation:low
          URL:https://coaufu.com/favicon.ico
          Preview:<html><body><h1>403 Forbidden</h1>.Request forbidden by administrative rules..</body></html>..
          No static file info

          Download Network PCAP: filteredfull

          • Total Packets: 58
          • 443 (HTTPS)
          • 80 (HTTP)
          • 53 (DNS)
          TimestampSource PortDest PortSource IPDest IP
          Apr 28, 2025 16:08:11.374564886 CEST49676443192.168.2.520.189.173.14
          Apr 28, 2025 16:08:11.685483932 CEST49676443192.168.2.520.189.173.14
          Apr 28, 2025 16:08:12.294856071 CEST49676443192.168.2.520.189.173.14
          Apr 28, 2025 16:08:12.344276905 CEST49672443192.168.2.5204.79.197.203
          Apr 28, 2025 16:08:13.498004913 CEST49676443192.168.2.520.189.173.14
          Apr 28, 2025 16:08:14.691890001 CEST4969180192.168.2.5192.178.49.195
          Apr 28, 2025 16:08:14.844101906 CEST8049691192.178.49.195192.168.2.5
          Apr 28, 2025 16:08:14.844176054 CEST4969180192.168.2.5192.178.49.195
          Apr 28, 2025 16:08:14.844384909 CEST4969180192.168.2.5192.178.49.195
          Apr 28, 2025 16:08:14.992535114 CEST8049691192.178.49.195192.168.2.5
          Apr 28, 2025 16:08:14.993139982 CEST8049691192.178.49.195192.168.2.5
          Apr 28, 2025 16:08:15.060482979 CEST4969180192.168.2.5192.178.49.195
          Apr 28, 2025 16:08:15.904534101 CEST49676443192.168.2.520.189.173.14
          Apr 28, 2025 16:08:20.748260021 CEST49676443192.168.2.520.189.173.14
          Apr 28, 2025 16:08:21.962265015 CEST49672443192.168.2.5204.79.197.203
          Apr 28, 2025 16:08:24.515971899 CEST49701443192.168.2.5142.250.69.4
          Apr 28, 2025 16:08:24.516015053 CEST44349701142.250.69.4192.168.2.5
          Apr 28, 2025 16:08:24.516315937 CEST49701443192.168.2.5142.250.69.4
          Apr 28, 2025 16:08:24.516315937 CEST49701443192.168.2.5142.250.69.4
          Apr 28, 2025 16:08:24.516351938 CEST44349701142.250.69.4192.168.2.5
          Apr 28, 2025 16:08:24.833475113 CEST44349701142.250.69.4192.168.2.5
          Apr 28, 2025 16:08:24.833741903 CEST49701443192.168.2.5142.250.69.4
          Apr 28, 2025 16:08:24.835975885 CEST49701443192.168.2.5142.250.69.4
          Apr 28, 2025 16:08:24.835990906 CEST44349701142.250.69.4192.168.2.5
          Apr 28, 2025 16:08:24.836194038 CEST44349701142.250.69.4192.168.2.5
          Apr 28, 2025 16:08:24.888482094 CEST49701443192.168.2.5142.250.69.4
          Apr 28, 2025 16:08:26.082669020 CEST49703443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.082730055 CEST44349703103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:26.082792044 CEST49703443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.083040953 CEST49703443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.083056927 CEST44349703103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:26.087888002 CEST4970480192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.088042021 CEST4970580192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.239047050 CEST8049705103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:26.239073038 CEST8049704103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:26.239166975 CEST4970580192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.239310980 CEST4970480192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.425196886 CEST44349703103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:26.425267935 CEST49703443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.426265001 CEST44349703103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:26.426328897 CEST49703443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.427515030 CEST49703443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.427524090 CEST44349703103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:26.428011894 CEST44349703103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:26.428323984 CEST49703443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.472316980 CEST44349703103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:26.717211008 CEST44349703103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:26.717344046 CEST44349703103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:26.717408895 CEST49703443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.771121979 CEST49703443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.771145105 CEST44349703103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:26.844659090 CEST49706443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.844716072 CEST44349706103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:26.844875097 CEST49706443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.845983982 CEST49706443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:26.846009970 CEST44349706103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:27.166199923 CEST44349706103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:27.166836977 CEST49706443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:27.166836977 CEST49706443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:27.166862965 CEST44349706103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:27.166877985 CEST44349706103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:27.473531961 CEST44349706103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:27.473624945 CEST44349706103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:27.479661942 CEST49706443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:27.520652056 CEST49706443192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:27.520673037 CEST44349706103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:30.358053923 CEST49676443192.168.2.520.189.173.14
          Apr 28, 2025 16:08:31.390335083 CEST8049705103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:31.390363932 CEST8049705103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:31.390377045 CEST8049704103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:31.390387058 CEST8049704103.224.182.206192.168.2.5
          Apr 28, 2025 16:08:31.390424013 CEST4970580192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:31.390435934 CEST4970480192.168.2.5103.224.182.206
          Apr 28, 2025 16:08:33.777486086 CEST49675443192.168.2.52.23.227.208
          Apr 28, 2025 16:08:33.777528048 CEST443496752.23.227.208192.168.2.5
          Apr 28, 2025 16:08:34.148837090 CEST49709443192.168.2.5150.171.27.254
          Apr 28, 2025 16:08:34.148880959 CEST44349709150.171.27.254192.168.2.5
          Apr 28, 2025 16:08:34.148983002 CEST49709443192.168.2.5150.171.27.254
          Apr 28, 2025 16:08:34.149401903 CEST49709443192.168.2.5150.171.27.254
          Apr 28, 2025 16:08:34.149415970 CEST44349709150.171.27.254192.168.2.5
          Apr 28, 2025 16:08:34.599689960 CEST44349709150.171.27.254192.168.2.5
          Apr 28, 2025 16:08:34.599802971 CEST49709443192.168.2.5150.171.27.254
          Apr 28, 2025 16:08:34.834069967 CEST44349701142.250.69.4192.168.2.5
          Apr 28, 2025 16:08:34.834120989 CEST44349701142.250.69.4192.168.2.5
          Apr 28, 2025 16:08:34.834491968 CEST49701443192.168.2.5142.250.69.4
          Apr 28, 2025 16:08:35.625680923 CEST49701443192.168.2.5142.250.69.4
          Apr 28, 2025 16:08:35.625705004 CEST44349701142.250.69.4192.168.2.5
          Apr 28, 2025 16:09:16.404577971 CEST4970580192.168.2.5103.224.182.206
          Apr 28, 2025 16:09:16.404592991 CEST4970480192.168.2.5103.224.182.206
          Apr 28, 2025 16:09:16.555905104 CEST8049704103.224.182.206192.168.2.5
          Apr 28, 2025 16:09:16.555923939 CEST8049705103.224.182.206192.168.2.5
          Apr 28, 2025 16:09:18.592499971 CEST4969180192.168.2.5192.178.49.195
          Apr 28, 2025 16:09:18.744599104 CEST8049691192.178.49.195192.168.2.5
          Apr 28, 2025 16:09:18.744673967 CEST4969180192.168.2.5192.178.49.195
          Apr 28, 2025 16:09:24.437146902 CEST49714443192.168.2.5142.250.69.4
          Apr 28, 2025 16:09:24.437189102 CEST44349714142.250.69.4192.168.2.5
          Apr 28, 2025 16:09:24.437267065 CEST49714443192.168.2.5142.250.69.4
          Apr 28, 2025 16:09:24.437418938 CEST49714443192.168.2.5142.250.69.4
          Apr 28, 2025 16:09:24.437427044 CEST44349714142.250.69.4192.168.2.5
          Apr 28, 2025 16:09:24.751750946 CEST44349714142.250.69.4192.168.2.5
          Apr 28, 2025 16:09:24.751998901 CEST49714443192.168.2.5142.250.69.4
          Apr 28, 2025 16:09:24.752021074 CEST44349714142.250.69.4192.168.2.5
          Apr 28, 2025 16:09:34.739012003 CEST44349714142.250.69.4192.168.2.5
          Apr 28, 2025 16:09:34.739064932 CEST44349714142.250.69.4192.168.2.5
          Apr 28, 2025 16:09:34.739115953 CEST49714443192.168.2.5142.250.69.4
          Apr 28, 2025 16:09:35.630186081 CEST49714443192.168.2.5142.250.69.4
          Apr 28, 2025 16:09:35.630213022 CEST44349714142.250.69.4192.168.2.5
          TimestampSource PortDest PortSource IPDest IP
          Apr 28, 2025 16:08:20.110835075 CEST53618821.1.1.1192.168.2.5
          Apr 28, 2025 16:08:20.240519047 CEST53493651.1.1.1192.168.2.5
          Apr 28, 2025 16:08:21.497684956 CEST53629001.1.1.1192.168.2.5
          Apr 28, 2025 16:08:24.373963118 CEST5164453192.168.2.51.1.1.1
          Apr 28, 2025 16:08:24.373963118 CEST5917853192.168.2.51.1.1.1
          Apr 28, 2025 16:08:24.514811039 CEST53591781.1.1.1192.168.2.5
          Apr 28, 2025 16:08:24.514849901 CEST53516441.1.1.1192.168.2.5
          Apr 28, 2025 16:08:25.892476082 CEST5392953192.168.2.51.1.1.1
          Apr 28, 2025 16:08:25.892602921 CEST6013553192.168.2.51.1.1.1
          Apr 28, 2025 16:08:25.902131081 CEST5516953192.168.2.51.1.1.1
          Apr 28, 2025 16:08:25.902277946 CEST6280753192.168.2.51.1.1.1
          Apr 28, 2025 16:08:26.063363075 CEST53628071.1.1.1192.168.2.5
          Apr 28, 2025 16:08:26.078439951 CEST53601351.1.1.1192.168.2.5
          Apr 28, 2025 16:08:26.078646898 CEST53551691.1.1.1192.168.2.5
          Apr 28, 2025 16:08:26.087137938 CEST53539291.1.1.1192.168.2.5
          Apr 28, 2025 16:08:38.542162895 CEST53545711.1.1.1192.168.2.5
          Apr 28, 2025 16:08:57.374806881 CEST53624971.1.1.1192.168.2.5
          Apr 28, 2025 16:09:14.648977041 CEST138138192.168.2.5192.168.2.255
          Apr 28, 2025 16:09:19.740438938 CEST53502081.1.1.1192.168.2.5
          Apr 28, 2025 16:09:19.743881941 CEST53505491.1.1.1192.168.2.5
          Apr 28, 2025 16:09:23.093231916 CEST53634861.1.1.1192.168.2.5
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Apr 28, 2025 16:08:24.373963118 CEST192.168.2.51.1.1.10xee30Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Apr 28, 2025 16:08:24.373963118 CEST192.168.2.51.1.1.10xff66Standard query (0)www.google.com65IN (0x0001)false
          Apr 28, 2025 16:08:25.892476082 CEST192.168.2.51.1.1.10x4433Standard query (0)coaufu.comA (IP address)IN (0x0001)false
          Apr 28, 2025 16:08:25.892602921 CEST192.168.2.51.1.1.10x3712Standard query (0)coaufu.com65IN (0x0001)false
          Apr 28, 2025 16:08:25.902131081 CEST192.168.2.51.1.1.10xdb7Standard query (0)coaufu.comA (IP address)IN (0x0001)false
          Apr 28, 2025 16:08:25.902277946 CEST192.168.2.51.1.1.10x6df3Standard query (0)coaufu.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Apr 28, 2025 16:08:24.514811039 CEST1.1.1.1192.168.2.50xff66No error (0)www.google.com65IN (0x0001)false
          Apr 28, 2025 16:08:24.514849901 CEST1.1.1.1192.168.2.50xee30No error (0)www.google.com142.250.69.4A (IP address)IN (0x0001)false
          Apr 28, 2025 16:08:26.078646898 CEST1.1.1.1192.168.2.50xdb7No error (0)coaufu.com103.224.182.206A (IP address)IN (0x0001)false
          Apr 28, 2025 16:08:26.087137938 CEST1.1.1.1192.168.2.50x4433No error (0)coaufu.com103.224.182.206A (IP address)IN (0x0001)false
          • coaufu.com
          • c.pki.goog
          Session IDSource IPSource PortDestination IPDestination Port
          0192.168.2.549691192.178.49.19580
          TimestampBytes transferredDirectionData
          Apr 28, 2025 16:08:14.844384909 CEST200OUTGET /r/r4.crl HTTP/1.1
          Cache-Control: max-age = 3000
          Connection: Keep-Alive
          Accept: */*
          If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
          User-Agent: Microsoft-CryptoAPI/10.0
          Host: c.pki.goog
          Apr 28, 2025 16:08:14.993139982 CEST1243INHTTP/1.1 200 OK
          Accept-Ranges: bytes
          Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
          Cross-Origin-Resource-Policy: cross-origin
          Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
          Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
          Content-Length: 530
          X-Content-Type-Options: nosniff
          Server: sffe
          X-XSS-Protection: 0
          Date: Mon, 28 Apr 2025 13:20:42 GMT
          Expires: Mon, 28 Apr 2025 14:10:42 GMT
          Cache-Control: public, max-age=3000
          Age: 2852
          Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
          Content-Type: application/pkix-crl
          Vary: Accept-Encoding
          Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
          Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.549705103.224.182.206806508C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Apr 28, 2025 16:08:31.390335083 CEST233INHTTP/1.1 408 Request Time-out
          Content-length: 110
          Cache-Control: no-cache
          Connection: close
          Content-Type: text/html
          Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 38 20 52 65 71 75 65 73 74 20 54 69 6d 65 2d 6f 75 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 69 64 6e 27 74 20 73 65 6e 64 20 61 20 63 6f 6d 70 6c 65 74 65 20 72 65 71 75 65 73 74 20 69 6e 20 74 69 6d 65 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
          Data Ascii: <html><body><h1>408 Request Time-out</h1>Your browser didn't send a complete request in time.</body></html>
          Apr 28, 2025 16:09:16.404577971 CEST6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.549704103.224.182.206806508C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          Apr 28, 2025 16:08:31.390377045 CEST233INHTTP/1.1 408 Request Time-out
          Content-length: 110
          Cache-Control: no-cache
          Connection: close
          Content-Type: text/html
          Data Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 38 20 52 65 71 75 65 73 74 20 54 69 6d 65 2d 6f 75 74 3c 2f 68 31 3e 0a 59 6f 75 72 20 62 72 6f 77 73 65 72 20 64 69 64 6e 27 74 20 73 65 6e 64 20 61 20 63 6f 6d 70 6c 65 74 65 20 72 65 71 75 65 73 74 20 69 6e 20 74 69 6d 65 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
          Data Ascii: <html><body><h1>408 Request Time-out</h1>Your browser didn't send a complete request in time.</body></html>
          Apr 28, 2025 16:09:16.404592991 CEST6OUTData Raw: 00
          Data Ascii:


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.549703103.224.182.2064436508C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-04-28 14:08:26 UTC666OUTGET /xr.php HTTP/1.1
          Host: coaufu.com
          Connection: keep-alive
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
          sec-ch-ua-mobile: ?0
          sec-ch-ua-platform: "Windows"
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: navigate
          Sec-Fetch-User: ?1
          Sec-Fetch-Dest: document
          Accept-Encoding: gzip, deflate, br, zstd
          Accept-Language: en-US,en;q=0.9
          2025-04-28 14:08:26 UTC150INHTTP/1.1 200 OK
          date: Mon, 28 Apr 2025 14:08:26 GMT
          server: Apache
          content-length: 0
          content-type: text/html; charset=UTF-8
          connection: close


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.549706103.224.182.2064436508C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2025-04-28 14:08:27 UTC589OUTGET /favicon.ico HTTP/1.1
          Host: coaufu.com
          Connection: keep-alive
          sec-ch-ua-platform: "Windows"
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
          sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"
          sec-ch-ua-mobile: ?0
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Sec-Fetch-Site: same-origin
          Sec-Fetch-Mode: no-cors
          Sec-Fetch-Dest: image
          Referer: https://coaufu.com/xr.php
          Accept-Encoding: gzip, deflate, br, zstd
          Accept-Language: en-US,en;q=0.9
          2025-04-28 14:08:27 UTC76INData Raw: 48 54 54 50 2f 31 2e 30 20 34 30 33 20 46 6f 72 62 69 64 64 65 6e 0d 0a 63 61 63 68 65 2d 63 6f 6e 74 72 6f 6c 3a 20 6e 6f 2d 63 61 63 68 65 0d 0a 63 6f 6e 74 65 6e 74 2d 74 79 70 65 3a 20 74 65 78 74 2f 68 74 6d 6c 0d 0a 0d 0a
          Data Ascii: HTTP/1.0 403 Forbiddencache-control: no-cachecontent-type: text/html
          2025-04-28 14:08:27 UTC94INData Raw: 3c 68 74 6d 6c 3e 3c 62 6f 64 79 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 0a 52 65 71 75 65 73 74 20 66 6f 72 62 69 64 64 65 6e 20 62 79 20 61 64 6d 69 6e 69 73 74 72 61 74 69 76 65 20 72 75 6c 65 73 2e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a 0a
          Data Ascii: <html><body><h1>403 Forbidden</h1>Request forbidden by administrative rules.</body></html>


          020406080s020406080100

          Click to jump to process

          020406080s0.0050100MB

          Click to jump to process

          Target ID:0
          Start time:10:08:13
          Start date:28/04/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff64a6f0000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:1
          Start time:10:08:18
          Start date:28/04/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2076,i,9472488879478441467,1154831689453066924,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2112 /prefetch:3
          Imagebase:0x7ff64a6f0000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:10:08:20
          Start date:28/04/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2076,i,9472488879478441467,1154831689453066924,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5012 /prefetch:8
          Imagebase:0x7ff64a6f0000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:5
          Start time:10:08:24
          Start date:28/04/2025
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://coaufu.com/xr.php"
          Imagebase:0x7ff64a6f0000
          File size:3'388'000 bytes
          MD5 hash:E81F54E6C1129887AEA47E7D092680BF
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly