Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://affordabletowingdesmoines.com

Overview

General Information

Sample URL:http://affordabletowingdesmoines.com
Analysis ID:1428212
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

Analysis Advice

Joe Sandbox was unable to browse the URL (domain or webserver down or HTTPS issue), try to browse the URL again later
Uses HTTPS for network communication, use the 'Proxy HTTPS (port 443) to read its encrypted data' cookbook for further analysis
  • System is w10x64
  • chrome.exe (PID: 2120 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2124 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2308 --field-trial-handle=2216,i,15104209022405836196,5877275991956964550,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6436 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://affordabletowingdesmoines.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownDNS traffic detected: queries for: affordabletowingdesmoines.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: unknown0.win@19/0@12/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2308 --field-trial-handle=2216,i,15104209022405836196,5877275991956964550,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://affordabletowingdesmoines.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2308 --field-trial-handle=2216,i,15104209022405836196,5877275991956964550,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    google.com
    173.194.219.101
    truefalse
      high
      www.google.com
      142.250.9.147
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          affordabletowingdesmoines.com
          unknown
          unknownfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            142.250.9.147
            www.google.comUnited States
            15169GOOGLEUSfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1428212
            Start date and time:2024-04-18 16:54:39 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 1m 56s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:http://affordabletowingdesmoines.com
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:5
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@19/0@12/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 173.194.219.94, 142.250.105.84, 74.125.138.100, 74.125.138.113, 74.125.138.139, 74.125.138.138, 74.125.138.101, 74.125.138.102, 34.104.35.123, 23.201.212.130, 13.85.23.86, 199.232.214.172, 192.229.211.108, 20.166.126.56
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: http://affordabletowingdesmoines.com
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Apr 18, 2024 16:55:21.552403927 CEST49675443192.168.2.4173.222.162.32
            Apr 18, 2024 16:55:21.896308899 CEST49678443192.168.2.4104.46.162.224
            Apr 18, 2024 16:55:31.160830021 CEST49675443192.168.2.4173.222.162.32
            Apr 18, 2024 16:55:32.414060116 CEST49737443192.168.2.4142.250.9.147
            Apr 18, 2024 16:55:32.414093018 CEST44349737142.250.9.147192.168.2.4
            Apr 18, 2024 16:55:32.414213896 CEST49737443192.168.2.4142.250.9.147
            Apr 18, 2024 16:55:32.414460897 CEST49737443192.168.2.4142.250.9.147
            Apr 18, 2024 16:55:32.414477110 CEST44349737142.250.9.147192.168.2.4
            Apr 18, 2024 16:55:32.655610085 CEST44349737142.250.9.147192.168.2.4
            Apr 18, 2024 16:55:32.657407045 CEST49737443192.168.2.4142.250.9.147
            Apr 18, 2024 16:55:32.657427073 CEST44349737142.250.9.147192.168.2.4
            Apr 18, 2024 16:55:32.658488035 CEST44349737142.250.9.147192.168.2.4
            Apr 18, 2024 16:55:32.658552885 CEST49737443192.168.2.4142.250.9.147
            Apr 18, 2024 16:55:32.662584066 CEST49737443192.168.2.4142.250.9.147
            Apr 18, 2024 16:55:32.662664890 CEST44349737142.250.9.147192.168.2.4
            Apr 18, 2024 16:55:32.703231096 CEST49737443192.168.2.4142.250.9.147
            Apr 18, 2024 16:55:32.703249931 CEST44349737142.250.9.147192.168.2.4
            Apr 18, 2024 16:55:32.750377893 CEST49737443192.168.2.4142.250.9.147
            Apr 18, 2024 16:55:42.657603979 CEST44349737142.250.9.147192.168.2.4
            Apr 18, 2024 16:55:42.657761097 CEST44349737142.250.9.147192.168.2.4
            Apr 18, 2024 16:55:42.657804966 CEST49737443192.168.2.4142.250.9.147
            Apr 18, 2024 16:55:44.281333923 CEST49737443192.168.2.4142.250.9.147
            Apr 18, 2024 16:55:44.281371117 CEST44349737142.250.9.147192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 18, 2024 16:55:27.889301062 CEST53584521.1.1.1192.168.2.4
            Apr 18, 2024 16:55:27.908169985 CEST53599461.1.1.1192.168.2.4
            Apr 18, 2024 16:55:28.518042088 CEST53532451.1.1.1192.168.2.4
            Apr 18, 2024 16:55:29.088243961 CEST5910053192.168.2.41.1.1.1
            Apr 18, 2024 16:55:29.098978996 CEST5099753192.168.2.41.1.1.1
            Apr 18, 2024 16:55:29.196959972 CEST53591001.1.1.1192.168.2.4
            Apr 18, 2024 16:55:29.209153891 CEST53509971.1.1.1192.168.2.4
            Apr 18, 2024 16:55:29.211781979 CEST5533153192.168.2.41.1.1.1
            Apr 18, 2024 16:55:29.316998005 CEST53553311.1.1.1192.168.2.4
            Apr 18, 2024 16:55:29.370966911 CEST6404453192.168.2.41.1.1.1
            Apr 18, 2024 16:55:29.371360064 CEST5480253192.168.2.48.8.8.8
            Apr 18, 2024 16:55:29.475720882 CEST53640441.1.1.1192.168.2.4
            Apr 18, 2024 16:55:29.476274014 CEST53548028.8.8.8192.168.2.4
            Apr 18, 2024 16:55:30.389084101 CEST6143253192.168.2.41.1.1.1
            Apr 18, 2024 16:55:30.389537096 CEST6087053192.168.2.41.1.1.1
            Apr 18, 2024 16:55:30.495940924 CEST53614321.1.1.1192.168.2.4
            Apr 18, 2024 16:55:30.512259007 CEST53608701.1.1.1192.168.2.4
            Apr 18, 2024 16:55:31.933228970 CEST5542753192.168.2.41.1.1.1
            Apr 18, 2024 16:55:31.933546066 CEST5130853192.168.2.41.1.1.1
            Apr 18, 2024 16:55:32.037615061 CEST53554271.1.1.1192.168.2.4
            Apr 18, 2024 16:55:32.037630081 CEST53513081.1.1.1192.168.2.4
            Apr 18, 2024 16:55:35.534066916 CEST5041653192.168.2.41.1.1.1
            Apr 18, 2024 16:55:35.534424067 CEST5937553192.168.2.41.1.1.1
            Apr 18, 2024 16:55:35.643893003 CEST53504161.1.1.1192.168.2.4
            Apr 18, 2024 16:55:35.654464006 CEST53593751.1.1.1192.168.2.4
            Apr 18, 2024 16:55:35.655229092 CEST6346153192.168.2.41.1.1.1
            Apr 18, 2024 16:55:35.774590015 CEST53634611.1.1.1192.168.2.4
            Apr 18, 2024 16:55:45.741555929 CEST53607031.1.1.1192.168.2.4
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 18, 2024 16:55:29.088243961 CEST192.168.2.41.1.1.10x7646Standard query (0)affordabletowingdesmoines.comA (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.098978996 CEST192.168.2.41.1.1.10xf0ebStandard query (0)affordabletowingdesmoines.com65IN (0x0001)false
            Apr 18, 2024 16:55:29.211781979 CEST192.168.2.41.1.1.10x10dbStandard query (0)affordabletowingdesmoines.comA (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.370966911 CEST192.168.2.41.1.1.10x8788Standard query (0)google.comA (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.371360064 CEST192.168.2.48.8.8.80x8568Standard query (0)google.comA (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:30.389084101 CEST192.168.2.41.1.1.10x31b4Standard query (0)affordabletowingdesmoines.comA (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:30.389537096 CEST192.168.2.41.1.1.10x9980Standard query (0)affordabletowingdesmoines.com65IN (0x0001)false
            Apr 18, 2024 16:55:31.933228970 CEST192.168.2.41.1.1.10x6f3eStandard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:31.933546066 CEST192.168.2.41.1.1.10x97dfStandard query (0)www.google.com65IN (0x0001)false
            Apr 18, 2024 16:55:35.534066916 CEST192.168.2.41.1.1.10x52feStandard query (0)affordabletowingdesmoines.comA (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:35.534424067 CEST192.168.2.41.1.1.10xbb45Standard query (0)affordabletowingdesmoines.com65IN (0x0001)false
            Apr 18, 2024 16:55:35.655229092 CEST192.168.2.41.1.1.10x4811Standard query (0)affordabletowingdesmoines.comA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 18, 2024 16:55:29.196959972 CEST1.1.1.1192.168.2.40x7646Name error (3)affordabletowingdesmoines.comnonenoneA (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.209153891 CEST1.1.1.1192.168.2.40xf0ebName error (3)affordabletowingdesmoines.comnonenone65IN (0x0001)false
            Apr 18, 2024 16:55:29.316998005 CEST1.1.1.1192.168.2.40x10dbName error (3)affordabletowingdesmoines.comnonenoneA (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.475720882 CEST1.1.1.1192.168.2.40x8788No error (0)google.com173.194.219.101A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.475720882 CEST1.1.1.1192.168.2.40x8788No error (0)google.com173.194.219.139A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.475720882 CEST1.1.1.1192.168.2.40x8788No error (0)google.com173.194.219.138A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.475720882 CEST1.1.1.1192.168.2.40x8788No error (0)google.com173.194.219.113A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.475720882 CEST1.1.1.1192.168.2.40x8788No error (0)google.com173.194.219.102A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.475720882 CEST1.1.1.1192.168.2.40x8788No error (0)google.com173.194.219.100A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.476274014 CEST8.8.8.8192.168.2.40x8568No error (0)google.com142.250.10.139A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.476274014 CEST8.8.8.8192.168.2.40x8568No error (0)google.com142.250.10.100A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.476274014 CEST8.8.8.8192.168.2.40x8568No error (0)google.com142.250.10.138A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.476274014 CEST8.8.8.8192.168.2.40x8568No error (0)google.com142.250.10.113A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.476274014 CEST8.8.8.8192.168.2.40x8568No error (0)google.com142.250.10.101A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:29.476274014 CEST8.8.8.8192.168.2.40x8568No error (0)google.com142.250.10.102A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:30.495940924 CEST1.1.1.1192.168.2.40x31b4Name error (3)affordabletowingdesmoines.comnonenoneA (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:30.512259007 CEST1.1.1.1192.168.2.40x9980Name error (3)affordabletowingdesmoines.comnonenone65IN (0x0001)false
            Apr 18, 2024 16:55:32.037615061 CEST1.1.1.1192.168.2.40x6f3eNo error (0)www.google.com142.250.9.147A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:32.037615061 CEST1.1.1.1192.168.2.40x6f3eNo error (0)www.google.com142.250.9.104A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:32.037615061 CEST1.1.1.1192.168.2.40x6f3eNo error (0)www.google.com142.250.9.106A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:32.037615061 CEST1.1.1.1192.168.2.40x6f3eNo error (0)www.google.com142.250.9.99A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:32.037615061 CEST1.1.1.1192.168.2.40x6f3eNo error (0)www.google.com142.250.9.105A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:32.037615061 CEST1.1.1.1192.168.2.40x6f3eNo error (0)www.google.com142.250.9.103A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:32.037630081 CEST1.1.1.1192.168.2.40x97dfNo error (0)www.google.com65IN (0x0001)false
            Apr 18, 2024 16:55:35.643893003 CEST1.1.1.1192.168.2.40x52feName error (3)affordabletowingdesmoines.comnonenoneA (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:35.654464006 CEST1.1.1.1192.168.2.40xbb45Name error (3)affordabletowingdesmoines.comnonenone65IN (0x0001)false
            Apr 18, 2024 16:55:35.774590015 CEST1.1.1.1192.168.2.40x4811Name error (3)affordabletowingdesmoines.comnonenoneA (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:45.099711895 CEST1.1.1.1192.168.2.40x13aeNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:45.099711895 CEST1.1.1.1192.168.2.40x13aeNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Apr 18, 2024 16:55:45.437990904 CEST1.1.1.1192.168.2.40x4c1No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 18, 2024 16:55:45.437990904 CEST1.1.1.1192.168.2.40x4c1No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false

            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:16:55:24
            Start date:18/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:16:55:26
            Start date:18/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2308 --field-trial-handle=2216,i,15104209022405836196,5877275991956964550,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:16:55:28
            Start date:18/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://affordabletowingdesmoines.com"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly