Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://datareport.webportal.top

Overview

General Information

Sample URL:http://datareport.webportal.top
Analysis ID:1522471
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:40%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 1420 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5324 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=2232,i,6055391278158036638,1229684990209609682,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6340 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://datareport.webportal.top" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: datareport.webportal.topConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: datareport.webportal.top
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 30 Sep 2024 05:51:09 GMTContent-Length: 0Connection: keep-aliveServer: F-WEBOrigin-Agent-Cluster: ?0Access-Control-Allow-Methods: *Access-Control-Max-Age: 3600Access-Control-Allow-Credentials: trueX-Ser: BC194_lt-obgp-fujian-xiamen-33-cache-1, BC6_DE-Frankfurt-Frankfurt-11-cache-1X-Cache: MISS from BC6_DE-Frankfurt-Frankfurt-11-cache-1(cloudsvr)
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: unknown0.win@17/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=2232,i,6055391278158036638,1229684990209609682,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://datareport.webportal.top"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=2232,i,6055391278158036638,1229684990209609682,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://datareport.webportal.top0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
zcmgbipv6.v.bsclink.cn0%VirustotalBrowse
datareport.webportal.top0%VirustotalBrowse
www.google.com0%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
SourceDetectionScannerLabelLink
http://datareport.webportal.top/0%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
zcmgbipv6.v.bsclink.cn
154.85.69.8
truefalseunknown
www.google.com
216.58.206.36
truefalseunknown
fp2e7a.wpc.phicdn.net
192.229.221.95
truefalseunknown
datareport.webportal.top
unknown
unknownfalseunknown
NameMaliciousAntivirus DetectionReputation
http://datareport.webportal.top/falseunknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
239.255.255.250
unknownReserved
unknownunknownfalse
154.85.69.8
zcmgbipv6.v.bsclink.cnSeychelles
35916MULTA-ASN1USfalse
216.58.206.36
www.google.comUnited States
15169GOOGLEUSfalse
IP
192.168.2.4
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1522471
Start date and time:2024-09-30 07:50:14 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 1m 51s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:browseurl.jbs
Sample URL:http://datareport.webportal.top
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:5
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Detection:UNKNOWN
Classification:unknown0.win@17/0@4/4
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • URL browsing timeout or error
  • URL not reachable
  • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
  • Excluded IPs from analysis (whitelisted): 172.217.18.3, 142.250.181.238, 74.125.71.84, 34.104.35.123, 184.28.90.27, 4.245.163.56, 93.184.221.240, 192.229.221.95, 20.3.187.198
  • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
  • Not all processes where analyzed, report is missing behavior information
  • Report size getting too big, too many NtSetInformationFile calls found.
No simulations
No context
No context
No context
No context
No context
No created / dropped files found
No static file info
TimestampSource PortDest PortSource IPDest IP
Sep 30, 2024 07:50:58.085515022 CEST49675443192.168.2.4173.222.162.32
Sep 30, 2024 07:51:07.693953991 CEST49675443192.168.2.4173.222.162.32
Sep 30, 2024 07:51:08.632013083 CEST4973580192.168.2.4154.85.69.8
Sep 30, 2024 07:51:08.632467031 CEST4973680192.168.2.4154.85.69.8
Sep 30, 2024 07:51:08.637177944 CEST8049735154.85.69.8192.168.2.4
Sep 30, 2024 07:51:08.637274027 CEST4973580192.168.2.4154.85.69.8
Sep 30, 2024 07:51:08.637326956 CEST8049736154.85.69.8192.168.2.4
Sep 30, 2024 07:51:08.637464046 CEST4973680192.168.2.4154.85.69.8
Sep 30, 2024 07:51:08.637573004 CEST4973580192.168.2.4154.85.69.8
Sep 30, 2024 07:51:08.642333984 CEST8049735154.85.69.8192.168.2.4
Sep 30, 2024 07:51:09.518594027 CEST8049735154.85.69.8192.168.2.4
Sep 30, 2024 07:51:09.564245939 CEST4973580192.168.2.4154.85.69.8
Sep 30, 2024 07:51:11.044239998 CEST49739443192.168.2.4216.58.206.36
Sep 30, 2024 07:51:11.044332027 CEST44349739216.58.206.36192.168.2.4
Sep 30, 2024 07:51:11.044403076 CEST49739443192.168.2.4216.58.206.36
Sep 30, 2024 07:51:11.045281887 CEST49739443192.168.2.4216.58.206.36
Sep 30, 2024 07:51:11.045315027 CEST44349739216.58.206.36192.168.2.4
Sep 30, 2024 07:51:11.697452068 CEST44349739216.58.206.36192.168.2.4
Sep 30, 2024 07:51:11.698205948 CEST49739443192.168.2.4216.58.206.36
Sep 30, 2024 07:51:11.698244095 CEST44349739216.58.206.36192.168.2.4
Sep 30, 2024 07:51:11.699234009 CEST44349739216.58.206.36192.168.2.4
Sep 30, 2024 07:51:11.699305058 CEST49739443192.168.2.4216.58.206.36
Sep 30, 2024 07:51:11.701407909 CEST49739443192.168.2.4216.58.206.36
Sep 30, 2024 07:51:11.701488972 CEST44349739216.58.206.36192.168.2.4
Sep 30, 2024 07:51:11.756087065 CEST49739443192.168.2.4216.58.206.36
Sep 30, 2024 07:51:11.756118059 CEST44349739216.58.206.36192.168.2.4
Sep 30, 2024 07:51:11.802962065 CEST49739443192.168.2.4216.58.206.36
Sep 30, 2024 07:51:21.595733881 CEST44349739216.58.206.36192.168.2.4
Sep 30, 2024 07:51:21.595791101 CEST44349739216.58.206.36192.168.2.4
Sep 30, 2024 07:51:21.595841885 CEST49739443192.168.2.4216.58.206.36
Sep 30, 2024 07:51:21.782090902 CEST49739443192.168.2.4216.58.206.36
Sep 30, 2024 07:51:21.782150030 CEST44349739216.58.206.36192.168.2.4
TimestampSource PortDest PortSource IPDest IP
Sep 30, 2024 07:51:07.440821886 CEST53498151.1.1.1192.168.2.4
Sep 30, 2024 07:51:07.482556105 CEST53540131.1.1.1192.168.2.4
Sep 30, 2024 07:51:08.454672098 CEST53540331.1.1.1192.168.2.4
Sep 30, 2024 07:51:08.612597942 CEST5436653192.168.2.41.1.1.1
Sep 30, 2024 07:51:08.613034010 CEST5819253192.168.2.41.1.1.1
Sep 30, 2024 07:51:08.623321056 CEST53543661.1.1.1192.168.2.4
Sep 30, 2024 07:51:09.918994904 CEST53581921.1.1.1192.168.2.4
Sep 30, 2024 07:51:11.033868074 CEST5067853192.168.2.41.1.1.1
Sep 30, 2024 07:51:11.034409046 CEST5444653192.168.2.41.1.1.1
Sep 30, 2024 07:51:11.042161942 CEST53544461.1.1.1192.168.2.4
Sep 30, 2024 07:51:11.042591095 CEST53506781.1.1.1192.168.2.4
Sep 30, 2024 07:51:25.578978062 CEST53573911.1.1.1192.168.2.4
Sep 30, 2024 07:51:27.029985905 CEST138138192.168.2.4192.168.2.255
TimestampSource IPDest IPChecksumCodeType
Sep 30, 2024 07:51:09.919115067 CEST192.168.2.41.1.1.1c271(Port unreachable)Destination Unreachable
TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
Sep 30, 2024 07:51:08.612597942 CEST192.168.2.41.1.1.10xc2f6Standard query (0)datareport.webportal.topA (IP address)IN (0x0001)false
Sep 30, 2024 07:51:08.613034010 CEST192.168.2.41.1.1.10xb048Standard query (0)datareport.webportal.top65IN (0x0001)false
Sep 30, 2024 07:51:11.033868074 CEST192.168.2.41.1.1.10x5000Standard query (0)www.google.comA (IP address)IN (0x0001)false
Sep 30, 2024 07:51:11.034409046 CEST192.168.2.41.1.1.10x262dStandard query (0)www.google.com65IN (0x0001)false
TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
Sep 30, 2024 07:51:08.623321056 CEST1.1.1.1192.168.2.40xc2f6No error (0)datareport.webportal.topdatareport.webportal.top.bsclink.cnCNAME (Canonical name)IN (0x0001)false
Sep 30, 2024 07:51:08.623321056 CEST1.1.1.1192.168.2.40xc2f6No error (0)datareport.webportal.top.bsclink.cnzcmgbipv6.v.bsclink.cnCNAME (Canonical name)IN (0x0001)false
Sep 30, 2024 07:51:08.623321056 CEST1.1.1.1192.168.2.40xc2f6No error (0)zcmgbipv6.v.bsclink.cn154.85.69.8A (IP address)IN (0x0001)false
Sep 30, 2024 07:51:08.623321056 CEST1.1.1.1192.168.2.40xc2f6No error (0)zcmgbipv6.v.bsclink.cn154.85.69.2A (IP address)IN (0x0001)false
Sep 30, 2024 07:51:08.623321056 CEST1.1.1.1192.168.2.40xc2f6No error (0)zcmgbipv6.v.bsclink.cn154.85.69.11A (IP address)IN (0x0001)false
Sep 30, 2024 07:51:08.623321056 CEST1.1.1.1192.168.2.40xc2f6No error (0)zcmgbipv6.v.bsclink.cn154.85.69.9A (IP address)IN (0x0001)false
Sep 30, 2024 07:51:08.623321056 CEST1.1.1.1192.168.2.40xc2f6No error (0)zcmgbipv6.v.bsclink.cn154.85.69.5A (IP address)IN (0x0001)false
Sep 30, 2024 07:51:08.623321056 CEST1.1.1.1192.168.2.40xc2f6No error (0)zcmgbipv6.v.bsclink.cn154.85.69.6A (IP address)IN (0x0001)false
Sep 30, 2024 07:51:08.623321056 CEST1.1.1.1192.168.2.40xc2f6No error (0)zcmgbipv6.v.bsclink.cn154.85.69.4A (IP address)IN (0x0001)false
Sep 30, 2024 07:51:08.623321056 CEST1.1.1.1192.168.2.40xc2f6No error (0)zcmgbipv6.v.bsclink.cn154.85.69.7A (IP address)IN (0x0001)false
Sep 30, 2024 07:51:08.623321056 CEST1.1.1.1192.168.2.40xc2f6No error (0)zcmgbipv6.v.bsclink.cn154.85.69.10A (IP address)IN (0x0001)false
Sep 30, 2024 07:51:08.623321056 CEST1.1.1.1192.168.2.40xc2f6No error (0)zcmgbipv6.v.bsclink.cn154.85.69.3A (IP address)IN (0x0001)false
Sep 30, 2024 07:51:09.918994904 CEST1.1.1.1192.168.2.40xb048No error (0)datareport.webportal.topdatareport.webportal.top.bsclink.cnCNAME (Canonical name)IN (0x0001)false
Sep 30, 2024 07:51:09.918994904 CEST1.1.1.1192.168.2.40xb048No error (0)datareport.webportal.top.bsclink.cnzcmgbipv6.v.bsclink.cnCNAME (Canonical name)IN (0x0001)false
Sep 30, 2024 07:51:11.042161942 CEST1.1.1.1192.168.2.40x262dNo error (0)www.google.com65IN (0x0001)false
Sep 30, 2024 07:51:11.042591095 CEST1.1.1.1192.168.2.40x5000No error (0)www.google.com216.58.206.36A (IP address)IN (0x0001)false
Sep 30, 2024 07:51:23.302849054 CEST1.1.1.1192.168.2.40xd1dbNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
Sep 30, 2024 07:51:23.302849054 CEST1.1.1.1192.168.2.40xd1dbNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
  • datareport.webportal.top
Session IDSource IPSource PortDestination IPDestination PortPIDProcess
0192.168.2.449735154.85.69.8805324C:\Program Files\Google\Chrome\Application\chrome.exe
TimestampBytes transferredDirectionData
Sep 30, 2024 07:51:08.637573004 CEST439OUTGET / HTTP/1.1
Host: datareport.webportal.top
Connection: keep-alive
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Sep 30, 2024 07:51:09.518594027 CEST404INHTTP/1.1 404 Not Found
Date: Mon, 30 Sep 2024 05:51:09 GMT
Content-Length: 0
Connection: keep-alive
Server: F-WEB
Origin-Agent-Cluster: ?0
Access-Control-Allow-Methods: *
Access-Control-Max-Age: 3600
Access-Control-Allow-Credentials: true
X-Ser: BC194_lt-obgp-fujian-xiamen-33-cache-1, BC6_DE-Frankfurt-Frankfurt-11-cache-1
X-Cache: MISS from BC6_DE-Frankfurt-Frankfurt-11-cache-1(cloudsvr)


Click to jump to process

Click to jump to process

Click to jump to process

Target ID:0
Start time:01:51:01
Start date:30/09/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Imagebase:0x7ff76e190000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Target ID:2
Start time:01:51:04
Start date:30/09/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=2232,i,6055391278158036638,1229684990209609682,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Imagebase:0x7ff76e190000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:false

Target ID:3
Start time:01:51:07
Start date:30/09/2024
Path:C:\Program Files\Google\Chrome\Application\chrome.exe
Wow64 process (32bit):false
Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://datareport.webportal.top"
Imagebase:0x7ff76e190000
File size:3'242'272 bytes
MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

No disassembly