Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://whatsapp-wug.com/

Overview

General Information

Sample URL:https://whatsapp-wug.com/
Analysis ID:1526829
Tags:openphish
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 2188 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1928 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2268 --field-trial-handle=2220,i,14724931619133752789,3456494080413759407,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6368 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://whatsapp-wug.com/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: whatsapp-wug.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: unknown0.win@19/0@12/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2268 --field-trial-handle=2220,i,14724931619133752789,3456494080413759407,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://whatsapp-wug.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2268 --field-trial-handle=2220,i,14724931619133752789,3456494080413759407,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
216.58.206.78
truefalse
    unknown
    www.google.com
    142.250.184.228
    truefalse
      unknown
      default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
      84.201.210.22
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.221.95
        truefalse
          unknown
          whatsapp-wug.com
          unknown
          unknownfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.184.228
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:41.0.0 Charoite
            Analysis ID:1526829
            Start date and time:2024-10-06 16:37:50 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 1m 59s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://whatsapp-wug.com/
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:7
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@19/0@12/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.184.195, 142.250.186.78, 142.251.168.84, 34.104.35.123, 184.28.90.27, 20.12.23.50, 84.201.210.22, 192.229.221.95, 20.3.187.198
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: https://whatsapp-wug.com/
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Oct 6, 2024 16:38:45.577431917 CEST49675443192.168.2.4173.222.162.32
            Oct 6, 2024 16:38:51.036533117 CEST49737443192.168.2.4142.250.184.228
            Oct 6, 2024 16:38:51.036566973 CEST44349737142.250.184.228192.168.2.4
            Oct 6, 2024 16:38:51.036624908 CEST49737443192.168.2.4142.250.184.228
            Oct 6, 2024 16:38:51.042191982 CEST49737443192.168.2.4142.250.184.228
            Oct 6, 2024 16:38:51.042206049 CEST44349737142.250.184.228192.168.2.4
            Oct 6, 2024 16:38:51.707515001 CEST44349737142.250.184.228192.168.2.4
            Oct 6, 2024 16:38:51.707860947 CEST49737443192.168.2.4142.250.184.228
            Oct 6, 2024 16:38:51.707878113 CEST44349737142.250.184.228192.168.2.4
            Oct 6, 2024 16:38:51.709613085 CEST44349737142.250.184.228192.168.2.4
            Oct 6, 2024 16:38:51.709755898 CEST49737443192.168.2.4142.250.184.228
            Oct 6, 2024 16:38:51.711452961 CEST49737443192.168.2.4142.250.184.228
            Oct 6, 2024 16:38:51.711539984 CEST44349737142.250.184.228192.168.2.4
            Oct 6, 2024 16:38:51.765141010 CEST49737443192.168.2.4142.250.184.228
            Oct 6, 2024 16:38:51.765167952 CEST44349737142.250.184.228192.168.2.4
            Oct 6, 2024 16:38:51.812040091 CEST49737443192.168.2.4142.250.184.228
            Oct 6, 2024 16:39:01.627613068 CEST44349737142.250.184.228192.168.2.4
            Oct 6, 2024 16:39:01.627701044 CEST44349737142.250.184.228192.168.2.4
            Oct 6, 2024 16:39:01.627753019 CEST49737443192.168.2.4142.250.184.228
            Oct 6, 2024 16:39:02.969676018 CEST49737443192.168.2.4142.250.184.228
            Oct 6, 2024 16:39:02.969713926 CEST44349737142.250.184.228192.168.2.4
            Oct 6, 2024 16:39:03.211790085 CEST4972380192.168.2.4199.232.214.172
            Oct 6, 2024 16:39:03.217114925 CEST8049723199.232.214.172192.168.2.4
            Oct 6, 2024 16:39:03.217173100 CEST4972380192.168.2.4199.232.214.172
            TimestampSource PortDest PortSource IPDest IP
            Oct 6, 2024 16:38:46.727243900 CEST53630821.1.1.1192.168.2.4
            Oct 6, 2024 16:38:46.794027090 CEST53508631.1.1.1192.168.2.4
            Oct 6, 2024 16:38:47.822036028 CEST53548571.1.1.1192.168.2.4
            Oct 6, 2024 16:38:48.641530991 CEST5677753192.168.2.41.1.1.1
            Oct 6, 2024 16:38:48.642298937 CEST5372353192.168.2.41.1.1.1
            Oct 6, 2024 16:38:48.653378010 CEST53567771.1.1.1192.168.2.4
            Oct 6, 2024 16:38:48.654210091 CEST53537231.1.1.1192.168.2.4
            Oct 6, 2024 16:38:48.656569958 CEST6201153192.168.2.41.1.1.1
            Oct 6, 2024 16:38:48.669138908 CEST53620111.1.1.1192.168.2.4
            Oct 6, 2024 16:38:48.808259010 CEST6195153192.168.2.48.8.8.8
            Oct 6, 2024 16:38:48.808626890 CEST5996353192.168.2.41.1.1.1
            Oct 6, 2024 16:38:48.815900087 CEST53599631.1.1.1192.168.2.4
            Oct 6, 2024 16:38:48.817439079 CEST53619518.8.8.8192.168.2.4
            Oct 6, 2024 16:38:49.863316059 CEST5883053192.168.2.41.1.1.1
            Oct 6, 2024 16:38:49.863903999 CEST5113653192.168.2.41.1.1.1
            Oct 6, 2024 16:38:49.873533964 CEST53511361.1.1.1192.168.2.4
            Oct 6, 2024 16:38:49.873553038 CEST53588301.1.1.1192.168.2.4
            Oct 6, 2024 16:38:50.606621981 CEST5046053192.168.2.41.1.1.1
            Oct 6, 2024 16:38:50.606800079 CEST5895553192.168.2.41.1.1.1
            Oct 6, 2024 16:38:50.613698006 CEST53504601.1.1.1192.168.2.4
            Oct 6, 2024 16:38:50.613715887 CEST53589551.1.1.1192.168.2.4
            Oct 6, 2024 16:38:54.926537037 CEST5577253192.168.2.41.1.1.1
            Oct 6, 2024 16:38:54.926790953 CEST5299853192.168.2.41.1.1.1
            Oct 6, 2024 16:38:54.936243057 CEST53557721.1.1.1192.168.2.4
            Oct 6, 2024 16:38:54.956955910 CEST5356953192.168.2.41.1.1.1
            Oct 6, 2024 16:38:54.958216906 CEST53529981.1.1.1192.168.2.4
            Oct 6, 2024 16:38:54.966142893 CEST53535691.1.1.1192.168.2.4
            Oct 6, 2024 16:39:03.459480047 CEST138138192.168.2.4192.168.2.255
            Oct 6, 2024 16:39:05.194664001 CEST53499521.1.1.1192.168.2.4
            TimestampSource IPDest IPChecksumCodeType
            Oct 6, 2024 16:38:54.958303928 CEST192.168.2.41.1.1.1c22f(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Oct 6, 2024 16:38:48.641530991 CEST192.168.2.41.1.1.10x73ecStandard query (0)whatsapp-wug.comA (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:48.642298937 CEST192.168.2.41.1.1.10x6dc2Standard query (0)whatsapp-wug.com65IN (0x0001)false
            Oct 6, 2024 16:38:48.656569958 CEST192.168.2.41.1.1.10x606fStandard query (0)whatsapp-wug.comA (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:48.808259010 CEST192.168.2.48.8.8.80x288fStandard query (0)google.comA (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:48.808626890 CEST192.168.2.41.1.1.10x9bc1Standard query (0)google.comA (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:49.863316059 CEST192.168.2.41.1.1.10x676eStandard query (0)whatsapp-wug.comA (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:49.863903999 CEST192.168.2.41.1.1.10xed9cStandard query (0)whatsapp-wug.com65IN (0x0001)false
            Oct 6, 2024 16:38:50.606621981 CEST192.168.2.41.1.1.10x888eStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:50.606800079 CEST192.168.2.41.1.1.10x4d1Standard query (0)www.google.com65IN (0x0001)false
            Oct 6, 2024 16:38:54.926537037 CEST192.168.2.41.1.1.10x99e8Standard query (0)whatsapp-wug.comA (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:54.926790953 CEST192.168.2.41.1.1.10x1dafStandard query (0)whatsapp-wug.com65IN (0x0001)false
            Oct 6, 2024 16:38:54.956955910 CEST192.168.2.41.1.1.10x254eStandard query (0)whatsapp-wug.comA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Oct 6, 2024 16:38:48.653378010 CEST1.1.1.1192.168.2.40x73ecName error (3)whatsapp-wug.comnonenoneA (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:48.654210091 CEST1.1.1.1192.168.2.40x6dc2Name error (3)whatsapp-wug.comnonenone65IN (0x0001)false
            Oct 6, 2024 16:38:48.669138908 CEST1.1.1.1192.168.2.40x606fName error (3)whatsapp-wug.comnonenoneA (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:48.815900087 CEST1.1.1.1192.168.2.40x9bc1No error (0)google.com216.58.206.78A (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:48.817439079 CEST8.8.8.8192.168.2.40x288fNo error (0)google.com142.250.184.238A (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:49.873533964 CEST1.1.1.1192.168.2.40xed9cName error (3)whatsapp-wug.comnonenone65IN (0x0001)false
            Oct 6, 2024 16:38:49.873553038 CEST1.1.1.1192.168.2.40x676eName error (3)whatsapp-wug.comnonenoneA (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:50.613698006 CEST1.1.1.1192.168.2.40x888eNo error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:50.613715887 CEST1.1.1.1192.168.2.40x4d1No error (0)www.google.com65IN (0x0001)false
            Oct 6, 2024 16:38:54.936243057 CEST1.1.1.1192.168.2.40x99e8Name error (3)whatsapp-wug.comnonenoneA (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:54.958216906 CEST1.1.1.1192.168.2.40x1dafName error (3)whatsapp-wug.comnonenone65IN (0x0001)false
            Oct 6, 2024 16:38:54.966142893 CEST1.1.1.1192.168.2.40x254eName error (3)whatsapp-wug.comnonenoneA (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:59.881459951 CEST1.1.1.1192.168.2.40x7529No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comdefault.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comCNAME (Canonical name)IN (0x0001)false
            Oct 6, 2024 16:38:59.881459951 CEST1.1.1.1192.168.2.40x7529No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com84.201.210.22A (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:59.881459951 CEST1.1.1.1192.168.2.40x7529No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com84.201.210.38A (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:59.881459951 CEST1.1.1.1192.168.2.40x7529No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.43A (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:59.881459951 CEST1.1.1.1192.168.2.40x7529No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.37A (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:59.881459951 CEST1.1.1.1192.168.2.40x7529No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.39A (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:59.881459951 CEST1.1.1.1192.168.2.40x7529No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.41A (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:59.881459951 CEST1.1.1.1192.168.2.40x7529No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.21A (IP address)IN (0x0001)false
            Oct 6, 2024 16:38:59.881459951 CEST1.1.1.1192.168.2.40x7529No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.23A (IP address)IN (0x0001)false
            Oct 6, 2024 16:39:02.140671015 CEST1.1.1.1192.168.2.40x44cbNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Oct 6, 2024 16:39:02.140671015 CEST1.1.1.1192.168.2.40x44cbNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false

            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:10:38:40
            Start date:06/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:10:38:44
            Start date:06/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2268 --field-trial-handle=2220,i,14724931619133752789,3456494080413759407,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:10:38:47
            Start date:06/10/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://whatsapp-wug.com/"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly