Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://us-usps-oiqkin.xyz/update/

Overview

General Information

Sample URL:https://us-usps-oiqkin.xyz/update/
Analysis ID:1526967
Tags:openphish
Infos:
Errors
  • URL not reachable

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Performs DNS queries to domains with low reputation
Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 4820 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4484 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2576 --field-trial-handle=1988,i,16740016220544362112,12865700351975462628,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6312 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://us-usps-oiqkin.xyz/update/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://us-usps-oiqkin.xyz/update/SlashNext: detection malicious, Label: Fraudulent Website type: Phishing & Social Engineering

Networking

barindex
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-oiqkin.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-oiqkin.xyz
Source: DNS query: us-usps-oiqkin.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-oiqkin.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-oiqkin.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-oiqkin.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-oiqkin.xyz
Source: DNS query: us-usps-oiqkin.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-oiqkin.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-oiqkin.xyz
Source: global trafficTCP traffic: 192.168.2.4:49674 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: us-usps-oiqkin.xyz
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: mal52.troj.win@24/0@14/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2576 --field-trial-handle=1988,i,16740016220544362112,12865700351975462628,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://us-usps-oiqkin.xyz/update/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2576 --field-trial-handle=1988,i,16740016220544362112,12865700351975462628,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://us-usps-oiqkin.xyz/update/100%SlashNextFraudulent Website type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.185.78
truefalse
    unknown
    www.google.com
    142.250.186.68
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        us-usps-oiqkin.xyz
        unknown
        unknowntrue
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          142.250.186.68
          www.google.comUnited States
          15169GOOGLEUSfalse
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          IP
          192.168.2.4
          Joe Sandbox version:41.0.0 Charoite
          Analysis ID:1526967
          Start date and time:2024-10-06 18:37:00 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 1m 56s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:https://us-usps-oiqkin.xyz/update/
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:7
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:MAL
          Classification:mal52.troj.win@24/0@14/3
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          Cookbook Comments:
          • URL browsing timeout or error
          • URL not reachable
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.250.185.227, 142.250.186.110, 173.194.76.84, 34.104.35.123, 184.28.90.27, 20.12.23.50, 93.184.221.240, 192.229.221.95, 13.95.31.18
          • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          • VT rate limit hit for: https://us-usps-oiqkin.xyz/update/
          No simulations
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Oct 6, 2024 18:37:55.983124971 CEST49675443192.168.2.4173.222.162.32
          Oct 6, 2024 18:37:59.052882910 CEST49737443192.168.2.4142.250.186.68
          Oct 6, 2024 18:37:59.052942038 CEST44349737142.250.186.68192.168.2.4
          Oct 6, 2024 18:37:59.053009987 CEST49737443192.168.2.4142.250.186.68
          Oct 6, 2024 18:37:59.054229975 CEST49737443192.168.2.4142.250.186.68
          Oct 6, 2024 18:37:59.054261923 CEST44349737142.250.186.68192.168.2.4
          Oct 6, 2024 18:37:59.700128078 CEST44349737142.250.186.68192.168.2.4
          Oct 6, 2024 18:37:59.701076031 CEST49737443192.168.2.4142.250.186.68
          Oct 6, 2024 18:37:59.701142073 CEST44349737142.250.186.68192.168.2.4
          Oct 6, 2024 18:37:59.702807903 CEST44349737142.250.186.68192.168.2.4
          Oct 6, 2024 18:37:59.702897072 CEST49737443192.168.2.4142.250.186.68
          Oct 6, 2024 18:37:59.892868996 CEST49737443192.168.2.4142.250.186.68
          Oct 6, 2024 18:37:59.893294096 CEST44349737142.250.186.68192.168.2.4
          Oct 6, 2024 18:37:59.936722994 CEST49737443192.168.2.4142.250.186.68
          Oct 6, 2024 18:37:59.936788082 CEST44349737142.250.186.68192.168.2.4
          Oct 6, 2024 18:37:59.983584881 CEST49737443192.168.2.4142.250.186.68
          Oct 6, 2024 18:38:01.431902885 CEST4967453192.168.2.41.1.1.1
          Oct 6, 2024 18:38:01.437079906 CEST53496741.1.1.1192.168.2.4
          Oct 6, 2024 18:38:01.437172890 CEST4967453192.168.2.41.1.1.1
          Oct 6, 2024 18:38:01.437196970 CEST4967453192.168.2.41.1.1.1
          Oct 6, 2024 18:38:01.442445040 CEST53496741.1.1.1192.168.2.4
          Oct 6, 2024 18:38:01.881184101 CEST53496741.1.1.1192.168.2.4
          Oct 6, 2024 18:38:01.913598061 CEST4967453192.168.2.41.1.1.1
          Oct 6, 2024 18:38:01.918867111 CEST53496741.1.1.1192.168.2.4
          Oct 6, 2024 18:38:01.918926954 CEST4967453192.168.2.41.1.1.1
          Oct 6, 2024 18:38:09.587110996 CEST44349737142.250.186.68192.168.2.4
          Oct 6, 2024 18:38:09.587258101 CEST44349737142.250.186.68192.168.2.4
          Oct 6, 2024 18:38:09.587347031 CEST49737443192.168.2.4142.250.186.68
          Oct 6, 2024 18:38:11.533216953 CEST49737443192.168.2.4142.250.186.68
          Oct 6, 2024 18:38:11.533257008 CEST44349737142.250.186.68192.168.2.4
          Oct 6, 2024 18:38:13.160370111 CEST4972380192.168.2.4199.232.214.172
          Oct 6, 2024 18:38:13.353652000 CEST8049723199.232.214.172192.168.2.4
          Oct 6, 2024 18:38:13.353724003 CEST4972380192.168.2.4199.232.214.172
          TimestampSource PortDest PortSource IPDest IP
          Oct 6, 2024 18:37:55.169918060 CEST53526691.1.1.1192.168.2.4
          Oct 6, 2024 18:37:55.205748081 CEST53628961.1.1.1192.168.2.4
          Oct 6, 2024 18:37:56.358875036 CEST53640461.1.1.1192.168.2.4
          Oct 6, 2024 18:37:56.886502028 CEST5796453192.168.2.41.1.1.1
          Oct 6, 2024 18:37:56.886763096 CEST5386053192.168.2.41.1.1.1
          Oct 6, 2024 18:37:56.906069994 CEST53538601.1.1.1192.168.2.4
          Oct 6, 2024 18:37:56.906595945 CEST53579641.1.1.1192.168.2.4
          Oct 6, 2024 18:37:56.907367945 CEST6464553192.168.2.41.1.1.1
          Oct 6, 2024 18:37:56.926184893 CEST53646451.1.1.1192.168.2.4
          Oct 6, 2024 18:37:56.991425991 CEST5273453192.168.2.48.8.8.8
          Oct 6, 2024 18:37:56.991667032 CEST6449453192.168.2.41.1.1.1
          Oct 6, 2024 18:37:56.998568058 CEST53644941.1.1.1192.168.2.4
          Oct 6, 2024 18:37:57.001291037 CEST53527348.8.8.8192.168.2.4
          Oct 6, 2024 18:37:58.002405882 CEST5598853192.168.2.41.1.1.1
          Oct 6, 2024 18:37:58.002804995 CEST5293653192.168.2.41.1.1.1
          Oct 6, 2024 18:37:58.011812925 CEST53559881.1.1.1192.168.2.4
          Oct 6, 2024 18:37:58.023341894 CEST53529361.1.1.1192.168.2.4
          Oct 6, 2024 18:37:59.041496992 CEST6529953192.168.2.41.1.1.1
          Oct 6, 2024 18:37:59.042120934 CEST5446353192.168.2.41.1.1.1
          Oct 6, 2024 18:37:59.050080061 CEST53544631.1.1.1192.168.2.4
          Oct 6, 2024 18:37:59.050380945 CEST53652991.1.1.1192.168.2.4
          Oct 6, 2024 18:38:01.431056976 CEST53522421.1.1.1192.168.2.4
          Oct 6, 2024 18:38:03.036286116 CEST5457253192.168.2.41.1.1.1
          Oct 6, 2024 18:38:03.036820889 CEST6492153192.168.2.41.1.1.1
          Oct 6, 2024 18:38:03.046627045 CEST53545721.1.1.1192.168.2.4
          Oct 6, 2024 18:38:03.053967953 CEST53649211.1.1.1192.168.2.4
          Oct 6, 2024 18:38:03.087198019 CEST6348553192.168.2.41.1.1.1
          Oct 6, 2024 18:38:03.098851919 CEST53634851.1.1.1192.168.2.4
          Oct 6, 2024 18:38:03.134915113 CEST5241553192.168.2.41.1.1.1
          Oct 6, 2024 18:38:03.135485888 CEST5488553192.168.2.41.1.1.1
          Oct 6, 2024 18:38:03.142725945 CEST53524151.1.1.1192.168.2.4
          Oct 6, 2024 18:38:03.145728111 CEST53548851.1.1.1192.168.2.4
          Oct 6, 2024 18:38:12.913110971 CEST138138192.168.2.4192.168.2.255
          TimestampSource IPDest IPChecksumCodeType
          Oct 6, 2024 18:37:58.023551941 CEST192.168.2.41.1.1.1c229(Port unreachable)Destination Unreachable
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Oct 6, 2024 18:37:56.886502028 CEST192.168.2.41.1.1.10x8077Standard query (0)us-usps-oiqkin.xyzA (IP address)IN (0x0001)false
          Oct 6, 2024 18:37:56.886763096 CEST192.168.2.41.1.1.10xd47dStandard query (0)us-usps-oiqkin.xyz65IN (0x0001)false
          Oct 6, 2024 18:37:56.907367945 CEST192.168.2.41.1.1.10xaa61Standard query (0)us-usps-oiqkin.xyzA (IP address)IN (0x0001)false
          Oct 6, 2024 18:37:56.991425991 CEST192.168.2.48.8.8.80x1b8Standard query (0)google.comA (IP address)IN (0x0001)false
          Oct 6, 2024 18:37:56.991667032 CEST192.168.2.41.1.1.10xe3afStandard query (0)google.comA (IP address)IN (0x0001)false
          Oct 6, 2024 18:37:58.002405882 CEST192.168.2.41.1.1.10x1a2Standard query (0)us-usps-oiqkin.xyzA (IP address)IN (0x0001)false
          Oct 6, 2024 18:37:58.002804995 CEST192.168.2.41.1.1.10xc708Standard query (0)us-usps-oiqkin.xyz65IN (0x0001)false
          Oct 6, 2024 18:37:59.041496992 CEST192.168.2.41.1.1.10x630Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Oct 6, 2024 18:37:59.042120934 CEST192.168.2.41.1.1.10x34a9Standard query (0)www.google.com65IN (0x0001)false
          Oct 6, 2024 18:38:03.036286116 CEST192.168.2.41.1.1.10xaf39Standard query (0)us-usps-oiqkin.xyzA (IP address)IN (0x0001)false
          Oct 6, 2024 18:38:03.036820889 CEST192.168.2.41.1.1.10xddf1Standard query (0)us-usps-oiqkin.xyz65IN (0x0001)false
          Oct 6, 2024 18:38:03.087198019 CEST192.168.2.41.1.1.10x69c3Standard query (0)us-usps-oiqkin.xyzA (IP address)IN (0x0001)false
          Oct 6, 2024 18:38:03.134915113 CEST192.168.2.41.1.1.10xca51Standard query (0)us-usps-oiqkin.xyzA (IP address)IN (0x0001)false
          Oct 6, 2024 18:38:03.135485888 CEST192.168.2.41.1.1.10x91caStandard query (0)us-usps-oiqkin.xyz65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Oct 6, 2024 18:37:56.906069994 CEST1.1.1.1192.168.2.40xd47dName error (3)us-usps-oiqkin.xyznonenone65IN (0x0001)false
          Oct 6, 2024 18:37:56.906595945 CEST1.1.1.1192.168.2.40x8077Name error (3)us-usps-oiqkin.xyznonenoneA (IP address)IN (0x0001)false
          Oct 6, 2024 18:37:56.926184893 CEST1.1.1.1192.168.2.40xaa61Name error (3)us-usps-oiqkin.xyznonenoneA (IP address)IN (0x0001)false
          Oct 6, 2024 18:37:56.998568058 CEST1.1.1.1192.168.2.40xe3afNo error (0)google.com142.250.185.78A (IP address)IN (0x0001)false
          Oct 6, 2024 18:37:57.001291037 CEST8.8.8.8192.168.2.40x1b8No error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
          Oct 6, 2024 18:37:58.011812925 CEST1.1.1.1192.168.2.40x1a2Name error (3)us-usps-oiqkin.xyznonenoneA (IP address)IN (0x0001)false
          Oct 6, 2024 18:37:58.023341894 CEST1.1.1.1192.168.2.40xc708Name error (3)us-usps-oiqkin.xyznonenone65IN (0x0001)false
          Oct 6, 2024 18:37:59.050080061 CEST1.1.1.1192.168.2.40x34a9No error (0)www.google.com65IN (0x0001)false
          Oct 6, 2024 18:37:59.050380945 CEST1.1.1.1192.168.2.40x630No error (0)www.google.com142.250.186.68A (IP address)IN (0x0001)false
          Oct 6, 2024 18:38:03.046627045 CEST1.1.1.1192.168.2.40xaf39Name error (3)us-usps-oiqkin.xyznonenoneA (IP address)IN (0x0001)false
          Oct 6, 2024 18:38:03.053967953 CEST1.1.1.1192.168.2.40xddf1Name error (3)us-usps-oiqkin.xyznonenone65IN (0x0001)false
          Oct 6, 2024 18:38:03.098851919 CEST1.1.1.1192.168.2.40x69c3Name error (3)us-usps-oiqkin.xyznonenoneA (IP address)IN (0x0001)false
          Oct 6, 2024 18:38:03.142725945 CEST1.1.1.1192.168.2.40xca51Name error (3)us-usps-oiqkin.xyznonenoneA (IP address)IN (0x0001)false
          Oct 6, 2024 18:38:03.145728111 CEST1.1.1.1192.168.2.40x91caName error (3)us-usps-oiqkin.xyznonenone65IN (0x0001)false
          Oct 6, 2024 18:38:11.904915094 CEST1.1.1.1192.168.2.40x4338No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Oct 6, 2024 18:38:11.904915094 CEST1.1.1.1192.168.2.40x4338No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false

          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:12:37:50
          Start date:06/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:12:37:52
          Start date:06/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2576 --field-trial-handle=1988,i,16740016220544362112,12865700351975462628,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:12:37:55
          Start date:06/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://us-usps-oiqkin.xyz/update/"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly