Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://leakemup.io/Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp4

Overview

General Information

Sample URL:https://leakemup.io/Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp4
Analysis ID:1430703
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3992 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2992 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2284 --field-trial-handle=2240,i,14587354550524089327,5314212494730964797,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6436 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://leakemup.io/Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp4" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://leakemup.io/Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp4HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.40.26.94:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.40.26.94:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.40.26.94
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.192.228.140
Source: unknownTCP traffic detected without corresponding DNS query: 23.192.228.140
Source: unknownTCP traffic detected without corresponding DNS query: 23.192.228.140
Source: unknownTCP traffic detected without corresponding DNS query: 23.192.228.140
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp4 HTTP/1.1Host: leakemup.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: leakemup.ioConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://leakemup.io/Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp4Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: unknownDNS traffic detected: queries for: leakemup.io
Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenServer: nginx/1.20.1Date: Wed, 24 Apr 2024 01:24:07 GMTContent-Type: text/htmlContent-Length: 555Connection: close
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.20.1Date: Wed, 24 Apr 2024 01:24:07 GMTContent-Type: text/htmlContent-Length: 555Connection: close
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49672
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 23.40.26.94:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.40.26.94:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: classification engineClassification label: clean0.win@16/4@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2284 --field-trial-handle=2240,i,14587354550524089327,5314212494730964797,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://leakemup.io/Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp4"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2284 --field-trial-handle=2240,i,14587354550524089327,5314212494730964797,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://leakemup.io/Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp40%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://leakemup.io/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
leakemup.io
91.209.70.219
truefalse
    unknown
    www.google.com
    142.250.101.106
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://leakemup.io/favicon.icofalse
        • Avira URL Cloud: safe
        unknown
        https://leakemup.io/Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp4false
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          142.250.101.106
          www.google.comUnited States
          15169GOOGLEUSfalse
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          91.209.70.219
          leakemup.ioRussian Federation
          43317FISHNET-ASRUfalse
          IP
          192.168.2.4
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1430703
          Start date and time:2024-04-24 03:23:03 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 3m 24s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:https://leakemup.io/Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp4
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:8
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:CLEAN
          Classification:clean0.win@16/4@4/4
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 74.125.137.94, 142.251.2.84, 142.251.2.139, 142.251.2.102, 142.251.2.101, 142.251.2.100, 142.251.2.138, 142.251.2.113, 34.104.35.123, 52.165.165.26, 23.223.17.204, 23.223.17.208, 13.85.23.206, 192.229.211.108, 142.251.2.94
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, glb.sls.prod.dcat.dsp.trafficmanager.net
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:HTML document, ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):555
          Entropy (8bit):4.707865486738638
          Encrypted:false
          SSDEEP:12:TvgsoCVIogs01lI5rruNGlTF5TF5TF5TF5TF5TFK:cEQtne5TPTPTPTPTPTc
          MD5:1879EFAD0805A8AB0FA79FBE7D39C7E5
          SHA1:9AD30E36140C292F3CCB2B75375521EC7B970489
          SHA-256:31516D62EF17249B8A8B275A4EAAB2FD9F21F573496DA31371266038C4214144
          SHA-512:03A6E6A1A321B2A972945C19CCCE199F2E9BC9EFCCF1D848ACED7D433CF7D85B944DACAE141BF42CC5FB0910C427BC34D3E51FFD0432AB50D667028E75A5028E
          Malicious:false
          Reputation:low
          URL:https://leakemup.io/Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp4
          Preview:<html>..<head><title>403 Forbidden</title></head>..<body>..<center><h1>403 Forbidden</h1></center>..<hr><center>nginx/1.20.1</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:HTML document, ASCII text, with CRLF line terminators
          Category:downloaded
          Size (bytes):555
          Entropy (8bit):4.73524642638354
          Encrypted:false
          SSDEEP:12:TjeRHVIdtklI5rruNGlTF5TF5TF5TF5TF5TFK:neRH68e5TPTPTPTPTPTc
          MD5:565C1EAE816296EB5A8240C33F015484
          SHA1:99A9E36394DAD3E08C38DB95E33469C0B31F2753
          SHA-256:922A7A005A299DAAB272EF3B0C7106716572ECE666C54C187CE6836B32474973
          SHA-512:67E5710ADA9F43699CFBCA159A089B84F85EB1B08E779753481BF19F2AA0F57655F7D82B2AF7C4C7DE14A5523FF6AC7D56FCBAF7831786E9A7C949AEF308BD0A
          Malicious:false
          Reputation:low
          URL:https://leakemup.io/favicon.ico
          Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx/1.20.1</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Apr 24, 2024 03:23:54.995846033 CEST49675443192.168.2.4173.222.162.32
          Apr 24, 2024 03:24:04.775099039 CEST49675443192.168.2.4173.222.162.32
          Apr 24, 2024 03:24:06.098258972 CEST49737443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.098304987 CEST4434973791.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.098355055 CEST49737443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.098673105 CEST49738443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.098705053 CEST4434973891.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.098858118 CEST49738443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.098958015 CEST49737443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.098973036 CEST4434973791.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.099216938 CEST49738443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.099231958 CEST4434973891.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.828797102 CEST4434973891.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.829185009 CEST49738443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.829207897 CEST4434973891.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.830678940 CEST4434973891.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.830796957 CEST49738443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.832127094 CEST49738443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.832206011 CEST4434973891.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.832582951 CEST49738443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.832591057 CEST4434973891.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.835738897 CEST4434973791.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.835969925 CEST49737443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.835993052 CEST4434973791.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.837666988 CEST4434973791.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.837764978 CEST49737443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.839483023 CEST49737443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.839562893 CEST4434973791.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.883919954 CEST49737443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.883924007 CEST49738443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:06.883930922 CEST4434973791.209.70.219192.168.2.4
          Apr 24, 2024 03:24:06.932179928 CEST49737443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:07.533802032 CEST4434973891.209.70.219192.168.2.4
          Apr 24, 2024 03:24:07.533905029 CEST4434973891.209.70.219192.168.2.4
          Apr 24, 2024 03:24:07.533955097 CEST49738443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:07.535679102 CEST49738443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:07.535696030 CEST4434973891.209.70.219192.168.2.4
          Apr 24, 2024 03:24:07.682643890 CEST49737443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:07.728137970 CEST4434973791.209.70.219192.168.2.4
          Apr 24, 2024 03:24:08.040004015 CEST4434973791.209.70.219192.168.2.4
          Apr 24, 2024 03:24:08.040194988 CEST4434973791.209.70.219192.168.2.4
          Apr 24, 2024 03:24:08.040254116 CEST49737443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:08.040770054 CEST49737443192.168.2.491.209.70.219
          Apr 24, 2024 03:24:08.040792942 CEST4434973791.209.70.219192.168.2.4
          Apr 24, 2024 03:24:08.345523119 CEST49739443192.168.2.4142.250.101.106
          Apr 24, 2024 03:24:08.345607042 CEST44349739142.250.101.106192.168.2.4
          Apr 24, 2024 03:24:08.345745087 CEST49739443192.168.2.4142.250.101.106
          Apr 24, 2024 03:24:08.346942902 CEST49739443192.168.2.4142.250.101.106
          Apr 24, 2024 03:24:08.346981049 CEST44349739142.250.101.106192.168.2.4
          Apr 24, 2024 03:24:08.467739105 CEST49740443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:08.467828989 CEST4434974023.40.26.94192.168.2.4
          Apr 24, 2024 03:24:08.467915058 CEST49740443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:08.470141888 CEST49740443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:08.470175028 CEST4434974023.40.26.94192.168.2.4
          Apr 24, 2024 03:24:08.717694044 CEST44349739142.250.101.106192.168.2.4
          Apr 24, 2024 03:24:08.718122959 CEST49739443192.168.2.4142.250.101.106
          Apr 24, 2024 03:24:08.718161106 CEST44349739142.250.101.106192.168.2.4
          Apr 24, 2024 03:24:08.719820023 CEST44349739142.250.101.106192.168.2.4
          Apr 24, 2024 03:24:08.719964027 CEST49739443192.168.2.4142.250.101.106
          Apr 24, 2024 03:24:08.722492933 CEST49739443192.168.2.4142.250.101.106
          Apr 24, 2024 03:24:08.722587109 CEST44349739142.250.101.106192.168.2.4
          Apr 24, 2024 03:24:08.775882959 CEST49739443192.168.2.4142.250.101.106
          Apr 24, 2024 03:24:08.775896072 CEST44349739142.250.101.106192.168.2.4
          Apr 24, 2024 03:24:08.822751999 CEST49739443192.168.2.4142.250.101.106
          Apr 24, 2024 03:24:08.825402021 CEST4434974023.40.26.94192.168.2.4
          Apr 24, 2024 03:24:08.825474977 CEST49740443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:08.830413103 CEST49740443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:08.830420017 CEST4434974023.40.26.94192.168.2.4
          Apr 24, 2024 03:24:08.830835104 CEST4434974023.40.26.94192.168.2.4
          Apr 24, 2024 03:24:08.885251999 CEST49740443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:08.894803047 CEST49740443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:08.940121889 CEST4434974023.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.172350883 CEST4434974023.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.172574997 CEST49740443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:09.172619104 CEST4434974023.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.172655106 CEST49740443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:09.172962904 CEST4434974023.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.173046112 CEST4434974023.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.173103094 CEST49740443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:09.207207918 CEST49741443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:09.207295895 CEST4434974123.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.207392931 CEST49741443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:09.207670927 CEST49741443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:09.207722902 CEST4434974123.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.564245939 CEST4434974123.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.564344883 CEST49741443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:09.565673113 CEST49741443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:09.565706015 CEST4434974123.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.566570997 CEST4434974123.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.567713022 CEST49741443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:09.612137079 CEST4434974123.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.957724094 CEST4434974123.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.960310936 CEST4434974123.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.960416079 CEST49741443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:09.978632927 CEST49741443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:09.978678942 CEST4434974123.40.26.94192.168.2.4
          Apr 24, 2024 03:24:09.978733063 CEST49741443192.168.2.423.40.26.94
          Apr 24, 2024 03:24:09.978749037 CEST4434974123.40.26.94192.168.2.4
          Apr 24, 2024 03:24:16.324553967 CEST49672443192.168.2.4173.222.162.32
          Apr 24, 2024 03:24:16.324593067 CEST44349672173.222.162.32192.168.2.4
          Apr 24, 2024 03:24:18.718185902 CEST44349739142.250.101.106192.168.2.4
          Apr 24, 2024 03:24:18.718369007 CEST44349739142.250.101.106192.168.2.4
          Apr 24, 2024 03:24:18.718450069 CEST49739443192.168.2.4142.250.101.106
          Apr 24, 2024 03:24:19.330573082 CEST4972380192.168.2.423.192.228.140
          Apr 24, 2024 03:24:19.509402990 CEST804972323.192.228.140192.168.2.4
          Apr 24, 2024 03:24:19.509478092 CEST4972380192.168.2.423.192.228.140
          Apr 24, 2024 03:24:19.933902979 CEST49739443192.168.2.4142.250.101.106
          Apr 24, 2024 03:24:19.933965921 CEST44349739142.250.101.106192.168.2.4
          Apr 24, 2024 03:25:04.744775057 CEST4972480192.168.2.423.192.228.140
          Apr 24, 2024 03:25:04.918215036 CEST804972423.192.228.140192.168.2.4
          Apr 24, 2024 03:25:04.918288946 CEST4972480192.168.2.423.192.228.140
          Apr 24, 2024 03:25:08.222965956 CEST49750443192.168.2.4142.250.101.106
          Apr 24, 2024 03:25:08.223016024 CEST44349750142.250.101.106192.168.2.4
          Apr 24, 2024 03:25:08.223294020 CEST49750443192.168.2.4142.250.101.106
          Apr 24, 2024 03:25:08.223628044 CEST49750443192.168.2.4142.250.101.106
          Apr 24, 2024 03:25:08.223638058 CEST44349750142.250.101.106192.168.2.4
          Apr 24, 2024 03:25:08.577729940 CEST44349750142.250.101.106192.168.2.4
          Apr 24, 2024 03:25:08.578042984 CEST49750443192.168.2.4142.250.101.106
          Apr 24, 2024 03:25:08.578059912 CEST44349750142.250.101.106192.168.2.4
          Apr 24, 2024 03:25:08.578444958 CEST44349750142.250.101.106192.168.2.4
          Apr 24, 2024 03:25:08.578759909 CEST49750443192.168.2.4142.250.101.106
          Apr 24, 2024 03:25:08.578869104 CEST44349750142.250.101.106192.168.2.4
          Apr 24, 2024 03:25:08.619596004 CEST49750443192.168.2.4142.250.101.106
          Apr 24, 2024 03:25:18.612263918 CEST44349750142.250.101.106192.168.2.4
          Apr 24, 2024 03:25:18.612330914 CEST44349750142.250.101.106192.168.2.4
          Apr 24, 2024 03:25:18.612462997 CEST49750443192.168.2.4142.250.101.106
          Apr 24, 2024 03:25:19.934119940 CEST49750443192.168.2.4142.250.101.106
          Apr 24, 2024 03:25:19.934145927 CEST44349750142.250.101.106192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          Apr 24, 2024 03:24:03.698793888 CEST53528561.1.1.1192.168.2.4
          Apr 24, 2024 03:24:03.817162991 CEST53501481.1.1.1192.168.2.4
          Apr 24, 2024 03:24:04.758341074 CEST53519111.1.1.1192.168.2.4
          Apr 24, 2024 03:24:05.329262018 CEST5940853192.168.2.41.1.1.1
          Apr 24, 2024 03:24:05.329510927 CEST6064153192.168.2.41.1.1.1
          Apr 24, 2024 03:24:05.977869987 CEST53606411.1.1.1192.168.2.4
          Apr 24, 2024 03:24:06.097517014 CEST53594081.1.1.1192.168.2.4
          Apr 24, 2024 03:24:08.157015085 CEST5405453192.168.2.41.1.1.1
          Apr 24, 2024 03:24:08.164174080 CEST5253253192.168.2.41.1.1.1
          Apr 24, 2024 03:24:08.311350107 CEST53540541.1.1.1192.168.2.4
          Apr 24, 2024 03:24:08.317744970 CEST53525321.1.1.1192.168.2.4
          Apr 24, 2024 03:24:16.313075066 CEST138138192.168.2.4192.168.2.255
          Apr 24, 2024 03:24:21.697184086 CEST53638211.1.1.1192.168.2.4
          Apr 24, 2024 03:24:40.719322920 CEST53553891.1.1.1192.168.2.4
          Apr 24, 2024 03:25:03.477639914 CEST53587821.1.1.1192.168.2.4
          Apr 24, 2024 03:25:03.558424950 CEST53499791.1.1.1192.168.2.4
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Apr 24, 2024 03:24:05.329262018 CEST192.168.2.41.1.1.10xbe64Standard query (0)leakemup.ioA (IP address)IN (0x0001)false
          Apr 24, 2024 03:24:05.329510927 CEST192.168.2.41.1.1.10xd0bbStandard query (0)leakemup.io65IN (0x0001)false
          Apr 24, 2024 03:24:08.157015085 CEST192.168.2.41.1.1.10x883eStandard query (0)www.google.comA (IP address)IN (0x0001)false
          Apr 24, 2024 03:24:08.164174080 CEST192.168.2.41.1.1.10x4095Standard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Apr 24, 2024 03:24:06.097517014 CEST1.1.1.1192.168.2.40xbe64No error (0)leakemup.io91.209.70.219A (IP address)IN (0x0001)false
          Apr 24, 2024 03:24:08.311350107 CEST1.1.1.1192.168.2.40x883eNo error (0)www.google.com142.250.101.106A (IP address)IN (0x0001)false
          Apr 24, 2024 03:24:08.311350107 CEST1.1.1.1192.168.2.40x883eNo error (0)www.google.com142.250.101.147A (IP address)IN (0x0001)false
          Apr 24, 2024 03:24:08.311350107 CEST1.1.1.1192.168.2.40x883eNo error (0)www.google.com142.250.101.99A (IP address)IN (0x0001)false
          Apr 24, 2024 03:24:08.311350107 CEST1.1.1.1192.168.2.40x883eNo error (0)www.google.com142.250.101.105A (IP address)IN (0x0001)false
          Apr 24, 2024 03:24:08.311350107 CEST1.1.1.1192.168.2.40x883eNo error (0)www.google.com142.250.101.104A (IP address)IN (0x0001)false
          Apr 24, 2024 03:24:08.311350107 CEST1.1.1.1192.168.2.40x883eNo error (0)www.google.com142.250.101.103A (IP address)IN (0x0001)false
          Apr 24, 2024 03:24:08.317744970 CEST1.1.1.1192.168.2.40x4095No error (0)www.google.com65IN (0x0001)false
          Apr 24, 2024 03:24:20.703650951 CEST1.1.1.1192.168.2.40x98c1No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 24, 2024 03:24:20.703650951 CEST1.1.1.1192.168.2.40x98c1No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Apr 24, 2024 03:24:36.759634018 CEST1.1.1.1192.168.2.40xcaf2No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 24, 2024 03:24:36.759634018 CEST1.1.1.1192.168.2.40xcaf2No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Apr 24, 2024 03:24:55.807241917 CEST1.1.1.1192.168.2.40x1b11No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 24, 2024 03:24:55.807241917 CEST1.1.1.1192.168.2.40x1b11No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Apr 24, 2024 03:25:16.711932898 CEST1.1.1.1192.168.2.40xbc8cNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 24, 2024 03:25:16.711932898 CEST1.1.1.1192.168.2.40xbc8cNo error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          • leakemup.io
          • https:
          • fs.microsoft.com
          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          0192.168.2.44973891.209.70.2194432992C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2024-04-24 01:24:06 UTC697OUTGET /Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp4 HTTP/1.1
          Host: leakemup.io
          Connection: keep-alive
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          sec-ch-ua-platform: "Windows"
          Upgrade-Insecure-Requests: 1
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
          Sec-Fetch-Site: none
          Sec-Fetch-Mode: navigate
          Sec-Fetch-User: ?1
          Sec-Fetch-Dest: document
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2024-04-24 01:24:07 UTC150INHTTP/1.1 403 Forbidden
          Server: nginx/1.20.1
          Date: Wed, 24 Apr 2024 01:24:07 GMT
          Content-Type: text/html
          Content-Length: 555
          Connection: close
          2024-04-24 01:24:07 UTC555INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 33 20 46 6f 72 62 69 64 64 65 6e 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 30 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20
          Data Ascii: <html><head><title>403 Forbidden</title></head><body><center><h1>403 Forbidden</h1></center><hr><center>nginx/1.20.1</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          1192.168.2.44973791.209.70.2194432992C:\Program Files\Google\Chrome\Application\chrome.exe
          TimestampBytes transferredDirectionData
          2024-04-24 01:24:07 UTC621OUTGET /favicon.ico HTTP/1.1
          Host: leakemup.io
          Connection: keep-alive
          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
          sec-ch-ua-mobile: ?0
          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
          sec-ch-ua-platform: "Windows"
          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
          Sec-Fetch-Site: same-origin
          Sec-Fetch-Mode: no-cors
          Sec-Fetch-Dest: image
          Referer: https://leakemup.io/Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp4
          Accept-Encoding: gzip, deflate, br
          Accept-Language: en-US,en;q=0.9
          2024-04-24 01:24:08 UTC150INHTTP/1.1 404 Not Found
          Server: nginx/1.20.1
          Date: Wed, 24 Apr 2024 01:24:07 GMT
          Content-Type: text/html
          Content-Length: 555
          Connection: close
          2024-04-24 01:24:08 UTC555INData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 32 30 2e 31 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20 43 68 72 6f 6d 65 20 66 72 69 65 6e 64 6c 79 20 65 72 72 6f 72 20 70 61 67 65 20 2d 2d 3e 0d 0a 3c 21 2d 2d 20 61 20 70 61 64 64 69 6e 67 20 74 6f 20 64 69 73 61 62 6c 65 20 4d 53 49 45 20 61 6e 64 20
          Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx/1.20.1</center></body></html>... a padding to disable MSIE and Chrome friendly error page -->... a padding to disable MSIE and


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          2192.168.2.44974023.40.26.94443
          TimestampBytes transferredDirectionData
          2024-04-24 01:24:08 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-04-24 01:24:09 UTC467INHTTP/1.1 200 OK
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (sac/250E)
          X-CID: 11
          X-Ms-ApiVersion: Distribute 1.2
          X-Ms-Region: prod-eus2-z1
          Cache-Control: public, max-age=20381
          Date: Wed, 24 Apr 2024 01:24:09 GMT
          Connection: close
          X-CID: 2


          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
          3192.168.2.44974123.40.26.94443
          TimestampBytes transferredDirectionData
          2024-04-24 01:24:09 UTC239OUTGET /fs/windows/config.json HTTP/1.1
          Connection: Keep-Alive
          Accept: */*
          Accept-Encoding: identity
          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
          Range: bytes=0-2147483646
          User-Agent: Microsoft BITS/7.8
          Host: fs.microsoft.com
          2024-04-24 01:24:09 UTC455INHTTP/1.1 200 OK
          ApiVersion: Distribute 1.1
          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
          Content-Type: application/octet-stream
          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
          Server: ECAcc (sac/2578)
          X-CID: 11
          Cache-Control: public, max-age=20416
          Date: Wed, 24 Apr 2024 01:24:09 GMT
          Content-Length: 55
          Connection: close
          X-CID: 2
          2024-04-24 01:24:09 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:03:23:58
          Start date:24/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:03:24:01
          Start date:24/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2284 --field-trial-handle=2240,i,14587354550524089327,5314212494730964797,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:03:24:03
          Start date:24/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://leakemup.io/Uploads/Media/Nov21/Mon15/9394/1841d7f4.mp4"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly