Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://us-usps-tiaqre.xyz/update/

Overview

General Information

Sample URL:https://us-usps-tiaqre.xyz/update/
Analysis ID:1526973
Tags:openphish
Infos:
Errors
  • URL not reachable

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Performs DNS queries to domains with low reputation

Classification

  • System is w10x64
  • chrome.exe (PID: 3848 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4348 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2412 --field-trial-handle=2372,i,2820300545790190874,2838082210650308826,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6300 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://us-usps-tiaqre.xyz/update/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://us-usps-tiaqre.xyz/update/SlashNext: detection malicious, Label: Fraudulent Website type: Phishing & Social Engineering

Networking

barindex
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-tiaqre.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-tiaqre.xyz
Source: DNS query: us-usps-tiaqre.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-tiaqre.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-tiaqre.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-tiaqre.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-tiaqre.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-tiaqre.xyz
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: us-usps-tiaqre.xyz
Source: DNS query: us-usps-tiaqre.xyz
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: us-usps-tiaqre.xyz
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: mal52.troj.win@19/0@14/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2412 --field-trial-handle=2372,i,2820300545790190874,2838082210650308826,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://us-usps-tiaqre.xyz/update/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2412 --field-trial-handle=2372,i,2820300545790190874,2838082210650308826,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://us-usps-tiaqre.xyz/update/100%SlashNextFraudulent Website type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.186.174
truefalse
    unknown
    www.google.com
    142.250.185.100
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        us-usps-tiaqre.xyz
        unknown
        unknowntrue
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          142.250.185.100
          www.google.comUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.4
          Joe Sandbox version:41.0.0 Charoite
          Analysis ID:1526973
          Start date and time:2024-10-06 18:42:05 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 1m 56s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:https://us-usps-tiaqre.xyz/update/
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:5
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:MAL
          Classification:mal52.troj.win@19/0@14/3
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          Cookbook Comments:
          • URL browsing timeout or error
          • URL not reachable
          • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 216.58.212.131, 142.250.184.238, 64.233.166.84, 34.104.35.123, 184.28.90.27, 4.175.87.197, 93.184.221.240, 40.69.42.241, 192.229.221.95
          • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          • VT rate limit hit for: https://us-usps-tiaqre.xyz/update/
          No simulations
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Oct 6, 2024 18:43:04.004842997 CEST49737443192.168.2.4142.250.185.100
          Oct 6, 2024 18:43:04.004889965 CEST44349737142.250.185.100192.168.2.4
          Oct 6, 2024 18:43:04.004982948 CEST49737443192.168.2.4142.250.185.100
          Oct 6, 2024 18:43:04.005302906 CEST49737443192.168.2.4142.250.185.100
          Oct 6, 2024 18:43:04.005316019 CEST44349737142.250.185.100192.168.2.4
          Oct 6, 2024 18:43:04.660417080 CEST44349737142.250.185.100192.168.2.4
          Oct 6, 2024 18:43:04.661216974 CEST49737443192.168.2.4142.250.185.100
