Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI

Overview

General Information

Sample URL:https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvj
Analysis ID:1592077
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Detected non-DNS traffic on DNS port

Classification

  • System is w10x64
  • chrome.exe (PID: 2800 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1432 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2012,i,6330271476746337855,15990199757900187295,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6552 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hIHTTP Parser: No favicon
Source: https://r.envoi.eeva.net/tr/un/doHTTP Parser: No favicon
Source: global trafficTCP traffic: 192.168.2.4:56873 -> 162.159.36.2:53
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI HTTP/1.1Host: r.envoi.eeva.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: r.envoi.eeva.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hIAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: r.envoi.eeva.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: r.envoi.eeva.net
Source: unknownHTTP traffic detected: POST /tr/un/do HTTP/1.1Host: r.envoi.eeva.netConnection: keep-aliveContent-Length: 269Cache-Control: max-age=0sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1Origin: https://r.envoi.eeva.netContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hIAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: chromecache_47.2.dr, chromecache_46.2.drString found in binary or memory: https://fonts.googleapis.com/css?family=Open
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTS-muw.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTS2mu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSCmu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSGmu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSKmu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSOmu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSumu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSymu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTUGmu1aB.woff2)
Source: chromecache_45.2.drString found in binary or memory: https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTVOmu1aB.woff2)
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56924
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 56924 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: classification engineClassification label: clean0.win@16/8@6/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2012,i,6330271476746337855,15990199757900187295,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2012,i,6330271476746337855,15990199757900187295,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://r.envoi.eeva.net/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
r1.mailin.fr
1.179.112.195
truefalse
    high
    www.google.com
    142.250.186.100
    truefalse
      high
      r.envoi.eeva.net
      unknown
      unknownfalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hIfalse
          unknown
          https://r.envoi.eeva.net/favicon.icofalse
          • Avira URL Cloud: safe
          unknown
          https://r.envoi.eeva.net/tr/un/dofalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.186.100
            www.google.comUnited States
            15169GOOGLEUSfalse
            1.179.112.195
            r1.mailin.frAustralia
            9723ISEEK-AS-APiseekCommunicationsPtyLtdAUfalse
            IP
            192.168.2.4
            Joe Sandbox version:42.0.0 Malachite
            Analysis ID:1592077
            Start date and time:2025-01-15 18:19:21 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 3m 1s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:8
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:CLEAN
            Classification:clean0.win@16/8@6/4
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 142.250.185.238, 216.58.212.131, 64.233.166.84, 216.58.206.46, 172.217.16.206, 142.250.186.46, 216.58.206.74, 172.217.16.195, 199.232.210.172, 2.17.190.73, 142.250.181.238, 142.250.185.206, 142.250.185.131, 142.250.184.206, 2.23.242.162, 20.109.210.53, 13.107.253.45
            • Excluded domains from analysis (whitelisted): fonts.googleapis.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, fonts.gstatic.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, 6.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.7.0.0.0.0.3.0.1.3.0.6.2.ip6.arpa, update.googleapis.com, clients.l.google.com
            • Not all processes where analyzed, report is missing behavior information
            • VT rate limit hit for: https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI
            No simulations
            No context
            No context
            No context
            No context
            No context
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
            Category:downloaded
            Size (bytes):48236
            Entropy (8bit):7.994912604882335
            Encrypted:true
            SSDEEP:768:uj6JxavgLx5rjTH3CdZ3y11o4uMb2IVEhiB6z6GAAHJApICtBgso6HaOjTXHRWK:ujoa4LxZPCdm3B2IVEhiB62apApISxos
            MD5:015C126A3520C9A8F6A27979D0266E96
            SHA1:2ACF956561D44434A6D84204670CF849D3215D5F
            SHA-256:3C4D6A1421C7DDB7E404521FE8C4CD5BE5AF446D7689CD880BE26612EAAD3CFA
            SHA-512:02A20F2788BB1C3B2C7D3142C664CDEC306B6BA5366E57E33C008EDB3EB78638B98DC03CDF932A9DC440DED7827956F99117E7A3A4D55ACADD29B006032D9C5C
            Malicious:false
            Reputation:low
            URL:https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTS-muw.woff2
            Preview:wOF2.......l......D...............................O..B..h?HVAR.x.`?STAT.$'...0+...|.../V........+..2.0..6.6.$..`. ..~......[B4q.....t..P.M_.z...1..R.S*...u.#..R....fR.1.N.v.N.P...;.2........!Z......Qs...5f.G.K.an2&....2...*......C.H.t..N!.....nh.<(.vN.....j.._.L.P.t..Ai.%.............._I.i,..o,C.].H.X9.....a.=N....k.....n.L..k.f.u..{...:.}^\[..~5...Z`...........`!...%4..,...K0..&.a/....P....S....m.Z......u...D.j.F...f.0`I.`.`.h#..)(FQ.F!o$........S.).MV8%Rh...r...x...T]$.=......Y...!.3.&U..."....Q....{.l/0..d..4iJ/..}...3....i[Z..NG.WD...>.[U..Q.h..@m.=..S...1C2...d...<..v.?.q.f..n...OUz.....&Z......Z."..N.....n...9.B..C..W....}...W..6Zs.i.+Z........jB.n..x.8M.....q..@I....-.%..,C,..K..#.2...4)/.v_..x.<....t.....%[.4?.=j.V..jj''..W.u..q....I.L.=......E...\.M.7{.>......W........C.`...,9$......\..o........y...4A..m.P.,X..=?.:................wF`..+.P..........M!.4.......l.>M..t.ff5r..^..Z.g...!fA,hIIQ...e.R>B.AH.VuX..>..\.=.ky...1>C....>C.c.;...6D.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:ASCII text, with very long lines (1572)
            Category:downloaded
            Size (bytes):11588
            Entropy (8bit):5.32113961330478
            Encrypted:false
            SSDEEP:192:weA85q1bfqbrbqGIwV4RePqceZFgqsmfqmrbqGIwV4YTPv8:Xf7qY4H4AqY4d
            MD5:B630D8EC59B107E15A64CB2E8236B144
            SHA1:246E8EB4235D443936F3AA35E329E7F8E5DA82FC
            SHA-256:4099D0DC74EA892BF49FD78A729C8ED5528E6D5F885786575AB525AE54E33978
            SHA-512:601F2F0DFE0E0DDA08720B34780865C47317C046DA3E93C256E926902DA7173DAD94D0962155D271FA5468732A583569882675C9239E5BB1192C5B51431FD22E
            Malicious:false
            Reputation:low
            URL:"https://fonts.googleapis.com/css?family=Open+Sans:400,700"
            Preview:/* cyrillic-ext */.@font-face {. font-family: 'Open Sans';. font-style: normal;. font-weight: 400;. font-stretch: 100%;. src: url(https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSKmu1aB.woff2) format('woff2');. unicode-range: U+0460-052F, U+1C80-1C8A, U+20B4, U+2DE0-2DFF, U+A640-A69F, U+FE2E-FE2F;.}./* cyrillic */.@font-face {. font-family: 'Open Sans';. font-style: normal;. font-weight: 400;. font-stretch: 100%;. src: url(https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSumu1aB.woff2) format('woff2');. unicode-range: U+0301, U+0400-045F, U+0490-0491, U+04B0-04B1, U+2116;.}./* greek-ext */.@font-face {. font-family: 'Open Sans';. font-style: normal;. font-weight: 400;. font-stretch: 100%;. src: url(https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSOmu1aB.woff2) format('woff2');. unicode-range: U+1F00-1FFF;.}./* greek */.@font-face {. font-family: 'Open Sans';. font-style: normal;
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text
            Category:downloaded
            Size (bytes):844
            Entropy (8bit):5.131860888496928
            Encrypted:false
            SSDEEP:24:hYPih+0Ncc0y+lW3K+XXFAmxx3KZYudDafk3KZYZ0ZgBS63:hhEKfa+nSSxaiudmfkaiZ2K
            MD5:5838EC6CB5D39389602137CC8B187E4D
            SHA1:59B07F30AC6FF294A74AC64FC5F646985D49CEAD
            SHA-256:67A18C31ACCF3157D14AC2126FEB10ED06F228868FE4EA487A7B75379B146294
            SHA-512:1A2A38404F47D5FE8E8E49A21388BA9C486DC15D5E84F31504DE650F3C65714C54175974FC947F00DE1C79B270F4CD112613DA6AEA3A84BE664F1CE055543495
            Malicious:false
            Reputation:low
            URL:https://r.envoi.eeva.net/tr/un/do
            Preview:<!DOCTYPE html>.<html>..<head>...<title>Brevo | </title>.......<link href="https://fonts.googleapis.com/css?family=Open+Sans:400,700" rel="stylesheet">....<style>....html, body {.....height: 100%;....}....body, button, input {.....font-family: 'Open Sans', sans-serif;....}....body {.....font-size: 0.875rem;.....color: #676a6c;.....line-height: 1.75rem;.....padding: 0 1.25rem;.....margin: 0;....}....#grey-box{.....background: #e4e4e4;.....max-width: 570px;.....margin: auto;.....padding: 1.25rem;.....border-radius: 5px;.....position: relative;.....top: 50%;.....transform: translateY(-50%);....}.....content {.....background: #f7f7f7;.....padding: 1.25rem;.....border-radius: 5px;....}....</style>..</head>..<body>...<div id="grey-box">...<div class="content">....You have been successfully unsubscribed....</div>..</div>...</body>.</html>.
            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
            File Type:HTML document, ASCII text, with very long lines (310)
            Category:downloaded
            Size (bytes):1649
            Entropy (8bit):5.526200674191201
            Encrypted:false
            SSDEEP:48:oj5EKfaEuS54akdmzUaqG2DoVHcmkx3hlbRKH:6iDwkCkx3h4
            MD5:DA61B14D726A577105B3E00903C79129
            SHA1:A79800FAF18DA7CBC653BF5B47825E05F8A763FF
            SHA-256:7BFEC07A6094AA4044598D0274761E7C215BC4B18CF4759963E00523E13AB512
            SHA-512:81C92DF608F0F58224984A100500A6DCD1E8F6E83A36B4738BF333F6B068E53CD1E4254DE11EE642D29A8175F3C130F78D62DC30FC49BA554EEE51063DF2C499
            Malicious:false
            Reputation:low
            URL:https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI
            Preview:<!DOCTYPE html>.<html>..<head>...<title>Brevo | Unsubscribe</title>.......<link href="https://fonts.googleapis.com/css?family=Open+Sans:400,700" rel="stylesheet">...<style>....html, body {.....height: 100%;....}....body, button, input {.....font-family: 'Open Sans', sans-serif;....}....body {.....font-size: 0.875rem;.....color: #676a6c;.....line-height: 1.75rem;.....padding: 0;.....margin: 0;....}....h1 {.....font-size: 1.25rem;.....font-weight: 300;....}....#unsubscribe-box {.....max-width: 570px;.....margin: auto;.....text-align: center;.....padding: 2rem;.....position: relative;.....top: 50%;.....transform: translateY(-50%);....}....#unsubscribe-button {.....background: #4ca4e0;.....padding: 0.75rem 2rem;.....border: none;.....color: #fff;.....border-radius: 5px;.....font-size: 0.875rem;.....font-weight: 300;.....text-transform: uppercase;.....cursor: pointer;....}....p {.....margin: 3rem 0 2rem;....}....p strong {.....font-weight: 700;....}...</style>..</head>..<body>...<div id="un
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Jan 15, 2025 18:20:16.479156017 CET49675443192.168.2.4173.222.162.32
            Jan 15, 2025 18:20:21.050769091 CET49738443192.168.2.4142.250.186.100
            Jan 15, 2025 18:20:21.050807953 CET44349738142.250.186.100192.168.2.4
            Jan 15, 2025 18:20:21.051393986 CET49738443192.168.2.4142.250.186.100
            Jan 15, 2025 18:20:21.051438093 CET49738443192.168.2.4142.250.186.100
            Jan 15, 2025 18:20:21.051445007 CET44349738142.250.186.100192.168.2.4
            Jan 15, 2025 18:20:21.703155994 CET44349738142.250.186.100192.168.2.4
            Jan 15, 2025 18:20:21.703475952 CET49738443192.168.2.4142.250.186.100
            Jan 15, 2025 18:20:21.703510046 CET44349738142.250.186.100192.168.2.4
            Jan 15, 2025 18:20:21.704982996 CET44349738142.250.186.100192.168.2.4
            Jan 15, 2025 18:20:21.705116987 CET49738443192.168.2.4142.250.186.100
            Jan 15, 2025 18:20:21.706239939 CET49738443192.168.2.4142.250.186.100
            Jan 15, 2025 18:20:21.706475019 CET44349738142.250.186.100192.168.2.4
            Jan 15, 2025 18:20:21.760247946 CET49738443192.168.2.4142.250.186.100
            Jan 15, 2025 18:20:21.760310888 CET44349738142.250.186.100192.168.2.4
            Jan 15, 2025 18:20:21.807478905 CET49738443192.168.2.4142.250.186.100
            Jan 15, 2025 18:20:22.546634912 CET49740443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:22.546668053 CET443497401.179.112.195192.168.2.4
            Jan 15, 2025 18:20:22.546726942 CET49740443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:22.547008991 CET49740443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:22.547017097 CET443497401.179.112.195192.168.2.4
            Jan 15, 2025 18:20:22.547383070 CET49741443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:22.547424078 CET443497411.179.112.195192.168.2.4
            Jan 15, 2025 18:20:22.547478914 CET49741443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:22.547739983 CET49741443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:22.547754049 CET443497411.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.170881033 CET443497411.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.171201944 CET49741443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:23.171219110 CET443497411.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.172662973 CET443497411.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.172797918 CET49741443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:23.177413940 CET49741443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:23.177495956 CET443497411.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.177709103 CET49741443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:23.177716017 CET443497411.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.230645895 CET49741443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:23.255284071 CET443497401.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.255564928 CET49740443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:23.255575895 CET443497401.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.259110928 CET443497401.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.259268045 CET49740443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:23.261233091 CET49740443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:23.261423111 CET443497401.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.311453104 CET49740443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:23.311467886 CET443497401.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.356584072 CET49740443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:23.484637976 CET443497411.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.484704971 CET443497411.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.485208988 CET49741443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:23.485219955 CET443497411.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.485589027 CET443497411.179.112.195192.168.2.4
            Jan 15, 2025 18:20:23.486136913 CET49741443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:23.507740021 CET49741443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:23.507757902 CET443497411.179.112.195192.168.2.4
            Jan 15, 2025 18:20:24.532959938 CET49740443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:24.579324007 CET443497401.179.112.195192.168.2.4
            Jan 15, 2025 18:20:24.712749004 CET443497401.179.112.195192.168.2.4
            Jan 15, 2025 18:20:24.712934971 CET443497401.179.112.195192.168.2.4
            Jan 15, 2025 18:20:24.713072062 CET49740443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:24.714672089 CET49740443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:24.714692116 CET443497401.179.112.195192.168.2.4
            Jan 15, 2025 18:20:24.763395071 CET49745443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:24.763432980 CET443497451.179.112.195192.168.2.4
            Jan 15, 2025 18:20:24.763489008 CET49745443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:24.763700962 CET49745443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:24.763716936 CET443497451.179.112.195192.168.2.4
            Jan 15, 2025 18:20:25.410897017 CET443497451.179.112.195192.168.2.4
            Jan 15, 2025 18:20:25.411178112 CET49745443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:25.411196947 CET443497451.179.112.195192.168.2.4
            Jan 15, 2025 18:20:25.412631035 CET443497451.179.112.195192.168.2.4
            Jan 15, 2025 18:20:25.412686110 CET49745443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:25.413057089 CET49745443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:25.413125992 CET443497451.179.112.195192.168.2.4
            Jan 15, 2025 18:20:25.413232088 CET49745443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:25.413244009 CET443497451.179.112.195192.168.2.4
            Jan 15, 2025 18:20:25.461529970 CET49745443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:25.714766979 CET443497451.179.112.195192.168.2.4
            Jan 15, 2025 18:20:25.714940071 CET443497451.179.112.195192.168.2.4
            Jan 15, 2025 18:20:25.715142012 CET49745443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:25.715857983 CET49745443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:25.715857983 CET49745443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:25.715887070 CET443497451.179.112.195192.168.2.4
            Jan 15, 2025 18:20:25.715939045 CET49745443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:31.590336084 CET44349738142.250.186.100192.168.2.4
            Jan 15, 2025 18:20:31.590395927 CET44349738142.250.186.100192.168.2.4
            Jan 15, 2025 18:20:31.590464115 CET49738443192.168.2.4142.250.186.100
            Jan 15, 2025 18:20:33.404274940 CET49738443192.168.2.4142.250.186.100
            Jan 15, 2025 18:20:33.404376984 CET44349738142.250.186.100192.168.2.4
            Jan 15, 2025 18:20:37.303152084 CET49752443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:37.303204060 CET443497521.179.112.195192.168.2.4
            Jan 15, 2025 18:20:37.303276062 CET49752443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:37.303430080 CET49753443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:37.303483963 CET443497531.179.112.195192.168.2.4
            Jan 15, 2025 18:20:37.303535938 CET49753443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:37.308891058 CET49753443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:37.308919907 CET443497531.179.112.195192.168.2.4
            Jan 15, 2025 18:20:37.309053898 CET49752443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:37.309065104 CET443497521.179.112.195192.168.2.4
            Jan 15, 2025 18:20:38.023096085 CET443497521.179.112.195192.168.2.4
            Jan 15, 2025 18:20:38.023547888 CET49752443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:38.023577929 CET443497521.179.112.195192.168.2.4
            Jan 15, 2025 18:20:38.024100065 CET443497521.179.112.195192.168.2.4
            Jan 15, 2025 18:20:38.024919987 CET49752443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:38.025079012 CET49752443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:38.025089025 CET443497521.179.112.195192.168.2.4
            Jan 15, 2025 18:20:38.025124073 CET443497521.179.112.195192.168.2.4
            Jan 15, 2025 18:20:38.045912027 CET443497531.179.112.195192.168.2.4
            Jan 15, 2025 18:20:38.046262026 CET49753443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:38.046303988 CET443497531.179.112.195192.168.2.4
            Jan 15, 2025 18:20:38.047626972 CET443497531.179.112.195192.168.2.4
            Jan 15, 2025 18:20:38.047982931 CET49753443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:38.048166990 CET443497531.179.112.195192.168.2.4
            Jan 15, 2025 18:20:38.069402933 CET49752443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:38.099889040 CET49753443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:38.548759937 CET443497521.179.112.195192.168.2.4
            Jan 15, 2025 18:20:38.548866034 CET443497521.179.112.195192.168.2.4
            Jan 15, 2025 18:20:38.548981905 CET49752443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:38.550127029 CET49752443192.168.2.41.179.112.195
            Jan 15, 2025 18:20:38.550168991 CET443497521.179.112.195192.168.2.4
            Jan 15, 2025 18:20:56.845469952 CET5687353192.168.2.4162.159.36.2
            Jan 15, 2025 18:20:56.850424051 CET5356873162.159.36.2192.168.2.4
            Jan 15, 2025 18:20:56.850533009 CET5687353192.168.2.4162.159.36.2
            Jan 15, 2025 18:20:56.855369091 CET5356873162.159.36.2192.168.2.4
            Jan 15, 2025 18:20:57.341566086 CET5687353192.168.2.4162.159.36.2
            Jan 15, 2025 18:20:57.346713066 CET5356873162.159.36.2192.168.2.4
            Jan 15, 2025 18:20:57.346950054 CET5687353192.168.2.4162.159.36.2
            Jan 15, 2025 18:21:08.775290012 CET443497531.179.112.195192.168.2.4
            Jan 15, 2025 18:21:08.775377035 CET443497531.179.112.195192.168.2.4
            Jan 15, 2025 18:21:08.775434971 CET49753443192.168.2.41.179.112.195
            Jan 15, 2025 18:21:09.400861979 CET49753443192.168.2.41.179.112.195
            Jan 15, 2025 18:21:09.400934935 CET443497531.179.112.195192.168.2.4
            Jan 15, 2025 18:21:21.103945971 CET56924443192.168.2.4142.250.186.100
            Jan 15, 2025 18:21:21.103996038 CET44356924142.250.186.100192.168.2.4
            Jan 15, 2025 18:21:21.104069948 CET56924443192.168.2.4142.250.186.100
            Jan 15, 2025 18:21:21.104377985 CET56924443192.168.2.4142.250.186.100
            Jan 15, 2025 18:21:21.104391098 CET44356924142.250.186.100192.168.2.4
            Jan 15, 2025 18:21:21.756795883 CET44356924142.250.186.100192.168.2.4
            Jan 15, 2025 18:21:21.757247925 CET56924443192.168.2.4142.250.186.100
            Jan 15, 2025 18:21:21.757313013 CET44356924142.250.186.100192.168.2.4
            Jan 15, 2025 18:21:21.757793903 CET44356924142.250.186.100192.168.2.4
            Jan 15, 2025 18:21:21.758132935 CET56924443192.168.2.4142.250.186.100
            Jan 15, 2025 18:21:21.758222103 CET44356924142.250.186.100192.168.2.4
            Jan 15, 2025 18:21:21.805752039 CET56924443192.168.2.4142.250.186.100
            Jan 15, 2025 18:21:31.651369095 CET44356924142.250.186.100192.168.2.4
            Jan 15, 2025 18:21:31.651510954 CET44356924142.250.186.100192.168.2.4
            Jan 15, 2025 18:21:31.651671886 CET56924443192.168.2.4142.250.186.100
            Jan 15, 2025 18:21:33.403681040 CET56924443192.168.2.4142.250.186.100
            Jan 15, 2025 18:21:33.403752089 CET44356924142.250.186.100192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Jan 15, 2025 18:20:16.522567987 CET53655251.1.1.1192.168.2.4
            Jan 15, 2025 18:20:16.523431063 CET53493851.1.1.1192.168.2.4
            Jan 15, 2025 18:20:17.645301104 CET53606171.1.1.1192.168.2.4
            Jan 15, 2025 18:20:21.042557955 CET5066753192.168.2.41.1.1.1
            Jan 15, 2025 18:20:21.042684078 CET6117953192.168.2.41.1.1.1
            Jan 15, 2025 18:20:21.049348116 CET53611791.1.1.1192.168.2.4
            Jan 15, 2025 18:20:21.049557924 CET53506671.1.1.1192.168.2.4
            Jan 15, 2025 18:20:22.492626905 CET6194653192.168.2.41.1.1.1
            Jan 15, 2025 18:20:22.492882967 CET5386353192.168.2.41.1.1.1
            Jan 15, 2025 18:20:22.544922113 CET53538631.1.1.1192.168.2.4
            Jan 15, 2025 18:20:22.545945883 CET53619461.1.1.1192.168.2.4
            Jan 15, 2025 18:20:23.514633894 CET53529401.1.1.1192.168.2.4
            Jan 15, 2025 18:20:24.720834970 CET5453453192.168.2.41.1.1.1
            Jan 15, 2025 18:20:24.720978022 CET6455753192.168.2.41.1.1.1
            Jan 15, 2025 18:20:24.743151903 CET53545341.1.1.1192.168.2.4
            Jan 15, 2025 18:20:24.765607119 CET53645571.1.1.1192.168.2.4
            Jan 15, 2025 18:20:34.312247992 CET138138192.168.2.4192.168.2.255
            Jan 15, 2025 18:20:34.626532078 CET53518061.1.1.1192.168.2.4
            Jan 15, 2025 18:20:53.564909935 CET53596081.1.1.1192.168.2.4
            Jan 15, 2025 18:20:56.844742060 CET5350182162.159.36.2192.168.2.4
            Jan 15, 2025 18:20:57.363048077 CET53650731.1.1.1192.168.2.4
            Jan 15, 2025 18:21:16.315908909 CET53606581.1.1.1192.168.2.4
            Jan 15, 2025 18:21:16.425247908 CET53605391.1.1.1192.168.2.4
            TimestampSource IPDest IPChecksumCodeType
            Jan 15, 2025 18:20:24.765680075 CET192.168.2.41.1.1.1c23c(Port unreachable)Destination Unreachable
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Jan 15, 2025 18:20:21.042557955 CET192.168.2.41.1.1.10xd471Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Jan 15, 2025 18:20:21.042684078 CET192.168.2.41.1.1.10xb83bStandard query (0)www.google.com65IN (0x0001)false
            Jan 15, 2025 18:20:22.492626905 CET192.168.2.41.1.1.10x7cf1Standard query (0)r.envoi.eeva.netA (IP address)IN (0x0001)false
            Jan 15, 2025 18:20:22.492882967 CET192.168.2.41.1.1.10xba55Standard query (0)r.envoi.eeva.net65IN (0x0001)false
            Jan 15, 2025 18:20:24.720834970 CET192.168.2.41.1.1.10xd456Standard query (0)r.envoi.eeva.netA (IP address)IN (0x0001)false
            Jan 15, 2025 18:20:24.720978022 CET192.168.2.41.1.1.10xe083Standard query (0)r.envoi.eeva.net65IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Jan 15, 2025 18:20:21.049348116 CET1.1.1.1192.168.2.40xb83bNo error (0)www.google.com65IN (0x0001)false
            Jan 15, 2025 18:20:21.049557924 CET1.1.1.1192.168.2.40xd471No error (0)www.google.com142.250.186.100A (IP address)IN (0x0001)false
            Jan 15, 2025 18:20:22.544922113 CET1.1.1.1192.168.2.40xba55No error (0)r.envoi.eeva.netr.mailin.frCNAME (Canonical name)IN (0x0001)false
            Jan 15, 2025 18:20:22.545945883 CET1.1.1.1192.168.2.40x7cf1No error (0)r.envoi.eeva.netr.mailin.frCNAME (Canonical name)IN (0x0001)false
            Jan 15, 2025 18:20:22.545945883 CET1.1.1.1192.168.2.40x7cf1No error (0)r.mailin.frr1.mailin.frCNAME (Canonical name)IN (0x0001)false
            Jan 15, 2025 18:20:22.545945883 CET1.1.1.1192.168.2.40x7cf1No error (0)r1.mailin.fr1.179.112.195A (IP address)IN (0x0001)false
            Jan 15, 2025 18:20:22.545945883 CET1.1.1.1192.168.2.40x7cf1No error (0)r1.mailin.fr1.179.112.196A (IP address)IN (0x0001)false
            Jan 15, 2025 18:20:22.545945883 CET1.1.1.1192.168.2.40x7cf1No error (0)r1.mailin.fr1.179.112.197A (IP address)IN (0x0001)false
            Jan 15, 2025 18:20:24.743151903 CET1.1.1.1192.168.2.40xd456No error (0)r.envoi.eeva.netr.mailin.frCNAME (Canonical name)IN (0x0001)false
            Jan 15, 2025 18:20:24.743151903 CET1.1.1.1192.168.2.40xd456No error (0)r.mailin.frr1.mailin.frCNAME (Canonical name)IN (0x0001)false
            Jan 15, 2025 18:20:24.743151903 CET1.1.1.1192.168.2.40xd456No error (0)r1.mailin.fr1.179.112.195A (IP address)IN (0x0001)false
            Jan 15, 2025 18:20:24.743151903 CET1.1.1.1192.168.2.40xd456No error (0)r1.mailin.fr1.179.112.197A (IP address)IN (0x0001)false
            Jan 15, 2025 18:20:24.743151903 CET1.1.1.1192.168.2.40xd456No error (0)r1.mailin.fr1.179.112.196A (IP address)IN (0x0001)false
            Jan 15, 2025 18:20:24.765607119 CET1.1.1.1192.168.2.40xe083No error (0)r.envoi.eeva.netr.mailin.frCNAME (Canonical name)IN (0x0001)false
            • r.envoi.eeva.net
            • https:
            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            0192.168.2.4497411.179.112.1954431432C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-01-15 17:20:23 UTC923OUTGET /tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI HTTP/1.1
            Host: r.envoi.eeva.net
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2025-01-15 17:20:23 UTC241INHTTP/1.1 200 OK
            Content-Length: 1649
            Content-Type: text/html; charset=utf-8
            Date: Wed, 15 Jan 2025 17:20:23 GMT
            X-Content-Type-Options: nosniff
            X-Sib-Server: gke-public-cluster-v2-1-179-112-89
            X-Xss-Protection: 1
            Connection: close
            2025-01-15 17:20:23 UTC945INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 09 3c 68 65 61 64 3e 0a 09 09 3c 74 69 74 6c 65 3e 42 72 65 76 6f 20 7c 20 55 6e 73 75 62 73 63 72 69 62 65 3c 2f 74 69 74 6c 65 3e 0a 0a 09 09 0a 09 09 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 66 6f 6e 74 73 2e 67 6f 6f 67 6c 65 61 70 69 73 2e 63 6f 6d 2f 63 73 73 3f 66 61 6d 69 6c 79 3d 4f 70 65 6e 2b 53 61 6e 73 3a 34 30 30 2c 37 30 30 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 3e 0a 09 09 3c 73 74 79 6c 65 3e 0a 09 09 09 68 74 6d 6c 2c 20 62 6f 64 79 20 7b 0a 09 09 09 09 68 65 69 67 68 74 3a 20 31 30 30 25 3b 0a 09 09 09 7d 0a 09 09 09 62 6f 64 79 2c 20 62 75 74 74 6f 6e 2c 20 69 6e 70 75 74 20 7b 0a 09 09 09 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 27
            Data Ascii: <!DOCTYPE html><html><head><title>Brevo | Unsubscribe</title><link href="https://fonts.googleapis.com/css?family=Open+Sans:400,700" rel="stylesheet"><style>html, body {height: 100%;}body, button, input {font-family: '
            2025-01-15 17:20:23 UTC704INData Raw: 68 74 3a 20 37 30 30 3b 0a 09 09 09 7d 0a 09 09 3c 2f 73 74 79 6c 65 3e 0a 09 3c 2f 68 65 61 64 3e 0a 09 3c 62 6f 64 79 3e 0a 0a 09 3c 64 69 76 20 69 64 3d 22 75 6e 73 75 62 73 63 72 69 62 65 2d 62 6f 78 22 3e 0a 09 09 3c 68 31 3e 55 6e 73 75 62 73 63 72 69 62 65 3c 2f 68 31 3e 0a 09 09 3c 70 3e 43 6c 69 63 6b 20 6f 6e 20 26 23 33 34 3b 55 6e 73 75 62 73 63 72 69 62 65 26 23 33 34 3b 20 74 6f 20 73 74 6f 70 20 72 65 63 65 69 76 69 6e 67 20 65 6d 61 69 6c 73 20 66 72 6f 6d 20 74 68 69 73 20 73 65 6e 64 65 72 20 6f 6e 20 74 68 69 73 20 65 6d 61 69 6c 20 61 64 64 72 65 73 73 3a 20 20 3c 73 74 72 6f 6e 67 3e 62 65 64 6d 6f 6e 64 73 40 6e 65 78 76 65 73 74 72 61 2e 63 6f 6d 3c 2f 73 74 72 6f 6e 67 3e 3c 2f 70 3e 0a 09 09 3c 66 6f 72 6d 20 61 63 74 69 6f 6e 20
            Data Ascii: ht: 700;}</style></head><body><div id="unsubscribe-box"><h1>Unsubscribe</h1><p>Click on &#34;Unsubscribe&#34; to stop receiving emails from this sender on this email address: <strong>bedmonds@nexvestra.com</strong></p><form action


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            1192.168.2.4497401.179.112.1954431432C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-01-15 17:20:24 UTC852OUTGET /favicon.ico HTTP/1.1
            Host: r.envoi.eeva.net
            Connection: keep-alive
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            sec-ch-ua-platform: "Windows"
            Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: no-cors
            Sec-Fetch-Dest: image
            Referer: https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2025-01-15 17:20:24 UTC329INHTTP/1.1 200 OK
            Accept-Ranges: bytes
            Content-Length: 0
            Content-Type: image/x-icon
            Date: Wed, 15 Jan 2025 17:20:24 GMT
            Etag: "65f97b52-0"
            Last-Modified: Tue, 19 Mar 2024 11:47:30 GMT
            Server: nginx
            X-Content-Type-Options: nosniff
            X-Sib-Server: gke-public-cluster-v2-1-179-114-10
            X-Xss-Protection: 1
            Connection: close


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            2192.168.2.4497451.179.112.1954431432C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-01-15 17:20:25 UTC351OUTGET /favicon.ico HTTP/1.1
            Host: r.envoi.eeva.net
            Connection: keep-alive
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: */*
            Sec-Fetch-Site: none
            Sec-Fetch-Mode: cors
            Sec-Fetch-Dest: empty
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2025-01-15 17:20:25 UTC329INHTTP/1.1 200 OK
            Accept-Ranges: bytes
            Content-Length: 0
            Content-Type: image/x-icon
            Date: Wed, 15 Jan 2025 17:20:25 GMT
            Etag: "65f97b52-0"
            Last-Modified: Tue, 19 Mar 2024 11:47:30 GMT
            Server: nginx
            X-Content-Type-Options: nosniff
            X-Sib-Server: gke-public-cluster-v2-1-179-114-13
            X-Xss-Protection: 1
            Connection: close


            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
            3192.168.2.4497521.179.112.1954431432C:\Program Files\Google\Chrome\Application\chrome.exe
            TimestampBytes transferredDirectionData
            2025-01-15 17:20:38 UTC1105OUTPOST /tr/un/do HTTP/1.1
            Host: r.envoi.eeva.net
            Connection: keep-alive
            Content-Length: 269
            Cache-Control: max-age=0
            sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
            sec-ch-ua-mobile: ?0
            sec-ch-ua-platform: "Windows"
            Upgrade-Insecure-Requests: 1
            Origin: https://r.envoi.eeva.net
            Content-Type: application/x-www-form-urlencoded
            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
            Sec-Fetch-Site: same-origin
            Sec-Fetch-Mode: navigate
            Sec-Fetch-User: ?1
            Sec-Fetch-Dest: document
            Referer: https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI
            Accept-Encoding: gzip, deflate, br
            Accept-Language: en-US,en;q=0.9
            2025-01-15 17:20:38 UTC269OUTData Raw: 65 6e 63 72 79 70 74 65 64 44 61 74 61 3d 6b 77 65 7a 59 74 30 78 36 34 39 2d 76 4d 79 31 2d 64 33 6d 38 58 57 6d 30 58 44 47 39 74 64 51 47 58 77 69 4e 75 4d 32 4c 47 42 6b 6f 45 5f 58 56 53 70 39 77 4b 52 4b 54 54 6f 38 34 7a 6c 56 42 33 30 64 74 45 34 51 78 62 36 62 54 64 51 37 42 4c 69 58 79 34 76 4a 4c 4e 47 61 4d 71 47 75 70 42 4e 75 36 4b 69 74 57 5f 41 52 31 75 71 65 79 57 55 34 47 31 4a 62 73 38 79 37 48 2d 46 54 57 70 48 2d 6b 55 6c 7a 65 42 56 49 49 5a 68 65 7a 45 69 78 5f 4a 75 65 78 6e 34 5a 49 4f 78 4a 76 5a 6e 74 76 6a 61 56 4f 5a 52 61 75 63 65 2d 54 51 51 6a 49 73 4d 64 74 51 65 39 32 48 51 48 46 5a 34 75 71 55 72 78 65 44 6c 50 63 63 41 6f 39 59 68 77 79 39 46 43 5a 47 52 69 63 56 72 46 44 70 38 70 58 67 4a 7a 6d 2d 31 37 75 5f 68 33 50
            Data Ascii: encryptedData=kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3P
            2025-01-15 17:20:38 UTC241INHTTP/1.1 200 OK
            Content-Length: 844
            Content-Type: text/html; charset=utf-8
            Date: Wed, 15 Jan 2025 17:20:38 GMT
            X-Content-Type-Options: nosniff
            X-Sib-Server: gke-public-cluster-v2-1-179-112-171
            X-Xss-Protection: 1
            Connection: close
            2025-01-15 17:20:38 UTC844INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 09 3c 68 65 61 64 3e 0a 09 09 3c 74 69 74 6c 65 3e 42 72 65 76 6f 20 7c 20 3c 2f 74 69 74 6c 65 3e 0a 0a 09 09 0a 09 09 3c 6c 69 6e 6b 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 66 6f 6e 74 73 2e 67 6f 6f 67 6c 65 61 70 69 73 2e 63 6f 6d 2f 63 73 73 3f 66 61 6d 69 6c 79 3d 4f 70 65 6e 2b 53 61 6e 73 3a 34 30 30 2c 37 30 30 22 20 72 65 6c 3d 22 73 74 79 6c 65 73 68 65 65 74 22 3e 0a 0a 09 09 3c 73 74 79 6c 65 3e 0a 09 09 09 68 74 6d 6c 2c 20 62 6f 64 79 20 7b 0a 09 09 09 09 68 65 69 67 68 74 3a 20 31 30 30 25 3b 0a 09 09 09 7d 0a 09 09 09 62 6f 64 79 2c 20 62 75 74 74 6f 6e 2c 20 69 6e 70 75 74 20 7b 0a 09 09 09 09 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 20 27 4f 70 65 6e 20 53 61 6e 73 27
            Data Ascii: <!DOCTYPE html><html><head><title>Brevo | </title><link href="https://fonts.googleapis.com/css?family=Open+Sans:400,700" rel="stylesheet"><style>html, body {height: 100%;}body, button, input {font-family: 'Open Sans'


            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:12:20:11
            Start date:15/01/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:12:20:15
            Start date:15/01/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2012,i,6330271476746337855,15990199757900187295,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:12:20:21
            Start date:15/01/2025
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly