Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://shreekhabar.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9TUZwUFluZz0mdWlkPVVTRVIxMDA3MjAyNFVOSVFVRTEyNTYwNzEwMTgyMDI0MjAyNDA3MTA1NjEyMTg=N0123N

Overview

General Information

Sample URL:https://shreekhabar.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9TUZwUFluZz0mdWlkPVVTRVIxMDA3MjAyNFVOSVFVRTEyNTYwNzEwMTgyMDI0MjAyNDA3MTA1NjEyMTg=N0123N
Analysis ID:1522756
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2332 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6016 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1728 --field-trial-handle=1872,i,15036180888019284213,10274172978205033578,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6384 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://shreekhabar.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9TUZwUFluZz0mdWlkPVVTRVIxMDA3MjAyNFVOSVFVRTEyNTYwNzEwMTgyMDI0MjAyNDA3MTA1NjEyMTg=N0123N" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9TUZwUFluZz0mdWlkPVVTRVIxMDA3MjAyNFVOSVFVRTEyNTYwNzEwMTgyMDI0MjAyNDA3MTA1NjEyMTg=N0123N HTTP/1.1Host: shreekhabar.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: shreekhabar.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://shreekhabar.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9TUZwUFluZz0mdWlkPVVTRVIxMDA3MjAyNFVOSVFVRTEyNTYwNzEwMTgyMDI0MjAyNDA3MTA1NjEyMTg=N0123NAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficDNS traffic detected: DNS query: shreekhabar.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundConnection: closecache-control: private, no-cache, no-store, must-revalidate, max-age=0pragma: no-cachecontent-type: text/htmlcontent-length: 1163date: Mon, 30 Sep 2024 14:06:27 GMTserver: LiteSpeedalt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/2@4/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1728 --field-trial-handle=1872,i,15036180888019284213,10274172978205033578,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://shreekhabar.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9TUZwUFluZz0mdWlkPVVTRVIxMDA3MjAyNFVOSVFVRTEyNTYwNzEwMTgyMDI0MjAyNDA3MTA1NjEyMTg=N0123N"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1728 --field-trial-handle=1872,i,15036180888019284213,10274172978205033578,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    shreekhabar.com
    23.94.181.5
    truefalse
      unknown
      www.google.com
      142.250.184.228
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          NameMaliciousAntivirus DetectionReputation
          https://shreekhabar.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9TUZwUFluZz0mdWlkPVVTRVIxMDA3MjAyNFVOSVFVRTEyNTYwNzEwMTgyMDI0MjAyNDA3MTA1NjEyMTg=N0123Nfalse
            unknown
            https://shreekhabar.com/favicon.icofalse
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              23.94.181.5
              shreekhabar.comUnited States
              36352AS-COLOCROSSINGUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              142.250.184.228
              www.google.comUnited States
              15169GOOGLEUSfalse
              IP
              192.168.2.4
              192.168.2.6
              Joe Sandbox version:41.0.0 Charoite
              Analysis ID:1522756
              Start date and time:2024-09-30 16:05:25 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 3m 14s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:browseurl.jbs
              Sample URL:https://shreekhabar.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9TUZwUFluZz0mdWlkPVVTRVIxMDA3MjAyNFVOSVFVRTEyNTYwNzEwMTgyMDI0MjAyNDA3MTA1NjEyMTg=N0123N
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:8
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Detection:CLEAN
              Classification:clean0.win@16/2@4/5
              EGA Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 142.250.185.67, 142.250.110.84, 216.58.206.78, 34.104.35.123, 4.245.163.56, 199.232.214.172, 192.229.221.95, 13.85.23.206, 20.3.187.198, 172.217.16.195
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtSetInformationFile calls found.
              • VT rate limit hit for: https://shreekhabar.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9TUZwUFluZz0mdWlkPVVTRVIxMDA3MjAyNFVOSVFVRTEyNTYwNzEwMTgyMDI0MjAyNDA3MTA1NjEyMTg=N0123N
              No simulations
              No context
              No context
              No context
              No context
              No context
              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
              File Type:very short file (no magic)
              Category:downloaded
              Size (bytes):1
              Entropy (8bit):0.0
              Encrypted:false
              SSDEEP:3:v:v
              MD5:68B329DA9893E34099C7D8AD5CB9C940
              SHA1:ADC83B19E793491B1C6EA0FD8B46CD9F32E592FC
              SHA-256:01BA4719C80B6FE911B091A7C05124B64EEECE964E09C058EF8F9805DACA546B
              SHA-512:BE688838CA8686E5C90689BF2AB585CEF1137C999B48C70B92F67A5C34DC15697B5D11C982ED6D71BE1E1E7F7B4E0733884AA97C3F7A339A8ED03577CF74BE09
              Malicious:false
              Reputation:low
              URL:https://shreekhabar.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9TUZwUFluZz0mdWlkPVVTRVIxMDA3MjAyNFVOSVFVRTEyNTYwNzEwMTgyMDI0MjAyNDA3MTA1NjEyMTg=N0123N
              Preview:.
              No static file info
              TimestampSource PortDest PortSource IPDest IP
              Sep 30, 2024 16:06:22.603563070 CEST49675443192.168.2.4173.222.162.32
              Sep 30, 2024 16:06:26.230562925 CEST49735443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:26.230608940 CEST4434973523.94.181.5192.168.2.4
              Sep 30, 2024 16:06:26.230695009 CEST49735443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:26.231230021 CEST49736443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:26.231276035 CEST4434973623.94.181.5192.168.2.4
              Sep 30, 2024 16:06:26.231342077 CEST49736443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:26.231520891 CEST49735443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:26.231534958 CEST4434973523.94.181.5192.168.2.4
              Sep 30, 2024 16:06:26.231709003 CEST49736443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:26.231724024 CEST4434973623.94.181.5192.168.2.4
              Sep 30, 2024 16:06:26.909580946 CEST4434973523.94.181.5192.168.2.4
              Sep 30, 2024 16:06:26.927048922 CEST49735443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:26.927067041 CEST4434973523.94.181.5192.168.2.4
              Sep 30, 2024 16:06:26.928142071 CEST4434973523.94.181.5192.168.2.4
              Sep 30, 2024 16:06:26.928203106 CEST49735443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:26.930263042 CEST4434973623.94.181.5192.168.2.4
              Sep 30, 2024 16:06:26.955761909 CEST49736443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:26.955774069 CEST4434973623.94.181.5192.168.2.4
              Sep 30, 2024 16:06:26.956720114 CEST49735443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:26.956799984 CEST4434973523.94.181.5192.168.2.4
              Sep 30, 2024 16:06:26.956847906 CEST4434973623.94.181.5192.168.2.4
              Sep 30, 2024 16:06:26.956923008 CEST49736443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:26.958033085 CEST49736443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:26.958118916 CEST4434973623.94.181.5192.168.2.4
              Sep 30, 2024 16:06:26.958961010 CEST49735443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:26.958976030 CEST4434973523.94.181.5192.168.2.4
              Sep 30, 2024 16:06:27.008651972 CEST49735443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:27.008795023 CEST49736443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:27.008804083 CEST4434973623.94.181.5192.168.2.4
              Sep 30, 2024 16:06:27.054918051 CEST49736443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:27.371464014 CEST4434973523.94.181.5192.168.2.4
              Sep 30, 2024 16:06:27.371881962 CEST4434973523.94.181.5192.168.2.4
              Sep 30, 2024 16:06:27.371942043 CEST49735443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:27.430583954 CEST49735443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:27.430613041 CEST4434973523.94.181.5192.168.2.4
              Sep 30, 2024 16:06:27.514125109 CEST49736443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:27.559416056 CEST4434973623.94.181.5192.168.2.4
              Sep 30, 2024 16:06:27.681207895 CEST4434973623.94.181.5192.168.2.4
              Sep 30, 2024 16:06:27.681766987 CEST4434973623.94.181.5192.168.2.4
              Sep 30, 2024 16:06:27.681827068 CEST49736443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:27.683521032 CEST49736443192.168.2.423.94.181.5
              Sep 30, 2024 16:06:27.683537960 CEST4434973623.94.181.5192.168.2.4
              Sep 30, 2024 16:06:27.882914066 CEST49738443192.168.2.4142.250.184.228
              Sep 30, 2024 16:06:27.882951021 CEST44349738142.250.184.228192.168.2.4
              Sep 30, 2024 16:06:27.883016109 CEST49738443192.168.2.4142.250.184.228
              Sep 30, 2024 16:06:27.883635044 CEST49738443192.168.2.4142.250.184.228
              Sep 30, 2024 16:06:27.883646011 CEST44349738142.250.184.228192.168.2.4
              Sep 30, 2024 16:06:28.719633102 CEST44349738142.250.184.228192.168.2.4
              Sep 30, 2024 16:06:28.725327015 CEST49738443192.168.2.4142.250.184.228
              Sep 30, 2024 16:06:28.725348949 CEST44349738142.250.184.228192.168.2.4
              Sep 30, 2024 16:06:28.726903915 CEST44349738142.250.184.228192.168.2.4
              Sep 30, 2024 16:06:28.727608919 CEST49738443192.168.2.4142.250.184.228
              Sep 30, 2024 16:06:28.764972925 CEST49738443192.168.2.4142.250.184.228
              Sep 30, 2024 16:06:28.765153885 CEST44349738142.250.184.228192.168.2.4
              Sep 30, 2024 16:06:28.808185101 CEST49738443192.168.2.4142.250.184.228
              Sep 30, 2024 16:06:28.808207989 CEST44349738142.250.184.228192.168.2.4
              Sep 30, 2024 16:06:28.857661963 CEST49738443192.168.2.4142.250.184.228
              Sep 30, 2024 16:06:29.714422941 CEST49741443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:29.714473009 CEST44349741184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:29.714544058 CEST49741443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:29.720762014 CEST49741443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:29.720777988 CEST44349741184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:30.378509045 CEST44349741184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:30.378592968 CEST49741443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:30.401818991 CEST49741443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:30.401846886 CEST44349741184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:30.402070045 CEST44349741184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:30.449424028 CEST49741443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:30.686347008 CEST49741443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:30.731403112 CEST44349741184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:30.874943972 CEST44349741184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:30.875020027 CEST44349741184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:30.875098944 CEST49741443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:30.913743019 CEST49741443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:30.913743019 CEST49741443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:30.913769007 CEST44349741184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:30.913778067 CEST44349741184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:31.042048931 CEST49742443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:31.042098999 CEST44349742184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:31.042282104 CEST49742443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:31.043131113 CEST49742443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:31.043144941 CEST44349742184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:31.674381971 CEST44349742184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:31.674534082 CEST49742443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:31.677099943 CEST49742443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:31.677108049 CEST44349742184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:31.677336931 CEST44349742184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:31.679312944 CEST49742443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:31.723407030 CEST44349742184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:32.147468090 CEST44349742184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:32.147543907 CEST44349742184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:32.147644043 CEST49742443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:32.170597076 CEST49742443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:32.170619965 CEST44349742184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:32.170641899 CEST49742443192.168.2.4184.28.90.27
              Sep 30, 2024 16:06:32.170648098 CEST44349742184.28.90.27192.168.2.4
              Sep 30, 2024 16:06:38.426115036 CEST44349738142.250.184.228192.168.2.4
              Sep 30, 2024 16:06:38.426192045 CEST44349738142.250.184.228192.168.2.4
              Sep 30, 2024 16:06:38.426233053 CEST49738443192.168.2.4142.250.184.228
              Sep 30, 2024 16:06:38.879203081 CEST49738443192.168.2.4142.250.184.228
              Sep 30, 2024 16:06:38.879236937 CEST44349738142.250.184.228192.168.2.4
              Sep 30, 2024 16:07:27.892379999 CEST49751443192.168.2.4142.250.184.228
              Sep 30, 2024 16:07:27.892432928 CEST44349751142.250.184.228192.168.2.4
              Sep 30, 2024 16:07:27.892497063 CEST49751443192.168.2.4142.250.184.228
              Sep 30, 2024 16:07:27.893243074 CEST49751443192.168.2.4142.250.184.228
              Sep 30, 2024 16:07:27.893260002 CEST44349751142.250.184.228192.168.2.4
              Sep 30, 2024 16:07:29.453943968 CEST44349751142.250.184.228192.168.2.4
              Sep 30, 2024 16:07:29.483954906 CEST49751443192.168.2.4142.250.184.228
              Sep 30, 2024 16:07:29.483990908 CEST44349751142.250.184.228192.168.2.4
              Sep 30, 2024 16:07:29.484364033 CEST44349751142.250.184.228192.168.2.4
              Sep 30, 2024 16:07:29.488389015 CEST49751443192.168.2.4142.250.184.228
              Sep 30, 2024 16:07:29.488456964 CEST44349751142.250.184.228192.168.2.4
              Sep 30, 2024 16:07:29.540766954 CEST49751443192.168.2.4142.250.184.228
              Sep 30, 2024 16:07:39.363782883 CEST44349751142.250.184.228192.168.2.4
              Sep 30, 2024 16:07:39.363858938 CEST44349751142.250.184.228192.168.2.4
              Sep 30, 2024 16:07:39.363933086 CEST49751443192.168.2.4142.250.184.228
              Sep 30, 2024 16:07:40.760834932 CEST49751443192.168.2.4142.250.184.228
              Sep 30, 2024 16:07:40.760874987 CEST44349751142.250.184.228192.168.2.4
              TimestampSource PortDest PortSource IPDest IP
              Sep 30, 2024 16:06:24.264343023 CEST53590191.1.1.1192.168.2.4
              Sep 30, 2024 16:06:24.537455082 CEST53524761.1.1.1192.168.2.4
              Sep 30, 2024 16:06:25.530911922 CEST53565961.1.1.1192.168.2.4
              Sep 30, 2024 16:06:25.888004065 CEST6298653192.168.2.41.1.1.1
              Sep 30, 2024 16:06:25.890146971 CEST6422753192.168.2.41.1.1.1
              Sep 30, 2024 16:06:26.202862024 CEST53629861.1.1.1192.168.2.4
              Sep 30, 2024 16:06:26.229588985 CEST53642271.1.1.1192.168.2.4
              Sep 30, 2024 16:06:27.871660948 CEST5549753192.168.2.41.1.1.1
              Sep 30, 2024 16:06:27.872320890 CEST5079953192.168.2.41.1.1.1
              Sep 30, 2024 16:06:27.879395962 CEST53507991.1.1.1192.168.2.4
              Sep 30, 2024 16:06:27.879709005 CEST53554971.1.1.1192.168.2.4
              Sep 30, 2024 16:06:38.519098997 CEST138138192.168.2.4192.168.2.255
              Sep 30, 2024 16:06:42.737127066 CEST53532091.1.1.1192.168.2.4
              Sep 30, 2024 16:07:01.747648954 CEST53571391.1.1.1192.168.2.4
              Sep 30, 2024 16:07:23.332539082 CEST53641521.1.1.1192.168.2.4
              Sep 30, 2024 16:07:24.032944918 CEST53554051.1.1.1192.168.2.4
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
              Sep 30, 2024 16:06:25.888004065 CEST192.168.2.41.1.1.10xd8d1Standard query (0)shreekhabar.comA (IP address)IN (0x0001)false
              Sep 30, 2024 16:06:25.890146971 CEST192.168.2.41.1.1.10x887aStandard query (0)shreekhabar.com65IN (0x0001)false
              Sep 30, 2024 16:06:27.871660948 CEST192.168.2.41.1.1.10xfdebStandard query (0)www.google.comA (IP address)IN (0x0001)false
              Sep 30, 2024 16:06:27.872320890 CEST192.168.2.41.1.1.10x1ac5Standard query (0)www.google.com65IN (0x0001)false
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
              Sep 30, 2024 16:06:26.202862024 CEST1.1.1.1192.168.2.40xd8d1No error (0)shreekhabar.com23.94.181.5A (IP address)IN (0x0001)false
              Sep 30, 2024 16:06:27.879395962 CEST1.1.1.1192.168.2.40x1ac5No error (0)www.google.com65IN (0x0001)false
              Sep 30, 2024 16:06:27.879709005 CEST1.1.1.1192.168.2.40xfdebNo error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
              Sep 30, 2024 16:06:36.591213942 CEST1.1.1.1192.168.2.40xbac0No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
              Sep 30, 2024 16:06:36.591213942 CEST1.1.1.1192.168.2.40xbac0No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
              Sep 30, 2024 16:06:38.039786100 CEST1.1.1.1192.168.2.40x4774No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 30, 2024 16:06:38.039786100 CEST1.1.1.1192.168.2.40x4774No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Sep 30, 2024 16:06:50.345701933 CEST1.1.1.1192.168.2.40x34b6No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 30, 2024 16:06:50.345701933 CEST1.1.1.1192.168.2.40x34b6No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Sep 30, 2024 16:07:16.798583031 CEST1.1.1.1192.168.2.40x29abNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 30, 2024 16:07:16.798583031 CEST1.1.1.1192.168.2.40x29abNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              Sep 30, 2024 16:07:36.442333937 CEST1.1.1.1192.168.2.40x2419No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
              Sep 30, 2024 16:07:36.442333937 CEST1.1.1.1192.168.2.40x2419No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
              • shreekhabar.com
              • https:
              • fs.microsoft.com
              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              0192.168.2.44973523.94.181.54436016C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-30 14:06:26 UTC775OUTGET /n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9TUZwUFluZz0mdWlkPVVTRVIxMDA3MjAyNFVOSVFVRTEyNTYwNzEwMTgyMDI0MjAyNDA3MTA1NjEyMTg=N0123N HTTP/1.1
              Host: shreekhabar.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              sec-ch-ua-platform: "Windows"
              Upgrade-Insecure-Requests: 1
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
              Sec-Fetch-Site: none
              Sec-Fetch-Mode: navigate
              Sec-Fetch-User: ?1
              Sec-Fetch-Dest: document
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-30 14:06:27 UTC331INHTTP/1.1 200 OK
              Connection: close
              content-type: text/html; charset=UTF-8
              content-length: 1
              date: Mon, 30 Sep 2024 14:06:27 GMT
              server: LiteSpeed
              alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
              2024-09-30 14:06:27 UTC1INData Raw: 0a
              Data Ascii:


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              1192.168.2.44973623.94.181.54436016C:\Program Files\Google\Chrome\Application\chrome.exe
              TimestampBytes transferredDirectionData
              2024-09-30 14:06:27 UTC703OUTGET /favicon.ico HTTP/1.1
              Host: shreekhabar.com
              Connection: keep-alive
              sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
              sec-ch-ua-mobile: ?0
              User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
              sec-ch-ua-platform: "Windows"
              Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
              Sec-Fetch-Site: same-origin
              Sec-Fetch-Mode: no-cors
              Sec-Fetch-Dest: image
              Referer: https://shreekhabar.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9TUZwUFluZz0mdWlkPVVTRVIxMDA3MjAyNFVOSVFVRTEyNTYwNzEwMTgyMDI0MjAyNDA3MTA1NjEyMTg=N0123N
              Accept-Encoding: gzip, deflate, br
              Accept-Language: en-US,en;q=0.9
              2024-09-30 14:06:27 UTC416INHTTP/1.1 404 Not Found
              Connection: close
              cache-control: private, no-cache, no-store, must-revalidate, max-age=0
              pragma: no-cache
              content-type: text/html
              content-length: 1163
              date: Mon, 30 Sep 2024 14:06:27 GMT
              server: LiteSpeed
              alt-svc: h3=":443"; ma=2592000, h3-29=":443"; ma=2592000, h3-Q050=":443"; ma=2592000, h3-Q046=":443"; ma=2592000, h3-Q043=":443"; ma=2592000, quic=":443"; ma=2592000; v="43,46"
              2024-09-30 14:06:27 UTC952INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 31 30 30 25 22 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 73 68 72 69 6e 6b 2d 74 6f 2d 66 69 74 3d 6e 6f 22 20 2f 3e 0a 3c 74 69 74 6c 65 3e 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0d 0a 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 34 34 34 3b 20 6d 61 72 67 69 6e 3a 30 3b 66 6f 6e 74 3a 20 6e 6f 72 6d 61 6c 20 31 34 70 78 2f 32 30 70 78 20 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73
              Data Ascii: <!DOCTYPE html><html style="height:100%"><head><meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no" /><title> 404 Not Found</title></head><body style="color: #444; margin:0;font: normal 14px/20px Arial, Helvetica, s
              2024-09-30 14:06:27 UTC211INData Raw: 62 72 3e 50 72 6f 75 64 6c 79 20 70 6f 77 65 72 65 64 20 62 79 20 4c 69 74 65 53 70 65 65 64 20 57 65 62 20 53 65 72 76 65 72 3c 70 3e 50 6c 65 61 73 65 20 62 65 20 61 64 76 69 73 65 64 20 74 68 61 74 20 4c 69 74 65 53 70 65 65 64 20 54 65 63 68 6e 6f 6c 6f 67 69 65 73 20 49 6e 63 2e 20 69 73 20 6e 6f 74 20 61 20 77 65 62 20 68 6f 73 74 69 6e 67 20 63 6f 6d 70 61 6e 79 20 61 6e 64 2c 20 61 73 20 73 75 63 68 2c 20 68 61 73 20 6e 6f 20 63 6f 6e 74 72 6f 6c 20 6f 76 65 72 20 63 6f 6e 74 65 6e 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 69 74 65 2e 3c 2f 70 3e 3c 2f 64 69 76 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a
              Data Ascii: br>Proudly powered by LiteSpeed Web Server<p>Please be advised that LiteSpeed Technologies Inc. is not a web hosting company and, as such, has no control over content found on this site.</p></div></body></html>


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              2192.168.2.449741184.28.90.27443
              TimestampBytes transferredDirectionData
              2024-09-30 14:06:30 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-09-30 14:06:30 UTC494INHTTP/1.1 200 OK
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (lpl/EF06)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-weu-z1
              Cache-Control: public, max-age=25951
              Date: Mon, 30 Sep 2024 14:06:30 GMT
              Connection: close
              X-CID: 2


              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
              3192.168.2.449742184.28.90.27443
              TimestampBytes transferredDirectionData
              2024-09-30 14:06:31 UTC239OUTGET /fs/windows/config.json HTTP/1.1
              Connection: Keep-Alive
              Accept: */*
              Accept-Encoding: identity
              If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
              Range: bytes=0-2147483646
              User-Agent: Microsoft BITS/7.8
              Host: fs.microsoft.com
              2024-09-30 14:06:32 UTC514INHTTP/1.1 200 OK
              ApiVersion: Distribute 1.1
              Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
              Content-Type: application/octet-stream
              ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
              Last-Modified: Tue, 16 May 2017 22:58:00 GMT
              Server: ECAcc (lpl/EF06)
              X-CID: 11
              X-Ms-ApiVersion: Distribute 1.2
              X-Ms-Region: prod-weu-z1
              Cache-Control: public, max-age=25954
              Date: Mon, 30 Sep 2024 14:06:31 GMT
              Content-Length: 55
              Connection: close
              X-CID: 2
              2024-09-30 14:06:32 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
              Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


              Click to jump to process

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:10:06:16
              Start date:30/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:2
              Start time:10:06:21
              Start date:30/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1728 --field-trial-handle=1872,i,15036180888019284213,10274172978205033578,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:false

              Target ID:3
              Start time:10:06:24
              Start date:30/09/2024
              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
              Wow64 process (32bit):false
              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://shreekhabar.com/n/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9TUZwUFluZz0mdWlkPVVTRVIxMDA3MjAyNFVOSVFVRTEyNTYwNzEwMTgyMDI0MjAyNDA3MTA1NjEyMTg=N0123N"
              Imagebase:0x7ff76e190000
              File size:3'242'272 bytes
              MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
              Has elevated privileges:true
              Has administrator privileges:true
              Programmed in:C, C++ or other language
              Reputation:low
              Has exited:true

              No disassembly