Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.com

Overview

General Information

Sample URL:https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.com
Analysis ID:756102
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Antivirus detection for URL or domain
URL contains potential PII (phishing indication)
HTML body contains low number of good links
Invalid T&C link found
No HTML title found

Classification

  • System is w10x64
  • chrome.exe (PID: 6012 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 3536 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1808 --field-trial-handle=1780,i,4275831116974464191,11394012430591457211,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 5524 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.com MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comSlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comAvira URL Cloud: detection malicious, Label: phishing
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comVirustotal: Detection: 13%Perma Link
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.htmlAvira URL Cloud: Label: phishing
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/images/favicon.icoAvira URL Cloud: Label: phishing
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comSample URL: PII: glenergy@glenergy.com
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comHTTP Parser: Number of links: 0
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comHTTP Parser: Number of links: 0
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comHTTP Parser: Invalid link: Privacy
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comHTTP Parser: Invalid link: Privacy
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comHTTP Parser: HTML title missing
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comHTTP Parser: HTML title missing
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comHTTP Parser: No <meta name="author".. found
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comHTTP Parser: No <meta name="author".. found
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comHTTP Parser: No <meta name="copyright".. found
Source: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comHTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownHTTPS traffic detected: 104.18.22.52:443 -> 192.168.2.5:49720 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.22.52:443 -> 192.168.2.5:49721 version: TLS 1.2
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: global trafficHTTP traffic detected: GET /meuro4elpez_cham-e.html HTTP/1.1Host: bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.linkConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /w3css/4/w3.css HTTP/1.1Host: www.w3schools.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/favicon.ico HTTP/1.1Host: bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.linkConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?getemailinfo=glenergy@glenergy.com&linkbox=meuro4elpez&url=https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html HTTP/1.1Host: netx3-gen-apiv3-chameleon-eeeennnn.us-south.cf.appdomain.cloudConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.linkSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/favicon.ico HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link
Source: global trafficHTTP traffic detected: GET /meuro4elpez_cham-e.html HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownHTTPS traffic detected: 104.18.22.52:443 -> 192.168.2.5:49720 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.22.52:443 -> 192.168.2.5:49721 version: TLS 1.2
Source: classification engineClassification label: mal64.win@25/0@8/10
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1808 --field-trial-handle=1780,i,4275831116974464191,11394012430591457211,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.com
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1808 --field-trial-handle=1780,i,4275831116974464191,11394012430591457211,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.com13%VirustotalBrowse
https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.com100%SlashNextCredential Stealing type: Phishing & Social Engineering
https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.com100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html100%Avira URL Cloudphishing
https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/images/favicon.ico100%Avira URL Cloudphishing
https://netx3-gen-apiv3-chameleon-eeeennnn.us-south.cf.appdomain.cloud/?getemailinfo=glenergy@glenergy.com&linkbox=meuro4elpez&url=https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
172.217.168.45
truefalse
    high
    cdnjs.cloudflare.com
    104.17.24.14
    truefalse
      high
      cs837.wac.edgecastcdn.net
      192.229.133.221
      truefalse
        high
        www.google.com
        172.217.168.36
        truefalse
          high
          netx3-gen-apiv3-chameleon-eeeennnn.us-south.cf.appdomain.cloud
          169.62.254.82
          truefalse
            unknown
            bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link
            104.18.22.52
            truefalse
              unknown
              clients.l.google.com
              142.250.203.110
              truefalse
                high
                clients2.google.com
                unknown
                unknownfalse
                  high
                  www.w3schools.com
                  unknown
                  unknownfalse
                    high
                    NameMaliciousAntivirus DetectionReputation
                    https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.htmlfalse
                    • Avira URL Cloud: phishing
                    unknown
                    https://netx3-gen-apiv3-chameleon-eeeennnn.us-south.cf.appdomain.cloud/?getemailinfo=glenergy@glenergy.com&linkbox=meuro4elpez&url=https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.htmlfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                      high
                      https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/images/favicon.icofalse
                      • Avira URL Cloud: phishing
                      unknown
                      https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                        high
                        https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.cssfalse
                          high
                          https://www.w3schools.com/w3css/4/w3.cssfalse
                            high
                            https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.comtrue
                              unknown
                              • No. of IPs < 25%
                              • 25% < No. of IPs < 50%
                              • 50% < No. of IPs < 75%
                              • 75% < No. of IPs
                              IPDomainCountryFlagASNASN NameMalicious
                              104.17.24.14
                              cdnjs.cloudflare.comUnited States
                              13335CLOUDFLARENETUSfalse
                              169.62.254.82
                              netx3-gen-apiv3-chameleon-eeeennnn.us-south.cf.appdomain.cloudUnited States
                              36351SOFTLAYERUSfalse
                              142.250.203.110
                              clients.l.google.comUnited States
                              15169GOOGLEUSfalse
                              192.229.133.221
                              cs837.wac.edgecastcdn.netUnited States
                              15133EDGECASTUSfalse
                              172.217.168.45
                              accounts.google.comUnited States
                              15169GOOGLEUSfalse
                              172.217.168.36
                              www.google.comUnited States
                              15169GOOGLEUSfalse
                              239.255.255.250
                              unknownReserved
                              unknownunknownfalse
                              104.18.22.52
                              bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.linkUnited States
                              13335CLOUDFLARENETUSfalse
                              IP
                              192.168.2.1
                              127.0.0.1
                              Joe Sandbox Version:36.0.0 Rainbow Opal
                              Analysis ID:756102
                              Start date and time:2022-11-29 16:35:45 +01:00
                              Joe Sandbox Product:CloudBasic
                              Overall analysis duration:0h 4m 31s
                              Hypervisor based Inspection enabled:false
                              Report type:light
                              Cookbook file name:browseurl.jbs
                              Sample URL:https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.com
                              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                              Number of analysed new started processes analysed:5
                              Number of new started drivers analysed:0
                              Number of existing processes analysed:0
                              Number of existing drivers analysed:0
                              Number of injected processes analysed:0
                              Technologies:
                              • HCA enabled
                              • EGA enabled
                              • HDC enabled
                              • AMSI enabled
                              Analysis Mode:default
                              Analysis stop reason:Timeout
                              Detection:MAL
                              Classification:mal64.win@25/0@8/10
                              EGA Information:Failed
                              HDC Information:Failed
                              HCA Information:
                              • Successful, ratio: 100%
                              • Number of executed functions: 0
                              • Number of non-executed functions: 0
                              • Exclude process from analysis (whitelisted): MpCmdRun.exe, conhost.exe
                              • TCP Packets have been reduced to 100
                              • Excluded IPs from analysis (whitelisted): 172.217.168.67, 34.104.35.123, 172.217.168.42, 172.217.168.74, 142.250.203.106, 216.58.215.234, 172.217.168.10, 142.250.203.100
                              • Excluded domains from analysis (whitelisted): client.wns.windows.com, edgedl.me.gvt1.com, content-autofill.googleapis.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, t3.gstatic.com
                              • Not all processes where analyzed, report is missing behavior information
                              • Report size getting too big, too many NtWriteVirtualMemory calls found.
                              No simulations
                              No context
                              No context
                              No context
                              No context
                              No context
                              No created / dropped files found
                              No static file info
                              TimestampSource PortDest PortSource IPDest IP
                              Nov 29, 2022 16:36:52.192600012 CET49702443192.168.2.5142.250.203.110
                              Nov 29, 2022 16:36:52.192656040 CET44349702142.250.203.110192.168.2.5
                              Nov 29, 2022 16:36:52.192776918 CET49702443192.168.2.5142.250.203.110
                              Nov 29, 2022 16:36:52.194288015 CET49704443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.194344044 CET44349704172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.194437027 CET49704443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.196091890 CET49705443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.196149111 CET44349705172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.196240902 CET49705443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.201035976 CET49706443192.168.2.5172.217.168.36
                              Nov 29, 2022 16:36:52.201085091 CET44349706172.217.168.36192.168.2.5
                              Nov 29, 2022 16:36:52.201178074 CET49706443192.168.2.5172.217.168.36
                              Nov 29, 2022 16:36:52.202960968 CET49702443192.168.2.5142.250.203.110
                              Nov 29, 2022 16:36:52.202987909 CET44349702142.250.203.110192.168.2.5
                              Nov 29, 2022 16:36:52.204045057 CET49704443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.204076052 CET44349704172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.204351902 CET49705443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.204386950 CET44349705172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.204926968 CET49706443192.168.2.5172.217.168.36
                              Nov 29, 2022 16:36:52.204958916 CET44349706172.217.168.36192.168.2.5
                              Nov 29, 2022 16:36:52.208432913 CET49708443192.168.2.5104.18.22.52
                              Nov 29, 2022 16:36:52.208477020 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:52.208551884 CET49708443192.168.2.5104.18.22.52
                              Nov 29, 2022 16:36:52.209290028 CET49708443192.168.2.5104.18.22.52
                              Nov 29, 2022 16:36:52.209307909 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:52.321921110 CET44349702142.250.203.110192.168.2.5
                              Nov 29, 2022 16:36:52.325030088 CET49702443192.168.2.5142.250.203.110
                              Nov 29, 2022 16:36:52.325063944 CET44349702142.250.203.110192.168.2.5
                              Nov 29, 2022 16:36:52.326003075 CET44349702142.250.203.110192.168.2.5
                              Nov 29, 2022 16:36:52.326103926 CET49702443192.168.2.5142.250.203.110
                              Nov 29, 2022 16:36:52.327344894 CET44349702142.250.203.110192.168.2.5
                              Nov 29, 2022 16:36:52.327424049 CET49702443192.168.2.5142.250.203.110
                              Nov 29, 2022 16:36:52.384345055 CET44349704172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.386132002 CET44349705172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.394582987 CET49705443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.394614935 CET44349705172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.394946098 CET49704443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.394985914 CET44349704172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.397383928 CET44349705172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.397505999 CET49705443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.397625923 CET44349704172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.397706985 CET49704443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.417339087 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:52.417450905 CET44349706172.217.168.36192.168.2.5
                              Nov 29, 2022 16:36:52.418498993 CET49706443192.168.2.5172.217.168.36
                              Nov 29, 2022 16:36:52.418534040 CET44349706172.217.168.36192.168.2.5
                              Nov 29, 2022 16:36:52.418817043 CET49708443192.168.2.5104.18.22.52
                              Nov 29, 2022 16:36:52.418845892 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:52.420460939 CET44349706172.217.168.36192.168.2.5
                              Nov 29, 2022 16:36:52.420552969 CET49706443192.168.2.5172.217.168.36
                              Nov 29, 2022 16:36:52.420677900 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:52.420768023 CET49708443192.168.2.5104.18.22.52
                              Nov 29, 2022 16:36:52.919751883 CET49706443192.168.2.5172.217.168.36
                              Nov 29, 2022 16:36:52.919816017 CET44349706172.217.168.36192.168.2.5
                              Nov 29, 2022 16:36:52.919995070 CET44349706172.217.168.36192.168.2.5
                              Nov 29, 2022 16:36:52.920667887 CET49704443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.920722961 CET44349704172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.920762062 CET49705443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.920792103 CET44349705172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.920878887 CET44349704172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.920979977 CET44349705172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.921164989 CET49708443192.168.2.5104.18.22.52
                              Nov 29, 2022 16:36:52.921190023 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:52.921345949 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:52.921514988 CET49702443192.168.2.5142.250.203.110
                              Nov 29, 2022 16:36:52.921545029 CET44349702142.250.203.110192.168.2.5
                              Nov 29, 2022 16:36:52.921663046 CET44349702142.250.203.110192.168.2.5
                              Nov 29, 2022 16:36:52.921690941 CET49704443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.921727896 CET44349704172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.921926022 CET49708443192.168.2.5104.18.22.52
                              Nov 29, 2022 16:36:52.921950102 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:52.921996117 CET49702443192.168.2.5142.250.203.110
                              Nov 29, 2022 16:36:52.922015905 CET44349702142.250.203.110192.168.2.5
                              Nov 29, 2022 16:36:52.977283955 CET44349704172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.977473021 CET44349704172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.977760077 CET49704443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.983900070 CET49704443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.983939886 CET44349704172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.990854025 CET49705443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:52.990871906 CET44349705172.217.168.45192.168.2.5
                              Nov 29, 2022 16:36:52.990888119 CET49702443192.168.2.5142.250.203.110
                              Nov 29, 2022 16:36:52.990914106 CET49708443192.168.2.5104.18.22.52
                              Nov 29, 2022 16:36:53.023339987 CET44349702142.250.203.110192.168.2.5
                              Nov 29, 2022 16:36:53.023557901 CET44349702142.250.203.110192.168.2.5
                              Nov 29, 2022 16:36:53.023638964 CET49702443192.168.2.5142.250.203.110
                              Nov 29, 2022 16:36:53.023931026 CET49706443192.168.2.5172.217.168.36
                              Nov 29, 2022 16:36:53.023940086 CET44349706172.217.168.36192.168.2.5
                              Nov 29, 2022 16:36:53.036806107 CET49702443192.168.2.5142.250.203.110
                              Nov 29, 2022 16:36:53.036827087 CET44349702142.250.203.110192.168.2.5
                              Nov 29, 2022 16:36:53.090918064 CET49705443192.168.2.5172.217.168.45
                              Nov 29, 2022 16:36:53.125768900 CET49706443192.168.2.5172.217.168.36
                              Nov 29, 2022 16:36:53.285386086 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:53.285465002 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:53.285511017 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:53.285554886 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:53.285552025 CET49708443192.168.2.5104.18.22.52
                              Nov 29, 2022 16:36:53.285593987 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:53.285614014 CET49708443192.168.2.5104.18.22.52
                              Nov 29, 2022 16:36:53.285649061 CET44349708104.18.22.52192.168.2.5
                              Nov 29, 2022 16:36:53.285681963 CET49708443192.168.2.5104.18.22.52
                              TimestampSource PortDest PortSource IPDest IP
                              Nov 29, 2022 16:36:52.025835991 CET4972453192.168.2.58.8.8.8
                              Nov 29, 2022 16:36:52.029284000 CET6145253192.168.2.58.8.8.8
                              Nov 29, 2022 16:36:52.030622959 CET6532353192.168.2.58.8.8.8
                              Nov 29, 2022 16:36:52.032983065 CET5148453192.168.2.58.8.8.8
                              Nov 29, 2022 16:36:52.048765898 CET53614528.8.8.8192.168.2.5
                              Nov 29, 2022 16:36:52.049890041 CET53653238.8.8.8192.168.2.5
                              Nov 29, 2022 16:36:52.053812981 CET53497248.8.8.8192.168.2.5
                              Nov 29, 2022 16:36:52.055362940 CET53514848.8.8.8192.168.2.5
                              Nov 29, 2022 16:36:53.394701004 CET6097553192.168.2.58.8.8.8
                              Nov 29, 2022 16:36:53.410052061 CET5922053192.168.2.58.8.8.8
                              Nov 29, 2022 16:36:53.416220903 CET53609758.8.8.8192.168.2.5
                              Nov 29, 2022 16:36:53.431782007 CET53592208.8.8.8192.168.2.5
                              Nov 29, 2022 16:36:53.944679022 CET5506853192.168.2.58.8.8.8
                              Nov 29, 2022 16:36:53.975847006 CET53550688.8.8.8192.168.2.5
                              Nov 29, 2022 16:37:04.987277985 CET6551353192.168.2.58.8.8.8
                              Nov 29, 2022 16:37:05.012047052 CET53655138.8.8.8192.168.2.5
                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                              Nov 29, 2022 16:36:52.025835991 CET192.168.2.58.8.8.80x1d4eStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:52.029284000 CET192.168.2.58.8.8.80x79eStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:52.030622959 CET192.168.2.58.8.8.80xd880Standard query (0)www.google.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:52.032983065 CET192.168.2.58.8.8.80x106cStandard query (0)bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.linkA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:53.394701004 CET192.168.2.58.8.8.80x6c54Standard query (0)cdnjs.cloudflare.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:53.410052061 CET192.168.2.58.8.8.80xc65bStandard query (0)www.w3schools.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:53.944679022 CET192.168.2.58.8.8.80xc9e9Standard query (0)netx3-gen-apiv3-chameleon-eeeennnn.us-south.cf.appdomain.cloudA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:37:04.987277985 CET192.168.2.58.8.8.80xad5cStandard query (0)bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.linkA (IP address)IN (0x0001)false
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Nov 29, 2022 16:36:52.048765898 CET8.8.8.8192.168.2.50x79eNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                              Nov 29, 2022 16:36:52.048765898 CET8.8.8.8192.168.2.50x79eNo error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:52.049890041 CET8.8.8.8192.168.2.50xd880No error (0)www.google.com172.217.168.36A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:52.053812981 CET8.8.8.8192.168.2.50x1d4eNo error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:52.055362940 CET8.8.8.8192.168.2.50x106cNo error (0)bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link104.18.22.52A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:52.055362940 CET8.8.8.8192.168.2.50x106cNo error (0)bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link104.18.23.52A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:53.416220903 CET8.8.8.8192.168.2.50x6c54No error (0)cdnjs.cloudflare.com104.17.24.14A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:53.416220903 CET8.8.8.8192.168.2.50x6c54No error (0)cdnjs.cloudflare.com104.17.25.14A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:53.431782007 CET8.8.8.8192.168.2.50xc65bNo error (0)www.w3schools.comcs837.wac.edgecastcdn.netCNAME (Canonical name)IN (0x0001)false
                              Nov 29, 2022 16:36:53.431782007 CET8.8.8.8192.168.2.50xc65bNo error (0)cs837.wac.edgecastcdn.net192.229.133.221A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:53.975847006 CET8.8.8.8192.168.2.50xc9e9No error (0)netx3-gen-apiv3-chameleon-eeeennnn.us-south.cf.appdomain.cloud169.62.254.82A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:53.975847006 CET8.8.8.8192.168.2.50xc9e9No error (0)netx3-gen-apiv3-chameleon-eeeennnn.us-south.cf.appdomain.cloud169.46.89.154A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:36:53.975847006 CET8.8.8.8192.168.2.50xc9e9No error (0)netx3-gen-apiv3-chameleon-eeeennnn.us-south.cf.appdomain.cloud169.47.124.25A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:37:05.012047052 CET8.8.8.8192.168.2.50xad5cNo error (0)bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link104.18.22.52A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:37:05.012047052 CET8.8.8.8192.168.2.50xad5cNo error (0)bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link104.18.23.52A (IP address)IN (0x0001)false
                              • accounts.google.com
                              • bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link
                              • clients2.google.com
                              • https:
                                • www.w3schools.com
                                • cdnjs.cloudflare.com
                                • netx3-gen-apiv3-chameleon-eeeennnn.us-south.cf.appdomain.cloud

                              Click to jump to process

                              Target ID:0
                              Start time:16:36:44
                              Start date:29/11/2022
                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                              Wow64 process (32bit):false
                              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                              Imagebase:0x7ff7d31b0000
                              File size:2851656 bytes
                              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:low

                              Target ID:1
                              Start time:16:36:46
                              Start date:29/11/2022
                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1808 --field-trial-handle=1780,i,4275831116974464191,11394012430591457211,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                              Imagebase:0x7ff7d31b0000
                              File size:2851656 bytes
                              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:low

                              Target ID:2
                              Start time:16:36:47
                              Start date:29/11/2022
                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                              Wow64 process (32bit):false
                              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bafybeiajl7jy5rq7cttxjilmyeun7jxorxidbcrh6td4a5z6om7jqgofiq.ipfs.w3s.link/meuro4elpez_cham-e.html#glenergy@glenergy.com
                              Imagebase:0x7ff7d31b0000
                              File size:2851656 bytes
                              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:low

                              No disassembly