Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://mss.ehs2.com/?dilywvqc

Overview

General Information

Sample URL:https://mss.ehs2.com/?dilywvqc
Analysis ID:1432303
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 5656 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5532 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2248 --field-trial-handle=2184,i,3220213239157023704,1200636855465309534,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 2824 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mss.ehs2.com/?dilywvqc" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://mss.ehs2.com/?dilywvqcSlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: mss.ehs2.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: classification engineClassification label: mal48.win@19/6@4/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2248 --field-trial-handle=2184,i,3220213239157023704,1200636855465309534,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mss.ehs2.com/?dilywvqc"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2248 --field-trial-handle=2184,i,3220213239157023704,1200636855465309534,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Google Drive.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.drLNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome AppsJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnkJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnkJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://mss.ehs2.com/?dilywvqc0%Avira URL Cloudsafe
https://mss.ehs2.com/?dilywvqc100%SlashNextCredential Stealing type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalse
    unknown
    www.google.com
    142.250.217.164
    truefalse
      high
      mss.ehs2.com
      157.245.93.173
      truefalse
        unknown
        fp2e7a.wpc.phicdn.net
        192.229.211.108
        truefalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          142.250.217.164
          www.google.comUnited States
          15169GOOGLEUSfalse
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          157.245.93.173
          mss.ehs2.comUnited States
          14061DIGITALOCEAN-ASNUSfalse
          IP
          192.168.2.5
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1432303
          Start date and time:2024-04-26 20:27:14 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 2m 6s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:https://mss.ehs2.com/?dilywvqc
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:6
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:MAL
          Classification:mal48.win@19/6@4/4
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          Cookbook Comments:
          • URL browsing timeout or error
          • URL not reachable
          • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.250.217.238, 74.125.139.84, 142.250.64.227, 34.104.35.123, 23.204.76.112, 40.68.123.157, 199.232.210.172, 192.229.211.108, 13.85.23.206, 20.242.39.171
          • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, ocsp.digicert.com, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          • VT rate limit hit for: https://mss.ehs2.com/?dilywvqc
          No simulations
          No context
          No context
          No context
          No context
          No context
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 17:28:03 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2677
          Entropy (8bit):3.979739749993418
          Encrypted:false
          SSDEEP:48:8qdNTVd2HgZidAKZdA19ehwiZUklqehly+3:8szx+y
          MD5:4C1F12324BF76EAAADC70D40FB487C72
          SHA1:8EBD97882A5CFB2999465EEB727790FDEC07D793
          SHA-256:67220AF9A01795DF5AEE64995574D64CD885CE68605FFECDA750F0EAB4ED18C2
          SHA-512:81338E20772754BBC73FFF8ACEEA538F262B42C6CA90AFBB0EC2F3790DF2EFBFF28EC8F08EF7B7D7E7372837DE83FC151633F5A0DDDD883449A8495756A5504F
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,....bF.y....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X}.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X}.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X}.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X}............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........")......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 17:28:03 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2679
          Entropy (8bit):3.9972883181559538
          Encrypted:false
          SSDEEP:48:8wdNTVd2HgZidAKZdA1weh/iZUkAQkqehuy+2:8SzD9QXy
          MD5:4F770A7FA13D3EDD5B4AF96816BA1778
          SHA1:AB7F8BB7880C91B3A75F18F19EBB6AB42085878E
          SHA-256:C31703D81BFA4B423596D6580AE4D10AF3BEFF7D71256F2B975EE03668C911D7
          SHA-512:41A2C4225064769DD812089B7F2A4D555366F1A7D0ADB6DCBB1A57957798A84F55F7B630916065677392BC28E395EA4B73DDEB56DE7FB2F085A00F0A39D0E1A9
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,....b].y....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X}.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X}.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X}.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X}............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........")......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2693
          Entropy (8bit):4.008609688267488
          Encrypted:false
          SSDEEP:48:8xudNTVdsHgZidAKZdA14tseh7sFiZUkmgqeh7sYy+BX:8xozNnSy
          MD5:2EDF3F25FA6E94F8E6B30AA3BC14E6A7
          SHA1:954A2F0833171566E86E3B5C407BA2C59E40748F
          SHA-256:6A890D4A78E2759B8779E02FF5245651B3E6732598C9C60166BA718E2086399C
          SHA-512:41507E57CA0B21565105C039752B961756B1B36A4C4C877F8D8944BF7B78D59657EE8723F600B993CB10632A80343AD814DE3FA9FBE355DB5A052ABBD6AB39C4
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,......e>....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X}.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X}.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X}.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X}............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VDW.n...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........")......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 17:28:03 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2681
          Entropy (8bit):3.995811236602992
          Encrypted:false
          SSDEEP:48:8gdNTVd2HgZidAKZdA1vehDiZUkwqeh6y+R:8Czggy
          MD5:51524F527CB8ACB47A897FAD335BE081
          SHA1:B6854FAA0ECE7CD7E0CDE1BADD4AB61A957DDC45
          SHA-256:D057B9D7DAD205A4429D28CBBB57DC9BFA2AEE3364511D187C9A20FB5BB412DF
          SHA-512:1714908BF9B70B282AF6BA86C6981304EB1B13F0A587F44163132BAB61E643E1A8FE72258907747AD011D89DE38F5878AC9B345CA7E6147C70250C2AC6D9D87E
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,.....9.y....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X}.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X}.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X}.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X}............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........")......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 17:28:03 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2681
          Entropy (8bit):3.986581874834039
          Encrypted:false
          SSDEEP:48:8FdNTVd2HgZidAKZdA1hehBiZUk1W1qehsy+C:8lzA9My
          MD5:C4A5968F883F7C29CA97A2370B3A5571
          SHA1:7BFC6B9951E065E708D2AB73AC0B3A6D72B0FBDA
          SHA-256:E394714A7018F17E0253F4480B84C6D51171E2C5E38B91B21BFD509868C7FDA4
          SHA-512:47382B35DE4B0F293553000FF568BAB7C492318801455A1E73EBF4FF1A635EACEFECE50263F8ADBFC8CD558F0567A47B771BAEC3598F0EA316178815C7709C46
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,......y....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X}.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X}.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X}.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X}............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........")......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 17:28:03 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2683
          Entropy (8bit):3.9955532675723773
          Encrypted:false
          SSDEEP:48:8CudNTVd2HgZidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbSy+yT+:8vzOT/TbxWOvTbSy7T
          MD5:6DCCBD164AF7EC7F9A92C4594DFBB665
          SHA1:E81667D964C4A31BBF478DE1ABB9A89C4C7C907C
          SHA-256:7C2E11CCC8055D37E8F40A1C740ADBF41F981705F1E6E1CA5FB4AEE8C6AE4230
          SHA-512:7C0020CD0289692B7BD7CFB7A1C27B22E545D069C488859A3A4D0E2F750AE0F610A9EB741B28F5731CB4F4BE150F225490ECF4A9CB7C45C85119BFC316407A23
          Malicious:false
          Reputation:low
          Preview:L..................F.@.. ...$+.,....$..y....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....DWWn..PROGRA~1..t......O.I.X}.....B...............J......SX.P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X}.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X}.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X}............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........")......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Apr 26, 2024 20:27:56.047198057 CEST49674443192.168.2.523.1.237.91
          Apr 26, 2024 20:27:56.047319889 CEST49675443192.168.2.523.1.237.91
          Apr 26, 2024 20:27:56.156568050 CEST49673443192.168.2.523.1.237.91
          Apr 26, 2024 20:28:04.245910883 CEST49710443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:04.245965004 CEST44349710157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:04.246056080 CEST49710443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:04.248373032 CEST49711443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:04.248452902 CEST44349711157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:04.248545885 CEST49711443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:04.255110025 CEST49710443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:04.255134106 CEST44349710157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:04.255316019 CEST49711443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:04.255351067 CEST44349711157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:04.827977896 CEST49713443192.168.2.5142.250.217.164
          Apr 26, 2024 20:28:04.828073978 CEST44349713142.250.217.164192.168.2.5
          Apr 26, 2024 20:28:04.828176975 CEST49713443192.168.2.5142.250.217.164
          Apr 26, 2024 20:28:04.828572035 CEST49713443192.168.2.5142.250.217.164
          Apr 26, 2024 20:28:04.828608990 CEST44349713142.250.217.164192.168.2.5
          Apr 26, 2024 20:28:05.229181051 CEST44349713142.250.217.164192.168.2.5
          Apr 26, 2024 20:28:05.229732037 CEST49713443192.168.2.5142.250.217.164
          Apr 26, 2024 20:28:05.229762077 CEST44349713142.250.217.164192.168.2.5
          Apr 26, 2024 20:28:05.231443882 CEST44349713142.250.217.164192.168.2.5
          Apr 26, 2024 20:28:05.231517076 CEST49713443192.168.2.5142.250.217.164
          Apr 26, 2024 20:28:05.233840942 CEST49713443192.168.2.5142.250.217.164
          Apr 26, 2024 20:28:05.233941078 CEST44349713142.250.217.164192.168.2.5
          Apr 26, 2024 20:28:05.287908077 CEST49713443192.168.2.5142.250.217.164
          Apr 26, 2024 20:28:05.287926912 CEST44349713142.250.217.164192.168.2.5
          Apr 26, 2024 20:28:05.390929937 CEST49713443192.168.2.5142.250.217.164
          Apr 26, 2024 20:28:05.754225016 CEST49675443192.168.2.523.1.237.91
          Apr 26, 2024 20:28:05.797269106 CEST49674443192.168.2.523.1.237.91
          Apr 26, 2024 20:28:05.876487017 CEST49673443192.168.2.523.1.237.91
          Apr 26, 2024 20:28:07.241674900 CEST4434970323.1.237.91192.168.2.5
          Apr 26, 2024 20:28:07.244204044 CEST49703443192.168.2.523.1.237.91
          Apr 26, 2024 20:28:15.203005075 CEST44349713142.250.217.164192.168.2.5
          Apr 26, 2024 20:28:15.203084946 CEST44349713142.250.217.164192.168.2.5
          Apr 26, 2024 20:28:15.206207991 CEST49713443192.168.2.5142.250.217.164
          Apr 26, 2024 20:28:15.432136059 CEST49713443192.168.2.5142.250.217.164
          Apr 26, 2024 20:28:15.432157040 CEST44349713142.250.217.164192.168.2.5
          Apr 26, 2024 20:28:19.659579039 CEST44349710157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:19.662425995 CEST49723443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:19.662463903 CEST44349723157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:19.662516117 CEST49723443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:19.663324118 CEST49723443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:19.663337946 CEST44349723157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:19.823581934 CEST44349723157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:19.914288998 CEST44349711157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:19.950969934 CEST49724443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:19.951013088 CEST44349724157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:19.951152086 CEST49724443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:19.951586008 CEST49724443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:19.951601028 CEST44349724157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:20.114198923 CEST44349724157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:20.918937922 CEST49725443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:20.918967009 CEST44349725157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:20.919069052 CEST49725443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:20.919555902 CEST49726443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:20.919586897 CEST44349726157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:20.919816971 CEST49726443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:20.920104027 CEST49725443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:20.920118093 CEST44349725157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:20.920413017 CEST49726443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:20.920428038 CEST44349726157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:21.080719948 CEST44349725157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:21.080871105 CEST44349726157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:21.082238913 CEST49727443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:21.082258940 CEST44349727157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:21.082325935 CEST49727443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:21.082770109 CEST49728443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:21.082823038 CEST44349728157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:21.083005905 CEST49728443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:21.083446026 CEST49727443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:21.083460093 CEST44349727157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:21.083815098 CEST49728443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:21.083831072 CEST44349728157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:21.246710062 CEST44349728157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:21.247090101 CEST44349727157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:27.617660999 CEST49729443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:27.617691040 CEST44349729157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:27.617822886 CEST49729443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:27.618251085 CEST49730443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:27.618292093 CEST44349730157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:27.618480921 CEST49730443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:27.618771076 CEST49729443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:27.618788004 CEST44349729157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:27.618937016 CEST49730443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:27.618958950 CEST44349730157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:27.788747072 CEST44349730157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:27.789311886 CEST49731443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:27.789350033 CEST44349731157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:27.789503098 CEST49731443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:27.789697886 CEST49731443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:27.789712906 CEST44349731157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:27.791587114 CEST44349729157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:27.791940928 CEST49732443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:27.791997910 CEST44349732157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:27.792057991 CEST49732443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:27.792227030 CEST49732443192.168.2.5157.245.93.173
          Apr 26, 2024 20:28:27.792242050 CEST44349732157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:27.960912943 CEST44349732157.245.93.173192.168.2.5
          Apr 26, 2024 20:28:27.978293896 CEST44349731157.245.93.173192.168.2.5
          TimestampSource PortDest PortSource IPDest IP
          Apr 26, 2024 20:28:01.016200066 CEST53614561.1.1.1192.168.2.5
          Apr 26, 2024 20:28:01.156850100 CEST53531041.1.1.1192.168.2.5
          Apr 26, 2024 20:28:01.981059074 CEST53652541.1.1.1192.168.2.5
          Apr 26, 2024 20:28:04.034471989 CEST5050953192.168.2.51.1.1.1
          Apr 26, 2024 20:28:04.034609079 CEST5277153192.168.2.51.1.1.1
          Apr 26, 2024 20:28:04.165868998 CEST53505091.1.1.1192.168.2.5
          Apr 26, 2024 20:28:04.197453976 CEST53527711.1.1.1192.168.2.5
          Apr 26, 2024 20:28:04.697196007 CEST5903253192.168.2.51.1.1.1
          Apr 26, 2024 20:28:04.697361946 CEST5475453192.168.2.51.1.1.1
          Apr 26, 2024 20:28:04.823138952 CEST53547541.1.1.1192.168.2.5
          Apr 26, 2024 20:28:04.823853016 CEST53590321.1.1.1192.168.2.5
          Apr 26, 2024 20:28:21.218730927 CEST53554101.1.1.1192.168.2.5
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Apr 26, 2024 20:28:04.034471989 CEST192.168.2.51.1.1.10xc218Standard query (0)mss.ehs2.comA (IP address)IN (0x0001)false
          Apr 26, 2024 20:28:04.034609079 CEST192.168.2.51.1.1.10x9f9aStandard query (0)mss.ehs2.com65IN (0x0001)false
          Apr 26, 2024 20:28:04.697196007 CEST192.168.2.51.1.1.10xda53Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Apr 26, 2024 20:28:04.697361946 CEST192.168.2.51.1.1.10x549Standard query (0)www.google.com65IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Apr 26, 2024 20:28:04.165868998 CEST1.1.1.1192.168.2.50xc218No error (0)mss.ehs2.com157.245.93.173A (IP address)IN (0x0001)false
          Apr 26, 2024 20:28:04.823138952 CEST1.1.1.1192.168.2.50x549No error (0)www.google.com65IN (0x0001)false
          Apr 26, 2024 20:28:04.823853016 CEST1.1.1.1192.168.2.50xda53No error (0)www.google.com142.250.217.164A (IP address)IN (0x0001)false
          Apr 26, 2024 20:28:16.869160891 CEST1.1.1.1192.168.2.50x38c2No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
          Apr 26, 2024 20:28:16.869160891 CEST1.1.1.1192.168.2.50x38c2No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
          Apr 26, 2024 20:28:17.293983936 CEST1.1.1.1192.168.2.50x787No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 26, 2024 20:28:17.293983936 CEST1.1.1.1192.168.2.50x787No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false
          Apr 26, 2024 20:28:31.236120939 CEST1.1.1.1192.168.2.50x56e9No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Apr 26, 2024 20:28:31.236120939 CEST1.1.1.1192.168.2.50x56e9No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false

          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:20:27:56
          Start date:26/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff715980000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:20:27:59
          Start date:26/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2248 --field-trial-handle=2184,i,3220213239157023704,1200636855465309534,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff715980000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:20:28:02
          Start date:26/04/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mss.ehs2.com/?dilywvqc"
          Imagebase:0x7ff715980000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly