Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://keraproxy.cc

Overview

General Information

Sample URL:https://keraproxy.cc
Analysis ID:1428264
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

Analysis Advice

Joe Sandbox was unable to browse the URL (domain or webserver down or HTTPS issue), try to browse the URL again later
Uses HTTPS for network communication, use the 'Proxy HTTPS (port 443) to read its encrypted data' cookbook for further analysis
  • System is w10x64
  • chrome.exe (PID: 4320 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2200 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2012,i,16442125824606188228,10390746680806239257,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6332 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://keraproxy.cc" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownDNS traffic detected: queries for: keraproxy.cc
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: unknown0.win@19/0@12/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2012,i,16442125824606188228,10390746680806239257,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://keraproxy.cc"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2012,i,16442125824606188228,10390746680806239257,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1428264 URL: https://keraproxy.cc Startdate: 18/04/2024 Architecture: WINDOWS Score: 0 14 keraproxy.cc 2->14 16 fp2e7a.wpc.phicdn.net 2->16 18 2 other IPs or domains 2->18 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 20 192.168.2.4, 138, 443, 49737 unknown unknown 6->20 22 239.255.255.250 unknown Reserved 6->22 11 chrome.exe 6->11         started        process5 dnsIp6 24 www.google.com 74.125.138.104, 443, 49737 GOOGLEUS United States 11->24 26 keraproxy.cc 11->26 28 google.com 11->28

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    google.com
    74.125.136.101
    truefalse
      high
      www.google.com
      74.125.138.104
      truefalse
        high
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          keraproxy.cc
          unknown
          unknownfalse
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            74.125.138.104
            www.google.comUnited States
            15169GOOGLEUSfalse
            239.255.255.250
            unknownReserved
            unknownunknownfalse
            IP
            192.168.2.4
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1428264
            Start date and time:2024-04-18 18:44:48 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 2m 3s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:browseurl.jbs
            Sample URL:https://keraproxy.cc
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:5
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Detection:UNKNOWN
            Classification:unknown0.win@19/0@12/3
            EGA Information:Failed
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 0
            • Number of non-executed functions: 0
            Cookbook Comments:
            • URL browsing timeout or error
            • URL not reachable
            • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
            • Excluded IPs from analysis (whitelisted): 173.194.219.94, 173.194.219.113, 173.194.219.102, 173.194.219.138, 173.194.219.100, 173.194.219.101, 173.194.219.139, 142.250.9.84, 34.104.35.123, 23.33.136.127, 52.165.165.26, 199.232.210.172, 13.85.23.206, 192.229.211.108
            • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtSetInformationFile calls found.
            • VT rate limit hit for: https://keraproxy.cc
            No simulations
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            No static file info
            TimestampSource PortDest PortSource IPDest IP
            Apr 18, 2024 18:45:33.379587889 CEST49675443192.168.2.4173.222.162.32
            Apr 18, 2024 18:45:42.987179041 CEST49675443192.168.2.4173.222.162.32
            Apr 18, 2024 18:45:43.905695915 CEST49737443192.168.2.474.125.138.104
            Apr 18, 2024 18:45:43.905735016 CEST4434973774.125.138.104192.168.2.4
            Apr 18, 2024 18:45:43.906450987 CEST49737443192.168.2.474.125.138.104
            Apr 18, 2024 18:45:43.906728983 CEST49737443192.168.2.474.125.138.104
            Apr 18, 2024 18:45:43.906768084 CEST4434973774.125.138.104192.168.2.4
            Apr 18, 2024 18:45:44.125396967 CEST4434973774.125.138.104192.168.2.4
            Apr 18, 2024 18:45:44.126636982 CEST49737443192.168.2.474.125.138.104
            Apr 18, 2024 18:45:44.126655102 CEST4434973774.125.138.104192.168.2.4
            Apr 18, 2024 18:45:44.127505064 CEST4434973774.125.138.104192.168.2.4
            Apr 18, 2024 18:45:44.127722025 CEST49737443192.168.2.474.125.138.104
            Apr 18, 2024 18:45:44.128942966 CEST49737443192.168.2.474.125.138.104
            Apr 18, 2024 18:45:44.129002094 CEST4434973774.125.138.104192.168.2.4
            Apr 18, 2024 18:45:44.175668001 CEST49737443192.168.2.474.125.138.104
            Apr 18, 2024 18:45:44.175693989 CEST4434973774.125.138.104192.168.2.4
            Apr 18, 2024 18:45:44.222441912 CEST49737443192.168.2.474.125.138.104
            Apr 18, 2024 18:45:54.125013113 CEST4434973774.125.138.104192.168.2.4
            Apr 18, 2024 18:45:54.125076056 CEST4434973774.125.138.104192.168.2.4
            Apr 18, 2024 18:45:54.125190020 CEST49737443192.168.2.474.125.138.104
            Apr 18, 2024 18:45:56.168258905 CEST49737443192.168.2.474.125.138.104
            Apr 18, 2024 18:45:56.168281078 CEST4434973774.125.138.104192.168.2.4
            TimestampSource PortDest PortSource IPDest IP
            Apr 18, 2024 18:45:39.572639942 CEST53599051.1.1.1192.168.2.4
            Apr 18, 2024 18:45:39.574584007 CEST53599231.1.1.1192.168.2.4
            Apr 18, 2024 18:45:40.174987078 CEST53577791.1.1.1192.168.2.4
            Apr 18, 2024 18:45:40.810707092 CEST6528253192.168.2.41.1.1.1
            Apr 18, 2024 18:45:40.815264940 CEST6394053192.168.2.41.1.1.1
            Apr 18, 2024 18:45:40.936623096 CEST53652821.1.1.1192.168.2.4
            Apr 18, 2024 18:45:40.971147060 CEST53639401.1.1.1192.168.2.4
            Apr 18, 2024 18:45:40.971937895 CEST5576453192.168.2.41.1.1.1
            Apr 18, 2024 18:45:41.096960068 CEST53557641.1.1.1192.168.2.4
            Apr 18, 2024 18:45:41.119734049 CEST6321353192.168.2.48.8.8.8
            Apr 18, 2024 18:45:41.119822979 CEST5437553192.168.2.41.1.1.1
            Apr 18, 2024 18:45:41.224785089 CEST53543751.1.1.1192.168.2.4
            Apr 18, 2024 18:45:41.224843025 CEST53632138.8.8.8192.168.2.4
            Apr 18, 2024 18:45:42.133164883 CEST6489753192.168.2.41.1.1.1
            Apr 18, 2024 18:45:42.133269072 CEST6365253192.168.2.41.1.1.1
            Apr 18, 2024 18:45:42.258136988 CEST53648971.1.1.1192.168.2.4
            Apr 18, 2024 18:45:42.259183884 CEST53636521.1.1.1192.168.2.4
            Apr 18, 2024 18:45:43.799108982 CEST5955953192.168.2.41.1.1.1
            Apr 18, 2024 18:45:43.799385071 CEST6463553192.168.2.41.1.1.1
            Apr 18, 2024 18:45:43.903805017 CEST53646351.1.1.1192.168.2.4
            Apr 18, 2024 18:45:43.904298067 CEST53595591.1.1.1192.168.2.4
            Apr 18, 2024 18:45:47.296601057 CEST5833953192.168.2.41.1.1.1
            Apr 18, 2024 18:45:47.296719074 CEST5760553192.168.2.41.1.1.1
            Apr 18, 2024 18:45:47.422593117 CEST53576051.1.1.1192.168.2.4
            Apr 18, 2024 18:45:47.423454046 CEST53583391.1.1.1192.168.2.4
            Apr 18, 2024 18:45:47.424189091 CEST5022753192.168.2.41.1.1.1
            Apr 18, 2024 18:45:47.582484961 CEST53502271.1.1.1192.168.2.4
            Apr 18, 2024 18:45:58.643838882 CEST53554091.1.1.1192.168.2.4
            Apr 18, 2024 18:46:01.745440006 CEST138138192.168.2.4192.168.2.255
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 18, 2024 18:45:40.810707092 CEST192.168.2.41.1.1.10xd4Standard query (0)keraproxy.ccA (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:40.815264940 CEST192.168.2.41.1.1.10x817bStandard query (0)keraproxy.cc65IN (0x0001)false
            Apr 18, 2024 18:45:40.971937895 CEST192.168.2.41.1.1.10xfc5aStandard query (0)keraproxy.ccA (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.119734049 CEST192.168.2.48.8.8.80x491Standard query (0)google.comA (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.119822979 CEST192.168.2.41.1.1.10x18c9Standard query (0)google.comA (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:42.133164883 CEST192.168.2.41.1.1.10x2b9cStandard query (0)keraproxy.ccA (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:42.133269072 CEST192.168.2.41.1.1.10x5bafStandard query (0)keraproxy.cc65IN (0x0001)false
            Apr 18, 2024 18:45:43.799108982 CEST192.168.2.41.1.1.10xb9e1Standard query (0)www.google.comA (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:43.799385071 CEST192.168.2.41.1.1.10x2975Standard query (0)www.google.com65IN (0x0001)false
            Apr 18, 2024 18:45:47.296601057 CEST192.168.2.41.1.1.10x36a1Standard query (0)keraproxy.ccA (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:47.296719074 CEST192.168.2.41.1.1.10x940fStandard query (0)keraproxy.cc65IN (0x0001)false
            Apr 18, 2024 18:45:47.424189091 CEST192.168.2.41.1.1.10xd870Standard query (0)keraproxy.ccA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Apr 18, 2024 18:45:40.936623096 CEST1.1.1.1192.168.2.40xd4Name error (3)keraproxy.ccnonenoneA (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:40.971147060 CEST1.1.1.1192.168.2.40x817bName error (3)keraproxy.ccnonenone65IN (0x0001)false
            Apr 18, 2024 18:45:41.096960068 CEST1.1.1.1192.168.2.40xfc5aName error (3)keraproxy.ccnonenoneA (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.224785089 CEST1.1.1.1192.168.2.40x18c9No error (0)google.com74.125.136.101A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.224785089 CEST1.1.1.1192.168.2.40x18c9No error (0)google.com74.125.136.102A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.224785089 CEST1.1.1.1192.168.2.40x18c9No error (0)google.com74.125.136.138A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.224785089 CEST1.1.1.1192.168.2.40x18c9No error (0)google.com74.125.136.100A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.224785089 CEST1.1.1.1192.168.2.40x18c9No error (0)google.com74.125.136.139A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.224785089 CEST1.1.1.1192.168.2.40x18c9No error (0)google.com74.125.136.113A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.224843025 CEST8.8.8.8192.168.2.40x491No error (0)google.com142.250.10.102A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.224843025 CEST8.8.8.8192.168.2.40x491No error (0)google.com142.250.10.139A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.224843025 CEST8.8.8.8192.168.2.40x491No error (0)google.com142.250.10.101A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.224843025 CEST8.8.8.8192.168.2.40x491No error (0)google.com142.250.10.138A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.224843025 CEST8.8.8.8192.168.2.40x491No error (0)google.com142.250.10.113A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:41.224843025 CEST8.8.8.8192.168.2.40x491No error (0)google.com142.250.10.100A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:42.258136988 CEST1.1.1.1192.168.2.40x2b9cName error (3)keraproxy.ccnonenoneA (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:42.259183884 CEST1.1.1.1192.168.2.40x5bafName error (3)keraproxy.ccnonenone65IN (0x0001)false
            Apr 18, 2024 18:45:43.903805017 CEST1.1.1.1192.168.2.40x2975No error (0)www.google.com65IN (0x0001)false
            Apr 18, 2024 18:45:43.904298067 CEST1.1.1.1192.168.2.40xb9e1No error (0)www.google.com74.125.138.104A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:43.904298067 CEST1.1.1.1192.168.2.40xb9e1No error (0)www.google.com74.125.138.99A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:43.904298067 CEST1.1.1.1192.168.2.40xb9e1No error (0)www.google.com74.125.138.105A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:43.904298067 CEST1.1.1.1192.168.2.40xb9e1No error (0)www.google.com74.125.138.103A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:43.904298067 CEST1.1.1.1192.168.2.40xb9e1No error (0)www.google.com74.125.138.147A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:43.904298067 CEST1.1.1.1192.168.2.40xb9e1No error (0)www.google.com74.125.138.106A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:47.422593117 CEST1.1.1.1192.168.2.40x940fName error (3)keraproxy.ccnonenone65IN (0x0001)false
            Apr 18, 2024 18:45:47.423454046 CEST1.1.1.1192.168.2.40x36a1Name error (3)keraproxy.ccnonenoneA (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:47.582484961 CEST1.1.1.1192.168.2.40xd870Name error (3)keraproxy.ccnonenoneA (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:56.472542048 CEST1.1.1.1192.168.2.40xc61No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:56.472542048 CEST1.1.1.1192.168.2.40xc61No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
            Apr 18, 2024 18:45:57.420439959 CEST1.1.1.1192.168.2.40x5f3aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
            Apr 18, 2024 18:45:57.420439959 CEST1.1.1.1192.168.2.40x5f3aNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false

            Click to jump to process

            Click to jump to process

            Click to jump to process

            Target ID:0
            Start time:18:45:35
            Start date:18/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:2
            Start time:18:45:37
            Start date:18/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2012,i,16442125824606188228,10390746680806239257,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:false

            Target ID:3
            Start time:18:45:39
            Start date:18/04/2024
            Path:C:\Program Files\Google\Chrome\Application\chrome.exe
            Wow64 process (32bit):false
            Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://keraproxy.cc"
            Imagebase:0x7ff76e190000
            File size:3'242'272 bytes
            MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
            Has elevated privileges:true
            Has administrator privileges:true
            Programmed in:C, C++ or other language
            Reputation:low
            Has exited:true

            No disassembly