Edit tour

Windows Analysis Report
http://fp2e7a.wpc.phicdn.net

Overview

General Information

Sample URL:http://fp2e7a.wpc.phicdn.net
Analysis ID:838353
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

No high impact signatures.

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • chrome.exe (PID: 5204 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 5660 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1808 --field-trial-handle=1844,i,5898606339779818629,16941514770715017671,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 5056 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://fp2e7a.wpc.phicdn.net MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: fp2e7a.wpc.phicdn.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: fp2e7a.wpc.phicdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://fp2e7a.wpc.phicdn.net/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: fp2e7a.wpc.phicdn.netConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Referer: http://fp2e7a.wpc.phicdn.net/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9If-None-Match: "63bf857b-34"If-Modified-Since: Thu, 12 Jan 2023 03:58:51 GMT
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: fp2e7a.wpc.phicdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://fp2e7a.wpc.phicdn.net/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9If-Modified-Since: Tue, 28 Mar 2023 20:55:15 GMT
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: fp2e7a.wpc.phicdn.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49696
Source: unknownNetwork traffic detected: HTTP traffic on port 49696 -> 443
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: clean0.win@24/3@3/6
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1808 --field-trial-handle=1844,i,5898606339779818629,16941514770715017671,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://fp2e7a.wpc.phicdn.net
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1808 --field-trial-handle=1844,i,5898606339779818629,16941514770715017671,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 838353 URL: http://fp2e7a.wpc.phicdn.net Startdate: 30/03/2023 Architecture: WINDOWS Score: 0 5 chrome.exe 15 1 2->5         started        8 chrome.exe 2->8         started        dnsIp3 13 192.168.2.1 unknown unknown 5->13 15 239.255.255.250 unknown Reserved 5->15 10 chrome.exe 5->10         started        process4 dnsIp5 17 accounts.google.com 142.251.209.13, 443, 49696 GOOGLEUS United States 10->17 19 clients.l.google.com 216.58.209.46, 443, 49698 GOOGLEUS United States 10->19 21 3 other IPs or domains 10->21

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://fp2e7a.wpc.phicdn.net0%VirustotalBrowse
http://fp2e7a.wpc.phicdn.net0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://fp2e7a.wpc.phicdn.net/0%VirustotalBrowse
http://fp2e7a.wpc.phicdn.net/favicon.ico0%VirustotalBrowse
http://fp2e7a.wpc.phicdn.net/favicon.ico0%Avira URL Cloudsafe

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.251.209.13
truefalse
    high
    clients.l.google.com
    216.58.209.46
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
            high
            http://fp2e7a.wpc.phicdn.net/falseunknown
            http://fp2e7a.wpc.phicdn.net/falseunknown
            http://fp2e7a.wpc.phicdn.net/favicon.icofalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              142.251.209.13
              accounts.google.comUnited States
              15169GOOGLEUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              192.229.221.95
              fp2e7a.wpc.phicdn.netUnited States
              15133EDGECASTUSfalse
              216.58.209.46
              clients.l.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.1
              127.0.0.1
              Joe Sandbox Version:37.0.0 Beryl
              Analysis ID:838353
              Start date and time:2023-03-30 19:47:20 +02:00
              Joe Sandbox Product:CloudBasic
              Overall analysis duration:0h 7m 25s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:http://fp2e7a.wpc.phicdn.net
              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
              Number of analysed new started processes analysed:5
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • HDC enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@24/3@3/6
              EGA Information:Failed
              HDC Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, conhost.exe
              • Excluded IPs from analysis (whitelisted): 142.251.209.35, 34.104.35.123
              • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtWriteVirtualMemory calls found.
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:data
              Category:dropped
              Size (bytes):5
              Entropy (8bit):2.321928094887362
              Encrypted:false
              SSDEEP:3:3:3
              MD5:5BFA51F3A417B98E7443ECA90FC94703
              SHA1:8C015D80B8A23F780BDD215DC842B0F5551F63BD
              SHA-256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
              SHA-512:4CD03686254BB28754CBAA635AE1264723E2BE80CE1DD0F78D1AB7AEE72232F5B285F79E488E9C5C49FF343015BD07BB8433D6CEE08AE3CEA8C317303E3AC399
              Malicious:false
              Reputation:low
              Preview:0....
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:HTML document, ASCII text
              Category:downloaded
              Size (bytes):52
              Entropy (8bit):4.435546689086912
              Encrypted:false
              SSDEEP:3:qVv5XLHZGUVOMGKqBc4NGb:qF5X1GMOMd34Qb
              MD5:06E3D924688D154C0D7EA0EB4676B1F9
              SHA1:01673556A81C6DC5B2BD4A92107869F6687F46BC
              SHA-256:04553D3029E486B7D50FA7DC9EC85AAE3C60A343E3EA039A49FF1A75877CB381
              SHA-512:65658E4B0796A7A32C49AB59ED24F8EBDB451DB02EC895274741B2DE5829563164B4600FA0C90B99448E487C87BB8628B8947BED25AE08F27CC45E6F3569E30F
              Malicious:false
              Reputation:low
              URL:http://fp2e7a.wpc.phicdn.net/
              Preview:<html>.<body>..CRL/CACERT Repository.</body>.</html>
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:data
              Category:downloaded
              Size (bytes):5
              Entropy (8bit):2.321928094887362
              Encrypted:false
              SSDEEP:3:3:3
              MD5:5BFA51F3A417B98E7443ECA90FC94703
              SHA1:8C015D80B8A23F780BDD215DC842B0F5551F63BD
              SHA-256:BEBE2853A3485D1C2E5C5BE4249183E0DDAFF9F87DE71652371700A89D937128
              SHA-512:4CD03686254BB28754CBAA635AE1264723E2BE80CE1DD0F78D1AB7AEE72232F5B285F79E488E9C5C49FF343015BD07BB8433D6CEE08AE3CEA8C317303E3AC399
              Malicious:false
              Reputation:low
              URL:http://fp2e7a.wpc.phicdn.net/favicon.ico
              Preview:0....
              No static file info

              Download Network PCAP: filteredfull

              • Total Packets: 24
              • 443 (HTTPS)
              • 53 (DNS)
              TimestampSource PortDest PortSource IPDest IP
              Mar 30, 2023 19:48:22.763449907 CEST4969580192.168.2.5192.229.221.95
              Mar 30, 2023 19:48:22.764533997 CEST49696443192.168.2.5142.251.209.13
              Mar 30, 2023 19:48:22.764599085 CEST44349696142.251.209.13192.168.2.5
              Mar 30, 2023 19:48:22.764714003 CEST49696443192.168.2.5142.251.209.13
              Mar 30, 2023 19:48:22.767142057 CEST49698443192.168.2.5216.58.209.46
              Mar 30, 2023 19:48:22.767199039 CEST44349698216.58.209.46192.168.2.5
              Mar 30, 2023 19:48:22.767282009 CEST49698443192.168.2.5216.58.209.46
              Mar 30, 2023 19:48:22.768096924 CEST49696443192.168.2.5142.251.209.13
              Mar 30, 2023 19:48:22.768151999 CEST44349696142.251.209.13192.168.2.5
              Mar 30, 2023 19:48:22.769062042 CEST49698443192.168.2.5216.58.209.46
              Mar 30, 2023 19:48:22.769093990 CEST44349698216.58.209.46192.168.2.5
              Mar 30, 2023 19:48:22.778678894 CEST8049695192.229.221.95192.168.2.5
              Mar 30, 2023 19:48:22.778825045 CEST4969580192.168.2.5192.229.221.95
              Mar 30, 2023 19:48:22.785876989 CEST4969580192.168.2.5192.229.221.95
              Mar 30, 2023 19:48:22.801011086 CEST8049695192.229.221.95192.168.2.5
              Mar 30, 2023 19:48:22.801414013 CEST8049695192.229.221.95192.168.2.5
              Mar 30, 2023 19:48:22.861949921 CEST44349698216.58.209.46192.168.2.5
              Mar 30, 2023 19:48:22.866822958 CEST44349696142.251.209.13192.168.2.5
              Mar 30, 2023 19:48:22.875004053 CEST49696443192.168.2.5142.251.209.13
              Mar 30, 2023 19:48:22.875080109 CEST44349696142.251.209.13192.168.2.5
              Mar 30, 2023 19:48:22.875294924 CEST49698443192.168.2.5216.58.209.46
              Mar 30, 2023 19:48:22.875370026 CEST44349698216.58.209.46192.168.2.5
              Mar 30, 2023 19:48:22.876364946 CEST44349698216.58.209.46192.168.2.5
              Mar 30, 2023 19:48:22.876468897 CEST49698443192.168.2.5216.58.209.46
              Mar 30, 2023 19:48:22.876653910 CEST44349696142.251.209.13192.168.2.5
              Mar 30, 2023 19:48:22.876790047 CEST49696443192.168.2.5142.251.209.13
              Mar 30, 2023 19:48:22.878703117 CEST44349698216.58.209.46192.168.2.5
              Mar 30, 2023 19:48:22.878823996 CEST49698443192.168.2.5216.58.209.46
              Mar 30, 2023 19:48:22.889609098 CEST4969580192.168.2.5192.229.221.95
              Mar 30, 2023 19:48:23.576749086 CEST49696443192.168.2.5142.251.209.13
              Mar 30, 2023 19:48:23.576787949 CEST44349696142.251.209.13192.168.2.5
              Mar 30, 2023 19:48:23.577032089 CEST44349696142.251.209.13192.168.2.5
              Mar 30, 2023 19:48:23.577227116 CEST49696443192.168.2.5142.251.209.13
              Mar 30, 2023 19:48:23.577256918 CEST44349696142.251.209.13192.168.2.5
              Mar 30, 2023 19:48:23.577708006 CEST49698443192.168.2.5216.58.209.46
              Mar 30, 2023 19:48:23.577750921 CEST44349698216.58.209.46192.168.2.5
              Mar 30, 2023 19:48:23.577929020 CEST49698443192.168.2.5216.58.209.46
              Mar 30, 2023 19:48:23.577933073 CEST44349698216.58.209.46192.168.2.5
              Mar 30, 2023 19:48:23.577956915 CEST44349698216.58.209.46192.168.2.5
              Mar 30, 2023 19:48:23.621507883 CEST44349698216.58.209.46192.168.2.5
              Mar 30, 2023 19:48:23.621646881 CEST49698443192.168.2.5216.58.209.46
              Mar 30, 2023 19:48:23.621673107 CEST44349698216.58.209.46192.168.2.5
              Mar 30, 2023 19:48:23.621689081 CEST44349698216.58.209.46192.168.2.5
              Mar 30, 2023 19:48:23.621768951 CEST49698443192.168.2.5216.58.209.46
              Mar 30, 2023 19:48:23.623891115 CEST49698443192.168.2.5216.58.209.46
              Mar 30, 2023 19:48:23.623922110 CEST44349698216.58.209.46192.168.2.5
              Mar 30, 2023 19:48:23.645057917 CEST44349696142.251.209.13192.168.2.5
              Mar 30, 2023 19:48:23.645207882 CEST49696443192.168.2.5142.251.209.13
              Mar 30, 2023 19:48:23.645235062 CEST44349696142.251.209.13192.168.2.5
              Mar 30, 2023 19:48:23.645340919 CEST44349696142.251.209.13192.168.2.5
              Mar 30, 2023 19:48:23.645405054 CEST49696443192.168.2.5142.251.209.13
              Mar 30, 2023 19:48:23.647368908 CEST49696443192.168.2.5142.251.209.13
              Mar 30, 2023 19:48:23.647403955 CEST44349696142.251.209.13192.168.2.5
              Mar 30, 2023 19:48:24.034046888 CEST4969580192.168.2.5192.229.221.95
              Mar 30, 2023 19:48:24.049046040 CEST8049695192.229.221.95192.168.2.5
              Mar 30, 2023 19:48:24.050390959 CEST8049695192.229.221.95192.168.2.5
              Mar 30, 2023 19:48:24.180383921 CEST4969580192.168.2.5192.229.221.95
              Mar 30, 2023 19:48:25.116357088 CEST4969580192.168.2.5192.229.221.95
              Mar 30, 2023 19:48:25.131608009 CEST8049695192.229.221.95192.168.2.5
              Mar 30, 2023 19:48:25.132483959 CEST8049695192.229.221.95192.168.2.5
              Mar 30, 2023 19:48:25.179115057 CEST4969580192.168.2.5192.229.221.95
              Mar 30, 2023 19:48:25.254482985 CEST4969580192.168.2.5192.229.221.95
              Mar 30, 2023 19:48:25.270859003 CEST8049695192.229.221.95192.168.2.5
              Mar 30, 2023 19:48:25.297600985 CEST4969580192.168.2.5192.229.221.95
              Mar 30, 2023 19:48:25.313642979 CEST8049695192.229.221.95192.168.2.5
              Mar 30, 2023 19:48:25.383877993 CEST4969580192.168.2.5192.229.221.95
              Mar 30, 2023 19:49:10.323144913 CEST4969580192.168.2.5192.229.221.95
              Mar 30, 2023 19:49:10.338975906 CEST8049695192.229.221.95192.168.2.5
              TimestampSource PortDest PortSource IPDest IP
              Mar 30, 2023 19:48:22.410904884 CEST5029553192.168.2.58.8.8.8
              Mar 30, 2023 19:48:22.412910938 CEST6084153192.168.2.58.8.8.8
              Mar 30, 2023 19:48:22.413194895 CEST6064953192.168.2.58.8.8.8
              Mar 30, 2023 19:48:22.442919970 CEST53502958.8.8.8192.168.2.5
              Mar 30, 2023 19:48:22.447072983 CEST53608418.8.8.8192.168.2.5
              Mar 30, 2023 19:48:22.447107077 CEST53606498.8.8.8192.168.2.5
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Mar 30, 2023 19:48:22.410904884 CEST192.168.2.58.8.8.80xc831Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
              Mar 30, 2023 19:48:22.412910938 CEST192.168.2.58.8.8.80x8ad1Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
              Mar 30, 2023 19:48:22.413194895 CEST192.168.2.58.8.8.80x206dStandard query (0)fp2e7a.wpc.phicdn.netA (IP address)IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Mar 30, 2023 19:48:22.442919970 CEST8.8.8.8192.168.2.50xc831No error (0)accounts.google.com142.251.209.13A (IP address)IN (0x0001)false
              Mar 30, 2023 19:48:22.447072983 CEST8.8.8.8192.168.2.50x8ad1No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
              Mar 30, 2023 19:48:22.447072983 CEST8.8.8.8192.168.2.50x8ad1No error (0)clients.l.google.com216.58.209.46A (IP address)IN (0x0001)false
              Mar 30, 2023 19:48:22.447107077 CEST8.8.8.8192.168.2.50x206dNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              • accounts.google.com
              • clients2.google.com
              • fp2e7a.wpc.phicdn.net
              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.549696142.251.209.13443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              1192.168.2.549698216.58.209.46443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData


              Session IDSource IPSource PortDestination IPDestination PortProcess
              2192.168.2.549695192.229.221.9580C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              Mar 30, 2023 19:48:22.785876989 CEST96OUTGET / HTTP/1.1
              Host: fp2e7a.wpc.phicdn.net
              Connection: keep-alive
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Mar 30, 2023 19:48:22.801414013 CEST97INHTTP/1.1 200 OK
              Accept-Ranges: bytes
              Age: 376259
              Content-Type: text/html
              Date: Thu, 30 Mar 2023 17:48:22 GMT
              Etag: "63bf857b-34"
              Last-Modified: Thu, 12 Jan 2023 03:58:51 GMT
              Server: ECAcc (muc/3381)
              X-Cache: HIT
              X-Content-Type-Options: nosniff
              X-Frame-Options: SAMEORIGIN
              X-XSS-Protection: 1; mode=block
              Content-Length: 52
              Data Raw: 3c 68 74 6d 6c 3e 0a 3c 62 6f 64 79 3e 0a 09 43 52 4c 2f 43 41 43 45 52 54 20 52 65 70 6f 73 69 74 6f 72 79 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e
              Data Ascii: <html><body>CRL/CACERT Repository</body></html>
              Mar 30, 2023 19:48:24.034046888 CEST185OUTGET /favicon.ico HTTP/1.1
              Host: fp2e7a.wpc.phicdn.net
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Referer: http://fp2e7a.wpc.phicdn.net/
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Mar 30, 2023 19:48:24.050390959 CEST186INHTTP/1.1 200 OK
              Accept-Ranges: bytes
              Age: 161589
              Cache-Control: 'max-age=300'
              Content-Type: application/ocsp-response
              Date: Thu, 30 Mar 2023 17:48:24 GMT
              Last-Modified: Tue, 28 Mar 2023 20:55:15 GMT
              Server: ECAcc (muc/330E)
              X-Cache: HIT
              Content-Length: 5
              Data Raw: 30 03 0a 01 06
              Data Ascii: 0
              Mar 30, 2023 19:48:25.116357088 CEST446OUTGET / HTTP/1.1
              Host: fp2e7a.wpc.phicdn.net
              Connection: keep-alive
              Cache-Control: max-age=0
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
              Referer: http://fp2e7a.wpc.phicdn.net/
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              If-None-Match: "63bf857b-34"
              If-Modified-Since: Thu, 12 Jan 2023 03:58:51 GMT
              Mar 30, 2023 19:48:25.132483959 CEST446INHTTP/1.1 200 OK
              Accept-Ranges: bytes
              Age: 166120
              Content-Type: text/html
              Date: Thu, 30 Mar 2023 17:48:25 GMT
              Etag: "63bf8588-34"
              last-modified: Thu, 12 Jan 2023 03:59:04 GMT
              Server: ECAcc (muc/3357)
              X-Cache: HIT
              x-content-type-options: nosniff
              x-frame-options: SAMEORIGIN
              x-xss-protection: 1; mode=block
              Content-Length: 52
              Data Raw: 3c 68 74 6d 6c 3e 0a 3c 62 6f 64 79 3e 0a 09 43 52 4c 2f 43 41 43 45 52 54 20 52 65 70 6f 73 69 74 6f 72 79 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e
              Data Ascii: <html><body>CRL/CACERT Repository</body></html>
              Mar 30, 2023 19:48:25.254482985 CEST447OUTGET /favicon.ico HTTP/1.1
              Host: fp2e7a.wpc.phicdn.net
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Referer: http://fp2e7a.wpc.phicdn.net/
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              If-Modified-Since: Tue, 28 Mar 2023 20:55:15 GMT
              Mar 30, 2023 19:48:25.270859003 CEST447INHTTP/1.1 304 Not Modified
              Accept-Ranges: bytes
              Age: 161590
              Cache-Control: 'max-age=300'
              Date: Thu, 30 Mar 2023 17:48:25 GMT
              Last-Modified: Tue, 28 Mar 2023 20:55:15 GMT
              Server: ECAcc (muc/330E)
              X-Cache: HIT
              Mar 30, 2023 19:48:25.297600985 CEST447OUTGET /favicon.ico HTTP/1.1
              Host: fp2e7a.wpc.phicdn.net
              Connection: keep-alive
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept: */*
              Accept-Encoding: gzip, deflate
              Accept-Language: en-US,en;q=0.9
              Mar 30, 2023 19:48:25.313642979 CEST448INHTTP/1.1 200 OK
              Accept-Ranges: bytes
              Age: 161590
              Cache-Control: 'max-age=300'
              Content-Type: application/ocsp-response
              Date: Thu, 30 Mar 2023 17:48:25 GMT
              Last-Modified: Tue, 28 Mar 2023 20:55:15 GMT
              Server: ECAcc (muc/330E)
              X-Cache: HIT
              Content-Length: 5
              Data Raw: 30 03 0a 01 06
              Data Ascii: 0
              Mar 30, 2023 19:49:10.323144913 CEST462OUTData Raw: 00
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortProcess
              0192.168.2.549696142.251.209.13443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-03-30 17:48:23 UTC0OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
              Host: accounts.google.com
              Connection: keep-alive
              Content-Length: 1
              Origin: https://www.google.com
              Content-Type: application/x-www-form-urlencoded
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2023-03-30 17:48:23 UTC0OUTData Raw: 20
              Data Ascii:
              2023-03-30 17:48:23 UTC2INHTTP/1.1 200 OK
              Content-Type: application/json; charset=utf-8
              Access-Control-Allow-Origin: https://www.google.com
              Access-Control-Allow-Credentials: true
              X-Content-Type-Options: nosniff
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Thu, 30 Mar 2023 17:48:23 GMT
              Strict-Transport-Security: max-age=31536000; includeSubDomains
              Cross-Origin-Opener-Policy: same-origin
              Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
              Content-Security-Policy: script-src 'report-sample' 'nonce-HbO7Llq_wb7MMFleUC5_lw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
              Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
              Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
              Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-platform=*, ch-ua-platform-version=*
              Server: ESF
              X-XSS-Protection: 0
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-03-30 17:48:23 UTC4INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
              Data Ascii: 11["gaia.l.a.r",[]]
              2023-03-30 17:48:23 UTC4INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              Session IDSource IPSource PortDestination IPDestination PortProcess
              1192.168.2.549698216.58.209.46443C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampkBytes transferredDirectionData
              2023-03-30 17:48:23 UTC0OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
              Host: clients2.google.com
              Connection: keep-alive
              X-Goog-Update-Interactivity: fg
              X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
              X-Goog-Update-Updater: chromecrx-104.0.5112.81
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: empty
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2023-03-30 17:48:23 UTC1INHTTP/1.1 200 OK
              Content-Security-Policy: script-src 'report-sample' 'nonce-zIWGYaSQ2ud6u08LNv3myQ' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
              Cache-Control: no-cache, no-store, max-age=0, must-revalidate
              Pragma: no-cache
              Expires: Mon, 01 Jan 1990 00:00:00 GMT
              Date: Thu, 30 Mar 2023 17:48:23 GMT
              Content-Type: text/xml; charset=UTF-8
              X-Daynum: 5932
              X-Daystart: 38903
              X-Content-Type-Options: nosniff
              X-Frame-Options: SAMEORIGIN
              X-XSS-Protection: 1; mode=block
              Server: GSE
              Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
              Accept-Ranges: none
              Vary: Accept-Encoding
              Connection: close
              Transfer-Encoding: chunked
              2023-03-30 17:48:23 UTC1INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 35 39 33 32 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 33 38 39 30 33 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
              Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="5932" elapsed_seconds="38903"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
              2023-03-30 17:48:23 UTC2INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
              Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
              2023-03-30 17:48:23 UTC2INData Raw: 30 0d 0a 0d 0a
              Data Ascii: 0


              020406080s020406080100

              Click to jump to process

              020406080s0.0020406080100MB

              Click to jump to process

              • File
              • Registry

              Click to dive into process behavior distribution

              Target ID:0
              Start time:19:48:16
              Start date:30/03/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
              Imagebase:0x7ff7d31b0000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.
              There is hidden Windows Behavior. Click on Show Windows Behavior to show it.

              Target ID:1
              Start time:19:48:17
              Start date:30/03/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1808 --field-trial-handle=1844,i,5898606339779818629,16941514770715017671,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff7d31b0000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              Target ID:2
              Start time:19:48:18
              Start date:30/03/2023
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://fp2e7a.wpc.phicdn.net
              Imagebase:0x7ff7d31b0000
              File size:2851656 bytes
              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low

              No disassembly