          Oct 6, 2024 18:43:04.661245108 CEST44349737142.250.185.100192.168.2.4
          Oct 6, 2024 18:43:04.662319899 CEST44349737142.250.185.100192.168.2.4
          Oct 6, 2024 18:43:04.662389040 CEST49737443192.168.2.4142.250.185.100
          Oct 6, 2024 18:43:04.665097952 CEST49737443192.168.2.4142.250.185.100
          Oct 6, 2024 18:43:04.665201902 CEST44349737142.250.185.100192.168.2.4
          Oct 6, 2024 18:43:04.713299036 CEST49737443192.168.2.4142.250.185.100
          Oct 6, 2024 18:43:04.713325977 CEST44349737142.250.185.100192.168.2.4
          Oct 6, 2024 18:43:04.760169029 CEST49737443192.168.2.4142.250.185.100
          Oct 6, 2024 18:43:14.563466072 CEST44349737142.250.185.100192.168.2.4
          Oct 6, 2024 18:43:14.563565969 CEST44349737142.250.185.100192.168.2.4
          Oct 6, 2024 18:43:14.563805103 CEST49737443192.168.2.4142.250.185.100
          Oct 6, 2024 18:43:15.684541941 CEST49737443192.168.2.4142.250.185.100
          Oct 6, 2024 18:43:15.684578896 CEST44349737142.250.185.100192.168.2.4
          Oct 6, 2024 18:43:19.078870058 CEST4972380192.168.2.4199.232.214.172
          Oct 6, 2024 18:43:19.084183931 CEST8049723199.232.214.172192.168.2.4
          Oct 6, 2024 18:43:19.084259987 CEST4972380192.168.2.4199.232.214.172
          TimestampSource PortDest PortSource IPDest IP
          Oct 6, 2024 18:43:01.444459915 CEST53614301.1.1.1192.168.2.4
          Oct 6, 2024 18:43:01.482359886 CEST53626971.1.1.1192.168.2.4
          Oct 6, 2024 18:43:02.502052069 CEST53623821.1.1.1192.168.2.4
          Oct 6, 2024 18:43:02.556617975 CEST5954453192.168.2.41.1.1.1
          Oct 6, 2024 18:43:02.557358027 CEST5383253192.168.2.41.1.1.1
          Oct 6, 2024 18:43:02.566562891 CEST53538321.1.1.1192.168.2.4
          Oct 6, 2024 18:43:02.568780899 CEST53595441.1.1.1192.168.2.4
          Oct 6, 2024 18:43:02.573369980 CEST5830553192.168.2.41.1.1.1
          Oct 6, 2024 18:43:02.592314005 CEST53583051.1.1.1192.168.2.4
          Oct 6, 2024 18:43:02.676048994 CEST5164553192.168.2.48.8.8.8
          Oct 6, 2024 18:43:02.676326990 CEST6504253192.168.2.41.1.1.1
          Oct 6, 2024 18:43:02.683877945 CEST53650421.1.1.1192.168.2.4
          Oct 6, 2024 18:43:02.684545994 CEST53516458.8.8.8192.168.2.4
          Oct 6, 2024 18:43:03.784478903 CEST5741253192.168.2.41.1.1.1
          Oct 6, 2024 18:43:03.784658909 CEST6294053192.168.2.41.1.1.1
          Oct 6, 2024 18:43:03.799437046 CEST53574121.1.1.1192.168.2.4
          Oct 6, 2024 18:43:03.802968025 CEST53629401.1.1.1192.168.2.4
          Oct 6, 2024 18:43:03.954361916 CEST6352753192.168.2.41.1.1.1
          Oct 6, 2024 18:43:03.954507113 CEST6418253192.168.2.41.1.1.1
          Oct 6, 2024 18:43:03.961451054 CEST53635271.1.1.1192.168.2.4
          Oct 6, 2024 18:43:03.961865902 CEST53641821.1.1.1192.168.2.4
          Oct 6, 2024 18:43:03.986464024 CEST5884353192.168.2.41.1.1.1
          Oct 6, 2024 18:43:03.986572027 CEST5615653192.168.2.41.1.1.1
          Oct 6, 2024 18:43:03.997179031 CEST53588431.1.1.1192.168.2.4
          Oct 6, 2024 18:43:04.004921913 CEST53561561.1.1.1192.168.2.4
          Oct 6, 2024 18:43:09.030635118 CEST5254853192.168.2.41.1.1.1
          Oct 6, 2024 18:43:09.030791044 CEST5496153192.168.2.41.1.1.1
          Oct 6, 2024 18:43:09.043504953 CEST53549611.1.1.1192.168.2.4
          Oct 6, 2024 18:43:09.186801910 CEST53525481.1.1.1192.168.2.4
          Oct 6, 2024 18:43:09.187939882 CEST5705353192.168.2.41.1.1.1
          Oct 6, 2024 18:43:09.217719078 CEST53570531.1.1.1192.168.2.4
          Oct 6, 2024 18:43:18.877331972 CEST138138192.168.2.4192.168.2.255
          Oct 6, 2024 18:43:20.071134090 CEST53520371.1.1.1192.168.2.4
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Oct 6, 2024 18:43:02.556617975 CEST192.168.2.41.1.1.10x9be2Standard query (0)us-usps-tiaqre.xyzA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:02.557358027 CEST192.168.2.41.1.1.10x1bb9Standard query (0)us-usps-tiaqre.xyz65IN (0x0001)false
          Oct 6, 2024 18:43:02.573369980 CEST192.168.2.41.1.1.10x2a06Standard query (0)us-usps-tiaqre.xyzA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:02.676048994 CEST192.168.2.48.8.8.80xa450Standard query (0)google.comA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:02.676326990 CEST192.168.2.41.1.1.10x18aaStandard query (0)google.comA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:03.784478903 CEST192.168.2.41.1.1.10x12adStandard query (0)us-usps-tiaqre.xyzA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:03.784658909 CEST192.168.2.41.1.1.10xf101Standard query (0)us-usps-tiaqre.xyz65IN (0x0001)false
          Oct 6, 2024 18:43:03.954361916 CEST192.168.2.41.1.1.10xd0a6Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:03.954507113 CEST192.168.2.41.1.1.10xfe25Standard query (0)www.google.com65IN (0x0001)false
          Oct 6, 2024 18:43:03.986464024 CEST192.168.2.41.1.1.10x99e2Standard query (0)us-usps-tiaqre.xyzA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:03.986572027 CEST192.168.2.41.1.1.10x3174Standard query (0)us-usps-tiaqre.xyz65IN (0x0001)false
          Oct 6, 2024 18:43:09.030635118 CEST192.168.2.41.1.1.10x71aeStandard query (0)us-usps-tiaqre.xyzA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:09.030791044 CEST192.168.2.41.1.1.10x5510Standard query (0)us-usps-tiaqre.xyz65IN (0x0001)false
          Oct 6, 2024 18:43:09.187939882 CEST192.168.2.41.1.1.10xcc46Standard query (0)us-usps-tiaqre.xyzA (IP address)IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Oct 6, 2024 18:43:02.566562891 CEST1.1.1.1192.168.2.40x1bb9Name error (3)us-usps-tiaqre.xyznonenone65IN (0x0001)false
          Oct 6, 2024 18:43:02.568780899 CEST1.1.1.1192.168.2.40x9be2Name error (3)us-usps-tiaqre.xyznonenoneA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:02.592314005 CEST1.1.1.1192.168.2.40x2a06Name error (3)us-usps-tiaqre.xyznonenoneA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:02.683877945 CEST1.1.1.1192.168.2.40x18aaNo error (0)google.com142.250.186.174A (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:02.684545994 CEST8.8.8.8192.168.2.40xa450No error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:03.799437046 CEST1.1.1.1192.168.2.40x12adName error (3)us-usps-tiaqre.xyznonenoneA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:03.802968025 CEST1.1.1.1192.168.2.40xf101Name error (3)us-usps-tiaqre.xyznonenone65IN (0x0001)false
          Oct 6, 2024 18:43:03.961451054 CEST1.1.1.1192.168.2.40xd0a6No error (0)www.google.com142.250.185.100A (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:03.961865902 CEST1.1.1.1192.168.2.40xfe25No error (0)www.google.com65IN (0x0001)false
          Oct 6, 2024 18:43:03.997179031 CEST1.1.1.1192.168.2.40x99e2Name error (3)us-usps-tiaqre.xyznonenoneA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:04.004921913 CEST1.1.1.1192.168.2.40x3174Name error (3)us-usps-tiaqre.xyznonenone65IN (0x0001)false
          Oct 6, 2024 18:43:09.043504953 CEST1.1.1.1192.168.2.40x5510Name error (3)us-usps-tiaqre.xyznonenone65IN (0x0001)false
          Oct 6, 2024 18:43:09.186801910 CEST1.1.1.1192.168.2.40x71aeName error (3)us-usps-tiaqre.xyznonenoneA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:09.217719078 CEST1.1.1.1192.168.2.40xcc46Name error (3)us-usps-tiaqre.xyznonenoneA (IP address)IN (0x0001)false
          Oct 6, 2024 18:43:18.015853882 CEST1.1.1.1192.168.2.40xec1No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Oct 6, 2024 18:43:18.015853882 CEST1.1.1.1192.168.2.40xec1No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false

          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:12:42:56
          Start date:06/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:12:42:57
          Start date:06/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2412 --field-trial-handle=2372,i,2820300545790190874,2838082210650308826,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:12:43:01
          Start date:06/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://us-usps-tiaqre.xyz/update/"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly