Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://pusat-bantuan-seller-tiktokshop.pages.dev/

Overview

General Information

Sample URL:http://pusat-bantuan-seller-tiktokshop.pages.dev/
Analysis ID:1526653
Tags:openphish
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 3716 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2476 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=2000,i,17277067403702545521,1002951410636684197,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6372 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://pusat-bantuan-seller-tiktokshop.pages.dev/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: global trafficTCP traffic: 192.168.2.4:49508 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: pusat-bantuan-seller-tiktokshop.pages.dev
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: unknown0.win@24/0@14/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=2000,i,17277067403702545521,1002951410636684197,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://pusat-bantuan-seller-tiktokshop.pages.dev/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=2000,i,17277067403702545521,1002951410636684197,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    google.com
    142.250.184.206
    truefalse
      unknown
      www.google.com
      142.250.184.196
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          pusat-bantuan-seller-tiktokshop.pages.dev
          unknown
          unknownfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            142.250.184.196
            www.google.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1526653
            Start date and time:2024-10-06 14:00:13 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 1m 57s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://pusat-bantuan-seller-tiktokshop.pages.dev/
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@24/0@14/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 216.58.206.67, 172.217.18.110, 64.233.167.84, 34.104.35.123, 184.28.90.27, 4.175.87.197, 199.232.210.172, 192.229.221.95, 20.3.187.198
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://pusat-bantuan-seller-tiktokshop.pages.dev/
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 6, 2024 14:01:09.121967077 CEST49675443192.168.2.4173.222.162.32
            Oct 6, 2024 14:01:14.272382975 CEST49737443192.168.2.4142.250.184.196
            Oct 6, 2024 14:01:14.272485971 CEST44349737142.250.184.196192.168.2.4
            Oct 6, 2024 14:01:14.272619009 CEST49737443192.168.2.4142.250.184.196
            Oct 6, 2024 14:01:14.275032043 CEST49737443192.168.2.4142.250.184.196
            Oct 6, 2024 14:01:14.275068998 CEST44349737142.250.184.196192.168.2.4
            Oct 6, 2024 14:01:14.923757076 CEST44349737142.250.184.196192.168.2.4
            Oct 6, 2024 14:01:14.934768915 CEST49737443192.168.2.4142.250.184.196
            Oct 6, 2024 14:01:14.934823990 CEST44349737142.250.184.196192.168.2.4
            Oct 6, 2024 14:01:14.937005043 CEST44349737142.250.184.196192.168.2.4
            Oct 6, 2024 14:01:14.937089920 CEST49737443192.168.2.4142.250.184.196
            Oct 6, 2024 14:01:14.949047089 CEST49737443192.168.2.4142.250.184.196
            Oct 6, 2024 14:01:14.949254990 CEST44349737142.250.184.196192.168.2.4
            Oct 6, 2024 14:01:14.990350008 CEST49737443192.168.2.4142.250.184.196
            Oct 6, 2024 14:01:14.990375996 CEST44349737142.250.184.196192.168.2.4
            Oct 6, 2024 14:01:15.037228107 CEST49737443192.168.2.4142.250.184.196
            Oct 6, 2024 14:01:15.890383005 CEST4950853192.168.2.41.1.1.1
            Oct 6, 2024 14:01:15.897854090 CEST53495081.1.1.1192.168.2.4
            Oct 6, 2024 14:01:15.897927046 CEST4950853192.168.2.41.1.1.1
            Oct 6, 2024 14:01:15.898000002 CEST4950853192.168.2.41.1.1.1
            Oct 6, 2024 14:01:15.902821064 CEST53495081.1.1.1192.168.2.4
            Oct 6, 2024 14:01:16.341963053 CEST53495081.1.1.1192.168.2.4
            Oct 6, 2024 14:01:16.342842102 CEST4950853192.168.2.41.1.1.1
            Oct 6, 2024 14:01:16.348031044 CEST53495081.1.1.1192.168.2.4
            Oct 6, 2024 14:01:16.348109961 CEST4950853192.168.2.41.1.1.1
            Oct 6, 2024 14:01:24.822791100 CEST44349737142.250.184.196192.168.2.4
            Oct 6, 2024 14:01:24.822855949 CEST44349737142.250.184.196192.168.2.4
            Oct 6, 2024 14:01:24.822982073 CEST49737443192.168.2.4142.250.184.196
            Oct 6, 2024 14:01:26.128915071 CEST49737443192.168.2.4142.250.184.196
            Oct 6, 2024 14:01:26.128954887 CEST44349737142.250.184.196192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Oct 6, 2024 14:01:09.832381964 CEST53554571.1.1.1192.168.2.4
            Oct 6, 2024 14:01:09.853888988 CEST53644151.1.1.1192.168.2.4
            Oct 6, 2024 14:01:11.131243944 CEST5734853192.168.2.41.1.1.1
            Oct 6, 2024 14:01:11.131623983 CEST6019553192.168.2.41.1.1.1
            Oct 6, 2024 14:01:11.229762077 CEST53601951.1.1.1192.168.2.4
            Oct 6, 2024 14:01:11.230204105 CEST53573481.1.1.1192.168.2.4
            Oct 6, 2024 14:01:11.231197119 CEST5919553192.168.2.41.1.1.1
            Oct 6, 2024 14:01:11.240900993 CEST53591951.1.1.1192.168.2.4
            Oct 6, 2024 14:01:11.518203020 CEST6048553192.168.2.48.8.8.8
            Oct 6, 2024 14:01:11.524971008 CEST6454253192.168.2.41.1.1.1
            Oct 6, 2024 14:01:11.527944088 CEST53604858.8.8.8192.168.2.4
            Oct 6, 2024 14:01:11.531636953 CEST53645421.1.1.1192.168.2.4
            Oct 6, 2024 14:01:11.736530066 CEST53578551.1.1.1192.168.2.4
            Oct 6, 2024 14:01:12.375735998 CEST5590353192.168.2.41.1.1.1
            Oct 6, 2024 14:01:12.375797033 CEST6326753192.168.2.41.1.1.1
            Oct 6, 2024 14:01:12.386332035 CEST53632671.1.1.1192.168.2.4
            Oct 6, 2024 14:01:12.387310982 CEST53559031.1.1.1192.168.2.4
            Oct 6, 2024 14:01:14.259058952 CEST5962453192.168.2.41.1.1.1
            Oct 6, 2024 14:01:14.259913921 CEST5319253192.168.2.41.1.1.1
            Oct 6, 2024 14:01:14.265999079 CEST53596241.1.1.1192.168.2.4
            Oct 6, 2024 14:01:14.266861916 CEST53531921.1.1.1192.168.2.4
            Oct 6, 2024 14:01:15.889527082 CEST53560341.1.1.1192.168.2.4
            Oct 6, 2024 14:01:17.475586891 CEST6017853192.168.2.41.1.1.1
            Oct 6, 2024 14:01:17.475929976 CEST5997953192.168.2.41.1.1.1
            Oct 6, 2024 14:01:17.486787081 CEST53599791.1.1.1192.168.2.4
            Oct 6, 2024 14:01:17.486845016 CEST53601781.1.1.1192.168.2.4
            Oct 6, 2024 14:01:17.592266083 CEST4979053192.168.2.41.1.1.1
            Oct 6, 2024 14:01:17.606204987 CEST53497901.1.1.1192.168.2.4
            Oct 6, 2024 14:01:17.627528906 CEST5555953192.168.2.41.1.1.1
            Oct 6, 2024 14:01:17.628158092 CEST5917053192.168.2.41.1.1.1
            Oct 6, 2024 14:01:17.638472080 CEST53555591.1.1.1192.168.2.4
            Oct 6, 2024 14:01:17.640923023 CEST53591701.1.1.1192.168.2.4
            Oct 6, 2024 14:01:27.050190926 CEST138138192.168.2.4192.168.2.255
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 6, 2024 14:01:11.131243944 CEST192.168.2.41.1.1.10xdc3dStandard query (0)pusat-bantuan-seller-tiktokshop.pages.devA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:11.131623983 CEST192.168.2.41.1.1.10xaf0cStandard query (0)pusat-bantuan-seller-tiktokshop.pages.dev65IN (0x0001)false
            Oct 6, 2024 14:01:11.231197119 CEST192.168.2.41.1.1.10x7c8aStandard query (0)pusat-bantuan-seller-tiktokshop.pages.devA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:11.518203020 CEST192.168.2.48.8.8.80x7075Standard query (0)google.comA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:11.524971008 CEST192.168.2.41.1.1.10xac46Standard query (0)google.comA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:12.375735998 CEST192.168.2.41.1.1.10x9439Standard query (0)pusat-bantuan-seller-tiktokshop.pages.devA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:12.375797033 CEST192.168.2.41.1.1.10xc160Standard query (0)pusat-bantuan-seller-tiktokshop.pages.dev65IN (0x0001)false
            Oct 6, 2024 14:01:14.259058952 CEST192.168.2.41.1.1.10xc6c9Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:14.259913921 CEST192.168.2.41.1.1.10xa4a1Standard query (0)www.google.com65IN (0x0001)false
            Oct 6, 2024 14:01:17.475586891 CEST192.168.2.41.1.1.10xeebStandard query (0)pusat-bantuan-seller-tiktokshop.pages.devA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:17.475929976 CEST192.168.2.41.1.1.10x1983Standard query (0)pusat-bantuan-seller-tiktokshop.pages.dev65IN (0x0001)false
            Oct 6, 2024 14:01:17.592266083 CEST192.168.2.41.1.1.10x3fb1Standard query (0)pusat-bantuan-seller-tiktokshop.pages.devA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:17.627528906 CEST192.168.2.41.1.1.10x6d05Standard query (0)pusat-bantuan-seller-tiktokshop.pages.devA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:17.628158092 CEST192.168.2.41.1.1.10xf4aaStandard query (0)pusat-bantuan-seller-tiktokshop.pages.dev65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 6, 2024 14:01:11.229762077 CEST1.1.1.1192.168.2.40xaf0cName error (3)pusat-bantuan-seller-tiktokshop.pages.devnonenone65IN (0x0001)false
            Oct 6, 2024 14:01:11.230204105 CEST1.1.1.1192.168.2.40xdc3dName error (3)pusat-bantuan-seller-tiktokshop.pages.devnonenoneA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:11.240900993 CEST1.1.1.1192.168.2.40x7c8aName error (3)pusat-bantuan-seller-tiktokshop.pages.devnonenoneA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:11.527944088 CEST8.8.8.8192.168.2.40x7075No error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:11.531636953 CEST1.1.1.1192.168.2.40xac46No error (0)google.com142.250.186.78A (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:12.386332035 CEST1.1.1.1192.168.2.40xc160Name error (3)pusat-bantuan-seller-tiktokshop.pages.devnonenone65IN (0x0001)false
            Oct 6, 2024 14:01:12.387310982 CEST1.1.1.1192.168.2.40x9439Name error (3)pusat-bantuan-seller-tiktokshop.pages.devnonenoneA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:14.265999079 CEST1.1.1.1192.168.2.40xc6c9No error (0)www.google.com142.250.184.196A (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:14.266861916 CEST1.1.1.1192.168.2.40xa4a1No error (0)www.google.com65IN (0x0001)false
            Oct 6, 2024 14:01:17.486787081 CEST1.1.1.1192.168.2.40x1983Name error (3)pusat-bantuan-seller-tiktokshop.pages.devnonenone65IN (0x0001)false
            Oct 6, 2024 14:01:17.486845016 CEST1.1.1.1192.168.2.40xeebName error (3)pusat-bantuan-seller-tiktokshop.pages.devnonenoneA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:17.606204987 CEST1.1.1.1192.168.2.40x3fb1Name error (3)pusat-bantuan-seller-tiktokshop.pages.devnonenoneA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:17.638472080 CEST1.1.1.1192.168.2.40x6d05Name error (3)pusat-bantuan-seller-tiktokshop.pages.devnonenoneA (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:17.640923023 CEST1.1.1.1192.168.2.40xf4aaName error (3)pusat-bantuan-seller-tiktokshop.pages.devnonenone65IN (0x0001)false
            Oct 6, 2024 14:01:22.953836918 CEST1.1.1.1192.168.2.40xd616No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:22.953836918 CEST1.1.1.1192.168.2.40xd616No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Oct 6, 2024 14:01:24.410868883 CEST1.1.1.1192.168.2.40x47beNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 6, 2024 14:01:24.410868883 CEST1.1.1.1192.168.2.40x47beNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false

            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:08:01:04
            Start date:06/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:08:01:08
            Start date:06/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=2000,i,17277067403702545521,1002951410636684197,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:08:01:10
            Start date:06/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://pusat-bantuan-seller-tiktokshop.pages.dev/"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly