Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://click.e.miro.com/?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a806863

Overview

General Information

Sample URL:https://click.e.miro.com/?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a806863
Analysis ID:800712
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5812 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 6004 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1932 --field-trial-handle=1724,i,2876507980441582479,18001650036527390366,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 4520 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://click.e.miro.com/?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a806863 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a806863 HTTP/1.1Host: click.e.miro.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /expired.html HTTP/1.1Host: click.e.miro.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: click.e.miro.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://click.e.miro.com/expired.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/htmlDate: Tue, 07 Feb 2023 17:34:43 GMTConnection: closeContent-Length: 1245
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: clean0.win@25/0@5/8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1932 --field-trial-handle=1724,i,2876507980441582479,18001650036527390366,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://click.e.miro.com/?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a806863
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1932 --field-trial-handle=1724,i,2876507980441582479,18001650036527390366,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://click.e.miro.com/?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a8068630%VirustotalBrowse
https://click.e.miro.com/?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a8068630%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://click.e.miro.com/favicon.ico0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
216.58.209.45
truefalse
    high
    www.google.com
    142.250.184.100
    truefalse
      high
      clients.l.google.com
      142.250.180.174
      truefalse
        high
        click.e.miro.com
        159.92.136.102
        truefalse
          unknown
          clients2.google.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
              high
              https://click.e.miro.com/?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a806863false
                unknown
                https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                  high
                  https://click.e.miro.com/favicon.icofalse
                  • Avira URL Cloud: safe
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  159.92.136.102
                  click.e.miro.comUnited States
                  14340SALESFORCEUSfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  216.58.209.45
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.184.100
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  142.250.180.174
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.1
                  192.168.2.4
                  127.0.0.1
                  Joe Sandbox Version:36.0.0 Rainbow Opal
                  Analysis ID:800712
                  Start date and time:2023-02-07 18:33:34 +01:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:0h 5m 46s
                  Hypervisor based Inspection enabled:false
                  Report type:light
                  Cookbook file name:browseurl.jbs
                  Sample URL:https://click.e.miro.com/?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a806863
                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                  Number of analysed new started processes analysed:11
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • HDC enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean0.win@25/0@5/8
                  EGA Information:Failed
                  HDC Information:Failed
                  HCA Information:
                  • Successful, ratio: 100%
                  • Number of executed functions: 0
                  • Number of non-executed functions: 0
                  • Exclude process from analysis (whitelisted): SgrmBroker.exe, backgroundTaskHost.exe, svchost.exe
                  • TCP Packets have been reduced to 100
                  • Excluded IPs from analysis (whitelisted): 142.250.184.99, 34.104.35.123, 142.250.180.163
                  • Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, fs.microsoft.com, edgedl.me.gvt1.com, login.live.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                  No simulations
                  No context
                  No context
                  No context
                  No context
                  No context
                  No created / dropped files found
                  No static file info
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 7, 2023 18:34:41.689753056 CET49713443192.168.2.7142.250.180.174
                  Feb 7, 2023 18:34:41.689815998 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:41.689889908 CET49713443192.168.2.7142.250.180.174
                  Feb 7, 2023 18:34:41.690248966 CET49714443192.168.2.7216.58.209.45
                  Feb 7, 2023 18:34:41.690291882 CET44349714216.58.209.45192.168.2.7
                  Feb 7, 2023 18:34:41.690361977 CET49714443192.168.2.7216.58.209.45
                  Feb 7, 2023 18:34:41.690685987 CET49715443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:41.690726042 CET44349715159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:41.690797091 CET49715443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:41.692467928 CET49713443192.168.2.7142.250.180.174
                  Feb 7, 2023 18:34:41.692497969 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:41.692990065 CET49714443192.168.2.7216.58.209.45
                  Feb 7, 2023 18:34:41.693020105 CET44349714216.58.209.45192.168.2.7
                  Feb 7, 2023 18:34:41.693567038 CET49715443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:41.693584919 CET44349715159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:41.810769081 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:41.826823950 CET44349714216.58.209.45192.168.2.7
                  Feb 7, 2023 18:34:41.845438957 CET44349715159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:41.866954088 CET49714443192.168.2.7216.58.209.45
                  Feb 7, 2023 18:34:41.874937057 CET49713443192.168.2.7142.250.180.174
                  Feb 7, 2023 18:34:41.974988937 CET49715443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:42.221183062 CET49715443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:42.221223116 CET44349715159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:42.227319956 CET44349715159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:42.227427959 CET44349715159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:42.227504015 CET49715443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:42.230400085 CET49714443192.168.2.7216.58.209.45
                  Feb 7, 2023 18:34:42.230443954 CET44349714216.58.209.45192.168.2.7
                  Feb 7, 2023 18:34:42.230746031 CET49713443192.168.2.7142.250.180.174
                  Feb 7, 2023 18:34:42.230783939 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:42.231617928 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:42.231637955 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:42.231801987 CET49713443192.168.2.7142.250.180.174
                  Feb 7, 2023 18:34:42.232466936 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:42.232661009 CET49713443192.168.2.7142.250.180.174
                  Feb 7, 2023 18:34:42.233311892 CET44349714216.58.209.45192.168.2.7
                  Feb 7, 2023 18:34:42.233424902 CET49714443192.168.2.7216.58.209.45
                  Feb 7, 2023 18:34:42.274995089 CET49715443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.005573988 CET49713443192.168.2.7142.250.180.174
                  Feb 7, 2023 18:34:43.005652905 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:43.005899906 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:43.005959988 CET49713443192.168.2.7142.250.180.174
                  Feb 7, 2023 18:34:43.005974054 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:43.006944895 CET49714443192.168.2.7216.58.209.45
                  Feb 7, 2023 18:34:43.006987095 CET44349714216.58.209.45192.168.2.7
                  Feb 7, 2023 18:34:43.007134914 CET49714443192.168.2.7216.58.209.45
                  Feb 7, 2023 18:34:43.007148027 CET44349714216.58.209.45192.168.2.7
                  Feb 7, 2023 18:34:43.007369995 CET49715443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.007394075 CET44349714216.58.209.45192.168.2.7
                  Feb 7, 2023 18:34:43.007441998 CET44349715159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.007606983 CET44349715159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.007654905 CET49715443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.007678986 CET44349715159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.048363924 CET44349715159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.048465014 CET49715443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.048505068 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:43.048578024 CET49713443192.168.2.7142.250.180.174
                  Feb 7, 2023 18:34:43.048607111 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:43.048738956 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:43.048821926 CET49713443192.168.2.7142.250.180.174
                  Feb 7, 2023 18:34:43.071314096 CET44349714216.58.209.45192.168.2.7
                  Feb 7, 2023 18:34:43.071453094 CET49714443192.168.2.7216.58.209.45
                  Feb 7, 2023 18:34:43.071484089 CET44349714216.58.209.45192.168.2.7
                  Feb 7, 2023 18:34:43.071695089 CET44349714216.58.209.45192.168.2.7
                  Feb 7, 2023 18:34:43.071768999 CET49714443192.168.2.7216.58.209.45
                  Feb 7, 2023 18:34:43.179939985 CET49714443192.168.2.7216.58.209.45
                  Feb 7, 2023 18:34:43.180010080 CET44349714216.58.209.45192.168.2.7
                  Feb 7, 2023 18:34:43.187951088 CET49713443192.168.2.7142.250.180.174
                  Feb 7, 2023 18:34:43.187999964 CET44349713142.250.180.174192.168.2.7
                  Feb 7, 2023 18:34:43.365984917 CET49715443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.366015911 CET44349715159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.370598078 CET49716443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.370650053 CET44349716159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.370764017 CET49716443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.371145010 CET49716443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.371162891 CET44349716159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.432178020 CET44349716159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.443118095 CET49716443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.443161964 CET44349716159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.444225073 CET44349716159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.445157051 CET49716443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.445188046 CET44349716159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.445318937 CET44349716159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.445494890 CET49716443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.445506096 CET44349716159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.490669012 CET44349716159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.491390944 CET44349716159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.491453886 CET49716443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.492955923 CET49716443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.492986917 CET44349716159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.752362013 CET49719443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.752413034 CET44349719159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.752506018 CET49719443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.752805948 CET49719443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.752825022 CET44349719159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.813182116 CET44349719159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.813718081 CET49719443192.168.2.7159.92.136.102
                  Feb 7, 2023 18:34:43.813756943 CET44349719159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.814476967 CET44349719159.92.136.102192.168.2.7
                  Feb 7, 2023 18:34:43.815272093 CET49719443192.168.2.7159.92.136.102
                  TimestampSource PortDest PortSource IPDest IP
                  Feb 7, 2023 18:34:41.567933083 CET6392653192.168.2.78.8.8.8
                  Feb 7, 2023 18:34:41.573301077 CET5100753192.168.2.78.8.8.8
                  Feb 7, 2023 18:34:41.575326920 CET5051353192.168.2.78.8.8.8
                  Feb 7, 2023 18:34:41.586741924 CET53639268.8.8.8192.168.2.7
                  Feb 7, 2023 18:34:41.594961882 CET53510078.8.8.8192.168.2.7
                  Feb 7, 2023 18:34:41.596585035 CET53505138.8.8.8192.168.2.7
                  Feb 7, 2023 18:34:43.804826021 CET5002453192.168.2.78.8.8.8
                  Feb 7, 2023 18:34:43.822906017 CET53500248.8.8.8192.168.2.7
                  Feb 7, 2023 18:35:43.869703054 CET6318753192.168.2.78.8.8.8
                  Feb 7, 2023 18:35:43.889578104 CET53631878.8.8.8192.168.2.7
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Feb 7, 2023 18:34:41.567933083 CET192.168.2.78.8.8.80x24daStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:34:41.573301077 CET192.168.2.78.8.8.80x7271Standard query (0)click.e.miro.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:34:41.575326920 CET192.168.2.78.8.8.80x4480Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:34:43.804826021 CET192.168.2.78.8.8.80x26a7Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  Feb 7, 2023 18:35:43.869703054 CET192.168.2.78.8.8.80x57e1Standard query (0)www.google.comA (IP address)IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Feb 7, 2023 18:34:41.586741924 CET8.8.8.8192.168.2.70x24daNo error (0)accounts.google.com216.58.209.45A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:34:41.594961882 CET8.8.8.8192.168.2.70x7271No error (0)click.e.miro.com159.92.136.102A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:34:41.596585035 CET8.8.8.8192.168.2.70x4480No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                  Feb 7, 2023 18:34:41.596585035 CET8.8.8.8192.168.2.70x4480No error (0)clients.l.google.com142.250.180.174A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:34:43.822906017 CET8.8.8.8192.168.2.70x26a7No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                  Feb 7, 2023 18:35:43.889578104 CET8.8.8.8192.168.2.70x57e1No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                  • clients2.google.com
                  • accounts.google.com
                  • click.e.miro.com
                  • https:

                  Click to jump to process

                  Target ID:0
                  Start time:18:34:37
                  Start date:07/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                  Imagebase:0x7ff7c2920000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:1
                  Start time:18:34:39
                  Start date:07/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1932 --field-trial-handle=1724,i,2876507980441582479,18001650036527390366,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                  Imagebase:0x7ff7c2920000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  Target ID:2
                  Start time:18:34:39
                  Start date:07/02/2023
                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://click.e.miro.com/?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a806863
                  Imagebase:0x7ff7c2920000
                  File size:2851656 bytes
                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:low

                  No disassembly