Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://hamurg.de

Overview

General Information

Sample URL:http://hamurg.de
Analysis ID:1428752

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 7156 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://hamurg.de/ MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 7064 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1960,i,3001896463917438986,3819214095284556955,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://86861.click.validclick.net/cad.php?srt_hash=Iyw4MDIrOy8vMSc5Pi4rIS0_PDo%2C&adv=16050&utm_source=86861&search=&aid=&b=&subid=9115565977&keyword=*HTTP Parser: No favicon
Source: https://fastblock.me/?c=23456k&subid=f_211087HTTP Parser: No favicon
Source: https://fastblock.me/?c=23456k&subid=f_211087HTTP Parser: No favicon
Source: https://fastblock.me/?c=23456k&subid=f_211087HTTP Parser: No favicon
Source: https://fastblock.me/?c=23456k&subid=f_211087HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 104.123.200.136:443 -> 192.168.2.16:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.123.200.136:443 -> 192.168.2.16:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49726 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49781 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 104.123.200.136
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: hamurg.deConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /zclkvisitor/467c4431-fe4d-11ee-bdba-12e87d8a0373/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=469830a2-fe4d-11ee-bdba-12e87d8a0373 HTTP/1.1Host: snorr-dbs.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /zclkredirect?visitid=467c4431-fe4d-11ee-bdba-12e87d8a0373&type=js&browserWidth=1280&browserHeight=907&iframeDetected=false&webdriverDetected=false&gpu=Google%20Inc.%20(Google)%3B%20ANGLE%20(Google%2C%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE))%2C%20SwiftShader%20driver)&timezone=UTC%2B02%3A00&timezoneName=Europe%2FZurich HTTP/1.1Host: snorr-dbs.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://snorr-dbs.com/zclkvisitor/467c4431-fe4d-11ee-bdba-12e87d8a0373/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=469830a2-fe4d-11ee-bdba-12e87d8a0373Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /click?seat=2476950&i=RMf7QQ896NQ_0 HTTP/1.1Host: xml-v4.sitamedal3.onlineConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://snorr-dbs.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: hamurg.deConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: sid=46775c02-fe4d-11ee-9505-b6d7f5572335
Source: global trafficHTTP traffic detected: GET /?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTcxMzUzOTA1MiwiaWF0IjoxNzEzNTMxODUyLCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIydjNyMDkwYWpobmFlaG91azgwMDQ1cWUiLCJuYmYiOjE3MTM1MzE4NTIsInRzIjoxNzEzNTMxODUyMDgxMDA2fQ.ezZ05aidcgO3H0pnePOKswrQRaumWQCJV-BdfAsE41s&sid=46775c02-fe4d-11ee-9505-b6d7f5572335 HTTP/1.1Host: hamurg.deConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://hamurg.de/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: sid=46775c02-fe4d-11ee-9505-b6d7f5572335
Source: global trafficHTTP traffic detected: GET /zclkvisitor/512796f0-fe4d-11ee-9748-0affc0a29989/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=5143aa72-fe4d-11ee-9748-0affc0a29989 HTTP/1.1Host: snorr-dbs.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://hamurg.de/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /zclkredirect?visitid=512796f0-fe4d-11ee-9748-0affc0a29989&type=js&browserWidth=1280&browserHeight=907&iframeDetected=false&webdriverDetected=false&gpu=Google%20Inc.%20(Google)%3B%20ANGLE%20(Google%2C%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE))%2C%20SwiftShader%20driver)&timezone=UTC%2B02%3A00&timezoneName=Europe%2FZurich HTTP/1.1Host: snorr-dbs.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://snorr-dbs.com/zclkvisitor/512796f0-fe4d-11ee-9748-0affc0a29989/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=5143aa72-fe4d-11ee-9748-0affc0a29989Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /click?i=739*MvlJSJg_0 HTTP/1.1Host: xml-v4.sitamedal3.onlineConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://snorr-dbs.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: hamurg.de
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownHTTPS traffic detected: 104.123.200.136:443 -> 192.168.2.16:49725 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.123.200.136:443 -> 192.168.2.16:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49726 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49781 version: TLS 1.2
Source: classification engineClassification label: clean0.win@24/26@32/136
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://hamurg.de/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1960,i,3001896463917438986,3819214095284556955,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1960,i,3001896463917438986,3819214095284556955,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
pixel.admedia.com
204.44.79.1
truefalse
    high
    api.admd.ink
    104.22.10.122
    truefalse
      unknown
      code.jquery.com
      151.101.66.137
      truefalse
        high
        www3.l.google.com
        142.250.105.101
        truefalse
          high
          86861.click.validclick.net
          173.198.250.30
          truefalse
            unknown
            fastblock.me
            178.128.246.195
            truefalse
              unknown
              www.google.com
              74.125.136.105
              truefalse
                high
                hamurg.de
                172.98.192.36
                truefalse
                  unknown
                  admd.ink
                  104.22.10.122
                  truefalse
                    unknown
                    snorr-dbs.com
                    34.239.34.67
                    truefalse
                      unknown
                      adventurefeeds.xml-v4.ak-is2.net
                      173.239.53.32
                      truefalse
                        unknown
                        xml-v4.sitamedal3.online
                        unknown
                        unknownfalse
                          unknown
                          www.choicehotels.com
                          unknown
                          unknownfalse
                            high
                            translate.google.com
                            unknown
                            unknownfalse
                              high
                              NameMaliciousAntivirus DetectionReputation
                              http://snorr-dbs.com/zclkvisitor/467c4431-fe4d-11ee-bdba-12e87d8a0373/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=469830a2-fe4d-11ee-bdba-12e87d8a0373false
                                unknown
                                http://snorr-dbs.com/zclkvisitor/512796f0-fe4d-11ee-9748-0affc0a29989/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=5143aa72-fe4d-11ee-9748-0affc0a29989false
                                  unknown
                                  http://snorr-dbs.com/zclkredirect?visitid=467c4431-fe4d-11ee-bdba-12e87d8a0373&type=js&browserWidth=1280&browserHeight=907&iframeDetected=false&webdriverDetected=false&gpu=Google%20Inc.%20(Google)%3B%20ANGLE%20(Google%2C%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE))%2C%20SwiftShader%20driver)&timezone=UTC%2B02%3A00&timezoneName=Europe%2FZurichfalse
                                    unknown
                                    https://fastblock.me/?c=23456k&subid=f_211087false
                                      unknown
                                      http://hamurg.de/?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTcxMzUzOTA1MiwiaWF0IjoxNzEzNTMxODUyLCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIydjNyMDkwYWpobmFlaG91azgwMDQ1cWUiLCJuYmYiOjE3MTM1MzE4NTIsInRzIjoxNzEzNTMxODUyMDgxMDA2fQ.ezZ05aidcgO3H0pnePOKswrQRaumWQCJV-BdfAsE41s&sid=46775c02-fe4d-11ee-9505-b6d7f5572335false
                                        unknown
                                        http://xml-v4.sitamedal3.online/click?seat=2476950&i=RMf7QQ896NQ_0false
                                          unknown
                                          https://86861.click.validclick.net/cad.php?srt_hash=Iyw4MDIrOy8vMSc5Pi4rIS0_PDo%2C&adv=16050&utm_source=86861&search=&aid=&b=&subid=9115565977&keyword=*false
                                            unknown
                                            http://hamurg.de/false
                                              unknown
                                              http://xml-v4.sitamedal3.online/click?i=739*MvlJSJg_0false
                                                unknown
                                                about:blankfalse
                                                  low
                                                  http://snorr-dbs.com/zclkredirect?visitid=512796f0-fe4d-11ee-9748-0affc0a29989&type=js&browserWidth=1280&browserHeight=907&iframeDetected=false&webdriverDetected=false&gpu=Google%20Inc.%20(Google)%3B%20ANGLE%20(Google%2C%20Vulkan%201.3.0%20(SwiftShader%20Device%20(Subzero)%20(0x0000C0DE))%2C%20SwiftShader%20driver)&timezone=UTC%2B02%3A00&timezoneName=Europe%2FZurichfalse
                                                    unknown
                                                    • No. of IPs < 25%
                                                    • 25% < No. of IPs < 50%
                                                    • 50% < No. of IPs < 75%
                                                    • 75% < No. of IPs
                                                    IPDomainCountryFlagASNASN NameMalicious
                                                    74.125.136.105
                                                    www.google.comUnited States
                                                    15169GOOGLEUSfalse
                                                    172.98.192.36
                                                    hamurg.deUnited States
                                                    31863DACEN-2USfalse
                                                    64.233.176.94
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    173.239.53.32
                                                    adventurefeeds.xml-v4.ak-is2.netUnited States
                                                    27257WEBAIR-INTERNETUSfalse
                                                    178.128.246.195
                                                    fastblock.meNetherlands
                                                    14061DIGITALOCEAN-ASNUSfalse
                                                    64.233.176.99
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    142.250.105.139
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    104.22.10.122
                                                    api.admd.inkUnited States
                                                    13335CLOUDFLARENETUSfalse
                                                    104.76.210.196
                                                    unknownUnited States
                                                    6762SEABONE-NETTELECOMITALIASPARKLESpAITfalse
                                                    151.101.66.137
                                                    code.jquery.comUnited States
                                                    54113FASTLYUSfalse
                                                    142.250.9.95
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    172.217.215.95
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    64.233.177.94
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    74.125.136.138
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    64.233.176.84
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    34.239.34.67
                                                    snorr-dbs.comUnited States
                                                    14618AMAZON-AESUSfalse
                                                    142.250.105.97
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    173.198.250.30
                                                    86861.click.validclick.netUnited States
                                                    40244TURNKEY-INTERNETUSfalse
                                                    142.250.105.101
                                                    www3.l.google.comUnited States
                                                    15169GOOGLEUSfalse
                                                    172.253.124.94
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    108.177.122.106
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    239.255.255.250
                                                    unknownReserved
                                                    unknownunknownfalse
                                                    204.44.79.1
                                                    pixel.admedia.comUnited States
                                                    8100ASN-QUADRANET-GLOBALUSfalse
                                                    64.233.185.95
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    108.177.122.94
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    108.177.122.95
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    IP
                                                    192.168.2.16
                                                    Joe Sandbox version:40.0.0 Tourmaline
                                                    Analysis ID:1428752
                                                    Start date and time:2024-04-19 15:03:21 +02:00
                                                    Joe Sandbox product:CloudBasic
                                                    Overall analysis duration:
                                                    Hypervisor based Inspection enabled:false
                                                    Report type:full
                                                    Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                    Sample URL:http://hamurg.de
                                                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                    Number of analysed new started processes analysed:10
                                                    Number of new started drivers analysed:0
                                                    Number of existing processes analysed:0
                                                    Number of existing drivers analysed:0
                                                    Number of injected processes analysed:0
                                                    Technologies:
                                                    • EGA enabled
                                                    Analysis Mode:stream
                                                    Analysis stop reason:Timeout
                                                    Detection:CLEAN
                                                    Classification:clean0.win@24/26@32/136
                                                    • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
                                                    • Excluded IPs from analysis (whitelisted): 64.233.185.94, 74.125.136.138, 74.125.136.101, 74.125.136.100, 74.125.136.102, 74.125.136.113, 74.125.136.139, 64.233.176.84, 34.104.35.123, 104.76.210.196, 104.76.210.212, 104.76.210.198
                                                    • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, e210160.a.akamaiedge.net, slscr.update.microsoft.com, clientservices.googleapis.com, clients.l.google.com, dsa-secure.choicehotels.com.edgekey.net
                                                    • Not all processes where analyzed, report is missing behavior information
                                                    • VT rate limit hit for: http://hamurg.de
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 12:03:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                    Category:dropped
                                                    Size (bytes):2673
                                                    Entropy (8bit):3.9856690184929127
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:49D5B7C6B46F708D5BDF5BFC41F08D3C
                                                    SHA1:5ACEDA3772468F23DDAE7FB79E85836905AF9340
                                                    SHA-256:3D97A7C83FD1F0F6BFDC464E46330DD7EC1FEC09528E329229D0CE7293C6CBA0
                                                    SHA-512:473B6087294BC4380A14A0CC0A79D41304C9ECE1154A71BE1B2DF03F9C4A1AB29FAE75F9BDAC8F24D4BC28BB0B38BB6968F7A3C69ED3E8AC94F0A97949005381
                                                    Malicious:false
                                                    Reputation:unknown
                                                    Preview:L..................F.@.. ...$+.,........Z...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Xqh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X{h....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X{h....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X{h..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X|h...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............S.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 12:03:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                    Category:dropped
                                                    Size (bytes):2675
                                                    Entropy (8bit):4.003255644802521
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:900238A27988921C0134EED0528F51D2
                                                    SHA1:6063DB4652287C07AAF00F2E54C803D1954F1E5A
                                                    SHA-256:AFDAE7635D459911222EC172B1C3035EA7809176A667B631E8FCBCDA6516CE28
                                                    SHA-512:D849CF629E955D090E07B3575C463088707A2A582EDD888404251CB1A8297C6D90C3FFEC4241CC8AB69FBE6433333B26160CCF739AF0257BFF831AA7335A299E
                                                    Malicious:false
                                                    Reputation:unknown
                                                    Preview:L..................F.@.. ...$+.,....;...Z...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Xqh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X{h....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X{h....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X{h..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X|h...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............S.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                    Category:dropped
