Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://prayas.co/assets/nagateliteqfuk.exe

Overview

General Information

Sample URL:https://prayas.co/assets/nagateliteqfuk.exe
Analysis ID:1429028
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file

Classification

  • System is w10x64
  • chrome.exe (PID: 5232 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 3228 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2152 --field-trial-handle=2004,i,16753486165056282435,4495913877883475114,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6380 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://prayas.co/assets/nagateliteqfuk.exe" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://prayas.co/assets/nagateliteqfuk.exeVirustotal: Detection: 6%Perma Link
Source: https://prayas.co/assets/nagateliteqfuk.exeHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.63.206.91
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.53.35
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.53.35
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.53.35
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.53.35
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.53.35
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /assets/nagateliteqfuk.exe HTTP/1.1Host: prayas.coConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: prayas.coConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://prayas.co/assets/nagateliteqfuk.exeAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: prayas.co
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Sat, 20 Apr 2024 03:46:56 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Sat, 20 Apr 2024 03:46:57 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.63.206.91:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: mal48.win@16/4@4/6
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2152 --field-trial-handle=2004,i,16753486165056282435,4495913877883475114,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://prayas.co/assets/nagateliteqfuk.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2152 --field-trial-handle=2004,i,16753486165056282435,4495913877883475114,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://prayas.co/assets/nagateliteqfuk.exe7%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
windowsupdatebg.s.llnwi.net0%VirustotalBrowse
prayas.co4%VirustotalBrowse
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
prayas.co
3.72.134.250
truefalseunknown
www.google.com
74.125.136.104
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalseunknown
    windowsupdatebg.s.llnwi.net
    69.164.42.0
    truefalseunknown
    NameMaliciousAntivirus DetectionReputation
    https://prayas.co/assets/nagateliteqfuk.exetrue
      unknown
      https://prayas.co/favicon.icofalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        74.125.136.104
        www.google.comUnited States
        15169GOOGLEUSfalse
        3.72.134.250
        prayas.coUnited States
        16509AMAZON-02USfalse
        IP
        192.168.2.4
        192.168.2.6
        192.168.2.5
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1429028
        Start date and time:2024-04-20 05:46:00 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 3m 18s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://prayas.co/assets/nagateliteqfuk.exe
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:8
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal48.win@16/4@4/6
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 64.233.185.94, 64.233.176.138, 64.233.176.113, 64.233.176.102, 64.233.176.139, 64.233.176.100, 64.233.176.101, 64.233.176.84, 34.104.35.123, 20.114.59.183, 69.164.42.0, 192.229.211.108, 13.95.31.18, 52.165.164.15, 172.217.215.94
        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        No simulations
        No context
        No context
        No context
        No context
        No context
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text
        Category:downloaded
        Size (bytes):315
        Entropy (8bit):5.0572271090563765
        Encrypted:false
        SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
        MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
        SHA1:A82190FC530C265AA40A045C21770D967F4767B8
        SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
        SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
        Malicious:false
        Reputation:low
        URL:https://prayas.co/favicon.ico
        Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
        File Type:HTML document, ASCII text
        Category:downloaded
        Size (bytes):315
        Entropy (8bit):5.0572271090563765
        Encrypted:false
        SSDEEP:6:pn0+Dy9xwGObRmEr6VnetdzRx3G0CezoFEHcLgabzjsKtgsg93wzRbKqD:J0+oxBeRmR9etdzRxGezZfCzjsKtgizR
        MD5:A34AC19F4AFAE63ADC5D2F7BC970C07F
        SHA1:A82190FC530C265AA40A045C21770D967F4767B8
        SHA-256:D5A89E26BEAE0BC03AD18A0B0D1D3D75F87C32047879D25DA11970CB5C4662A3
        SHA-512:42E53D96E5961E95B7A984D9C9778A1D3BD8EE0C87B8B3B515FA31F67C2D073C8565AFC2F4B962C43668C4EFA1E478DA9BB0ECFFA79479C7E880731BC4C55765
        Malicious:false
        Reputation:low
        URL:https://prayas.co/assets/nagateliteqfuk.exe
        Preview:<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>404 Not Found</title>.</head><body>.<h1>Not Found</h1>.<p>The requested URL was not found on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Apr 20, 2024 05:46:45.717216969 CEST49675443192.168.2.4173.222.162.32
        Apr 20, 2024 05:46:55.323815107 CEST49675443192.168.2.4173.222.162.32
        Apr 20, 2024 05:46:56.017004013 CEST49735443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.017079115 CEST443497353.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.017175913 CEST49735443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.017405987 CEST49736443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.017440081 CEST443497363.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.017503977 CEST49736443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.017956972 CEST49735443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.017991066 CEST443497353.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.018336058 CEST49736443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.018347025 CEST443497363.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.449096918 CEST443497363.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.449321985 CEST49736443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.449342966 CEST443497363.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.451000929 CEST443497363.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.451082945 CEST49736443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.452022076 CEST49736443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.452126026 CEST443497363.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.452228069 CEST49736443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.452238083 CEST443497363.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.456401110 CEST443497353.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.456623077 CEST49735443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.456681013 CEST443497353.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.458364964 CEST443497353.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.458439112 CEST49735443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.459306955 CEST49735443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.459402084 CEST443497353.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.498126030 CEST49736443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.513912916 CEST49735443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.513968945 CEST443497353.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.560049057 CEST49735443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.861872911 CEST443497363.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.862096071 CEST443497363.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.862162113 CEST49736443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.864607096 CEST49736443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:56.864624023 CEST443497363.72.134.250192.168.2.4
        Apr 20, 2024 05:46:56.975409985 CEST49735443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:57.020116091 CEST443497353.72.134.250192.168.2.4
        Apr 20, 2024 05:46:57.190360069 CEST443497353.72.134.250192.168.2.4
        Apr 20, 2024 05:46:57.190437078 CEST443497353.72.134.250192.168.2.4
        Apr 20, 2024 05:46:57.190501928 CEST49735443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:57.193312883 CEST49735443192.168.2.43.72.134.250
        Apr 20, 2024 05:46:57.193350077 CEST443497353.72.134.250192.168.2.4
        Apr 20, 2024 05:46:58.224282980 CEST49739443192.168.2.474.125.136.104
        Apr 20, 2024 05:46:58.224327087 CEST4434973974.125.136.104192.168.2.4
        Apr 20, 2024 05:46:58.224383116 CEST49739443192.168.2.474.125.136.104
        Apr 20, 2024 05:46:58.225231886 CEST49739443192.168.2.474.125.136.104
        Apr 20, 2024 05:46:58.225253105 CEST4434973974.125.136.104192.168.2.4
        Apr 20, 2024 05:46:58.454962969 CEST4434973974.125.136.104192.168.2.4
        Apr 20, 2024 05:46:58.464566946 CEST49739443192.168.2.474.125.136.104
        Apr 20, 2024 05:46:58.464597940 CEST4434973974.125.136.104192.168.2.4
        Apr 20, 2024 05:46:58.466876030 CEST4434973974.125.136.104192.168.2.4
        Apr 20, 2024 05:46:58.466939926 CEST49739443192.168.2.474.125.136.104
        Apr 20, 2024 05:46:58.470139980 CEST49739443192.168.2.474.125.136.104
        Apr 20, 2024 05:46:58.470264912 CEST4434973974.125.136.104192.168.2.4
        Apr 20, 2024 05:46:58.520675898 CEST49739443192.168.2.474.125.136.104
        Apr 20, 2024 05:46:58.520684958 CEST4434973974.125.136.104192.168.2.4
        Apr 20, 2024 05:46:58.567548037 CEST49739443192.168.2.474.125.136.104
        Apr 20, 2024 05:46:58.646862030 CEST49740443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:58.646908045 CEST4434974023.63.206.91192.168.2.4
        Apr 20, 2024 05:46:58.646981001 CEST49740443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:58.649717093 CEST49740443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:58.649754047 CEST4434974023.63.206.91192.168.2.4
        Apr 20, 2024 05:46:58.878182888 CEST4434974023.63.206.91192.168.2.4
        Apr 20, 2024 05:46:58.878348112 CEST49740443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:58.884664059 CEST49740443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:58.884692907 CEST4434974023.63.206.91192.168.2.4
        Apr 20, 2024 05:46:58.885143042 CEST4434974023.63.206.91192.168.2.4
        Apr 20, 2024 05:46:58.927057981 CEST49740443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:58.956265926 CEST49740443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:59.004118919 CEST4434974023.63.206.91192.168.2.4
        Apr 20, 2024 05:46:59.076742887 CEST4434974023.63.206.91192.168.2.4
        Apr 20, 2024 05:46:59.076898098 CEST4434974023.63.206.91192.168.2.4
        Apr 20, 2024 05:46:59.076968908 CEST49740443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:59.077049971 CEST49740443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:59.077049971 CEST49740443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:59.077090025 CEST4434974023.63.206.91192.168.2.4
        Apr 20, 2024 05:46:59.077120066 CEST4434974023.63.206.91192.168.2.4
        Apr 20, 2024 05:46:59.120192051 CEST49741443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:59.120229959 CEST4434974123.63.206.91192.168.2.4
        Apr 20, 2024 05:46:59.120296001 CEST49741443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:59.120554924 CEST49741443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:59.120573044 CEST4434974123.63.206.91192.168.2.4
        Apr 20, 2024 05:46:59.341924906 CEST4434974123.63.206.91192.168.2.4
        Apr 20, 2024 05:46:59.342010975 CEST49741443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:59.343132019 CEST49741443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:59.343141079 CEST4434974123.63.206.91192.168.2.4
        Apr 20, 2024 05:46:59.343461990 CEST4434974123.63.206.91192.168.2.4
        Apr 20, 2024 05:46:59.344454050 CEST49741443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:59.392113924 CEST4434974123.63.206.91192.168.2.4
        Apr 20, 2024 05:46:59.547724009 CEST4434974123.63.206.91192.168.2.4
        Apr 20, 2024 05:46:59.547959089 CEST4434974123.63.206.91192.168.2.4
        Apr 20, 2024 05:46:59.548022032 CEST49741443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:59.559169054 CEST49741443192.168.2.423.63.206.91
        Apr 20, 2024 05:46:59.559195042 CEST4434974123.63.206.91192.168.2.4
        Apr 20, 2024 05:47:08.447855949 CEST4434973974.125.136.104192.168.2.4
        Apr 20, 2024 05:47:08.448016882 CEST4434973974.125.136.104192.168.2.4
        Apr 20, 2024 05:47:08.448174953 CEST49739443192.168.2.474.125.136.104
        Apr 20, 2024 05:47:10.307029009 CEST49739443192.168.2.474.125.136.104
        Apr 20, 2024 05:47:10.307092905 CEST4434973974.125.136.104192.168.2.4
        Apr 20, 2024 05:47:12.767076969 CEST8049723217.20.53.35192.168.2.4
        Apr 20, 2024 05:47:12.767221928 CEST4972380192.168.2.4217.20.53.35
        Apr 20, 2024 05:47:12.767286062 CEST4972380192.168.2.4217.20.53.35
        Apr 20, 2024 05:47:13.089667082 CEST4972380192.168.2.4217.20.53.35
        Apr 20, 2024 05:47:13.229881048 CEST8049723217.20.53.35192.168.2.4
        Apr 20, 2024 05:47:27.536406040 CEST8049724217.20.53.35192.168.2.4
        Apr 20, 2024 05:47:27.538995981 CEST4972480192.168.2.4217.20.53.35
        Apr 20, 2024 05:47:27.558183908 CEST4972480192.168.2.4217.20.53.35
        Apr 20, 2024 05:47:27.698246956 CEST8049724217.20.53.35192.168.2.4
        Apr 20, 2024 05:47:58.156400919 CEST49750443192.168.2.474.125.136.104
        Apr 20, 2024 05:47:58.156500101 CEST4434975074.125.136.104192.168.2.4
        Apr 20, 2024 05:47:58.156579971 CEST49750443192.168.2.474.125.136.104
        Apr 20, 2024 05:47:58.156925917 CEST49750443192.168.2.474.125.136.104
        Apr 20, 2024 05:47:58.156965971 CEST4434975074.125.136.104192.168.2.4
        Apr 20, 2024 05:47:58.374587059 CEST4434975074.125.136.104192.168.2.4
        Apr 20, 2024 05:47:58.375027895 CEST49750443192.168.2.474.125.136.104
        Apr 20, 2024 05:47:58.375066996 CEST4434975074.125.136.104192.168.2.4
        Apr 20, 2024 05:47:58.375744104 CEST4434975074.125.136.104192.168.2.4
        Apr 20, 2024 05:47:58.376068115 CEST49750443192.168.2.474.125.136.104
        Apr 20, 2024 05:47:58.376183033 CEST4434975074.125.136.104192.168.2.4
        Apr 20, 2024 05:47:58.417330027 CEST49750443192.168.2.474.125.136.104
        Apr 20, 2024 05:48:08.375195026 CEST4434975074.125.136.104192.168.2.4
        Apr 20, 2024 05:48:08.375272036 CEST4434975074.125.136.104192.168.2.4
        Apr 20, 2024 05:48:08.375324011 CEST49750443192.168.2.474.125.136.104
        Apr 20, 2024 05:48:10.184923887 CEST49750443192.168.2.474.125.136.104
        Apr 20, 2024 05:48:10.184956074 CEST4434975074.125.136.104192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Apr 20, 2024 05:46:53.905991077 CEST53607381.1.1.1192.168.2.4
        Apr 20, 2024 05:46:53.970022917 CEST53492961.1.1.1192.168.2.4
        Apr 20, 2024 05:46:54.570158958 CEST53570121.1.1.1192.168.2.4
        Apr 20, 2024 05:46:55.761521101 CEST5957353192.168.2.41.1.1.1
        Apr 20, 2024 05:46:55.761698961 CEST6076453192.168.2.41.1.1.1
        Apr 20, 2024 05:46:55.960691929 CEST53595731.1.1.1192.168.2.4
        Apr 20, 2024 05:46:56.049252033 CEST53607641.1.1.1192.168.2.4
        Apr 20, 2024 05:46:58.110570908 CEST5166453192.168.2.41.1.1.1
        Apr 20, 2024 05:46:58.110838890 CEST5639953192.168.2.41.1.1.1
        Apr 20, 2024 05:46:58.215395927 CEST53563991.1.1.1192.168.2.4
        Apr 20, 2024 05:46:58.215444088 CEST53516641.1.1.1192.168.2.4
        Apr 20, 2024 05:47:11.821639061 CEST53506451.1.1.1192.168.2.4
        Apr 20, 2024 05:47:13.800029039 CEST138138192.168.2.4192.168.2.255
        Apr 20, 2024 05:47:30.857902050 CEST53649881.1.1.1192.168.2.4
        Apr 20, 2024 05:47:53.539222956 CEST53608751.1.1.1192.168.2.4
        Apr 20, 2024 05:47:53.728393078 CEST53654721.1.1.1192.168.2.4
        TimestampSource IPDest IPChecksumCodeType
        Apr 20, 2024 05:46:56.049458981 CEST192.168.2.41.1.1.1c235(Port unreachable)Destination Unreachable
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 20, 2024 05:46:55.761521101 CEST192.168.2.41.1.1.10x6502Standard query (0)prayas.coA (IP address)IN (0x0001)false
        Apr 20, 2024 05:46:55.761698961 CEST192.168.2.41.1.1.10x24e3Standard query (0)prayas.co65IN (0x0001)false
        Apr 20, 2024 05:46:58.110570908 CEST192.168.2.41.1.1.10xf9b0Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 20, 2024 05:46:58.110838890 CEST192.168.2.41.1.1.10x73b7Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 20, 2024 05:46:55.960691929 CEST1.1.1.1192.168.2.40x6502No error (0)prayas.co3.72.134.250A (IP address)IN (0x0001)false
        Apr 20, 2024 05:46:58.215395927 CEST1.1.1.1192.168.2.40x73b7No error (0)www.google.com65IN (0x0001)false
        Apr 20, 2024 05:46:58.215444088 CEST1.1.1.1192.168.2.40xf9b0No error (0)www.google.com74.125.136.104A (IP address)IN (0x0001)false
        Apr 20, 2024 05:46:58.215444088 CEST1.1.1.1192.168.2.40xf9b0No error (0)www.google.com74.125.136.103A (IP address)IN (0x0001)false
        Apr 20, 2024 05:46:58.215444088 CEST1.1.1.1192.168.2.40xf9b0No error (0)www.google.com74.125.136.106A (IP address)IN (0x0001)false
        Apr 20, 2024 05:46:58.215444088 CEST1.1.1.1192.168.2.40xf9b0No error (0)www.google.com74.125.136.99A (IP address)IN (0x0001)false
        Apr 20, 2024 05:46:58.215444088 CEST1.1.1.1192.168.2.40xf9b0No error (0)www.google.com74.125.136.105A (IP address)IN (0x0001)false
        Apr 20, 2024 05:46:58.215444088 CEST1.1.1.1192.168.2.40xf9b0No error (0)www.google.com74.125.136.147A (IP address)IN (0x0001)false
        Apr 20, 2024 05:47:08.844412088 CEST1.1.1.1192.168.2.40x17e7No error (0)windowsupdatebg.s.llnwi.net69.164.42.0A (IP address)IN (0x0001)false
        Apr 20, 2024 05:47:09.207182884 CEST1.1.1.1192.168.2.40x8e54No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 20, 2024 05:47:09.207182884 CEST1.1.1.1192.168.2.40x8e54No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 20, 2024 05:47:22.258291960 CEST1.1.1.1192.168.2.40x13aaNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 20, 2024 05:47:22.258291960 CEST1.1.1.1192.168.2.40x13aaNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 20, 2024 05:47:45.945375919 CEST1.1.1.1192.168.2.40x13e6No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 20, 2024 05:47:45.945375919 CEST1.1.1.1192.168.2.40x13e6No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        Apr 20, 2024 05:48:06.463192940 CEST1.1.1.1192.168.2.40x4592No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 20, 2024 05:48:06.463192940 CEST1.1.1.1192.168.2.40x4592No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
        • prayas.co
        • https:
        • fs.microsoft.com
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.4497363.72.134.2504433228C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2024-04-20 03:46:56 UTC677OUTGET /assets/nagateliteqfuk.exe HTTP/1.1
        Host: prayas.co
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        sec-ch-ua-platform: "Windows"
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Sec-Fetch-Site: none
        Sec-Fetch-Mode: navigate
        Sec-Fetch-User: ?1
        Sec-Fetch-Dest: document
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2024-04-20 03:46:56 UTC164INHTTP/1.1 404 Not Found
        Date: Sat, 20 Apr 2024 03:46:56 GMT
        Server: Apache
        Content-Length: 315
        Connection: close
        Content-Type: text/html; charset=iso-8859-1
        2024-04-20 03:46:56 UTC315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
        Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        1192.168.2.4497353.72.134.2504433228C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        2024-04-20 03:46:56 UTC599OUTGET /favicon.ico HTTP/1.1
        Host: prayas.co
        Connection: keep-alive
        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
        sec-ch-ua-mobile: ?0
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        sec-ch-ua-platform: "Windows"
        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
        Sec-Fetch-Site: same-origin
        Sec-Fetch-Mode: no-cors
        Sec-Fetch-Dest: image
        Referer: https://prayas.co/assets/nagateliteqfuk.exe
        Accept-Encoding: gzip, deflate, br
        Accept-Language: en-US,en;q=0.9
        2024-04-20 03:46:57 UTC164INHTTP/1.1 404 Not Found
        Date: Sat, 20 Apr 2024 03:46:57 GMT
        Server: Apache
        Content-Length: 315
        Connection: close
        Content-Type: text/html; charset=iso-8859-1
        2024-04-20 03:46:57 UTC315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65
        Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        2192.168.2.44974023.63.206.91443
        TimestampBytes transferredDirectionData
        2024-04-20 03:46:58 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-20 03:46:59 UTC466INHTTP/1.1 200 OK
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        Content-Type: application/octet-stream
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        Server: ECAcc (chd/073D)
        X-CID: 11
        X-Ms-ApiVersion: Distribute 1.2
        X-Ms-Region: prod-eus-z1
        Cache-Control: public, max-age=98209
        Date: Sat, 20 Apr 2024 03:46:59 GMT
        Connection: close
        X-CID: 2


        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        3192.168.2.44974123.63.206.91443
        TimestampBytes transferredDirectionData
        2024-04-20 03:46:59 UTC239OUTGET /fs/windows/config.json HTTP/1.1
        Connection: Keep-Alive
        Accept: */*
        Accept-Encoding: identity
        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
        Range: bytes=0-2147483646
        User-Agent: Microsoft BITS/7.8
        Host: fs.microsoft.com
        2024-04-20 03:46:59 UTC530INHTTP/1.1 200 OK
        Content-Type: application/octet-stream
        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
        ApiVersion: Distribute 1.1
        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
        X-Azure-Ref: 0rcGnYgAAAAANOnx9vccHTr21ROgX9ESTU0pDRURHRTAzMDkAY2VmYzI1ODMtYTliMi00NGE3LTk3NTUtYjc2ZDE3ZTA1Zjdm
        Cache-Control: public, max-age=98194
        Date: Sat, 20 Apr 2024 03:46:59 GMT
        Content-Length: 55
        Connection: close
        X-CID: 2
        2024-04-20 03:46:59 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:05:46:49
        Start date:20/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:05:46:52
        Start date:20/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2152 --field-trial-handle=2004,i,16753486165056282435,4495913877883475114,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:05:46:55
        Start date:20/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://prayas.co/assets/nagateliteqfuk.exe"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly