Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://hqqak.ondigitalocean.app

Overview

General Information

Sample URL:http://hqqak.ondigitalocean.app
Analysis ID:1391073
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 6128 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5724 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1952,i,15935143292258005548,8705793493078961674,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6580 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://hqqak.ondigitalocean.app MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: classification engineClassification label: unknown0.win@19/0@16/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1952,i,15935143292258005548,8705793493078961674,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://hqqak.ondigitalocean.app
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1952,i,15935143292258005548,8705793493078961674,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://hqqak.ondigitalocean.app0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
172.253.126.138
truefalse
    high
    accounts.google.com
    74.125.138.84
    truefalse
      high
      www.google.com
      64.233.185.99
      truefalse
        high
        clients.l.google.com
        173.194.219.139
        truefalse
          high
          fp2e7a.wpc.phicdn.net
          192.229.211.108
          truefalse
            unknown
            clients2.google.com
            unknown
            unknownfalse
              high
              hqqak.ondigitalocean.app
              unknown
              unknownfalse
                unknown
                NameMaliciousAntivirus DetectionReputation
                https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
                  high
                  https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    173.194.219.139
                    clients.l.google.comUnited States
                    15169GOOGLEUSfalse
                    74.125.138.84
                    accounts.google.comUnited States
                    15169GOOGLEUSfalse
                    64.233.185.99
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    IP
                    192.168.2.4
                    Joe Sandbox version:40.0.0 Tourmaline
                    Analysis ID:1391073
                    Start date and time:2024-02-12 20:20:50 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 1m 59s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:http://hqqak.ondigitalocean.app
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:5
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:UNKNOWN
                    Classification:unknown0.win@19/0@16/5
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    Cookbook Comments:
                    • URL browsing timeout or error
                    • URL not reachable
                    • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 74.125.136.94, 34.104.35.123, 23.33.136.127, 52.165.165.26, 72.21.81.240, 192.229.211.108, 20.242.39.171
                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, wu.ec.azureedge.net, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu-bg-shim.trafficmanager.net, wu.azureedge.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                    • Not all processes where analyzed, report is missing behavior information
                    • Report size getting too big, too many NtOpenFile calls found.
                    • Report size getting too big, too many NtSetInformationFile calls found.
                    • VT rate limit hit for: http://hqqak.ondigitalocean.app
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    No context
                    No created / dropped files found
                    No static file info
                    TimestampSource PortDest PortSource IPDest IP
                    Feb 12, 2024 20:21:32.599805117 CET49678443192.168.2.4104.46.162.224
                    Feb 12, 2024 20:21:33.849692106 CET49675443192.168.2.4173.222.162.32
                    Feb 12, 2024 20:21:40.604290009 CET49730443192.168.2.474.125.138.84
                    Feb 12, 2024 20:21:40.604337931 CET4434973074.125.138.84192.168.2.4
                    Feb 12, 2024 20:21:40.604398012 CET49730443192.168.2.474.125.138.84
                    Feb 12, 2024 20:21:40.604795933 CET49731443192.168.2.4173.194.219.139
                    Feb 12, 2024 20:21:40.604885101 CET44349731173.194.219.139192.168.2.4
                    Feb 12, 2024 20:21:40.604950905 CET49731443192.168.2.4173.194.219.139
                    Feb 12, 2024 20:21:40.605338097 CET49730443192.168.2.474.125.138.84
                    Feb 12, 2024 20:21:40.605356932 CET4434973074.125.138.84192.168.2.4
                    Feb 12, 2024 20:21:40.605463982 CET49731443192.168.2.4173.194.219.139
                    Feb 12, 2024 20:21:40.605503082 CET44349731173.194.219.139192.168.2.4
                    Feb 12, 2024 20:21:40.851958036 CET44349731173.194.219.139192.168.2.4
                    Feb 12, 2024 20:21:40.852572918 CET49731443192.168.2.4173.194.219.139
                    Feb 12, 2024 20:21:40.852638960 CET44349731173.194.219.139192.168.2.4
                    Feb 12, 2024 20:21:40.853236914 CET44349731173.194.219.139192.168.2.4
                    Feb 12, 2024 20:21:40.853308916 CET49731443192.168.2.4173.194.219.139
                    Feb 12, 2024 20:21:40.854379892 CET44349731173.194.219.139192.168.2.4
                    Feb 12, 2024 20:21:40.854433060 CET49731443192.168.2.4173.194.219.139
                    Feb 12, 2024 20:21:40.856523037 CET49731443192.168.2.4173.194.219.139
                    Feb 12, 2024 20:21:40.856592894 CET44349731173.194.219.139192.168.2.4
                    Feb 12, 2024 20:21:40.857892990 CET49731443192.168.2.4173.194.219.139
                    Feb 12, 2024 20:21:40.857913017 CET44349731173.194.219.139192.168.2.4
                    Feb 12, 2024 20:21:40.861825943 CET4434973074.125.138.84192.168.2.4
                    Feb 12, 2024 20:21:40.862055063 CET49730443192.168.2.474.125.138.84
                    Feb 12, 2024 20:21:40.862133980 CET4434973074.125.138.84192.168.2.4
                    Feb 12, 2024 20:21:40.863558054 CET4434973074.125.138.84192.168.2.4
                    Feb 12, 2024 20:21:40.863626957 CET49730443192.168.2.474.125.138.84
                    Feb 12, 2024 20:21:40.865442038 CET49730443192.168.2.474.125.138.84
                    Feb 12, 2024 20:21:40.865606070 CET49730443192.168.2.474.125.138.84
                    Feb 12, 2024 20:21:40.865617990 CET4434973074.125.138.84192.168.2.4
                    Feb 12, 2024 20:21:40.865637064 CET4434973074.125.138.84192.168.2.4
                    Feb 12, 2024 20:21:40.910648108 CET49730443192.168.2.474.125.138.84
                    Feb 12, 2024 20:21:40.910672903 CET4434973074.125.138.84192.168.2.4
                    Feb 12, 2024 20:21:40.957534075 CET49730443192.168.2.474.125.138.84
                    Feb 12, 2024 20:21:41.061444044 CET44349731173.194.219.139192.168.2.4
                    Feb 12, 2024 20:21:41.061556101 CET49731443192.168.2.4173.194.219.139
                    Feb 12, 2024 20:21:41.061618090 CET44349731173.194.219.139192.168.2.4
                    Feb 12, 2024 20:21:41.061754942 CET44349731173.194.219.139192.168.2.4
                    Feb 12, 2024 20:21:41.061827898 CET49731443192.168.2.4173.194.219.139
                    Feb 12, 2024 20:21:41.062975883 CET49731443192.168.2.4173.194.219.139
                    Feb 12, 2024 20:21:41.063010931 CET44349731173.194.219.139192.168.2.4
                    Feb 12, 2024 20:21:41.107021093 CET4434973074.125.138.84192.168.2.4
                    Feb 12, 2024 20:21:41.107184887 CET49730443192.168.2.474.125.138.84
                    Feb 12, 2024 20:21:41.107245922 CET4434973074.125.138.84192.168.2.4
                    Feb 12, 2024 20:21:41.107604980 CET4434973074.125.138.84192.168.2.4
                    Feb 12, 2024 20:21:41.107671022 CET49730443192.168.2.474.125.138.84
                    Feb 12, 2024 20:21:41.108674049 CET49730443192.168.2.474.125.138.84
                    Feb 12, 2024 20:21:41.108701944 CET4434973074.125.138.84192.168.2.4
                    Feb 12, 2024 20:21:43.458081007 CET49675443192.168.2.4173.222.162.32
                    Feb 12, 2024 20:21:44.402692080 CET49736443192.168.2.464.233.185.99
                    Feb 12, 2024 20:21:44.402779102 CET4434973664.233.185.99192.168.2.4
                    Feb 12, 2024 20:21:44.402883053 CET49736443192.168.2.464.233.185.99
                    Feb 12, 2024 20:21:44.403661013 CET49736443192.168.2.464.233.185.99
                    Feb 12, 2024 20:21:44.403693914 CET4434973664.233.185.99192.168.2.4
                    Feb 12, 2024 20:21:44.616919994 CET4434973664.233.185.99192.168.2.4
                    Feb 12, 2024 20:21:44.630752087 CET49736443192.168.2.464.233.185.99
                    Feb 12, 2024 20:21:44.630822897 CET4434973664.233.185.99192.168.2.4
                    Feb 12, 2024 20:21:44.631829023 CET4434973664.233.185.99192.168.2.4
                    Feb 12, 2024 20:21:44.631906033 CET49736443192.168.2.464.233.185.99
                    Feb 12, 2024 20:21:44.635051966 CET49736443192.168.2.464.233.185.99
                    Feb 12, 2024 20:21:44.635122061 CET4434973664.233.185.99192.168.2.4
                    Feb 12, 2024 20:21:44.676290989 CET49736443192.168.2.464.233.185.99
                    Feb 12, 2024 20:21:44.676353931 CET4434973664.233.185.99192.168.2.4
                    Feb 12, 2024 20:21:44.723155975 CET49736443192.168.2.464.233.185.99
                    Feb 12, 2024 20:21:54.623493910 CET4434973664.233.185.99192.168.2.4
                    Feb 12, 2024 20:21:54.623562098 CET4434973664.233.185.99192.168.2.4
                    Feb 12, 2024 20:21:54.623670101 CET49736443192.168.2.464.233.185.99
                    Feb 12, 2024 20:21:54.745167017 CET49736443192.168.2.464.233.185.99
                    Feb 12, 2024 20:21:54.745194912 CET4434973664.233.185.99192.168.2.4
                    TimestampSource PortDest PortSource IPDest IP
                    Feb 12, 2024 20:21:40.465600014 CET6515353192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:40.466326952 CET4997253192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:40.467320919 CET5107453192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:40.467489958 CET5470153192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:40.561754942 CET53644721.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:40.583646059 CET53651531.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:40.584861040 CET53510741.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:40.584898949 CET53547011.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:40.588207006 CET53499721.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:41.267380953 CET53647211.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:41.767940998 CET5129353192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:41.768529892 CET5649753192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:41.890548944 CET53564971.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:41.891395092 CET53512931.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:41.893280983 CET5073653192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:42.013825893 CET53507361.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:42.047580957 CET5244253192.168.2.48.8.8.8
                    Feb 12, 2024 20:21:42.048336029 CET5496553192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:42.151277065 CET53524428.8.8.8192.168.2.4
                    Feb 12, 2024 20:21:42.166347980 CET53549651.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:43.060059071 CET5275053192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:43.060400963 CET5897653192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:43.181941032 CET53589761.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:43.190023899 CET53527501.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:44.274250984 CET6386153192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:44.275110960 CET5555753192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:44.391999960 CET53638611.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:44.392648935 CET53555571.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:48.618279934 CET5602753192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:48.619385958 CET6028853192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:48.738667965 CET53560271.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:48.741564989 CET53602881.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:48.742269993 CET6196953192.168.2.41.1.1.1
                    Feb 12, 2024 20:21:48.860986948 CET53619691.1.1.1192.168.2.4
                    Feb 12, 2024 20:21:58.347155094 CET53596871.1.1.1192.168.2.4
                    Feb 12, 2024 20:22:03.122836113 CET138138192.168.2.4192.168.2.255
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Feb 12, 2024 20:21:40.465600014 CET192.168.2.41.1.1.10x288cStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:40.466326952 CET192.168.2.41.1.1.10x4758Standard query (0)clients2.google.com65IN (0x0001)false
                    Feb 12, 2024 20:21:40.467320919 CET192.168.2.41.1.1.10xa52Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:40.467489958 CET192.168.2.41.1.1.10xa96dStandard query (0)accounts.google.com65IN (0x0001)false
                    Feb 12, 2024 20:21:41.767940998 CET192.168.2.41.1.1.10xe3b4Standard query (0)hqqak.ondigitalocean.appA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:41.768529892 CET192.168.2.41.1.1.10x5d05Standard query (0)hqqak.ondigitalocean.app65IN (0x0001)false
                    Feb 12, 2024 20:21:41.893280983 CET192.168.2.41.1.1.10xfa9aStandard query (0)hqqak.ondigitalocean.appA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.047580957 CET192.168.2.48.8.8.80xa7daStandard query (0)google.comA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.048336029 CET192.168.2.41.1.1.10xd3c9Standard query (0)google.comA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:43.060059071 CET192.168.2.41.1.1.10x7a3aStandard query (0)hqqak.ondigitalocean.appA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:43.060400963 CET192.168.2.41.1.1.10x3867Standard query (0)hqqak.ondigitalocean.app65IN (0x0001)false
                    Feb 12, 2024 20:21:44.274250984 CET192.168.2.41.1.1.10xfa8cStandard query (0)www.google.comA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:44.275110960 CET192.168.2.41.1.1.10x9b4eStandard query (0)www.google.com65IN (0x0001)false
                    Feb 12, 2024 20:21:48.618279934 CET192.168.2.41.1.1.10x44c3Standard query (0)hqqak.ondigitalocean.appA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:48.619385958 CET192.168.2.41.1.1.10x5430Standard query (0)hqqak.ondigitalocean.app65IN (0x0001)false
                    Feb 12, 2024 20:21:48.742269993 CET192.168.2.41.1.1.10x5aadStandard query (0)hqqak.ondigitalocean.appA (IP address)IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Feb 12, 2024 20:21:40.583646059 CET1.1.1.1192.168.2.40x288cNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Feb 12, 2024 20:21:40.583646059 CET1.1.1.1192.168.2.40x288cNo error (0)clients.l.google.com173.194.219.139A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:40.583646059 CET1.1.1.1192.168.2.40x288cNo error (0)clients.l.google.com173.194.219.101A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:40.583646059 CET1.1.1.1192.168.2.40x288cNo error (0)clients.l.google.com173.194.219.138A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:40.583646059 CET1.1.1.1192.168.2.40x288cNo error (0)clients.l.google.com173.194.219.113A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:40.583646059 CET1.1.1.1192.168.2.40x288cNo error (0)clients.l.google.com173.194.219.100A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:40.583646059 CET1.1.1.1192.168.2.40x288cNo error (0)clients.l.google.com173.194.219.102A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:40.584861040 CET1.1.1.1192.168.2.40xa52No error (0)accounts.google.com74.125.138.84A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:40.588207006 CET1.1.1.1192.168.2.40x4758No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                    Feb 12, 2024 20:21:41.890548944 CET1.1.1.1192.168.2.40x5d05Name error (3)hqqak.ondigitalocean.appnonenone65IN (0x0001)false
                    Feb 12, 2024 20:21:41.891395092 CET1.1.1.1192.168.2.40xe3b4Name error (3)hqqak.ondigitalocean.appnonenoneA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.013825893 CET1.1.1.1192.168.2.40xfa9aName error (3)hqqak.ondigitalocean.appnonenoneA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.151277065 CET8.8.8.8192.168.2.40xa7daNo error (0)google.com172.253.126.138A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.151277065 CET8.8.8.8192.168.2.40xa7daNo error (0)google.com172.253.126.100A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.151277065 CET8.8.8.8192.168.2.40xa7daNo error (0)google.com172.253.126.102A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.151277065 CET8.8.8.8192.168.2.40xa7daNo error (0)google.com172.253.126.101A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.151277065 CET8.8.8.8192.168.2.40xa7daNo error (0)google.com172.253.126.139A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.151277065 CET8.8.8.8192.168.2.40xa7daNo error (0)google.com172.253.126.113A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.166347980 CET1.1.1.1192.168.2.40xd3c9No error (0)google.com74.125.138.102A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.166347980 CET1.1.1.1192.168.2.40xd3c9No error (0)google.com74.125.138.101A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.166347980 CET1.1.1.1192.168.2.40xd3c9No error (0)google.com74.125.138.100A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.166347980 CET1.1.1.1192.168.2.40xd3c9No error (0)google.com74.125.138.138A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.166347980 CET1.1.1.1192.168.2.40xd3c9No error (0)google.com74.125.138.113A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:42.166347980 CET1.1.1.1192.168.2.40xd3c9No error (0)google.com74.125.138.139A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:43.181941032 CET1.1.1.1192.168.2.40x3867Name error (3)hqqak.ondigitalocean.appnonenone65IN (0x0001)false
                    Feb 12, 2024 20:21:43.190023899 CET1.1.1.1192.168.2.40x7a3aName error (3)hqqak.ondigitalocean.appnonenoneA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:44.391999960 CET1.1.1.1192.168.2.40xfa8cNo error (0)www.google.com64.233.185.99A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:44.391999960 CET1.1.1.1192.168.2.40xfa8cNo error (0)www.google.com64.233.185.104A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:44.391999960 CET1.1.1.1192.168.2.40xfa8cNo error (0)www.google.com64.233.185.103A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:44.391999960 CET1.1.1.1192.168.2.40xfa8cNo error (0)www.google.com64.233.185.147A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:44.391999960 CET1.1.1.1192.168.2.40xfa8cNo error (0)www.google.com64.233.185.105A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:44.391999960 CET1.1.1.1192.168.2.40xfa8cNo error (0)www.google.com64.233.185.106A (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:44.392648935 CET1.1.1.1192.168.2.40x9b4eNo error (0)www.google.com65IN (0x0001)false
                    Feb 12, 2024 20:21:48.738667965 CET1.1.1.1192.168.2.40x44c3Name error (3)hqqak.ondigitalocean.appnonenoneA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:48.741564989 CET1.1.1.1192.168.2.40x5430Name error (3)hqqak.ondigitalocean.appnonenone65IN (0x0001)false
                    Feb 12, 2024 20:21:48.860986948 CET1.1.1.1192.168.2.40x5aadName error (3)hqqak.ondigitalocean.appnonenoneA (IP address)IN (0x0001)false
                    Feb 12, 2024 20:21:57.567015886 CET1.1.1.1192.168.2.40xb7ccNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                    Feb 12, 2024 20:21:57.567015886 CET1.1.1.1192.168.2.40xb7ccNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                    • clients2.google.com
                    • accounts.google.com
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.449731173.194.219.1394435724C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-02-12 19:21:40 UTC752OUTGET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1
                    Host: clients2.google.com
                    Connection: keep-alive
                    X-Goog-Update-Interactivity: fg
                    X-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda
                    X-Goog-Update-Updater: chromecrx-117.0.5938.132
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    2024-02-12 19:21:41 UTC732INHTTP/1.1 200 OK
                    Content-Security-Policy: script-src 'report-sample' 'nonce-rt3xb4RTg6rln9bxBw9d6g' 'unsafe-inline' 'strict-dynamic' https: http:;object-src 'none';base-uri 'self';report-uri https://csp.withgoogle.com/csp/clientupdate-aus/1
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Mon, 12 Feb 2024 19:21:41 GMT
                    Content-Type: text/xml; charset=UTF-8
                    X-Daynum: 6251
                    X-Daystart: 40901
                    X-Content-Type-Options: nosniff
                    X-Frame-Options: SAMEORIGIN
                    X-XSS-Protection: 1; mode=block
                    Server: GSE
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2024-02-12 19:21:41 UTC520INData Raw: 32 63 39 0d 0a 3c 3f 78 6d 6c 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 22 20 65 6e 63 6f 64 69 6e 67 3d 22 55 54 46 2d 38 22 3f 3e 3c 67 75 70 64 61 74 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 2f 75 70 64 61 74 65 32 2f 72 65 73 70 6f 6e 73 65 22 20 70 72 6f 74 6f 63 6f 6c 3d 22 32 2e 30 22 20 73 65 72 76 65 72 3d 22 70 72 6f 64 22 3e 3c 64 61 79 73 74 61 72 74 20 65 6c 61 70 73 65 64 5f 64 61 79 73 3d 22 36 32 35 31 22 20 65 6c 61 70 73 65 64 5f 73 65 63 6f 6e 64 73 3d 22 34 30 39 30 31 22 2f 3e 3c 61 70 70 20 61 70 70 69 64 3d 22 6e 6d 6d 68 6b 6b 65 67 63 63 61 67 64 6c 64 67 69 69 6d 65 64 70 69 63 63 6d 67 6d 69 65 64 61 22 20 63 6f 68 6f 72 74 3d 22 31 3a 3a 22 20 63 6f 68 6f 72 74 6e 61 6d 65 3d 22 22
                    Data Ascii: 2c9<?xml version="1.0" encoding="UTF-8"?><gupdate xmlns="http://www.google.com/update2/response" protocol="2.0" server="prod"><daystart elapsed_days="6251" elapsed_seconds="40901"/><app appid="nmmhkkegccagdldgiimedpiccmgmieda" cohort="1::" cohortname=""
                    2024-02-12 19:21:41 UTC200INData Raw: 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 68 61 73 68 5f 73 68 61 32 35 36 3d 22 38 31 65 33 61 34 64 34 33 61 37 33 36 39 39 65 31 62 37 37 38 31 37 32 33 66 35 36 62 38 37 31 37 31 37 35 63 35 33 36 36 38 35 63 35 34 35 30 31 32 32 62 33 30 37 38 39 34 36 34 61 64 38 32 22 20 70 72 6f 74 65 63 74 65 64 3d 22 30 22 20 73 69 7a 65 3d 22 32 34 38 35 33 31 22 20 73 74 61 74 75 73 3d 22 6f 6b 22 20 76 65 72 73 69 6f 6e 3d 22 31 2e 30 2e 30 2e 36 22 2f 3e 3c 2f 61 70 70 3e 3c 2f 67 75 70 64 61 74 65 3e 0d 0a
                    Data Ascii: 723f56b8717175c536685c5450122b30789464ad82" hash_sha256="81e3a4d43a73699e1b7781723f56b8717175c536685c5450122b30789464ad82" protected="0" size="248531" status="ok" version="1.0.0.6"/></app></gupdate>
                    2024-02-12 19:21:41 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    1192.168.2.44973074.125.138.844435724C:\Program Files\Google\Chrome\Application\chrome.exe
                    TimestampBytes transferredDirectionData
                    2024-02-12 19:21:40 UTC680OUTPOST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1
                    Host: accounts.google.com
                    Connection: keep-alive
                    Content-Length: 1
                    Origin: https://www.google.com
                    Content-Type: application/x-www-form-urlencoded
                    Sec-Fetch-Site: none
                    Sec-Fetch-Mode: no-cors
                    Sec-Fetch-Dest: empty
                    User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                    Accept-Encoding: gzip, deflate, br
                    Accept-Language: en-US,en;q=0.9
                    Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
                    2024-02-12 19:21:40 UTC1OUTData Raw: 20
                    Data Ascii:
                    2024-02-12 19:21:41 UTC1798INHTTP/1.1 200 OK
                    Content-Type: application/json; charset=utf-8
                    Access-Control-Allow-Origin: https://www.google.com
                    Access-Control-Allow-Credentials: true
                    X-Content-Type-Options: nosniff
                    Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                    Pragma: no-cache
                    Expires: Mon, 01 Jan 1990 00:00:00 GMT
                    Date: Mon, 12 Feb 2024 19:21:41 GMT
                    Strict-Transport-Security: max-age=31536000; includeSubDomains
                    Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factor=*, ch-ua-platform=*, ch-ua-platform-version=*
                    Content-Security-Policy: script-src 'report-sample' 'nonce-O8MTLWxM2ZiEhSS-35UX8A' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/IdentityListAccountsHttp/cspreport;worker-src 'self'
                    Content-Security-Policy: script-src 'unsafe-inline' 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/IdentityListAccountsHttp/cspreport/allowlist
                    Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/IdentityListAccountsHttp/cspreport
                    Cross-Origin-Opener-Policy: same-origin
                    Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factor, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                    reporting-endpoints: default="/_/IdentityListAccountsHttp/web-reports?context=eJzjMtDikmLw1JBiOHxtB5Meyy0mIyCe2_2UaSEQH4x7znQUiHf4eLA4pc9gDQBiIW6Oo_dXrmMTaOjcJwIAnfcWuA"
                    Server: ESF
                    X-XSS-Protection: 0
                    Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                    Accept-Ranges: none
                    Vary: Accept-Encoding
                    Connection: close
                    Transfer-Encoding: chunked
                    2024-02-12 19:21:41 UTC23INData Raw: 31 31 0d 0a 5b 22 67 61 69 61 2e 6c 2e 61 2e 72 22 2c 5b 5d 5d 0d 0a
                    Data Ascii: 11["gaia.l.a.r",[]]
                    2024-02-12 19:21:41 UTC5INData Raw: 30 0d 0a 0d 0a
                    Data Ascii: 0


                    Click to jump to process

                    Click to jump to process

                    Click to jump to process

                    Target ID:0
                    Start time:20:21:36
                    Start date:12/02/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:2
                    Start time:20:21:38
                    Start date:12/02/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1952,i,15935143292258005548,8705793493078961674,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:false

                    Target ID:3
                    Start time:20:21:40
                    Start date:12/02/2024
                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                    Wow64 process (32bit):false
                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://hqqak.ondigitalocean.app
                    Imagebase:0x7ff76e190000
                    File size:3'242'272 bytes
                    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Reputation:low
                    Has exited:true

                    No disassembly