                                                    Size (bytes):2689
                                                    Entropy (8bit):4.008910368962402
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:C67481F543497B31EAC5C7317DC5EC16
                                                    SHA1:4E3006F18C512F93781A6008F92EC3EF674992B1
                                                    SHA-256:277243D5478F0292740C371B3216710F8F93B02DEA3AEC1640271832972ED477
                                                    SHA-512:84376DCDCAD9DBF9DBEFFE5DFE15E567D05CA044F59E39D255B6FC2536308BB4050836D341CDFD3E393CA16F1EA6F454AD7C0B6F034A766055FF13E47EAEF860
                                                    Malicious:false
                                                    Reputation:unknown
                                                    Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Xqh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X{h....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X{h....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X{h..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............S.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 12:03:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                    Category:dropped
                                                    Size (bytes):2677
                                                    Entropy (8bit):4.001205687116709
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:1F3787641F3A38F01B8E0E7E72124F16
                                                    SHA1:7499CFE8BB7DC6BEB5F205178718D59FF688280E
                                                    SHA-256:D2493C05FEA89B1491F5BC194A2A96BE539D23C186354B6200F9954C2DDC3779
                                                    SHA-512:026714C1A5D67F09C1E7EDCA564FC7060ED06D55DB5057C19F544267512D157FDF188592D559032B9834C47C57309718FB1768EC2C5BC3AF20EBAAF89F50A9BE
                                                    Malicious:false
                                                    Reputation:unknown
                                                    Preview:L..................F.@.. ...$+.,....R...Z...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Xqh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X{h....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X{h....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X{h..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X|h...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............S.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 12:03:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                    Category:dropped
                                                    Size (bytes):2677
                                                    Entropy (8bit):3.9903706687313307
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:DAAC25E178C4F418F1E9A52DA0BED756
                                                    SHA1:9E9F16729C02A47F2B32C53A6E57B880E4738AEB
                                                    SHA-256:AB9716DC8CE0793F5B0750D008077C300D5076EDF22D8108C61A1A7020F30CA5
                                                    SHA-512:ECBFD2E98CE7569D9B868B70786DC73121CBC6BFD80E5A050B4A8FC78BAC591A3CE03E1CED05B56BF55C34701132937F04CB2EB6963F5F4F22BC12B4B2463EC6
                                                    Malicious:false
                                                    Reputation:unknown
                                                    Preview:L..................F.@.. ...$+.,....0...Z...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Xqh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X{h....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X{h....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X{h..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X|h...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............S.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 12:03:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                    Category:dropped
                                                    Size (bytes):2679
                                                    Entropy (8bit):4.0013603808931455
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:EC3DA794F03B305F6210BEDE67EFBD84
                                                    SHA1:44F8AD011FE090462CC9C00881821D9863D741F2
                                                    SHA-256:0877E378983317FA3D628A5D98468B42D5FE2D6317713918BBABB47CCDBC45CD
                                                    SHA-512:81C47D624E82CB40E9E340A6B32717D78D548E5F955960A077958213B7BEEAF3BF881925E3787534B13569AB9E1728BD965F4D39C651174300DB9F24359D92CA
                                                    Malicious:false
                                                    Reputation:unknown
                                                    Preview:L..................F.@.. ...$+.,........Z...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Xqh....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X{h....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X{h....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X{h..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X|h...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............S.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:SVG Scalable Vector Graphics image
                                                    Category:downloaded
                                                    Size (bytes):8014
                                                    Entropy (8bit):4.64327448628233
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:2A237DA86FF476E04A2FD54B230E3CF3
                                                    SHA1:C49B44B34CE9907753CA1C9F3E33D349B2A57C15
                                                    SHA-256:E9A25816E16EFE7023E43282C885DE07D42E2FDA2246071359CAC1B8F814A107
                                                    SHA-512:0826116B2CBD59EE70E032B973B99C83EBE6CAEA4C10FFF23B1DD38DDC90091777466A722707896AF2E22AD97EA284D4A441A2A527263D52C33FE1351A9AE2E4
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://fastblock.me/images/logo.svg
                                                    Preview:<?xml version="1.0" encoding="utf-8"?>.. Generator: Adobe Illustrator 28.0.0, SVG Export Plug-In . SVG Version: 6.00 Build 0) -->..<svg version="1.1" id="...._1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px"... viewBox="0 0 128 128" style="enable-background:new 0 0 128 128;" xml:space="preserve">..<style type="text/css">....st0{fill:url(#SVGID_1_);}....st1{fill:#B30000;}....st2{fill:#FFFFFF;}....st3{fill:#EE4F4F;}....st4{display:none;}....st5{display:inline;}..</style>..<g>...<g>....<g>...........<linearGradient id="SVGID_1_" gradientUnits="userSpaceOnUse" x1="3" y1="66" x2="125" y2="66" gradientTransform="matrix(1 0 0 -1 0 130)">......<stop offset="0" style="stop-color:#D90000"/>......<stop offset="1" style="stop-color:#EE0000"/>.....</linearGradient>.....<path class="st0" d="M125,41v46c0,1.5-0.6,2.9-1.6,3.9l-30.8,30.8l-1.7,1.6l0,0c-0.5,0.5-1.2,0.9-1.9,1.2l0,0......c-0.6,0.2-1.3,0.4-2,0.4H41c-1.5,0-2.9-0.6-3.9-1.6L4.6,90.9c-1-
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:assembler source, ASCII text, with very long lines (387), with CRLF line terminators
                                                    Category:downloaded
                                                    Size (bytes):16942
                                                    Entropy (8bit):5.032432908870572
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:7E5F253C8B9E0AD3E1682F3EB88E95D8
                                                    SHA1:A58AC3F122DCCC3E7B2A6EA88A1FE73010847FAF
                                                    SHA-256:9F68E1942CF962266A0E1D445711D70480DEB89B6EDFACF2753BA43EF95D6040
                                                    SHA-512:DFA3DB8F3EBA8CA06CB0AF06795DDACC7AD24BFB4DD3C946566AC10144388B12B084328977A896BFF14F1F8EB196D9E4DB796CAF0284A800864E4B49CD04CD2B
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://fastblock.me/css/styles.css?2
                                                    Preview:@import url(https://fonts.googleapis.com/css2?family=Roboto&display=swap);.....bls, .bls-install {.. font-size: 18px;.. line-height: 26px;.. color: #333..}.....bls .container, .bls-install .container {.. max-width: 1266px;.. margin: 0 auto;.. padding: 0..}.....bls *, .bls-install * {.. font-family: "Open Sans", sans-serif..}.....bls .white-color, .bls-install .white-color {.. color: #fff..}.....bls a, .bls-install a {.. font-size: 14px;.. line-height: 20px;.. color: #EE4F4F;.. text-decoration: none..}.....bls a:hover, .bls-install a:hover {.. text-decoration: underline..}.....bls h1, .bls h2, .bls h3, .bls-install h1, .bls-install h2, .bls-install h3 {.. color: #333..}.....bls h1, .bls-install h1 {.. font-weight: 800;.. font-size: 64px;.. line-height: 76px..}.....bls h2, .bls-install h2 {.. font-weight: 800;.. font-size: 50px;.. line-height: 68px..}.....bls h3, .bls-install h3 {.. font-weight: 700;.. font-size: 24px;..
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:PNG image data, 68 x 28, 8-bit/color RGBA, non-interlaced
                                                    Category:downloaded
                                                    Size (bytes):1597
                                                    Entropy (8bit):7.848005717819246
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:C4A931D597DECD2553AAC6634B766CF2
                                                    SHA1:6EC84FB4A2745B4B71520241BE77DB1FD1013830
                                                    SHA-256:F56402B127698DB4B4DC611A97A6F081D04C4691C60522C5912D189E37C94A9E
                                                    SHA-512:4932E0F7F38085A7C52539BDD5C7F470740E560A4471BEA30D12EF9E3EFE77F6BBFAC28D26C62A245C43D98EBF74C824B2B414843080A27EDF1563A5F874AC84
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://www.gstatic.com/images/branding/googlelogo/1x/googlelogo_color_68x28dp.png
                                                    Preview:.PNG........IHDR...D............(....IDATX..Y]l.U....V#../..R......vfv.b...j.?/<@...!.FW....!..X.B...C.b....K.y.?..`...v;3.....3wvg....&...d2.g...s...[.Zj.7.'t./.wl<.*]. .TY+..(].E...WJ.z.............<..7...-/.#......ZQ.I.a.H...\.....n.b.O!.......S...>.5+...W.s{..!m.Oy...k.r.5....4.>..j.....=..Z~...yc+k..U..Q..e..:8/@ ....p{......P.#u..0.n.p.*DQ...O.,Y=.g.0.W.........>W..RM.'v.?...-,0..y..c..............@..........<cf.5`k..XF..6.y,......y#..4..4.[`........\.......SD.-(...GwM8.U....2.[..._.|...n.....t.&;..z_...4~w.....W.-..W...wf.9e...+..o* Y...r.@......l.A.N...o..T.....7.SJ96..c.V#.{..h.....].....q._u.cg.B.Z..ol4,>E....j........k....$...r.....s.r'h.o.......`...}.!.ze......v..`.2.?.....+J..:..Q..w....L8.s..{<y:.x. .K...........,..T.!...Mi......]...MM.......5k..,......C..)..L.q.K]W.3...d.~R..BNG....i.&eN...l..M.a.]..".2@|4...IC......6.=. ....Dp...>..*K4Q.;...S....*....#.2.~\`....m..H..j.b3...62...QbPKQe..L9P. z4p.$..(o.4.^..~f.....*
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text
                                                    Category:downloaded
                                                    Size (bytes):2316
                                                    Entropy (8bit):5.408193825994515
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:DDFFFA73A3AD101DE750962D005D7037
                                                    SHA1:4C82D80E86B6562BAF0AB94A56BE20C44B4F6F47
                                                    SHA-256:838E680CA964A26C94665951577F3F0902EF54DE2EE063D3465F22945DC44AFA
                                                    SHA-512:A0A5A009F97833388DE820832DCF863CF10C3CBB9B062B0CD80AFAB9A15C871F8CF11D31D8DA73986BC31A86A46F70710D35480413948585F56BA3D5D3DFA0AD
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://fonts.googleapis.com/css2?family=Roboto&display=swap
                                                    Preview:/* cyrillic-ext */.@font-face {. font-family: 'Roboto';. font-style: normal;. font-weight: 400;. font-display: swap;. src: url(https://fonts.gstatic.com/s/roboto/v30/KFOmCnqEu92Fr1Mu72xKOzY.woff2) format('woff2');. unicode-range: U+0460-052F, U+1C80-1C88, U+20B4, U+2DE0-2DFF, U+A640-A69F, U+FE2E-FE2F;.}./* cyrillic */.@font-face {. font-family: 'Roboto';. font-style: normal;. font-weight: 400;. font-display: swap;. src: url(https://fonts.gstatic.com/s/roboto/v30/KFOmCnqEu92Fr1Mu5mxKOzY.woff2) format('woff2');. unicode-range: U+0301, U+0400-045F, U+0490-0491, U+04B0-04B1, U+2116;.}./* greek-ext */.@font-face {. font-family: 'Roboto';. font-style: normal;. font-weight: 400;. font-display: swap;. src: url(https://fonts.gstatic.com/s/roboto/v30/KFOmCnqEu92Fr1Mu7mxKOzY.woff2) format('woff2');. unicode-range: U+1F00-1FFF;.}./* greek */.@font-face {. font-family: 'Roboto';. font-style: normal;. font-weight: 400;. font-display: swap;. src: url(https://fonts.gstatic.com/s
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (3034)
                                                    Category:downloaded
                                                    Size (bytes):269416
                                                    Entropy (8bit):5.562424748122164
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:57312654620AC1D40180C848EC3793BB
                                                    SHA1:A8DAFE31C785558F9D71E5CA09758801E1868467
                                                    SHA-256:79C1980B0FF6C1D5DF0AE254FE17387C4BB5A997317236A16C27F2D755743D4E
                                                    SHA-512:FA38A5620AE071F878198271139C05B4C172B41CED65635FC86C8B2C9DB25C030806DE2628A3A102C879520908BCAE40DE273ADBF997B5192424F07AB2E80D6A
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://www.googletagmanager.com/gtag/js?id=G-0H01VB5FB9
                                                    Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0},{"vtp_signal":0,"function":"__c","vtp_value":0}],. "tags":[{"function":"__gct","vtp_trackingId":"G-0H01VB5FB9","vtp_sessionDuration":0,"tag_id":1},{"function":"__ccd_conversion_marking","vtp_conversionRules":["list",["map","matchingRules","{\"type\":5,\"args\":[{\"stringValue\":\"purchase\"},{\"contextValue\":{\"namespaceType\":1,\"keyParts\":[\"eventName\"]}}]}"]],"vtp_instanceDestinationId":"G-0H01VB5FB9","tag_id":3},{"function":"__ccd_em_download","vtp_includeParams":true,"vtp_instanceDestinationId":"G-0H01VB5FB9","tag_id":5},{"function":"__ccd_em_outbound_click","priority":0,"vtp_includeParams":true,"vtp_instanceDestinationId":"G-0H01VB5FB9","tag_id":6},{"function":"__ccd_em_page_view","vtp_historyEvents":true,"vtp_includeParams":true,"vtp_instanceDestinationId":"G-0H01VB
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:PNG image data, 42 x 16, 8-bit/color RGBA, non-interlaced
                                                    Category:downloaded
                                                    Size (bytes):910
                                                    Entropy (8bit):7.7455040862049085
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:EFA6BB2BFE459BC6F4BDAFA3DB0383F6
                                                    SHA1:52D15CE52FE50643E542C17812DE43F4ED1B6EE0
                                                    SHA-256:6318394F737C66F0E2CCFCD88E3935C6667633A1B95FA29FBA2B75431D55EEF2
                                                    SHA-512:E23C04D8997F5C2F92070E09261B7EE50D9DF8753F45CF66F604F0874FFA8D99E947C97C528EC02A2C3FBE8E43D840B343A7D0225532980D5DA95031216415B7
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://www.gstatic.com/images/branding/googlelogo/1x/googlelogo_color_42x16dp.png
                                                    Preview:.PNG........IHDR...*.........`"....UIDATx..T...=.Mm......&[....Sl..m.m....U....;.uf..frrr...v...U)...).....2Q..`.y.*...U.9..;..0.^........B.......].h.^..... . L3....jQw..vB.D....<..P.4..|.B....d..?.....Qv.....Dv..$...._.|.*.@........k....`..JG...$..T.y|T.......v.iH...yc6'...%..&.w.oI.ZS{..!6A@.Y.....a....U]..:...g-......01F........Q...k#..G\....~.+....z.>....F...}1[..~.9..r[.?..9......2~....e."1.).}[.WW.{.r...|D..<7..t.M.`..S...8.ab..F ....n..S.:n.>1(g.p$.:k1..6...Y..@.5.8.0y.....R...;.K\. 0p...g.,r.E...............=.....!.^..Y!..D.Z.....aV.....;F.4...!.`^.L.VQ.....&...d....O.\...I).!1....{......K.f*.e ....L......~.%IY(..Y.....NeA...?.^..2.C..^........P....)T.&?.zm.Sl.b..l.D...%.{.B>X{.9Y..M..:.)......EK..b.......}....|.o..].....GH?..3F.B(.:.....AdA........Z... .L....)..@?...f.F....6......u..oQfMC.....OC.1[3..j..j.G...&..D`........@>...g....IEND.B`.
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (1572)
                                                    Category:downloaded
                                                    Size (bytes):29085
                                                    Entropy (8bit):5.358949210911638
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:3B3A4C3F168D62A6ED57D0128ED376ED
                                                    SHA1:3F48AC47817C6C52BD975297BE3C03FFE38513A8
                                                    SHA-256:90787CA0E77942034765D1F69EFF786ED8FBB616ED49BA6FBC8E9F56207C579E
                                                    SHA-512:3D06772233977AA22EAF1D1BD8BCAD2480B51C37C06D1C9F8EF3491E822C06D77F017C62BC725E88468F50CB8471D9506F9F9EABAC9380CBE61E32AC92432C1A
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://fonts.googleapis.com/css2?family=Open+Sans:wght@100;300;400;500;600;700;900&display=swap
                                                    Preview:/* cyrillic-ext */.@font-face {. font-family: 'Open Sans';. font-style: normal;. font-weight: 300;. font-stretch: 100%;. font-display: swap;. src: url(https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSKmu1aB.woff2) format('woff2');. unicode-range: U+0460-052F, U+1C80-1C88, U+20B4, U+2DE0-2DFF, U+A640-A69F, U+FE2E-FE2F;.}./* cyrillic */.@font-face {. font-family: 'Open Sans';. font-style: normal;. font-weight: 300;. font-stretch: 100%;. font-display: swap;. src: url(https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSumu1aB.woff2) format('woff2');. unicode-range: U+0301, U+0400-045F, U+0490-0491, U+04B0-04B1, U+2116;.}./* greek-ext */.@font-face {. font-family: 'Open Sans';. font-style: normal;. font-weight: 300;. font-stretch: 100%;. font-display: swap;. src: url(https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTSOmu1aB.woff2) format('woff2');. unicode-range: U+1F00-1FFF;.}./* greek
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:HTML document, ASCII text, with CRLF line terminators
                                                    Category:downloaded
                                                    Size (bytes):571
                                                    Entropy (8bit):4.773627074908672
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:7CCAD328E5B7CA3D91BF0B6609723468
                                                    SHA1:FDAC4F5901F859CF3D7ABB903E5FCBA93A8B5027
                                                    SHA-256:D50B9852CE176350C41F3A8B9BC01132659F8B18B9CCEC1CDEA6E98D28176DAF
                                                    SHA-512:427CC7779182707F81055870CF042967DB7281A666A9E296E1A3C0BE8196E375E68A72D7B8942E032FDB3F47452485CBB47DE870B1FBD0A9ECA26DBCE84C5895
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://fastblock.me/favicon.ico
                                                    Preview:<html>..<head><title>404 Not Found</title></head>..<body bgcolor="white">..<center><h1>404 Not Found</h1></center>..<hr><center>nginx/1.14.2</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (2333)
                                                    Category:downloaded
                                                    Size (bytes):213194
                                                    Entropy (8bit):5.568409286247371
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:4BB91F7D3340C67FBC422FE923CB4CE4
                                                    SHA1:AA81F4DAF848D66F92F853BE4BB57333694B2712
                                                    SHA-256:2244A4C055184ACC3EE54D04F44CDE9F71829B12A6ADC7AD0956E76EB48C072A
                                                    SHA-512:8E5029A0F81F5EA431E012A7E13A9EC877F7794250C81744A17AFFC9ACE4D8CC703AE8B82C8310201B34F13CA19AA0C88C14B96E608D22DA5C060353571F22DF
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://translate.googleapis.com/_/translate_http/_/js/k=translate_http.tr.en_US.KtUE6FYZ1Qc.O/am=AAQ/d=1/exm=el_conf/ed=1/rs=AN8SPfqjxy10wbAnofU91ERWTVjA0pBlWQ/m=el_main
                                                    Preview:"use strict";this.default_tr=this.default_tr||{};(function(_){var window=this;.try{.var Jh,Kh,Lh,Th,di,ei,fi,gi,ki,Ph;Jh=function(a){return _.Aa?_.Ba?_.Ba.brands.some(function(b){return(b=b.brand)&&-1!=b.indexOf(a)}):!1:!1};Kh=function(){return _.v("Firefox")||_.v("FxiOS")};Lh=function(){return _.Ca()?Jh("Chromium"):(_.v("Chrome")||_.v("CriOS"))&&!(_.Ca()?0:_.v("Edge"))||_.v("Silk")};._.Mh=function(){return _.v("Safari")&&!(Lh()||(_.Ca()?0:_.v("Coast"))||_.Da()||(_.Ca()?0:_.v("Edge"))||(_.Ca()?Jh("Microsoft Edge"):_.v("Edg/"))||(_.Ca()?Jh("Opera"):_.v("OPR"))||Kh()||_.v("Silk")||_.v("Android"))};_.Nh=function(){return _.v("Android")&&!(Lh()||Kh()||_.Da()||_.v("Silk"))};_.Oh=function(a){if(a instanceof _.Nc)return a.g;throw Error("A");};_.Qh=function(a){if(Ph.test(a))return a};_.Rh=function(a){return a instanceof _.Nc?_.Oh(a):_.Qh(a)};_.Sh=function(a){return Array.prototype.slice.call(a)};.Th=function(a){return"function"===typeof Symbol&&"symbol"===typeof Symbol()?Symbol():a};_.Vh=funct
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:HTML document, ASCII text, with very long lines (470), with no line terminators
                                                    Category:downloaded
                                                    Size (bytes):470
                                                    Entropy (8bit):5.829821573895347
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:AE6D93D451C340F537A9DBAFB11F74A9
                                                    SHA1:BC2344C5C024478233B50FECF0E2FE72BDDC4C88
                                                    SHA-256:0E6E491D342088E4A3797602E1BF1EC1DCD633F816ED2F097FADB39239A24439
                                                    SHA-512:AF7D63CCBC57604375FB661A36E018743D9FEA23D4BB45361E60A4498BDE46A96C60E4EFA76744AE55DF3697B5B911F0B2B27D19DA9E4AC414C7E707D41B0514
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:http://hamurg.de/
                                                    Preview:<html><head><title>Loading...</title></head><body><script type='text/javascript'>window.location.replace('http://hamurg.de/?ch=1&js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTcxMzUzOTA1MiwiaWF0IjoxNzEzNTMxODUyLCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIydjNyMDkwYWpobmFlaG91azgwMDQ1cWUiLCJuYmYiOjE3MTM1MzE4NTIsInRzIjoxNzEzNTMxODUyMDgxMDA2fQ.ezZ05aidcgO3H0pnePOKswrQRaumWQCJV-BdfAsE41s&sid=46775c02-fe4d-11ee-9505-b6d7f5572335');</script></body></html>
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with very long lines (22367), with no line terminators
                                                    Category:downloaded
                                                    Size (bytes):22367
                                                    Entropy (8bit):5.542626302580642
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:B0B46B807EEE39AF0AAD8F5FEFC9B3A2
                                                    SHA1:0FB04F15599BC0844063A6AB776C86E73CB9FBFC
                                                    SHA-256:71CA2652E2B3FFD3C0EC966958604714CE6C7AF01D961B44ADC438518EB58CB3
                                                    SHA-512:4EEC49904A5480940124A1C1B9C9DAE764EBB115829CBCE4356E66A1D7F077DFD204A4634B0622FFB14CC6EBFF7062D7F30502BF0BC7D998A1A55FC8C876DA8E
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://www.gstatic.com/_/translate_http/_/ss/k=translate_http.tr.26tY-h6gH9w.L.W.O/am=wA/d=0/rs=AN8SPfpPTNr3cQN8QhzqvQYsNrDu3oHhow/m=el_main_css
                                                    Preview:.VIpgJd-ZVi9od-ORHb-OEVmcd{left:0;top:0;height:39px;width:100%;z-index:10000001;position:fixed;border:none;border-bottom:1px solid #6B90DA;margin:0;box-shadow:0 0 8px 1px #999}.VIpgJd-ZVi9od-xl07Ob-OEVmcd{z-index:10000002;border:none;position:fixed;box-shadow:0 3px 8px 2px #999}.VIpgJd-ZVi9od-SmfZ-OEVmcd{z-index:10000000;border:none;margin:0}.goog-te-gadget{font-family:arial;font-size:11px;color:#666;white-space:nowrap}.goog-te-gadget img{vertical-align:middle;border:none}.goog-te-gadget-simple{background-color:#FFF;border-left:1px solid #D5D5D5;border-top:1px solid #9B9B9B;border-bottom:1px solid #E8E8E8;border-right:1px solid #D5D5D5;font-size:10pt;display:inline-block;padding-top:1px;padding-bottom:2px;cursor:pointer}.goog-te-gadget-icon{margin-left:2px;margin-right:2px;width:19px;height:19px;border:none;vertical-align:middle}.goog-te-combo{margin-left:4px;margin-right:4px;vertical-align:baseline}.goog-te-gadget .goog-te-combo{margin:4px 0}.VIpgJd-ZVi9od-l4eHX-hSRGPd,.VIpgJd-ZVi9od-
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:SVG Scalable Vector Graphics image
                                                    Category:downloaded
                                                    Size (bytes):6225
                                                    Entropy (8bit):5.976934819783072
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:2BD5C073A88B83ED74DB88282A56DDFB
                                                    SHA1:D0EBFC376F8C6A44A8D4CD216817DCD7D0C33650
                                                    SHA-256:AB5C23A05E39DEED14D9D8262B0DCE9F024F86105A27196CAD37D14A3F516E09
                                                    SHA-512:5C6C4A92E93FC0F6A675658CC84F6187FDEBD3EEE94EFD07E24658736CBA598F3BC7156B19834B13FB44C1D43FCB7DF9FCCA7F0A453037E30DA76BA8F4B23B89
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://fonts.gstatic.com/s/i/productlogos/translate/v14/24px.svg
                                                    Preview:<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" height="24" viewBox="0 0 24 24" width="24"><path d="M0 0h24v24H0z" fill="none"/><defs><path d="M21.5 5h-9.17L11 1H2.5C1.68 1 1 1.68 1 2.5v15c0 .83.68 1.5 1.5 1.5h9.17L13 23h8.5c.82 0 1.5-.68 1.5-1.5v-15c0-.83-.68-1.5-1.5-1.5z" id="a"/></defs><clipPath id="b"><use overflow="visible" xlink:href="#a"/></clipPath><g clip-path="url(#b)"><image height="31" opacity=".2" overflow="visible" transform="translate(3 1)" width="29" xlink:href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAB0AAAAfCAYAAAAbW8YEAAAACXBIWXMAAAsSAAALEgHS3X78AAAA GXRFWHRTb2Z0d2FyZQBBZG9iZSBJbWFnZVJlYWR5ccllPAAABQBJREFUeNq8V8tu20YUvXdm+LCk RKiMwI1TFEXhVZJd1gW66xekv9DPqPsvXdU/UaDroJskKy+CInCcGpKtFy2SM/f2DEXZia0odtKW AkFJ8zhzzn3S0Ycvps+79EMDbj3Yfgv4EM+XTN/fEOb3Zg3AXmq7j64D5/e/x/EfzZMnX5jx+LFZ LLyp6yNDOzskYb6RubFdpbdvKUl2Jc+d9PvP5dmzUyH6TVoYXQOq+H5g9vb+cONsO9maLpIyyZPU kZNAppmh9Vpg5kSXwCSVJ5/Vi/r8Tl73y2F9ePidJ3oaga+B4vkUgF+6EW1ndz11gvNdDdL1bDN
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
                                                    Category:downloaded
                                                    Size (bytes):48236
                                                    Entropy (8bit):7.994912604882335
                                                    Encrypted:true
                                                    SSDEEP:
                                                    MD5:015C126A3520C9A8F6A27979D0266E96
                                                    SHA1:2ACF956561D44434A6D84204670CF849D3215D5F
                                                    SHA-256:3C4D6A1421C7DDB7E404521FE8C4CD5BE5AF446D7689CD880BE26612EAAD3CFA
                                                    SHA-512:02A20F2788BB1C3B2C7D3142C664CDEC306B6BA5366E57E33C008EDB3EB78638B98DC03CDF932A9DC440DED7827956F99117E7A3A4D55ACADD29B006032D9C5C
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTS-muw.woff2
                                                    Preview:wOF2.......l......D...............................O..B..h?HVAR.x.`?STAT.$'...0+...|.../V........+..2.0..6.6.$..`. ..~......[B4q.....t..P.M_.z...1..R.S*...u.#..R....fR.1.N.v.N.P...;.2........!Z......Qs...5f.G.K.an2&....2...*......C.H.t..N!.....nh.<(.vN.....j.._.L.P.t..Ai.%.............._I.i,..o,C.].H.X9.....a.=N....k.....n.L..k.f.u..{...:.}^\[..~5...Z`...........`!...%4..,...K0..&.a/....P....S....m.Z......u...D.j.F...f.0`I.`.`.h#..)(FQ.F!o$........S.).MV8%Rh...r...x...T]$.=......Y...!.3.&U..."....Q....{.l/0..d..4iJ/..}...3....i[Z..NG.WD...>.[U..Q.h..@m.=..S...1C2...d...<..v.?.q.f..n...OUz.....&Z......Z."..N.....n...9.B..C..W....}...W..6Zs.i.+Z........jB.n..x.8M.....q..@I....-.%..,C,..K..#.2...4)/.v_..x.<....t.....%[.4?.=j.V..jj''..W.u..q....I.L.=......E...\.M.7{.>......W........C.`...,9$......\..o........y...4A..m.P.,X..=?.:................wF`..+.P..........M!.4.......l.>M..t.ff5r..^..Z.g...!fA,hIIQ...e.R>B.AH.VuX..>..\.=.ky...1>C....>C.c.;...6D.
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:HTML document, ASCII text, with very long lines (369), with CRLF line terminators
                                                    Category:downloaded
                                                    Size (bytes):3689
                                                    Entropy (8bit):5.204986735486541
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:A4015034D03D94735BED355EEE2A1BA9
                                                    SHA1:96129DDD000FA43F2D05F3FEC01A4DBE558BA08E
                                                    SHA-256:DBEC3816F7FF8637D89733BD9D57E9F90546EAC9B2979BA00BB98E395CD32C37
                                                    SHA-512:A18652F036CBCB33CE3866EB9983199A7EF560B8A889624263CB27E7C5502592E37D766249938DDED4209A94B01FF171D239069E77EEEC5D084C179F3F08C195
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://86861.click.validclick.net/cad.php?srt_hash=Iyw4MDIrOy8vMSc5Pi4rIS0_PDo%2C&adv=16050&utm_source=86861&search=&aid=&b=&subid=9115565977&keyword=*
                                                    Preview:<!DOCTYPE html>..<html>..<head>.. .. .. <script type="text/javascript">.. window.history.forward(1);.. function clicklink() {.. window.location.href = "https://www.choicehotels.com/country-inn-suites?mc=smamimuscxn&pmf=admedia&kw=%2A&utm_medium=sem&utm_source=admedia&utm_account=admedia&utm_campaign=Search_2_Radisson_Park_Inn_CBE_OLD&clickID=MUdrUnBBNU9zajRvNk1IYnR0TEw4QytUYUpGWXZ3OFpFUDRrWjlyRFF3QT0";.. }.. </script>.. ...... .. <script type="text/javascript" >.. if (window.top !== window.self) {.. document.write = "";.. window.top.location = window.self.location; setTimeout(function(){.. document.body.innerHTML='';.. },1);.. window.self.onload=function(evt){.. document.body.innerHTML='';.. };.. }.. </script>.. ..
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with no line terminators
                                                    Category:downloaded
                                                    Size (bytes):64
                                                    Entropy (8bit):4.492897276113269
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:C0DDB93C144B94DA946DC9F727D05538
                                                    SHA1:517BA8265D63543D2F4F2D3E2247A9A9CEE79E9D
                                                    SHA-256:4760B35732ACF6B7C363E144C5FD126EAFEE7315885510FEAF23B0D53938D33F
                                                    SHA-512:FE7BBEF81355A517C2124C01EBA6CB7460E36F0E608849E37721C23B53FE1C9349CBE949016BCD2CABF97629AAB127CC6318B5EC4F6ED87BDB2982580843AD73
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISLAn9uqUg1dGU6RIFDRVQj_4SBQ1a3e0uEgUNUopJoxIFDUC-9V0SBQ1AWQ9b?alt=proto
                                                    Preview:Ci0KBw0VUI/+GgAKBw1a3e0uGgAKBw1SikmjGgAKBw1AvvVdGgAKBw1AWQ9bGgA=
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:HTML document, ASCII text, with very long lines (1533), with CRLF line terminators
                                                    Category:downloaded
                                                    Size (bytes):20222
                                                    Entropy (8bit):4.8634049745423695
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:EFEF2550AA9AC96FCA3F187D454B45A8
                                                    SHA1:2B1AE098E9C21A25B7D83DFD8683C9F2B7E134F5
                                                    SHA-256:C4F2C31BE3BA1F4DB34917280D4BAB568E3CE0750BA5F48F99AD5BCCAA20613E
                                                    SHA-512:405B5ACD419EBB0CF1360A1AE588B020E2524BC442881162DA5809F68D3A46AED1162A450DB929CF98B2B6B1CA0A80361D54B6972F6140F4E52E7B4054E69CA3
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://fastblock.me/?c=23456k&subid=f_211087
                                                    Preview:<html lang="en">..<head>.. <meta charset="utf-8">.. <title>FastBlock</title>.. <meta name="viewport" content="width=1024">.. <link rel="chrome-webstore-item".. href="https://chromewebstore.google.com/detail/blockall-block-ads/jbbpjeecholbhpbicnogbcfoaejengla">.. <link rel="canonical" href="fastblock.me">.. <link rel="preconnect" href="https://fonts.gstatic.com">.. <link href="https://fonts.googleapis.com/css2?family=Open+Sans:wght@100;300;400;500;600;700;900&amp;display=swap".. rel="stylesheet">.... <meta name="robots" content="noindex, nofollow">.. <link href="css/styles.css?2" rel="stylesheet">.. <script src="https://code.jquery.com/jquery-3.6.0.js"></script>.. <script async src="https://www.googletagmanager.com/gtag/js?id=G-0H01VB5FB9"></script>.. <script>.. window.dataLayer = window.dataLayer || [];.. function gtag(){dataLayer.push(arguments);}.. gtag('js', new Date());.... gtag('config', 'G-0H01VB5FB
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:GIF image data, version 89a, 16 x 16
                                                    Category:downloaded
                                                    Size (bytes):702
                                                    Entropy (8bit):6.58442013519738
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:EEFAA072B284A305C12C06608333ABC2
                                                    SHA1:58272721CCC1EFDA26EAA22354022C7C793EDBB6
                                                    SHA-256:FB6B7BCC1AB09F27DB17BCBDF5239CE1D52AF34F1FC5125B3FC8528A07848D21
                                                    SHA-512:C5CCFDCD9CE76DE85F043A1733C9F0B620E15BABBAF2A5639684C7B2BB8E5A66473C9A83F14CB48D9CB6C6A1C6B36F2C5A28E25ABAF131FB85EC5EEDECBAE4AC
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://translate.googleapis.com/translate_static/img/loading.gif
                                                    Preview:GIF89a................BBB...bbb......!..NETSCAPE2.0.....!..Built with GIF Movie Gear 4.0.!..Made by AjaxLoad.info.!.......,..........3....0.Ik.c.:....N.f.E.1......`..q.-[.9..9...Jk.H..!.......,..........4....N.! ......DqBQT`1. `LE[..|..u..a... ...C..%$*..!.......,..........6..2#+.A..V/..c....N.IBa..p.......+.Y.......2.d.....!.......,..........3..b%+.2...V_.....!..1D.a...F.....bR].=.08,...r9L..!.......,..........2..r'+J.d....L..&v.`\bT.....hYB)..@....<..&,...R...!.......,..........3.. .9..t..0....!.B...W..1....sa..5....0.....m)J..!.......,..........2........U]....qp.`..a..4..AF.0..`......@..1......!.......,..........2....0.I.eB.)..... ..q..10...P..a..V.. ub...[....;..........
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text
                                                    Category:downloaded
                                                    Size (bytes):288580
                                                    Entropy (8bit):5.066983843372853
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:2849239B95F5A9A2AEA3F6ED9420BB88
                                                    SHA1:AF32F706407AB08F800C5E697CCE92466E735847
                                                    SHA-256:1FE2BB5390A75E5D61E72C107CAB528FC3C29A837D69AAB7D200E1DBB5DCD239
                                                    SHA-512:9FFE201D6DDAB4CDD0A9171B0A7E9EC26A7170B00719A0E3A4406EE3165DE3B3745B6A10FBAABBA1CDCF5ECB6B2585DC6CD535387750D53EE900FFA08B962EF2
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://code.jquery.com/jquery-3.6.0.js
                                                    Preview:/*!. * jQuery JavaScript Library v3.6.0. * https://jquery.com/. *. * Includes Sizzle.js. * https://sizzlejs.com/. *. * Copyright OpenJS Foundation and other contributors. * Released under the MIT license. * https://jquery.org/license. *. * Date: 2021-03-02T17:08Z. */.( function( global, factory ) {..."use strict";...if ( typeof module === "object" && typeof module.exports === "object" ) {....// For CommonJS and CommonJS-like environments where a proper `window`...// is present, execute the factory and get jQuery....// For environments that do not have a `window` with a `document`...// (such as Node.js), expose a factory as module.exports....// This accentuates the need for the creation of a real `window`....// e.g. var jQuery = require("jquery")(window);...// See ticket #14549 for more info....module.exports = global.document ?....factory( global, true ) :....function( w ) {.....if ( !w.document ) {......throw new Error( "jQuery requires a window with a document" );.....}.....return fa
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
                                                    Category:downloaded
                                                    Size (bytes):1842
                                                    Entropy (8bit):7.844880044441599
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:C69C796362406F9E11C7F4BF5BB628DA
                                                    SHA1:E489CE95AB56208090868882113D7416ABF46775
                                                    SHA-256:4DAC0026FBFA2615DCE30C0AF12830863FE885F84387A0147B9E338F548D5D82
                                                    SHA-512:D3AD560ED0FD29BE7D2CC434694F09E5A6FBEA8B29C0611AECB54A1B73B4D722C53F42A19DAE9E3D5D358444E50FB8FFFBC39D67CE751BDBC8C861F6F95D3162
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://www.gstatic.com/images/branding/product/2x/translate_24dp.png
                                                    Preview:.PNG........IHDR...0...0.....W.......IDATx..Uw.X...........b.....pb.Sfff.6....3o.wvF.(..r.u..9_|...Is%..D......Xz.c....;...y;.....&#.l......H...X..s..]}..5`aZ..D.m....uk.c..i.|.H... I#yB.7.0..._E.".h..Xt.....9.4.......0:y.....F.ua^.|.....K..G..b&2;.z."...B/l$..s3.@..G..Z..`...p..EUU.hni...aZZZT......."...H.Z.....H....<..g.......U.........f."../...Gg...$....<YTU.p.....ND"$^.5!..@.8....Nhj.f.]......"..B..i..,...oh.5.....F.L........;"C...bO...*.Qa.G..!.....4.._....l..N.].....g...PoD....1r{......X.1..!.....}.o....=..^6i.{.......9`i...\~...Dyy9..`..D...n>.....7:.....1...t.(.D.=>....DH.0...K.Mx....,....$..1.1.P.T.............@'..6...Kv..e...D.?.X...k.2..|l.$m&...K/.c......Vn....V ...`I......8al.zT.=..+Wr..%?.X.`..g....,..[...nc..:!..$.@2..3.|....sB...&..*.a.<..}).zX.Q.)5....X.1..bk.....Vn...C#.c......mx.=.[...,.r.G....OMS....e.06.#.+..8Fne......B!...%..,........W...*.F..x#.Vv....I..c(...x5..u.....`hP.......&>......8...D#Cg.v.{Hyb.v..8.K7X`.....|O.z.
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:SVG Scalable Vector Graphics image
                                                    Category:downloaded
                                                    Size (bytes):2509
                                                    Entropy (8bit):4.949969962571623
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:AB782785504F7290D6B79683A2C118CC
                                                    SHA1:F65E0F9012CF6022D393499AB5D9E10229298389
                                                    SHA-256:F27F73621B439DA67360B910D8D696E444E2B02A7DDE37E9508CCFA720B0AA3F
                                                    SHA-512:7B94FDCFC33D385DF4065B74F194DD06E431D26DE60B3558B45C5B0F936E229FCDAAFCEC0F6932B137EF6F2D40A1623A345C63B324887536EE3C29D6FFA2BA5F
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://fastblock.me/images/rocket.svg
                                                    Preview:<?xml version="1.0" encoding="iso-8859-1"?>.. Generator: Adobe Illustrator 16.0.0, SVG Export Plug-In . SVG Version: 6.00 Build 0) -->..<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">..<svg version="1.1" id="Capa_1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px"... width="369.998px" height="369.997px" fill="#EE4F4F" viewBox="0 0 369.998 369.997" style="enable-background:new 0 0 369.998 369.997;"... xml:space="preserve">..<g>...<g>....<g>.....<path d="M369.993,6.919c0.022-1.846-0.692-3.622-1.998-4.927c-1.303-1.302-3.083-2.023-4.924-1.991......c-3.591,0.057-88.576,2.038-143.287,56.748l-69.377,69.377c-16.128-5.68-71.071-16.34-148.411,60.994......c-2.354,2.356-2.656,6.065-0.72,8.777c0.221,0.31,0.461,0.594,0.728,0.859c2.026,2.025,5.166,2.593,7.816,1.291......c0.524-0.259,49.841-24.086,76.021-7.355l-17.168,17.167c-0.417,0.417-0.776,0.887-1.074,1.394......c-0.723,1.257-17.33,31.098,22.357,70
                                                    No static file info