Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://gemini-usa_llogin.godaddysites.com/

Overview

General Information

Sample URL:https://gemini-usa_llogin.godaddysites.com/
Analysis ID:1521037
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection

Classification

  • System is w10x64
  • chrome.exe (PID: 3180 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5952 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2360 --field-trial-handle=2304,i,9947208696722969055,14244982195149310420,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 5000 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gemini-usa_llogin.godaddysites.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://gemini-usa_llogin.godaddysites.com/SlashNext: detection malicious, Label: Fraudulent Website type: Phishing & Social Engineering
Source: https://gemini-usa_llogin.godaddysites.com/HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49725 version: TLS 1.0
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49725 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: gemini-usa_llogin.godaddysites.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: gemini-usa_llogin.godaddysites.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://gemini-usa_llogin.godaddysites.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: dps_site_id=us-east-1
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: gemini-usa_llogin.godaddysites.com
Source: global trafficDNS traffic detected: DNS query: img1.wsimg.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/html;charset=utf-8Content-Length: 964Vary: Accept-EncodingServer: DPS/2.0.0+sha-227ca78X-Version: 227ca78X-SiteId: us-east-1Set-Cookie: dps_site_id=us-east-1; path=/; secureDate: Sat, 28 Sep 2024 01:24:56 GMTConnection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/html;charset=utf-8Content-Length: 964Vary: Accept-EncodingServer: DPS/2.0.0+sha-227ca78X-Version: 227ca78X-SiteId: us-east-1Set-Cookie: dps_site_id=us-east-1; path=/; secureDate: Sat, 28 Sep 2024 01:24:57 GMTConnection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.5:49718 version: TLS 1.2
Source: classification engineClassification label: mal48.win@16/10@6/5
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2360 --field-trial-handle=2304,i,9947208696722969055,14244982195149310420,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gemini-usa_llogin.godaddysites.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2360 --field-trial-handle=2304,i,9947208696722969055,14244982195149310420,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://gemini-usa_llogin.godaddysites.com/100%SlashNextFraudulent Website type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
gemini-usa_llogin.godaddysites.com
13.248.243.5
truefalse
    unknown
    bg.microsoft.map.fastly.net
    199.232.210.172
    truefalse
      unknown
      www.google.com
      142.250.186.68
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          img1.wsimg.com
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://gemini-usa_llogin.godaddysites.com/true
              unknown
              https://gemini-usa_llogin.godaddysites.com/favicon.icotrue
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.250.186.68
                www.google.comUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                13.248.243.5
                gemini-usa_llogin.godaddysites.comUnited States
                16509AMAZON-02USfalse
                IP
                192.168.2.4
                192.168.2.5
                Joe Sandbox version:41.0.0 Charoite
                Analysis ID:1521037
                Start date and time:2024-09-28 03:24:01 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 30s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:browseurl.jbs
                Sample URL:https://gemini-usa_llogin.godaddysites.com/
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:7
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal48.win@16/10@6/5
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 216.58.206.67, 142.250.185.142, 74.125.133.84, 34.104.35.123, 23.38.98.78, 23.38.98.114, 52.165.165.26, 199.232.210.172, 192.229.221.95, 13.85.23.206, 40.69.42.241, 142.250.186.35, 93.184.221.240
                • Excluded domains from analysis (whitelisted): e40258.g.akamaiedge.net, slscr.update.microsoft.com, clientservices.googleapis.com, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, sls.update.microsoft.com, update.googleapis.com, hlb.apr-52dd2-0.edgecastdns.net, global-wildcard.wsimg.com.sni-only.edgekey.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                • VT rate limit hit for: https://gemini-usa_llogin.godaddysites.com/
                No simulations
                InputOutput
                URL: https://gemini-usa_llogin.godaddysites.com/ Model: jbxai
                {
                "brand":["Globi"],
                "contains_trigger_text":false,
                "trigger_text":"unknown",
                "prominent_button_name":"unknown",
                "text_input_field_labels":"unknown",
                "pdf_icon_visible":false,
                "has_visible_captcha":false,
                "has_urgent_text":false,
                "has_visible_qrcode":false}
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 00:24:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2677
                Entropy (8bit):3.9792264057133044
                Encrypted:false
                SSDEEP:48:8d2d7TjvLHMidAKZdA19ehwiZUklqehRy+3:8dane+y
                MD5:6D7FA49B1A85281DDDEDBD57338237DE
                SHA1:D917B8BE31CC36824E3DDFDEF5E7EB2315E7D7EA
                SHA-256:E01BF16ED9E8041EB2DB47DA9B64EBF3F6475BB51B0D02B41570713E598CEB8D
                SHA-512:EAB3E0A992A0E021EE63D8DC96DA6B2DF44560A619F60473809A7F7B6DBA7B6ABE826A976599BC22803C68005AB33A8DF9F0D6209233C0F4C5C7125DCE711F3A
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,....J.O9E...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I<Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V<Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V<Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V<Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V<Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 00:24:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2679
                Entropy (8bit):3.994458010811168
                Encrypted:false
                SSDEEP:48:8/2d7TjvLHMidAKZdA1weh/iZUkAQkqehuy+2:8/an89Qzy
                MD5:640646F64030EDBFA27DA451E2BD0EBB
                SHA1:10055CA58D6AB9B2566A0A7E4ECA06C2E82D59CE
                SHA-256:F308B7D9300ECF062C802B66723979E03462C32AE524E9BFA6052EF274AB904F
                SHA-512:9E6E076D28F6FA3950237DAF58E0DDBB1D8119742B1469395B5516C90B2D64C3622C65D2E5032CA280025AC05303B17ABFDA07B7F3F1E7D33D3B705A5A9EDC10
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,......E9E...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I<Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V<Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V<Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V<Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V<Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2693
                Entropy (8bit):4.008649463576296
                Encrypted:false
                SSDEEP:48:8xN2d7TjvsHMidAKZdA14tseh7sFiZUkmgqeh7sYy+BX:8xNanlnqy
                MD5:DEB0E4B240AC0CC7CBF6F1E75D5B2CCF
                SHA1:4730F9A0178C1D72EB92A2C5481C9E328B5202E1
                SHA-256:9137CF46A139646976C18127B21FA7B9AEE0E97F93001050BA31AE7F896D53F8
                SHA-512:4B9D505DAA61B1EEA5ADADB2C41FC29FADB571D88834BA170A1F96EC59DFF3A5ADA45A11E24D603E9A487B4E1629D02B4906322F7C29EE6F44E8C6341DD6DB5A
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I<Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V<Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V<Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V<Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 00:24:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2681
                Entropy (8bit):3.9947949309116386
                Encrypted:false
                SSDEEP:48:8X72d7TjvLHMidAKZdA1vehDiZUkwqehCy+R:8X7anHQy
                MD5:0A56821270CD34CE6AA233674F9BF95B
                SHA1:7640426BBDF0A5BEE72280AC6C4CA5963CD5CBE5
                SHA-256:AAD3DF2F807362A755101B56400532AC5F22A21F94EC7DC014DE5F09C8061DF3
                SHA-512:B8971635F1318D77B32914B6E835DC2994FF8F10A5F4727C603BD1E008F5E0C34FB3058EDB0F0062A0087473BD23993ACC97EED0620538B523409D0558283EF2
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,......@9E...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I<Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V<Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V<Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V<Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V<Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 00:24:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2681
                Entropy (8bit):3.982764459480497
                Encrypted:false
                SSDEEP:48:87Z2d7TjvLHMidAKZdA1hehBiZUk1W1qehEy+C:8dan39ky
                MD5:203CA80EEE746087ECCEB0BF433D7C78
                SHA1:9CDDBE3511083940BF00E48B075E23477DB0C58D
                SHA-256:4D1F977E371877ED04A12DA77D1E6A4EE37AA7FA5C2234915F0065A4C419AD57
                SHA-512:650B1ABAE1E1D266523A5996F1DA639B2913C9DC46C0F9EE77EBB9B074F3E0EF53B604C74F912423BF89C804CF7CF1598F022B8435ED29F43C590786E85E5E93
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,....T.J9E...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I<Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V<Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V<Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V<Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V<Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 00:24:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2683
                Entropy (8bit):3.994096231537071
                Encrypted:false
                SSDEEP:48:8M2d7TjvLHMidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbqy+yT+:8Man/T/TbxWOvTbqy7T
                MD5:1452FD4F114CFC6CC11864E82FE41997
                SHA1:19589508B224FC87218ACD8BAEB9C543749CE0E9
                SHA-256:04B144678BAA270A575DBF29CB8FFD824E9141BF1835744FF4D43B177CF1E131
                SHA-512:3A404AA3FE87655EB473A0B1776BB6F2884F616E922B1FD51CFD756A43671760F2C8D559719DBF403CCB3882E7E14DB6DC788778F14E69312705A994E8BB0A9D
                Malicious:false
                Reputation:low
                Preview:L..................F.@.. ...$+.,.....79E...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I<Y......B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V<Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V<Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V<Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V<Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text
                Category:downloaded
                Size (bytes):964
                Entropy (8bit):4.838435923338608
                Encrypted:false
                SSDEEP:24:hYfeRJspxwCxykxKon1xJRvey836x/CWHOFqV2g:Ae8pHlxX1xJRvB834Cw/
                MD5:A0F191E36F48B24420FA1A51A42A91D1
                SHA1:947DA7A79DCFAE9B6811D2FC42F0BD510A1D5533
                SHA-256:5C789BF141C0262059DB82230F158B698AD8D835760E4D2A46D2C50524CEEDA2
                SHA-512:FD72C0EEF46869126E996FA7E5260EE682C4CDDF1C83E877A34B548ED25853887B611FB1C7F8B84D3F8CC59158E78FE4310F52B1FC75BBE164764F35E6C32250
                Malicious:false
                Reputation:low
                URL:https://gemini-usa_llogin.godaddysites.com/favicon.ico
                Preview:<!DOCTYPE html>.<html>.<head>. <title>404 Not Found</title>. <meta http-equiv="content-type" content="text/html; charset=utf-8">. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <link href="//img1.wsimg.com/dps/css/uxcore.css" rel="stylesheet">. <link href="//img1.wsimg.com/dps/css/customer-comp.css" rel="stylesheet">.</head>..<body>.<div id="error-img"><img src="//img1.wsimg.com/dps/images/404_background.jpg"></div>.<div class="container text-center" id="error">. <div class="row">. <div class="col-md-12">. <div class="main-icon text-warning"><span class="uxicon uxicon-alert"></span></div>. <h1>File not found (404 error)</h1>. </div>. </div>. <div class="row">. <div class="col-md-6 col-md-push-3">. <p class="lead">If you think what you're looking for should be here, please contact the site owner.</p>. </div>. </div>.</div>..</body>.</html>.
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text
                Category:downloaded
                Size (bytes):964
                Entropy (8bit):4.838435923338608
                Encrypted:false
                SSDEEP:24:hYfeRJspxwCxykxKon1xJRvey836x/CWHOFqV2g:Ae8pHlxX1xJRvB834Cw/
                MD5:A0F191E36F48B24420FA1A51A42A91D1
                SHA1:947DA7A79DCFAE9B6811D2FC42F0BD510A1D5533
                SHA-256:5C789BF141C0262059DB82230F158B698AD8D835760E4D2A46D2C50524CEEDA2
                SHA-512:FD72C0EEF46869126E996FA7E5260EE682C4CDDF1C83E877A34B548ED25853887B611FB1C7F8B84D3F8CC59158E78FE4310F52B1FC75BBE164764F35E6C32250
                Malicious:false
                Reputation:low
                URL:https://gemini-usa_llogin.godaddysites.com/
                Preview:<!DOCTYPE html>.<html>.<head>. <title>404 Not Found</title>. <meta http-equiv="content-type" content="text/html; charset=utf-8">. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <link href="//img1.wsimg.com/dps/css/uxcore.css" rel="stylesheet">. <link href="//img1.wsimg.com/dps/css/customer-comp.css" rel="stylesheet">.</head>..<body>.<div id="error-img"><img src="//img1.wsimg.com/dps/images/404_background.jpg"></div>.<div class="container text-center" id="error">. <div class="row">. <div class="col-md-12">. <div class="main-icon text-warning"><span class="uxicon uxicon-alert"></span></div>. <h1>File not found (404 error)</h1>. </div>. </div>. <div class="row">. <div class="col-md-6 col-md-push-3">. <p class="lead">If you think what you're looking for should be here, please contact the site owner.</p>. </div>. </div>.</div>..</body>.</html>.
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Sep 28, 2024 03:24:48.106556892 CEST49674443192.168.2.523.1.237.91
                Sep 28, 2024 03:24:48.106559038 CEST49675443192.168.2.523.1.237.91
                Sep 28, 2024 03:24:48.215892076 CEST49673443192.168.2.523.1.237.91
                Sep 28, 2024 03:24:55.525060892 CEST49709443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:55.525105000 CEST4434970913.248.243.5192.168.2.5
                Sep 28, 2024 03:24:55.525182009 CEST49709443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:55.525209904 CEST49710443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:55.525218010 CEST4434971013.248.243.5192.168.2.5
                Sep 28, 2024 03:24:55.525295019 CEST49710443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:55.525536060 CEST49709443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:55.525551081 CEST4434970913.248.243.5192.168.2.5
                Sep 28, 2024 03:24:55.525788069 CEST49710443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:55.525795937 CEST4434971013.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.002863884 CEST4434970913.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.003107071 CEST49709443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:56.003114939 CEST4434970913.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.004106045 CEST4434970913.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.004173040 CEST49709443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:56.007590055 CEST49709443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:56.007642031 CEST4434970913.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.007762909 CEST49709443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:56.007767916 CEST4434970913.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.009403944 CEST4434971013.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.013257027 CEST49710443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:56.013263941 CEST4434971013.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.014400959 CEST4434971013.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.014470100 CEST49710443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:56.017848969 CEST49710443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:56.017910957 CEST4434971013.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.070538044 CEST49710443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:56.070552111 CEST4434971013.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.072115898 CEST49709443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:56.120762110 CEST4434970913.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.120832920 CEST4434970913.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.120883942 CEST49709443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:56.128248930 CEST49709443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:56.128253937 CEST4434970913.248.243.5192.168.2.5
                Sep 28, 2024 03:24:56.262248993 CEST49710443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:57.708852053 CEST49675443192.168.2.523.1.237.91
                Sep 28, 2024 03:24:57.708858013 CEST49674443192.168.2.523.1.237.91
                Sep 28, 2024 03:24:57.779244900 CEST49710443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:57.818733931 CEST49673443192.168.2.523.1.237.91
                Sep 28, 2024 03:24:57.819401979 CEST4434971013.248.243.5192.168.2.5
                Sep 28, 2024 03:24:57.884141922 CEST4434971013.248.243.5192.168.2.5
                Sep 28, 2024 03:24:57.884212971 CEST4434971013.248.243.5192.168.2.5
                Sep 28, 2024 03:24:57.884367943 CEST49710443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:57.887578964 CEST49710443192.168.2.513.248.243.5
                Sep 28, 2024 03:24:57.887593985 CEST4434971013.248.243.5192.168.2.5
                Sep 28, 2024 03:24:58.470876932 CEST49716443192.168.2.5142.250.186.68
                Sep 28, 2024 03:24:58.470921993 CEST44349716142.250.186.68192.168.2.5
                Sep 28, 2024 03:24:58.471764088 CEST49716443192.168.2.5142.250.186.68
                Sep 28, 2024 03:24:58.472335100 CEST49716443192.168.2.5142.250.186.68
                Sep 28, 2024 03:24:58.472352028 CEST44349716142.250.186.68192.168.2.5
                Sep 28, 2024 03:24:59.134231091 CEST44349716142.250.186.68192.168.2.5
                Sep 28, 2024 03:24:59.178502083 CEST49716443192.168.2.5142.250.186.68
                Sep 28, 2024 03:24:59.222937107 CEST49716443192.168.2.5142.250.186.68
                Sep 28, 2024 03:24:59.222946882 CEST44349716142.250.186.68192.168.2.5
                Sep 28, 2024 03:24:59.224150896 CEST44349716142.250.186.68192.168.2.5
                Sep 28, 2024 03:24:59.224215984 CEST49716443192.168.2.5142.250.186.68
                Sep 28, 2024 03:24:59.288587093 CEST49716443192.168.2.5142.250.186.68
                Sep 28, 2024 03:24:59.288808107 CEST44349716142.250.186.68192.168.2.5
                Sep 28, 2024 03:24:59.334755898 CEST49716443192.168.2.5142.250.186.68
                Sep 28, 2024 03:24:59.334790945 CEST44349716142.250.186.68192.168.2.5
                Sep 28, 2024 03:24:59.381629944 CEST49716443192.168.2.5142.250.186.68
                Sep 28, 2024 03:24:59.449129105 CEST49717443192.168.2.5184.28.90.27
                Sep 28, 2024 03:24:59.449166059 CEST44349717184.28.90.27192.168.2.5
                Sep 28, 2024 03:24:59.449234009 CEST49717443192.168.2.5184.28.90.27
                Sep 28, 2024 03:24:59.451231003 CEST49717443192.168.2.5184.28.90.27
                Sep 28, 2024 03:24:59.451240063 CEST44349717184.28.90.27192.168.2.5
                Sep 28, 2024 03:24:59.483711958 CEST4434970323.1.237.91192.168.2.5
                Sep 28, 2024 03:24:59.483800888 CEST49703443192.168.2.523.1.237.91
                Sep 28, 2024 03:25:00.090306997 CEST44349717184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:00.090428114 CEST49717443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:00.177514076 CEST49717443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:00.177537918 CEST44349717184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:00.178616047 CEST44349717184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:00.223356009 CEST49717443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:00.259797096 CEST49717443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:00.303400993 CEST44349717184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:00.445039988 CEST44349717184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:00.445115089 CEST44349717184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:00.445174932 CEST49717443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:00.445453882 CEST49717443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:00.445471048 CEST44349717184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:00.597237110 CEST49718443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:00.597268105 CEST44349718184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:00.597322941 CEST49718443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:00.597783089 CEST49718443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:00.597791910 CEST44349718184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:01.238233089 CEST44349718184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:01.238313913 CEST49718443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:01.241463900 CEST49718443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:01.241468906 CEST44349718184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:01.241760969 CEST44349718184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:01.243515968 CEST49718443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:01.287409067 CEST44349718184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:01.511554956 CEST44349718184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:01.511723042 CEST44349718184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:01.511779070 CEST49718443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:01.516700029 CEST49718443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:01.516711950 CEST44349718184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:01.516722918 CEST49718443192.168.2.5184.28.90.27
                Sep 28, 2024 03:25:01.516727924 CEST44349718184.28.90.27192.168.2.5
                Sep 28, 2024 03:25:09.127628088 CEST44349716142.250.186.68192.168.2.5
                Sep 28, 2024 03:25:09.127697945 CEST44349716142.250.186.68192.168.2.5
                Sep 28, 2024 03:25:09.127752066 CEST49716443192.168.2.5142.250.186.68
                Sep 28, 2024 03:25:10.596488953 CEST49716443192.168.2.5142.250.186.68
                Sep 28, 2024 03:25:10.596502066 CEST44349716142.250.186.68192.168.2.5
                Sep 28, 2024 03:25:10.639018059 CEST49703443192.168.2.523.1.237.91
                Sep 28, 2024 03:25:10.639226913 CEST49703443192.168.2.523.1.237.91
                Sep 28, 2024 03:25:10.642205000 CEST49725443192.168.2.523.1.237.91
                Sep 28, 2024 03:25:10.642235994 CEST4434972523.1.237.91192.168.2.5
                Sep 28, 2024 03:25:10.642465115 CEST49725443192.168.2.523.1.237.91
                Sep 28, 2024 03:25:10.643800020 CEST4434970323.1.237.91192.168.2.5
                Sep 28, 2024 03:25:10.643923044 CEST4434970323.1.237.91192.168.2.5
                Sep 28, 2024 03:25:10.661418915 CEST49725443192.168.2.523.1.237.91
                Sep 28, 2024 03:25:10.661439896 CEST4434972523.1.237.91192.168.2.5
                Sep 28, 2024 03:25:11.258613110 CEST4434972523.1.237.91192.168.2.5
                Sep 28, 2024 03:25:11.258682013 CEST49725443192.168.2.523.1.237.91
                Sep 28, 2024 03:25:30.416215897 CEST4434972523.1.237.91192.168.2.5
                Sep 28, 2024 03:25:30.417072058 CEST49725443192.168.2.523.1.237.91
                Sep 28, 2024 03:25:58.522377968 CEST49729443192.168.2.5142.250.186.68
                Sep 28, 2024 03:25:58.522427082 CEST44349729142.250.186.68192.168.2.5
                Sep 28, 2024 03:25:58.522769928 CEST49729443192.168.2.5142.250.186.68
                Sep 28, 2024 03:25:58.523001909 CEST49729443192.168.2.5142.250.186.68
                Sep 28, 2024 03:25:58.523014069 CEST44349729142.250.186.68192.168.2.5
                Sep 28, 2024 03:25:59.170795918 CEST44349729142.250.186.68192.168.2.5
                Sep 28, 2024 03:25:59.171130896 CEST49729443192.168.2.5142.250.186.68
                Sep 28, 2024 03:25:59.171149015 CEST44349729142.250.186.68192.168.2.5
                Sep 28, 2024 03:25:59.171530008 CEST44349729142.250.186.68192.168.2.5
                Sep 28, 2024 03:25:59.172055006 CEST49729443192.168.2.5142.250.186.68
                Sep 28, 2024 03:25:59.172122002 CEST44349729142.250.186.68192.168.2.5
                Sep 28, 2024 03:25:59.224225998 CEST49729443192.168.2.5142.250.186.68
                Sep 28, 2024 03:26:09.081151962 CEST44349729142.250.186.68192.168.2.5
                Sep 28, 2024 03:26:09.081315994 CEST44349729142.250.186.68192.168.2.5
                Sep 28, 2024 03:26:09.081379890 CEST49729443192.168.2.5142.250.186.68
                Sep 28, 2024 03:26:10.314394951 CEST49729443192.168.2.5142.250.186.68
                Sep 28, 2024 03:26:10.314424038 CEST44349729142.250.186.68192.168.2.5
                TimestampSource PortDest PortSource IPDest IP
                Sep 28, 2024 03:24:53.814594984 CEST53552171.1.1.1192.168.2.5
                Sep 28, 2024 03:24:53.820972919 CEST53629471.1.1.1192.168.2.5
                Sep 28, 2024 03:24:54.890002966 CEST53526701.1.1.1192.168.2.5
                Sep 28, 2024 03:24:55.513530970 CEST5149753192.168.2.51.1.1.1
                Sep 28, 2024 03:24:55.514116049 CEST6255553192.168.2.51.1.1.1
                Sep 28, 2024 03:24:55.521629095 CEST53514971.1.1.1192.168.2.5
                Sep 28, 2024 03:24:55.522469997 CEST53625551.1.1.1192.168.2.5
                Sep 28, 2024 03:24:56.163413048 CEST6016153192.168.2.51.1.1.1
                Sep 28, 2024 03:24:56.163686037 CEST5427753192.168.2.51.1.1.1
                Sep 28, 2024 03:24:58.461863995 CEST5464853192.168.2.51.1.1.1
                Sep 28, 2024 03:24:58.462126017 CEST6153653192.168.2.51.1.1.1
                Sep 28, 2024 03:24:58.468420982 CEST53546481.1.1.1192.168.2.5
                Sep 28, 2024 03:24:58.468887091 CEST53615361.1.1.1192.168.2.5
                Sep 28, 2024 03:25:11.935770988 CEST53612431.1.1.1192.168.2.5
                Sep 28, 2024 03:25:31.018306971 CEST53533701.1.1.1192.168.2.5
                Sep 28, 2024 03:25:53.648082972 CEST53555791.1.1.1192.168.2.5
                Sep 28, 2024 03:25:53.650605917 CEST53538341.1.1.1192.168.2.5
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Sep 28, 2024 03:24:55.513530970 CEST192.168.2.51.1.1.10xe2c3Standard query (0)gemini-usa_llogin.godaddysites.comA (IP address)IN (0x0001)false
                Sep 28, 2024 03:24:55.514116049 CEST192.168.2.51.1.1.10x4521Standard query (0)gemini-usa_llogin.godaddysites.com65IN (0x0001)false
                Sep 28, 2024 03:24:56.163413048 CEST192.168.2.51.1.1.10xc2aaStandard query (0)img1.wsimg.comA (IP address)IN (0x0001)false
                Sep 28, 2024 03:24:56.163686037 CEST192.168.2.51.1.1.10x3ad0Standard query (0)img1.wsimg.com65IN (0x0001)false
                Sep 28, 2024 03:24:58.461863995 CEST192.168.2.51.1.1.10x4b5aStandard query (0)www.google.comA (IP address)IN (0x0001)false
                Sep 28, 2024 03:24:58.462126017 CEST192.168.2.51.1.1.10x27aeStandard query (0)www.google.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Sep 28, 2024 03:24:55.521629095 CEST1.1.1.1192.168.2.50xe2c3No error (0)gemini-usa_llogin.godaddysites.com13.248.243.5A (IP address)IN (0x0001)false
                Sep 28, 2024 03:24:55.521629095 CEST1.1.1.1192.168.2.50xe2c3No error (0)gemini-usa_llogin.godaddysites.com76.223.105.230A (IP address)IN (0x0001)false
                Sep 28, 2024 03:24:56.170510054 CEST1.1.1.1192.168.2.50x3ad0No error (0)img1.wsimg.comglobal-wildcard.wsimg.com.sni-only.edgekey.netCNAME (Canonical name)IN (0x0001)false
                Sep 28, 2024 03:24:56.170552969 CEST1.1.1.1192.168.2.50xc2aaNo error (0)img1.wsimg.comglobal-wildcard.wsimg.com.sni-only.edgekey.netCNAME (Canonical name)IN (0x0001)false
                Sep 28, 2024 03:24:58.468420982 CEST1.1.1.1192.168.2.50x4b5aNo error (0)www.google.com142.250.186.68A (IP address)IN (0x0001)false
                Sep 28, 2024 03:24:58.468887091 CEST1.1.1.1192.168.2.50x27aeNo error (0)www.google.com65IN (0x0001)false
                Sep 28, 2024 03:25:09.058429956 CEST1.1.1.1192.168.2.50xf888No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                Sep 28, 2024 03:25:09.058429956 CEST1.1.1.1192.168.2.50xf888No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                Sep 28, 2024 03:25:09.720531940 CEST1.1.1.1192.168.2.50x3779No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Sep 28, 2024 03:25:09.720531940 CEST1.1.1.1192.168.2.50x3779No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                Sep 28, 2024 03:25:23.402697086 CEST1.1.1.1192.168.2.50xaa05No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Sep 28, 2024 03:25:23.402697086 CEST1.1.1.1192.168.2.50xaa05No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                Sep 28, 2024 03:25:46.146766901 CEST1.1.1.1192.168.2.50x150dNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Sep 28, 2024 03:25:46.146766901 CEST1.1.1.1192.168.2.50x150dNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                Sep 28, 2024 03:26:06.980973005 CEST1.1.1.1192.168.2.50xdc83No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Sep 28, 2024 03:26:06.980973005 CEST1.1.1.1192.168.2.50xdc83No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                • gemini-usa_llogin.godaddysites.com
                • https:
                • fs.microsoft.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.54970913.248.243.54435952C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-09-28 01:24:56 UTC677OUTGET / HTTP/1.1
                Host: gemini-usa_llogin.godaddysites.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                sec-ch-ua-platform: "Windows"
                Upgrade-Insecure-Requests: 1
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                Sec-Fetch-Site: none
                Sec-Fetch-Mode: navigate
                Sec-Fetch-User: ?1
                Sec-Fetch-Dest: document
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                2024-09-28 01:24:56 UTC288INHTTP/1.1 404 Not Found
                Content-Type: text/html;charset=utf-8
                Content-Length: 964
                Vary: Accept-Encoding
                Server: DPS/2.0.0+sha-227ca78
                X-Version: 227ca78
                X-SiteId: us-east-1
                Set-Cookie: dps_site_id=us-east-1; path=/; secure
                Date: Sat, 28 Sep 2024 01:24:56 GMT
                Connection: close
                2024-09-28 01:24:56 UTC964INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 2f 2f 69 6d 67 31 2e 77 73 69 6d 67 2e 63 6f 6d 2f 64 70 73 2f 63 73 73 2f 75 78 63 6f
                Data Ascii: <!DOCTYPE html><html><head> <title>404 Not Found</title> <meta http-equiv="content-type" content="text/html; charset=utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <link href="//img1.wsimg.com/dps/css/uxco


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.54971013.248.243.54435952C:\Program Files\Google\Chrome\Application\chrome.exe
                TimestampBytes transferredDirectionData
                2024-09-28 01:24:57 UTC655OUTGET /favicon.ico HTTP/1.1
                Host: gemini-usa_llogin.godaddysites.com
                Connection: keep-alive
                sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                sec-ch-ua-mobile: ?0
                User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                sec-ch-ua-platform: "Windows"
                Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                Sec-Fetch-Site: same-origin
                Sec-Fetch-Mode: no-cors
                Sec-Fetch-Dest: image
                Referer: https://gemini-usa_llogin.godaddysites.com/
                Accept-Encoding: gzip, deflate, br
                Accept-Language: en-US,en;q=0.9
                Cookie: dps_site_id=us-east-1
                2024-09-28 01:24:57 UTC288INHTTP/1.1 404 Not Found
                Content-Type: text/html;charset=utf-8
                Content-Length: 964
                Vary: Accept-Encoding
                Server: DPS/2.0.0+sha-227ca78
                X-Version: 227ca78
                X-SiteId: us-east-1
                Set-Cookie: dps_site_id=us-east-1; path=/; secure
                Date: Sat, 28 Sep 2024 01:24:57 GMT
                Connection: close
                2024-09-28 01:24:57 UTC964INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 63 6f 6e 74 65 6e 74 2d 74 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 2f 2f 69 6d 67 31 2e 77 73 69 6d 67 2e 63 6f 6d 2f 64 70 73 2f 63 73 73 2f 75 78 63 6f
                Data Ascii: <!DOCTYPE html><html><head> <title>404 Not Found</title> <meta http-equiv="content-type" content="text/html; charset=utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <link href="//img1.wsimg.com/dps/css/uxco


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.549717184.28.90.27443
                TimestampBytes transferredDirectionData
                2024-09-28 01:25:00 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-09-28 01:25:00 UTC467INHTTP/1.1 200 OK
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (lpl/EF67)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-neu-z1
                Cache-Control: public, max-age=228002
                Date: Sat, 28 Sep 2024 01:25:00 GMT
                Connection: close
                X-CID: 2


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.549718184.28.90.27443
                TimestampBytes transferredDirectionData
                2024-09-28 01:25:01 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                Accept-Encoding: identity
                If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                Range: bytes=0-2147483646
                User-Agent: Microsoft BITS/7.8
                Host: fs.microsoft.com
                2024-09-28 01:25:01 UTC515INHTTP/1.1 200 OK
                ApiVersion: Distribute 1.1
                Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                Content-Type: application/octet-stream
                ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                Server: ECAcc (lpl/EF06)
                X-CID: 11
                X-Ms-ApiVersion: Distribute 1.2
                X-Ms-Region: prod-weu-z1
                Cache-Control: public, max-age=228031
                Date: Sat, 28 Sep 2024 01:25:01 GMT
                Content-Length: 55
                Connection: close
                X-CID: 2
                2024-09-28 01:25:01 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                Click to jump to process

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:21:24:49
                Start date:27/09/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:2
                Start time:21:24:52
                Start date:27/09/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2360 --field-trial-handle=2304,i,9947208696722969055,14244982195149310420,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:21:24:54
                Start date:27/09/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gemini-usa_llogin.godaddysites.com/"
                Imagebase:0x7ff715980000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly