Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://40terrastaffinggroup.com/service.svc/s/GetAttachmentThumbnail?id=AAMkAGJkNzFkZWJlLTQwODUtNGNlMi1hYTNjLTdkN2YzNWU0YmVjMABGAAAAAABYpOmuJi7tQ6q5WuWub8ZLBwAtSgssfhXVSpJpksK16V0%2FAAAAAaZAAAD9bQqaleUESLifjGau%2Fsr4AALg9NVMAAABEgAQAJuQeKWKJU1KjyY7L4gSFMo%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiI

Overview

General Information

Sample URL:http://40terrastaffinggroup.com/service.svc/s/GetAttachmentThumbnail?id=AAMkAGJkNzFkZWJlLTQwODUtNGNlMi1hYTNjLTdkN2YzNWU0YmVjMABGAAAAAABYpOmuJi7tQ6q5WuWub8ZLBwAtSgssfhXVSpJpksK16V0%2FAAAAAaZAAAD9bQqale
Analysis ID:1525193
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 4176 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2896 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2508,i,10359561964786021580,17757563042689177643,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6384 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://40terrastaffinggroup.com/service.svc/s/GetAttachmentThumbnail?id=AAMkAGJkNzFkZWJlLTQwODUtNGNlMi1hYTNjLTdkN2YzNWU0YmVjMABGAAAAAABYpOmuJi7tQ6q5WuWub8ZLBwAtSgssfhXVSpJpksK16V0%2FAAAAAaZAAAD9bQqaleUESLifjGau%2Fsr4AALg9NVMAAABEgAQAJuQeKWKJU1KjyY7L4gSFMo%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IkU1RDJGMEY4REE5M0I2NzA5QzQzQTlFOEE2MTQzQzAzRDYyRjlBODAiLCJ0eXAiOiJKV1QiLCJ4NXQiOiI1ZEx3LU5xVHRuQ2NRNm5vcGhROEE5WXZtb0EifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiNjc1YTc1M2Q1MzRjNDEzZWEwNWE0NzNiMjBmMTNiZGIiLCJzaWduaW5fc3RhdGUiOiJrbXNpIiwidmVyIjoiRXhjaGFuZ2UuQ2FsbGJhY2suVjEiLCJhcHBjdHhzZW5kZXIiOiJPd2FEb3dubG9hZEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJpc3NyaW5nIjoiV1ciLCJhcHBjdHgiOiJ7XCJtc2V4Y2hwcm90XCI6XCJvd2FcIixcInB1aWRcIjpcIjExNTM4MDExMTk3Njc5MzA0NzJcIixcInNjb3BlXCI6XCJPd2FEb3dubG9hZFwiLFwib2lkXCI6XCIxOTBlMzE0NS0yZWQyLTRmMjItOTQ1OS01ZDhlMWZjOGI1MWVcIixcInByaW1hcnlzaWRcIjpcIlMtMS01LTIxLTM3NzMyMDA0NjctMTY0ODM0NzEzOC0zMzMzMzM0NDYyLTM1MTMxNDU2XCJ9IiwibmJmIjoxNzI3NzM4OTI3LCJleHAiOjE3Mjc3MzkyMjcsImlzcyI6IjAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJhdWQiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvYXR0YWNobWVudHMub2ZmaWNlLm5ldEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJoYXBwIjoib3dhIn0.DDCiPDY1j1uNmVpBJdSsAokX770OONzh8rv5z3s3gS-I-LsZMYCozhUrKhO2nQu85lawIrkoCL0RO8eT_rPCoQ3V2_5tTd-ECtyx_m8GRUsYCdWK0T-Az3fT7NIZIgikR3QFZXLLU0TVXK_M7DYsIECpjB4cA2rzUxYWUq20Y-DuKKf2BUUhaEjjqr8eB76_2oGXY1Xmli7920rKxpnH3vI8dTEDOqiSzre4gptAP6UcYoEXVHYMSRG7sdJXbXzw95rp1YaDecWGC5eRukjrW0UJC_PIguBm8pVd8uCcTUweRTH6CJ1725v0e5iFYzPPnTtLozIN7b7d1ZFnZQJ6ww&X-OWA-CANARY=bdvoV2GyMV8AAAAAAAAAAPDZi7in4dwYPpU5wYHasUhFap6Og7aDZ8VkPg5v52xCxWVdx1uX1GI.&owa=outlook.office.com&scriptVer=20240920004.10&clientId=03F5E497FBFD4312A9E577D9C247289D&animation=true" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: chrome.exeMemory has grown: Private usage: 1MB later: 36MB
Source: global trafficTCP traffic: 192.168.2.4:49730 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.4:60210 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: 40terrastaffinggroup.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: unknown0.win@19/0@14/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2508,i,10359561964786021580,17757563042689177643,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://40terrastaffinggroup.com/service.svc/s/GetAttachmentThumbnail?id=AAMkAGJkNzFkZWJlLTQwODUtNGNlMi1hYTNjLTdkN2YzNWU0YmVjMABGAAAAAABYpOmuJi7tQ6q5WuWub8ZLBwAtSgssfhXVSpJpksK16V0%2FAAAAAaZAAAD9bQqaleUESLifjGau%2Fsr4AALg9NVMAAABEgAQAJuQeKWKJU1KjyY7L4gSFMo%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IkU1RDJGMEY4REE5M0I2NzA5QzQzQTlFOEE2MTQzQzAzRDYyRjlBODAiLCJ0eXAiOiJKV1QiLCJ4NXQiOiI1ZEx3LU5xVHRuQ2NRNm5vcGhROEE5WXZtb0EifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiNjc1YTc1M2Q1MzRjNDEzZWEwNWE0NzNiMjBmMTNiZGIiLCJzaWduaW5fc3RhdGUiOiJrbXNpIiwidmVyIjoiRXhjaGFuZ2UuQ2FsbGJhY2suVjEiLCJhcHBjdHhzZW5kZXIiOiJPd2FEb3dubG9hZEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJpc3NyaW5nIjoiV1ciLCJhcHBjdHgiOiJ7XCJtc2V4Y2hwcm90XCI6XCJvd2FcIixcInB1aWRcIjpcIjExNTM4MDExMTk3Njc5MzA0NzJcIixcInNjb3BlXCI6XCJPd2FEb3dubG9hZFwiLFwib2lkXCI6XCIxOTBlMzE0NS0yZWQyLTRmMjItOTQ1OS01ZDhlMWZjOGI1MWVcIixcInByaW1hcnlzaWRcIjpcIlMtMS01LTIxLTM3NzMyMDA0NjctMTY0ODM0NzEzOC0zMzMzMzM0NDYyLTM1MTMxNDU2XCJ9IiwibmJmIjoxNzI3NzM4OTI3LCJleHAiOjE3Mjc3MzkyMjcsImlzcyI6IjAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJhdWQiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvYXR0YWNobWVudHMub2ZmaWNlLm5ldEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJoYXBwIjoib3dhIn0.DDCiPDY1j1uNmVpBJdSsAokX770OONzh8rv5z3s3gS-I-LsZMYCozhUrKhO2nQu85lawIrkoCL0RO8eT_rPCoQ3V2_5tTd-ECtyx_m8GRUsYCdWK0T-Az3fT7NIZIgikR3QFZXLLU0TVXK_M7DYsIECpjB4cA2rzUxYWUq20Y-DuKKf2BUUhaEjjqr8eB76_2oGXY1Xmli7920rKxpnH3vI8dTEDOqiSzre4gptAP6UcYoEXVHYMSRG7sdJXbXzw95rp1YaDecWGC5eRukjrW0UJC_PIguBm8pVd8uCcTUweRTH6CJ1725v0e5iFYzPPnTtLozIN7b7d1ZFnZQJ6ww&X-OWA-CANARY=bdvoV2GyMV8AAAAAAAAAAPDZi7in4dwYPpU5wYHasUhFap6Og7aDZ8VkPg5v52xCxWVdx1uX1GI.&owa=outlook.office.com&scriptVer=20240920004.10&clientId=03F5E497FBFD4312A9E577D9C247289D&animation=true"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2508,i,10359561964786021580,17757563042689177643,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Extra Window Memory Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
216.58.206.78
truefalse
    unknown
    www.google.com
    142.250.186.36
    truefalse
      unknown
      default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
      217.20.57.41
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          40terrastaffinggroup.com
          unknown
          unknownfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.186.36
            www.google.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1525193
            Start date and time:2024-10-03 20:49:20 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 1s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://40terrastaffinggroup.com/service.svc/s/GetAttachmentThumbnail?id=AAMkAGJkNzFkZWJlLTQwODUtNGNlMi1hYTNjLTdkN2YzNWU0YmVjMABGAAAAAABYpOmuJi7tQ6q5WuWub8ZLBwAtSgssfhXVSpJpksK16V0%2FAAAAAaZAAAD9bQqaleUESLifjGau%2Fsr4AALg9NVMAAABEgAQAJuQeKWKJU1KjyY7L4gSFMo%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IkU1RDJGMEY4REE5M0I2NzA5QzQzQTlFOEE2MTQzQzAzRDYyRjlBODAiLCJ0eXAiOiJKV1QiLCJ4NXQiOiI1ZEx3LU5xVHRuQ2NRNm5vcGhROEE5WXZtb0EifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiNjc1YTc1M2Q1MzRjNDEzZWEwNWE0NzNiMjBmMTNiZGIiLCJzaWduaW5fc3RhdGUiOiJrbXNpIiwidmVyIjoiRXhjaGFuZ2UuQ2FsbGJhY2suVjEiLCJhcHBjdHhzZW5kZXIiOiJPd2FEb3dubG9hZEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJpc3NyaW5nIjoiV1ciLCJhcHBjdHgiOiJ7XCJtc2V4Y2hwcm90XCI6XCJvd2FcIixcInB1aWRcIjpcIjExNTM4MDExMTk3Njc5MzA0NzJcIixcInNjb3BlXCI6XCJPd2FEb3dubG9hZFwiLFwib2lkXCI6XCIxOTBlMzE0NS0yZWQyLTRmMjItOTQ1OS01ZDhlMWZjOGI1MWVcIixcInByaW1hcnlzaWRcIjpcIlMtMS01LTIxLTM3NzMyMDA0NjctMTY0ODM0NzEzOC0zMzMzMzM0NDYyLTM1MTMxNDU2XCJ9IiwibmJmIjoxNzI3NzM4OTI3LCJleHAiOjE3Mjc3MzkyMjcsImlzcyI6IjAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJhdWQiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvYXR0YWNobWVudHMub2ZmaWNlLm5ldEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJoYXBwIjoib3dhIn0.DDCiPDY1j1uNmVpBJdSsAokX770OONzh8rv5z3s3gS-I-LsZMYCozhUrKhO2nQu85lawIrkoCL0RO8eT_rPCoQ3V2_5tTd-ECtyx_m8GRUsYCdWK0T-Az3fT7NIZIgikR3QFZXLLU0TVXK_M7DYsIECpjB4cA2rzUxYWUq20Y-DuKKf2BUUhaEjjqr8eB76_2oGXY1Xmli7920rKxpnH3vI8dTEDOqiSzre4gptAP6UcYoEXVHYMSRG7sdJXbXzw95rp1YaDecWGC5eRukjrW0UJC_PIguBm8pVd8uCcTUweRTH6CJ1725v0e5iFYzPPnTtLozIN7b7d1ZFnZQJ6ww&X-OWA-CANARY=bdvoV2GyMV8AAAAAAAAAAPDZi7in4dwYPpU5wYHasUhFap6Og7aDZ8VkPg5v52xCxWVdx1uX1GI.&owa=outlook.office.com&scriΡtVer=20240920004.10&clientId=03F5E497FBFD4312A9E577D9C247289D&animation=true
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@19/0@14/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 172.217.16.206, 108.177.15.84, 142.250.176.195, 34.104.35.123, 23.211.8.90, 172.202.163.200, 217.20.57.41, 13.85.23.206, 192.229.221.95
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://40terrastaffinggroup.com/service.svc/s/GetAttachmentThumbnail?id=AAMkAGJkNzFkZWJlLTQwODUtNGNlMi1hYTNjLTdkN2YzNWU0YmVjMABGAAAAAABYpOmuJi7tQ6q5WuWub8ZLBwAtSgssfhXVSpJpksK16V0%2FAAAAAaZAAAD9bQqaleUESLifjGau%2Fsr4AALg9NVMAAABEgAQAJuQeKWKJU1KjyY7L4gSFMo%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IkU1RDJGMEY4REE5M0I2NzA5QzQzQTlFOEE2MTQzQzAzRDYyRjlBODAiLCJ0eXAiOiJKV1QiLCJ4NXQiOiI1ZEx3LU5xVHRuQ2NRNm5vcGhROEE5WXZtb0EifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiNjc1YTc1M2Q1MzRjNDEzZWEwNWE0NzNiMjBmMTNiZGIiLCJzaWduaW5fc3RhdGUiOiJrbXNpIiwidmVyIjoiRXhjaGFuZ2UuQ2FsbGJhY2suVjEiLCJhcHBjdHhzZW5kZXIiOiJPd2FEb3dubG9hZEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJpc3NyaW5nIjoiV1ciLCJhcHBjdHgiOiJ7XCJtc2V4Y2hwcm90XCI6XCJvd2FcIixcInB1aWRcIjpcIjExNTM4MDExMTk3Njc5MzA0NzJcIixcInNjb3BlXCI6XCJPd2FEb3dubG9hZFwiLFwib2lkXCI6XCIxOTBlMzE0NS0yZWQyLTRmMjItOTQ1OS01ZDhlMWZjOGI1MWVcIixcInByaW1hcnlzaWRcIjpcIlMtMS01LTIxLTM3NzMyMDA0NjctMTY0ODM0NzEzOC0zMzMzMzM0NDYyLTM1MTMxNDU2XCJ9Iiwi
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 3, 2024 20:50:15.800489902 CEST49675443192.168.2.4173.222.162.32
            Oct 3, 2024 20:50:16.577188015 CEST4973053192.168.2.41.1.1.1
            Oct 3, 2024 20:50:16.583671093 CEST53497301.1.1.1192.168.2.4
            Oct 3, 2024 20:50:16.583734035 CEST4973053192.168.2.41.1.1.1
            Oct 3, 2024 20:50:16.584453106 CEST4973053192.168.2.41.1.1.1
            Oct 3, 2024 20:50:16.584682941 CEST4973053192.168.2.41.1.1.1
            Oct 3, 2024 20:50:16.593420982 CEST53497301.1.1.1192.168.2.4
            Oct 3, 2024 20:50:16.593430042 CEST53497301.1.1.1192.168.2.4
            Oct 3, 2024 20:50:17.092555046 CEST53497301.1.1.1192.168.2.4
            Oct 3, 2024 20:50:17.093131065 CEST4973053192.168.2.41.1.1.1
            Oct 3, 2024 20:50:17.098462105 CEST53497301.1.1.1192.168.2.4
            Oct 3, 2024 20:50:17.098537922 CEST4973053192.168.2.41.1.1.1
            Oct 3, 2024 20:50:20.657345057 CEST49739443192.168.2.4142.250.186.36
            Oct 3, 2024 20:50:20.657382011 CEST44349739142.250.186.36192.168.2.4
            Oct 3, 2024 20:50:20.657479048 CEST49739443192.168.2.4142.250.186.36
            Oct 3, 2024 20:50:20.659421921 CEST49739443192.168.2.4142.250.186.36
            Oct 3, 2024 20:50:20.659436941 CEST44349739142.250.186.36192.168.2.4
            Oct 3, 2024 20:50:21.307008028 CEST44349739142.250.186.36192.168.2.4
            Oct 3, 2024 20:50:21.361905098 CEST49739443192.168.2.4142.250.186.36
            Oct 3, 2024 20:50:21.389273882 CEST49739443192.168.2.4142.250.186.36
            Oct 3, 2024 20:50:21.389296055 CEST44349739142.250.186.36192.168.2.4
            Oct 3, 2024 20:50:21.393171072 CEST44349739142.250.186.36192.168.2.4
            Oct 3, 2024 20:50:21.393188953 CEST44349739142.250.186.36192.168.2.4
            Oct 3, 2024 20:50:21.393273115 CEST49739443192.168.2.4142.250.186.36
            Oct 3, 2024 20:50:21.445065975 CEST49739443192.168.2.4142.250.186.36
            Oct 3, 2024 20:50:21.445298910 CEST44349739142.250.186.36192.168.2.4
            Oct 3, 2024 20:50:21.486859083 CEST49739443192.168.2.4142.250.186.36
            Oct 3, 2024 20:50:21.486885071 CEST44349739142.250.186.36192.168.2.4
            Oct 3, 2024 20:50:21.533730030 CEST49739443192.168.2.4142.250.186.36
            Oct 3, 2024 20:50:31.221283913 CEST44349739142.250.186.36192.168.2.4
            Oct 3, 2024 20:50:31.221442938 CEST44349739142.250.186.36192.168.2.4
            Oct 3, 2024 20:50:31.221492052 CEST49739443192.168.2.4142.250.186.36
            Oct 3, 2024 20:50:32.770651102 CEST49739443192.168.2.4142.250.186.36
            Oct 3, 2024 20:50:32.770682096 CEST44349739142.250.186.36192.168.2.4
            Oct 3, 2024 20:50:32.815644979 CEST4972380192.168.2.493.184.221.240
            Oct 3, 2024 20:50:32.822113037 CEST804972393.184.221.240192.168.2.4
            Oct 3, 2024 20:50:32.822154045 CEST4972380192.168.2.493.184.221.240
            Oct 3, 2024 20:50:38.666867971 CEST6021053192.168.2.41.1.1.1
            Oct 3, 2024 20:50:38.671700954 CEST53602101.1.1.1192.168.2.4
            Oct 3, 2024 20:50:38.671777010 CEST6021053192.168.2.41.1.1.1
            Oct 3, 2024 20:50:38.671801090 CEST6021053192.168.2.41.1.1.1
            Oct 3, 2024 20:50:38.676635981 CEST53602101.1.1.1192.168.2.4
            Oct 3, 2024 20:50:39.155633926 CEST53602101.1.1.1192.168.2.4
            Oct 3, 2024 20:50:39.155893087 CEST6021053192.168.2.41.1.1.1
            Oct 3, 2024 20:50:39.161154032 CEST53602101.1.1.1192.168.2.4
            Oct 3, 2024 20:50:39.161211967 CEST6021053192.168.2.41.1.1.1
            TimestampSource PortDest PortSource IPDest IP
            Oct 3, 2024 20:50:16.574359894 CEST53644961.1.1.1192.168.2.4
            Oct 3, 2024 20:50:16.575038910 CEST53502391.1.1.1192.168.2.4
            Oct 3, 2024 20:50:16.590612888 CEST53571231.1.1.1192.168.2.4
            Oct 3, 2024 20:50:17.599515915 CEST53575681.1.1.1192.168.2.4
            Oct 3, 2024 20:50:18.209435940 CEST5610153192.168.2.41.1.1.1
            Oct 3, 2024 20:50:18.209634066 CEST6127953192.168.2.41.1.1.1
            Oct 3, 2024 20:50:18.223742008 CEST53561011.1.1.1192.168.2.4
            Oct 3, 2024 20:50:18.242767096 CEST53612791.1.1.1192.168.2.4
            Oct 3, 2024 20:50:18.243423939 CEST6160753192.168.2.41.1.1.1
            Oct 3, 2024 20:50:18.256548882 CEST53616071.1.1.1192.168.2.4
            Oct 3, 2024 20:50:18.310652018 CEST6040653192.168.2.48.8.8.8
            Oct 3, 2024 20:50:18.310883999 CEST5311853192.168.2.41.1.1.1
            Oct 3, 2024 20:50:18.318845034 CEST53531181.1.1.1192.168.2.4
            Oct 3, 2024 20:50:18.320902109 CEST53604068.8.8.8192.168.2.4
            Oct 3, 2024 20:50:19.309653044 CEST5275753192.168.2.41.1.1.1
            Oct 3, 2024 20:50:19.310687065 CEST5323853192.168.2.41.1.1.1
            Oct 3, 2024 20:50:19.319963932 CEST53527571.1.1.1192.168.2.4
            Oct 3, 2024 20:50:19.323616028 CEST53532381.1.1.1192.168.2.4
            Oct 3, 2024 20:50:19.391851902 CEST6280453192.168.2.41.1.1.1
            Oct 3, 2024 20:50:19.392712116 CEST6351053192.168.2.41.1.1.1
            Oct 3, 2024 20:50:19.402749062 CEST53628041.1.1.1192.168.2.4
            Oct 3, 2024 20:50:19.425445080 CEST53635101.1.1.1192.168.2.4
            Oct 3, 2024 20:50:20.645454884 CEST6138153192.168.2.41.1.1.1
            Oct 3, 2024 20:50:20.645596981 CEST5339153192.168.2.41.1.1.1
            Oct 3, 2024 20:50:20.655869961 CEST53613811.1.1.1192.168.2.4
            Oct 3, 2024 20:50:20.655909061 CEST53533911.1.1.1192.168.2.4
            Oct 3, 2024 20:50:24.453748941 CEST6111853192.168.2.41.1.1.1
            Oct 3, 2024 20:50:24.454786062 CEST5755853192.168.2.41.1.1.1
            Oct 3, 2024 20:50:24.521050930 CEST53575581.1.1.1192.168.2.4
            Oct 3, 2024 20:50:24.542454958 CEST53611181.1.1.1192.168.2.4
            Oct 3, 2024 20:50:24.616250992 CEST4994953192.168.2.41.1.1.1
            Oct 3, 2024 20:50:24.623718023 CEST53499491.1.1.1192.168.2.4
            Oct 3, 2024 20:50:33.387693882 CEST138138192.168.2.4192.168.2.255
            Oct 3, 2024 20:50:34.622638941 CEST53559991.1.1.1192.168.2.4
            Oct 3, 2024 20:50:38.666445017 CEST53604521.1.1.1192.168.2.4
            TimestampSource IPDest IPChecksumCodeType
            Oct 3, 2024 20:50:19.425522089 CEST192.168.2.41.1.1.1c237(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 3, 2024 20:50:18.209435940 CEST192.168.2.41.1.1.10xedeStandard query (0)40terrastaffinggroup.comA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:18.209634066 CEST192.168.2.41.1.1.10x6ee4Standard query (0)40terrastaffinggroup.com65IN (0x0001)false
            Oct 3, 2024 20:50:18.243423939 CEST192.168.2.41.1.1.10x48fbStandard query (0)40terrastaffinggroup.comA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:18.310652018 CEST192.168.2.48.8.8.80x5b0fStandard query (0)google.comA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:18.310883999 CEST192.168.2.41.1.1.10xb1aStandard query (0)google.comA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:19.309653044 CEST192.168.2.41.1.1.10xad0fStandard query (0)40terrastaffinggroup.comA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:19.310687065 CEST192.168.2.41.1.1.10x4a4Standard query (0)40terrastaffinggroup.com65IN (0x0001)false
            Oct 3, 2024 20:50:19.391851902 CEST192.168.2.41.1.1.10x1d3eStandard query (0)40terrastaffinggroup.comA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:19.392712116 CEST192.168.2.41.1.1.10x8057Standard query (0)40terrastaffinggroup.com65IN (0x0001)false
            Oct 3, 2024 20:50:20.645454884 CEST192.168.2.41.1.1.10x9717Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:20.645596981 CEST192.168.2.41.1.1.10x5cb4Standard query (0)www.google.com65IN (0x0001)false
            Oct 3, 2024 20:50:24.453748941 CEST192.168.2.41.1.1.10xa898Standard query (0)40terrastaffinggroup.comA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:24.454786062 CEST192.168.2.41.1.1.10xb9eaStandard query (0)40terrastaffinggroup.com65IN (0x0001)false
            Oct 3, 2024 20:50:24.616250992 CEST192.168.2.41.1.1.10x1813Standard query (0)40terrastaffinggroup.comA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 3, 2024 20:50:18.223742008 CEST1.1.1.1192.168.2.40xedeName error (3)40terrastaffinggroup.comnonenoneA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:18.242767096 CEST1.1.1.1192.168.2.40x6ee4Name error (3)40terrastaffinggroup.comnonenone65IN (0x0001)false
            Oct 3, 2024 20:50:18.256548882 CEST1.1.1.1192.168.2.40x48fbName error (3)40terrastaffinggroup.comnonenoneA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:18.318845034 CEST1.1.1.1192.168.2.40xb1aNo error (0)google.com216.58.206.78A (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:18.320902109 CEST8.8.8.8192.168.2.40x5b0fNo error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:19.319963932 CEST1.1.1.1192.168.2.40xad0fName error (3)40terrastaffinggroup.comnonenoneA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:19.323616028 CEST1.1.1.1192.168.2.40x4a4Name error (3)40terrastaffinggroup.comnonenone65IN (0x0001)false
            Oct 3, 2024 20:50:19.402749062 CEST1.1.1.1192.168.2.40x1d3eName error (3)40terrastaffinggroup.comnonenoneA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:19.425445080 CEST1.1.1.1192.168.2.40x8057Name error (3)40terrastaffinggroup.comnonenone65IN (0x0001)false
            Oct 3, 2024 20:50:20.655869961 CEST1.1.1.1192.168.2.40x9717No error (0)www.google.com142.250.186.36A (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:20.655909061 CEST1.1.1.1192.168.2.40x5cb4No error (0)www.google.com65IN (0x0001)false
            Oct 3, 2024 20:50:24.521050930 CEST1.1.1.1192.168.2.40xb9eaName error (3)40terrastaffinggroup.comnonenone65IN (0x0001)false
            Oct 3, 2024 20:50:24.542454958 CEST1.1.1.1192.168.2.40xa898Name error (3)40terrastaffinggroup.comnonenoneA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:24.623718023 CEST1.1.1.1192.168.2.40x1813Name error (3)40terrastaffinggroup.comnonenoneA (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:29.859889030 CEST1.1.1.1192.168.2.40xf85bNo error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comdefault.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comCNAME (Canonical name)IN (0x0001)false
            Oct 3, 2024 20:50:29.859889030 CEST1.1.1.1192.168.2.40xf85bNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.41A (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:29.859889030 CEST1.1.1.1192.168.2.40xf85bNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.39A (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:29.859889030 CEST1.1.1.1192.168.2.40xf85bNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com84.201.210.34A (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:29.859889030 CEST1.1.1.1192.168.2.40xf85bNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.19A (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:29.859889030 CEST1.1.1.1192.168.2.40xf85bNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.36A (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:29.859889030 CEST1.1.1.1192.168.2.40xf85bNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.42A (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:29.859889030 CEST1.1.1.1192.168.2.40xf85bNo error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.37A (IP address)IN (0x0001)false
            Oct 3, 2024 20:50:31.780878067 CEST1.1.1.1192.168.2.40xa129No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 3, 2024 20:50:31.780878067 CEST1.1.1.1192.168.2.40xa129No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false

            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:14:50:10
            Start date:03/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:14:50:14
            Start date:03/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=2508,i,10359561964786021580,17757563042689177643,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:14:50:16
            Start date:03/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://40terrastaffinggroup.com/service.svc/s/GetAttachmentThumbnail?id=AAMkAGJkNzFkZWJlLTQwODUtNGNlMi1hYTNjLTdkN2YzNWU0YmVjMABGAAAAAABYpOmuJi7tQ6q5WuWub8ZLBwAtSgssfhXVSpJpksK16V0%2FAAAAAaZAAAD9bQqaleUESLifjGau%2Fsr4AALg9NVMAAABEgAQAJuQeKWKJU1KjyY7L4gSFMo%3D&thumbnailType=2&token=eyJhbGciOiJSUzI1NiIsImtpZCI6IkU1RDJGMEY4REE5M0I2NzA5QzQzQTlFOEE2MTQzQzAzRDYyRjlBODAiLCJ0eXAiOiJKV1QiLCJ4NXQiOiI1ZEx3LU5xVHRuQ2NRNm5vcGhROEE5WXZtb0EifQ.eyJvcmlnaW4iOiJodHRwczovL291dGxvb2sub2ZmaWNlLmNvbSIsInVjIjoiNjc1YTc1M2Q1MzRjNDEzZWEwNWE0NzNiMjBmMTNiZGIiLCJzaWduaW5fc3RhdGUiOiJrbXNpIiwidmVyIjoiRXhjaGFuZ2UuQ2FsbGJhY2suVjEiLCJhcHBjdHhzZW5kZXIiOiJPd2FEb3dubG9hZEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJpc3NyaW5nIjoiV1ciLCJhcHBjdHgiOiJ7XCJtc2V4Y2hwcm90XCI6XCJvd2FcIixcInB1aWRcIjpcIjExNTM4MDExMTk3Njc5MzA0NzJcIixcInNjb3BlXCI6XCJPd2FEb3dubG9hZFwiLFwib2lkXCI6XCIxOTBlMzE0NS0yZWQyLTRmMjItOTQ1OS01ZDhlMWZjOGI1MWVcIixcInByaW1hcnlzaWRcIjpcIlMtMS01LTIxLTM3NzMyMDA0NjctMTY0ODM0NzEzOC0zMzMzMzM0NDYyLTM1MTMxNDU2XCJ9IiwibmJmIjoxNzI3NzM4OTI3LCJleHAiOjE3Mjc3MzkyMjcsImlzcyI6IjAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJhdWQiOiIwMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvYXR0YWNobWVudHMub2ZmaWNlLm5ldEA2OWEwNzAzYy05YTMxLTQxODMtYjkxYi04ZTRjYjA4NGZiZjAiLCJoYXBwIjoib3dhIn0.DDCiPDY1j1uNmVpBJdSsAokX770OONzh8rv5z3s3gS-I-LsZMYCozhUrKhO2nQu85lawIrkoCL0RO8eT_rPCoQ3V2_5tTd-ECtyx_m8GRUsYCdWK0T-Az3fT7NIZIgikR3QFZXLLU0TVXK_M7DYsIECpjB4cA2rzUxYWUq20Y-DuKKf2BUUhaEjjqr8eB76_2oGXY1Xmli7920rKxpnH3vI8dTEDOqiSzre4gptAP6UcYoEXVHYMSRG7sdJXbXzw95rp1YaDecWGC5eRukjrW0UJC_PIguBm8pVd8uCcTUweRTH6CJ1725v0e5iFYzPPnTtLozIN7b7d1ZFnZQJ6ww&X-OWA-CANARY=bdvoV2GyMV8AAAAAAAAAAPDZi7in4dwYPpU5wYHasUhFap6Og7aDZ8VkPg5v52xCxWVdx1uX1GI.&owa=outlook.office.com&scriptVer=20240920004.10&clientId=03F5E497FBFD4312A9E577D9C247289D&animation=true"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly