Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://zwgaleriamlodych.pl

Overview

General Information

Sample URL:http://zwgaleriamlodych.pl
Analysis ID:1395948
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for domain / URL
Creates files inside the system directory

Classification

  • System is w10x64
  • chrome.exe (PID: 3320 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5228 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=2308,i,2546780249924042766,14441408258148433188,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6508 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://zwgaleriamlodych.pl MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: highperformancedformats.comVirustotal: Detection: 6%Perma Link
Source: https://dilutegulpedshirt.com/t9hiwrkd?key=d928d7c4e235fa6eb6c04ecc0f7abe92&cid=23n0u3tmsl3HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.54.68.82:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.54.68.82:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 23.54.68.82
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-117.0.5938.132Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: zwgaleriamlodych.plConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /t9hiwrkd?key=d928d7c4e235fa6eb6c04ecc0f7abe92&cid=23n0u3tmsl3 HTTP/1.1Host: dilutegulpedshirt.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: dilutegulpedshirt.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-full-version: "117.0.5938.132"sec-ch-ua-platform-version: "10.0.0"sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.132", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.132"sec-ch-ua-model: ""sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://dilutegulpedshirt.com/t9hiwrkd?key=d928d7c4e235fa6eb6c04ecc0f7abe92&cid=23n0u3tmsl3Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: u_pl=15107318
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: dilutegulpedshirt.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: u_pl=15107318
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /anonymous/ HTTP/1.1Host: highperformancedformats.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: NID=511=j8SQUTltnVU5cOAeyzqSxW-qHOakRuBHDQGLTGeceC9Z5rRzk5trMKb4CuZC_CFmc7KFwQcRJL-qGz8MvkkzMZmElvXAFWLO-TPZ9PMqBYA78ZAuaepnXIRHe-TAolVoW6Z7dQnqpgyX0m-TmS72bebAgoqZv5GkpRFUcZIw1Kk
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: nginx/1.21.6Date: Wed, 21 Feb 2024 08:24:57 GMTContent-Type: text/htmlContent-Length: 0Connection: keep-aliveP3P: CP="IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT"Accept-CH: Device-Stock-UA,Sec-CH-UA,Sec-CH-UA-Full-Version,Sec-CH-UA-Full-Version-List,Sec-CH-UA-Mobile,Sec-CH-UA-Model,Sec-CH-UA-Platform,Sec-CH-UA-Platform-Version,User-Agent,X-Device-User-Agent,X-OperaMini-Phone-UA,X-UCBrowser-Device-UA
Source: chromecache_41.1.drString found in binary or memory: http://highperformancedformats.com/anonymous/
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.54.68.82:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.54.68.82:443 -> 192.168.2.4:49743 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_3320_1322997098Jump to behavior
Source: classification engineClassification label: mal48.win@19/2@16/9
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=2308,i,2546780249924042766,14441408258148433188,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://zwgaleriamlodych.pl
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=2308,i,2546780249924042766,14441408258148433188,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://zwgaleriamlodych.pl0%Avira URL Cloudsafe
http://zwgaleriamlodych.pl0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
dilutegulpedshirt.com1%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
highperformancedformats.com7%VirustotalBrowse
zwgaleriamlodych.pl0%VirustotalBrowse
SourceDetectionScannerLabelLink
https://zwgaleriamlodych.pl/0%Avira URL Cloudsafe
http://highperformancedformats.com/anonymous/0%Avira URL Cloudsafe
https://dilutegulpedshirt.com/favicon.ico0%Avira URL Cloudsafe
https://zwgaleriamlodych.pl/0%VirustotalBrowse
http://highperformancedformats.com/anonymous/3%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
dilutegulpedshirt.com
192.243.61.227
truefalseunknown
accounts.google.com
172.253.122.84
truefalse
    high
    highperformancedformats.com
    172.240.108.76
    truefalseunknown
    www.google.com
    142.251.35.164
    truefalse
      high
      clients.l.google.com
      142.250.65.174
      truefalse
        high
        zwgaleriamlodych.pl
        172.67.160.242
        truefalseunknown
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalseunknown
        clients2.google.com
        unknown
        unknownfalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://zwgaleriamlodych.pl/false
          • 0%, Virustotal, Browse
          • Avira URL Cloud: safe
          unknown
          https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1false
            high
            https://dilutegulpedshirt.com/favicon.icofalse
            • Avira URL Cloud: safe
            unknown
            https://dilutegulpedshirt.com/t9hiwrkd?key=d928d7c4e235fa6eb6c04ecc0f7abe92&cid=23n0u3tmsl3false
              unknown
              https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                high
                http://highperformancedformats.com/anonymous/false
                • 3%, Virustotal, Browse
                • Avira URL Cloud: safe
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                172.240.108.76
                highperformancedformats.comUnited States
                7979SERVERS-COMUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                142.250.65.174
                clients.l.google.comUnited States
                15169GOOGLEUSfalse
                192.243.61.227
                dilutegulpedshirt.comDominica
                39572ADVANCEDHOSTERS-ASNLfalse
                172.240.108.84
                unknownUnited States
                7979SERVERS-COMUSfalse
                104.21.9.178
                unknownUnited States
                13335CLOUDFLARENETUSfalse
                142.251.35.164
                www.google.comUnited States
                15169GOOGLEUSfalse
                172.253.122.84
                accounts.google.comUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.4
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1395948
                Start date and time:2024-02-21 09:23:48 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 3m 8s
                Hypervisor based Inspection enabled:false
                Report type:light
                Cookbook file name:browseurl.jbs
                Sample URL:http://zwgaleriamlodych.pl
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:7
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal48.win@19/2@16/9
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                Cookbook Comments:
                • Browse: http://highperformancedformats.com/anonymous/
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
                • TCP Packets have been reduced to 100
                • Excluded IPs from analysis (whitelisted): 142.250.65.195, 34.104.35.123, 13.85.23.86, 104.102.251.17, 104.102.251.57, 192.229.211.108, 52.165.164.15, 20.3.187.198, 142.251.40.227
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, glb.sls.prod.dcat.dsp.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtSetInformationFile calls found.
                No simulations
                No context
                No context
                No context
                No context
                No context
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with no line terminators
                Category:downloaded
                Size (bytes):115
                Entropy (8bit):4.719823396275518
                Encrypted:false
                SSDEEP:3:uNXADiFCDRAWMO5h1KRWLRE+Vs2+ZJiNRDs7SGKy:uFAyTWLhgRW2+T+ZJas7Sdy
                MD5:16579CC322E9E105427ECFA57890EF69
                SHA1:8BB47EC30CF894AB49032D7271A45F0C778BAA05
                SHA-256:F28CE5BEFE08ED90A2E12B6B2A5E9FDAFAA6AD173503079155260AA480C66590
                SHA-512:FCF36F77D99F6594929BDED28F200BEE11FAB9B316A5E437567345B8877CFC6707BF8A116C03F07B03C0235B587E71DBD4843560564BAE07BAD2F5B6295CCE3F
                Malicious:false
                Reputation:low
                URL:https://dilutegulpedshirt.com/t9hiwrkd?key=d928d7c4e235fa6eb6c04ecc0f7abe92&cid=23n0u3tmsl3
                Preview:<a href = 'http://highperformancedformats.com/anonymous/' target='_blank'>Anonymous Proxy detected, click here.</a>
                No static file info
                TimestampSource PortDest PortSource IPDest IP
                Feb 21, 2024 09:24:36.143358946 CET49675443192.168.2.4173.222.162.32
                Feb 21, 2024 09:24:42.209597111 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.209681988 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.209758043 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.210087061 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.210109949 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.210161924 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.210534096 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.210566998 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.210803032 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.210815907 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.413261890 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.414351940 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.414361954 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.414804935 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.414859056 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.415807962 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.415854931 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.426202059 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.426259995 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.426382065 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.426388979 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.429553032 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.430176020 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.430231094 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.431695938 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.431768894 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.436444044 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.436537027 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.440104008 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.440120935 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.485451937 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.522351980 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.613079071 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.613236904 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.613291025 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.618107080 CET49731443192.168.2.4142.250.65.174
                Feb 21, 2024 09:24:42.618122101 CET44349731142.250.65.174192.168.2.4
                Feb 21, 2024 09:24:42.646348000 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.646761894 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:42.646841049 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.647708893 CET49730443192.168.2.4172.253.122.84
                Feb 21, 2024 09:24:42.647747993 CET44349730172.253.122.84192.168.2.4
                Feb 21, 2024 09:24:43.693319082 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.693402052 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:43.693501949 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.693700075 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.693717957 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:43.897238970 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:43.897588015 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.897607088 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:43.899080992 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:43.899147987 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.900043964 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.900126934 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:43.900249004 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:43.900257111 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:44.049365044 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:44.303739071 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:44.304162025 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:44.304239988 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:44.308173895 CET49734443192.168.2.4104.21.9.178
                Feb 21, 2024 09:24:44.308196068 CET44349734104.21.9.178192.168.2.4
                Feb 21, 2024 09:24:44.399168015 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.399208069 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.399279118 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.399602890 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.399651051 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.707329035 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.707763910 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.707819939 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.709606886 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.709693909 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.710772991 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.710869074 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.710987091 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.711003065 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.766478062 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.809854031 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.810112000 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.810306072 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.811184883 CET49735443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.811218977 CET44349735192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.887384892 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.887479067 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:44.887559891 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.887871981 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:44.887904882 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.181703091 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.181988955 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:45.182018995 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.182740927 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.183116913 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:45.183151007 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:45.183213949 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.235363007 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:45.277672052 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.277854919 CET44349738192.243.61.227192.168.2.4
                Feb 21, 2024 09:24:45.278012991 CET49738443192.168.2.4192.243.61.227
                Feb 21, 2024 09:24:45.279342890 CET49738443192.168.2.4192.243.61.227
                TimestampSource PortDest PortSource IPDest IP
                Feb 21, 2024 09:24:42.117466927 CET6194253192.168.2.41.1.1.1
                Feb 21, 2024 09:24:42.117759943 CET5249853192.168.2.41.1.1.1
                Feb 21, 2024 09:24:42.118524075 CET5297353192.168.2.41.1.1.1
                Feb 21, 2024 09:24:42.118746042 CET5805653192.168.2.41.1.1.1
                Feb 21, 2024 09:24:42.188942909 CET53508711.1.1.1192.168.2.4
                Feb 21, 2024 09:24:42.205507994 CET53619421.1.1.1192.168.2.4
                Feb 21, 2024 09:24:42.206618071 CET53529731.1.1.1192.168.2.4
                Feb 21, 2024 09:24:42.206737041 CET53524981.1.1.1192.168.2.4
                Feb 21, 2024 09:24:42.206865072 CET53580561.1.1.1192.168.2.4
                Feb 21, 2024 09:24:42.752068043 CET53595461.1.1.1192.168.2.4
                Feb 21, 2024 09:24:43.500464916 CET5734253192.168.2.41.1.1.1
                Feb 21, 2024 09:24:43.500746965 CET5695753192.168.2.41.1.1.1
                Feb 21, 2024 09:24:43.590240955 CET53573421.1.1.1192.168.2.4
                Feb 21, 2024 09:24:43.590987921 CET53569571.1.1.1192.168.2.4
                Feb 21, 2024 09:24:43.592792034 CET5159653192.168.2.41.1.1.1
                Feb 21, 2024 09:24:43.593051910 CET6435853192.168.2.41.1.1.1
                Feb 21, 2024 09:24:43.681495905 CET53515961.1.1.1192.168.2.4
                Feb 21, 2024 09:24:43.692238092 CET53643581.1.1.1192.168.2.4
                Feb 21, 2024 09:24:44.309912920 CET5459053192.168.2.41.1.1.1
                Feb 21, 2024 09:24:44.310506105 CET5952653192.168.2.41.1.1.1
                Feb 21, 2024 09:24:44.398276091 CET53545901.1.1.1192.168.2.4
                Feb 21, 2024 09:24:44.398387909 CET53595261.1.1.1192.168.2.4
                Feb 21, 2024 09:24:45.283561945 CET6094753192.168.2.41.1.1.1
                Feb 21, 2024 09:24:45.283848047 CET6409253192.168.2.41.1.1.1
                Feb 21, 2024 09:24:45.372205973 CET53609471.1.1.1192.168.2.4
                Feb 21, 2024 09:24:45.494402885 CET5680053192.168.2.41.1.1.1
                Feb 21, 2024 09:24:45.495861053 CET5267553192.168.2.41.1.1.1
                Feb 21, 2024 09:24:45.582165003 CET53568001.1.1.1192.168.2.4
                Feb 21, 2024 09:24:45.584068060 CET53526751.1.1.1192.168.2.4
                Feb 21, 2024 09:24:45.631890059 CET53640921.1.1.1192.168.2.4
                Feb 21, 2024 09:24:56.515297890 CET5178553192.168.2.41.1.1.1
                Feb 21, 2024 09:24:56.518250942 CET6531153192.168.2.41.1.1.1
                Feb 21, 2024 09:24:56.864346027 CET53517851.1.1.1192.168.2.4
                Feb 21, 2024 09:24:56.866496086 CET53653111.1.1.1192.168.2.4
                Feb 21, 2024 09:24:59.809118032 CET53494361.1.1.1192.168.2.4
                Feb 21, 2024 09:25:01.943603039 CET138138192.168.2.4192.168.2.255
                Feb 21, 2024 09:25:18.606254101 CET53514861.1.1.1192.168.2.4
                Feb 21, 2024 09:25:41.358896971 CET53505711.1.1.1192.168.2.4
                Feb 21, 2024 09:25:41.386491060 CET53524211.1.1.1192.168.2.4
                TimestampSource IPDest IPChecksumCodeType
                Feb 21, 2024 09:24:45.631989002 CET192.168.2.41.1.1.1c22f(Port unreachable)Destination Unreachable
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Feb 21, 2024 09:24:42.117466927 CET192.168.2.41.1.1.10xb600Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:42.117759943 CET192.168.2.41.1.1.10x7397Standard query (0)clients2.google.com65IN (0x0001)false
                Feb 21, 2024 09:24:42.118524075 CET192.168.2.41.1.1.10x7d25Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:42.118746042 CET192.168.2.41.1.1.10x3e5eStandard query (0)accounts.google.com65IN (0x0001)false
                Feb 21, 2024 09:24:43.500464916 CET192.168.2.41.1.1.10xcf7aStandard query (0)zwgaleriamlodych.plA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:43.500746965 CET192.168.2.41.1.1.10x91deStandard query (0)zwgaleriamlodych.pl65IN (0x0001)false
                Feb 21, 2024 09:24:43.592792034 CET192.168.2.41.1.1.10xed88Standard query (0)zwgaleriamlodych.plA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:43.593051910 CET192.168.2.41.1.1.10x9b2bStandard query (0)zwgaleriamlodych.pl65IN (0x0001)false
                Feb 21, 2024 09:24:44.309912920 CET192.168.2.41.1.1.10x91f0Standard query (0)dilutegulpedshirt.comA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.310506105 CET192.168.2.41.1.1.10x5c0eStandard query (0)dilutegulpedshirt.com65IN (0x0001)false
                Feb 21, 2024 09:24:45.283561945 CET192.168.2.41.1.1.10x4be0Standard query (0)dilutegulpedshirt.comA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.283848047 CET192.168.2.41.1.1.10xe477Standard query (0)dilutegulpedshirt.com65IN (0x0001)false
                Feb 21, 2024 09:24:45.494402885 CET192.168.2.41.1.1.10x352bStandard query (0)www.google.comA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.495861053 CET192.168.2.41.1.1.10x40eeStandard query (0)www.google.com65IN (0x0001)false
                Feb 21, 2024 09:24:56.515297890 CET192.168.2.41.1.1.10x6d47Standard query (0)highperformancedformats.comA (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.518250942 CET192.168.2.41.1.1.10x9b8eStandard query (0)highperformancedformats.com65IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Feb 21, 2024 09:24:42.205507994 CET1.1.1.1192.168.2.40xb600No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 09:24:42.205507994 CET1.1.1.1192.168.2.40xb600No error (0)clients.l.google.com142.250.65.174A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:42.206618071 CET1.1.1.1192.168.2.40x7d25No error (0)accounts.google.com172.253.122.84A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:42.206737041 CET1.1.1.1192.168.2.40x7397No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 09:24:43.590240955 CET1.1.1.1192.168.2.40xcf7aNo error (0)zwgaleriamlodych.pl172.67.160.242A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:43.590240955 CET1.1.1.1192.168.2.40xcf7aNo error (0)zwgaleriamlodych.pl104.21.9.178A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:43.590987921 CET1.1.1.1192.168.2.40x91deNo error (0)zwgaleriamlodych.pl65IN (0x0001)false
                Feb 21, 2024 09:24:43.681495905 CET1.1.1.1192.168.2.40xed88No error (0)zwgaleriamlodych.pl104.21.9.178A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:43.681495905 CET1.1.1.1192.168.2.40xed88No error (0)zwgaleriamlodych.pl172.67.160.242A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:43.692238092 CET1.1.1.1192.168.2.40x9b2bNo error (0)zwgaleriamlodych.pl65IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com192.243.61.227A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com192.243.59.20A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com172.240.108.76A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com192.243.59.13A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com172.240.253.132A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com172.240.108.84A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com192.243.61.225A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com192.243.59.12A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com172.240.108.92A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:44.398276091 CET1.1.1.1192.168.2.40x91f0No error (0)dilutegulpedshirt.com172.240.108.68A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com172.240.108.84A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com172.240.108.76A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com192.243.61.227A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com172.240.108.68A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com192.243.59.20A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com192.243.59.13A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com172.240.253.132A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com192.243.61.225A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com172.240.108.92A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.372205973 CET1.1.1.1192.168.2.40x4be0No error (0)dilutegulpedshirt.com192.243.59.12A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.582165003 CET1.1.1.1192.168.2.40x352bNo error (0)www.google.com142.251.35.164A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:45.584068060 CET1.1.1.1192.168.2.40x40eeNo error (0)www.google.com65IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com172.240.108.76A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com192.243.61.227A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com192.243.59.13A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com172.240.108.84A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com172.240.108.92A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com172.240.253.132A (IP address)IN (0x0001)false
                Feb 21, 2024 09:24:56.864346027 CET1.1.1.1192.168.2.40x6d47No error (0)highperformancedformats.com192.243.61.225A (IP address)IN (0x0001)false
                Feb 21, 2024 09:25:00.207549095 CET1.1.1.1192.168.2.40x62eeNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 09:25:00.207549095 CET1.1.1.1192.168.2.40x62eeNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Feb 21, 2024 09:25:14.933439016 CET1.1.1.1192.168.2.40xea2eNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 09:25:14.933439016 CET1.1.1.1192.168.2.40xea2eNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Feb 21, 2024 09:25:33.668837070 CET1.1.1.1192.168.2.40xeb0aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 09:25:33.668837070 CET1.1.1.1192.168.2.40xeb0aNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                Feb 21, 2024 09:25:54.199307919 CET1.1.1.1192.168.2.40x2482No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                Feb 21, 2024 09:25:54.199307919 CET1.1.1.1192.168.2.40x2482No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
                • clients2.google.com
                • accounts.google.com
                • zwgaleriamlodych.pl
                • dilutegulpedshirt.com
                • https:
                • fs.microsoft.com
                • highperformancedformats.com

                Click to jump to process

                Target ID:0
                Start time:09:24:38
                Start date:21/02/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:1
                Start time:09:24:40
                Start date:21/02/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=2308,i,2546780249924042766,14441408258148433188,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:false

                Target ID:3
                Start time:09:24:42
                Start date:21/02/2024
                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                Wow64 process (32bit):false
                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://zwgaleriamlodych.pl
                Imagebase:0x7ff76e190000
                File size:3'242'272 bytes
                MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:low
                Has exited:true

                No disassembly