Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://protect-us.mimecast.com/s/-B0VC4xq3JiBXWWVfNGpvG

Overview

General Information

Sample URL:https://protect-us.mimecast.com/s/-B0VC4xq3JiBXWWVfNGpvG
Analysis ID:1317968

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Phishing site detected (based on shot match)
HTML page contains hidden URLs or javascript code

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 5172 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://protect-us.mimecast.com/s/-B0VC4xq3JiBXWWVfNGpvG MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 4116 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1784,i,2649465807346734097,10995708982618343785,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: https://42ye4uf5v.edudemac.ru/8qu98b4hmrzMatcher: Template: captcha matched
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalMatcher: Template: captcha matched
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalMatcher: Template: captcha matched
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv1/D41Hb5yisP1Oq0h/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalMatcher: Template: captcha matched
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv1/D41Hb5yisP1Oq0h/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalMatcher: Template: captcha matched
Source: https://42ye4uf5v.edudemac.ru/8qu98b4hmrzMatcher: Template: captcha matched
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv2/alM3mn70axwXsTW/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalMatcher: Template: captcha matched
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalHTTP Parser: Base64 decoded: http://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normal
Source: https://www.evernote.com/shard/s429/client/snv/ceHTTP Parser: No favicon
Source: https://www.evernote.com/shard/s429/client/snv/ceHTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalHTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalHTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalHTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv1/D41Hb5yisP1Oq0h/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalHTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv1/D41Hb5yisP1Oq0h/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalHTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv1/D41Hb5yisP1Oq0h/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalHTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv2/alM3mn70axwXsTW/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalHTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv2/alM3mn70axwXsTW/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalHTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv2/alM3mn70axwXsTW/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalHTTP Parser: No favicon
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: classification engineClassification label: mal48.phis.win@26/116@14/161
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdater
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://protect-us.mimecast.com/s/-B0VC4xq3JiBXWWVfNGpvG
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1784,i,2649465807346734097,10995708982618343785,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1784,i,2649465807346734097,10995708982618343785,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://protect-us.mimecast.com/s/-B0VC4xq3JiBXWWVfNGpvG0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://42ye4uf5v.edudemac.ru/8qu98b4hmrz0%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
protect-us.mimecast.com
207.211.31.106
truefalse
    high
    accounts.google.com
    142.250.176.13
    truefalse
      high
      code.jquery.com
      151.101.66.137
      truefalse
        high
        dashboard.svc.www.evernote.com
        35.190.3.250
        truefalse
          high
          challenges.cloudflare.com
          104.17.3.184
          truefalse
            high
            www.google.com
            142.250.217.132
            truefalse
              high
              www.evernote.com
              34.120.241.214
              truefalse
                high
                clients.l.google.com
                142.250.176.14
                truefalse
                  high
                  stats.g.doubleclick.net
                  142.250.101.156
                  truefalse
                    high
                    42ye4uf5v.edudemac.ru
                    172.67.184.254
                    truefalse
                      unknown
                      clients2.google.com
                      unknown
                      unknownfalse
                        high
                        content.evernote.com
                        unknown
                        unknownfalse
                          high
                          NameMaliciousAntivirus DetectionReputation
                          https://www.evernote.com/shard/s429/client/snv/cefalse
                            high
                            https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv2/alM3mn70axwXsTW/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalfalse
                              high
                              https://42ye4uf5v.edudemac.ru/8qu98b4hmrzfalseunknown
                              https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalfalse
                                high
                                https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv1/D41Hb5yisP1Oq0h/gujyy/0x4AAAAAAAKdjHFwNlqKWmav/auto/normalfalse
                                  high
                                  https://www.evernote.com/shard/s429/client/snv?isnewsnv=true&noteGuid=be487e09-21f4-211d-3539-769e8f4a8d7b&noteKey=5m6b28q4ZcdC4MP4gSn4ss22TpF6zI7deuzV3LlRqADbhyMhu1-Nx-xxBw&sn=https%3A%2F%2Fwww.evernote.com%2Fshard%2Fs429%2Fsh%2Fbe487e09-21f4-211d-3539-769e8f4a8d7b%2F5m6b28q4ZcdC4MP4gSn4ss22TpF6zI7deuzV3LlRqADbhyMhu1-Nx-xxBw&title=Ricky%2BSimmons%2Bshared%2Ba%2Bdocument%2Bvia%2BOneDrivefalse
                                    high
                                    • No. of IPs < 25%
                                    • 25% < No. of IPs < 50%
                                    • 50% < No. of IPs < 75%
                                    • 75% < No. of IPs
                                    IPDomainCountryFlagASNASN NameMalicious
                                    9.9.9.9
                                    unknownUnited States
                                    19281QUAD9-AS-1USfalse
                                    1.1.1.1
                                    unknownAustralia
                                    13335CLOUDFLARENETUSfalse
                                    207.211.31.106
                                    protect-us.mimecast.comUnited States
                                    14135NAVISITE-EAST-2USfalse
                                    142.250.176.3
                                    unknownUnited States
                                    15169GOOGLEUSfalse
                                    142.250.101.156
                                    stats.g.doubleclick.netUnited States
                                    15169GOOGLEUSfalse
                                    104.17.3.184
                                    challenges.cloudflare.comUnited States
                                    13335CLOUDFLARENETUSfalse
                                    142.250.217.132
                                    www.google.comUnited States
                                    15169GOOGLEUSfalse
                                    142.250.176.14
                                    clients.l.google.comUnited States
                                    15169GOOGLEUSfalse
                                    142.250.176.13
                                    accounts.google.comUnited States
                                    15169GOOGLEUSfalse
                                    239.255.255.250
                                    unknownReserved
                                    unknownunknownfalse
                                    34.120.241.214
                                    www.evernote.comUnited States
                                    15169GOOGLEUSfalse
                                    151.101.66.137
                                    code.jquery.comUnited States
                                    54113FASTLYUSfalse
                                    35.190.3.250
                                    dashboard.svc.www.evernote.comUnited States
                                    15169GOOGLEUSfalse
                                    142.250.72.131
                                    unknownUnited States
                                    15169GOOGLEUSfalse
                                    172.67.184.254
                                    42ye4uf5v.edudemac.ruUnited States
                                    13335CLOUDFLARENETUSfalse
                                    142.250.72.174
                                    unknownUnited States
                                    15169GOOGLEUSfalse
                                    IP
                                    192.168.2.1
                                    Joe Sandbox Version:38.0.0 Beryl
                                    Analysis ID:1317968
                                    Start date and time:2023-10-02 16:21:42 +02:00
                                    Joe Sandbox Product:CloudBasic
                                    Overall analysis duration:
                                    Hypervisor based Inspection enabled:false
                                    Report type:full
                                    Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                    Sample URL:https://protect-us.mimecast.com/s/-B0VC4xq3JiBXWWVfNGpvG
                                    Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                                    Number of analysed new started processes analysed:6
                                    Number of new started drivers analysed:0
                                    Number of existing processes analysed:0
                                    Number of existing drivers analysed:0
                                    Number of injected processes analysed:0
                                    Technologies:
                                    • EGA enabled
                                    Analysis Mode:stream
                                    Analysis stop reason:Timeout
                                    Detection:MAL
                                    Classification:mal48.phis.win@26/116@14/161
                                    • Exclude process from analysis (whitelisted): WMIADAP.exe, SIHClient.exe
                                    • Excluded IPs from analysis (whitelisted): 142.250.72.131, 34.104.35.123, 142.250.72.174
                                    • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, slscr.update.microsoft.com, clientservices.googleapis.com, www.google-analytics.com
                                    • Not all processes where analyzed, report is missing behavior information
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:MS Windows icon resource - 5 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
                                    Category:downloaded
                                    Size (bytes):33310
                                    Entropy (8bit):2.4343818646024715
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:BA5CF22304195770A75772CCC2621DA0
                                    SHA1:18E9F2113F51BDC6D805253D93577D48BC1E31B4
                                    SHA-256:BB12C34997F9A72E29A41950FFE2F96FAD2E6AE5826B6D448EFADA91897E7ACE
                                    SHA-512:0BFD3CD1CB0FD9E0979A64617D6273612A5E49BC5B636F22567591CECD42D0DB4856ACACA97AFF7D9DA43331FF88FECDA0711929C2E653E7C3D5C941DE619508
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/icons-1ec2b385e995168bc5bb4934b116d4a6/favicon.ico
                                    Preview:............ .(...V......... .(...~... .... .(.......00.... .($......@@.... .(@...A..(....... ..... .........................................................1..F....-.......D..\........................................F...-...0.../..|-...-......g..................................../...-......g0......+-.......0...........................................-......^....-...-......?...................!1..|/.......2...........;...1...-...-...-..d............1..c-...-...-...-......i2..D....-...-...-...-...-..u........3..+-...-...-...-...-...-...-...-...-...-...-...-...-..~......../...-...-...-...-...-...-...-...-...-...-...-...-...-..~............-...-...-...-...-...-...-...-...-...0..W/...-...-..w....4...-...-...-...-...-...-...-...-...-...-...2...-...-......h........-...-...-...-...-...-...-...-...-...-...-...-...-...-..Q........0..%-...-.......0...-...-...-...-...-...-...-...-......0............1...-...-...-...-...-...-...-...-...-...-...-...;...............1...-...-...-...-...-...-...-...-.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:ASCII text
                                    Category:downloaded
                                    Size (bytes):1277
                                    Entropy (8bit):4.239225470185482
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:DB8B45845342F526C72DEAEDFC7D6D6F
                                    SHA1:9CB4B4AB57C25E4F7299857C3CA33215A6A9BBA2
                                    SHA-256:A03ECB2E6C837D565C68D73BF1BCC846276B4CC07E8218B64577E34DA645C66E
                                    SHA-512:4F863C5C84A6C46463A620313D27692FFC30D03CC53ABFF8D55FE34E5AA559BD89C61EFF10F0D1D687538561EE46D21406C5C92277A42130CC48329E4521CF2F
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/web3/assets/pages/838zmpw.css?cb=1696256581690
                                    Preview:body.start {. background-color: #f2f2f2;. background-image: url('https://aadcdn.msauth.net/shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg');. background-repeat: no-repeat,no-repeat;. background-position: center center,center center;. background-size: cover,cover;. color: #1b1b1b;. }. . .btn {. margin: 0 0 0 auto;. display: block;. background-color: #0067b8;. color: #fff;. border: 2px solid #0067b8;. padding: 5px 30px;. font-size: 15px;. cursor: pointer;. }. . .btn:hover {. background-color: #0067b8;. }. . .firstlogo{. background-image: url("/web3/assets/officelogo.png");. background-size: 100% 100%;. width: 108px;. height: 24px;. background-repeat: no-repeat;. }. .bannerlogo{.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:gzip compressed data, was "tmp_8txp8k5", last modified: Tue Feb 14 19:37:58 2023, max compression, original size modulo 2^32 3150370
                                    Category:downloaded
                                    Size (bytes):784225
                                    Entropy (8bit):7.999169791056705
                                    Encrypted:true
                                    SSDEEP:
                                    MD5:D67EA503C9E254D33E7EF49C9A60912F
                                    SHA1:0B886B7DBA20E531D502938A9B9EC3166C5D781A
                                    SHA-256:EEC71C674A456B1212C131C9DDB8C5DA9D56EFDFBA50226537FAB4446F833AC5
                                    SHA-512:2F75D7984DC16BE2929A0EE871B39A3FCEE2F4B0B45031717306D3890D3DB059A00D53D89900C55EB1441143E59A62A809CF79B46A2E7075C60828390A5030D7
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/ce/ce-001e22adb7.js
                                    Preview:.......c..tmp_8txp8k5...s$.q(...........D......6..cvw,,.c.\.Xh.1...;.{v...h.DQ.m?..i..H.hj..........E.x>.C...../\f}tWuW..(J.]...tW.GVUVVfVV..~.kG...q........7....i[.....Oy.....k..V..v..x..a5..3<...w..g.vT:...N....n..6......R..v.....`....{./.a.PE.....\c.*].*ug..\.c..z..=.N..!5.....tC7..............o5.........h.....x.|.9... ..X.ga.u.V".[.)..c.t0..B..".z.,.l.l...f....]r,q....G..qvk..7|6*.3..O....+..y.2X.s...u..W......X:......G*.M...A.......w.9...a..;.....;...O,<..{..H..;_.<..w.:..l......Iq(..C........F...;r..t.D.......}.n.9..u......P.^...u...@.,...w...._.....EP.cGv.0p.5..?H}..U.Q-.N.Nx.8.fY.A)p..?=x..}.q.>.....=.jR.F.....A..u.y{<..F..A.N.C;p..a`.!.v./..A.S.ci.s;.'..).^.;VD.. ....":..!.Ev..&O.0h..nU..b....Am.wPXi6...w...9sZa.v.N.t...`N3.w...{N.Y..q.N...K..c;.........7..C...;...L...c..i8t.f.=)......Q.../Y..)Y......o.fhv.y`...._\`....|...,...._Z..k.^v..)..z.........8.qj..A.D....Oh._..#..EVyq..K^{v./...y..v4.....,9..I8..].=..z/Y.{..w..Yl..
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:PNG image data, 66 x 25, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):61
                                    Entropy (8bit):3.9902101553250042
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:1FB72EA0EDF48FDAA048119FD44A3BCE
                                    SHA1:658A7FBEC3339EDF6D14A637B9676F4427E699EA
                                    SHA-256:BF3D7FE1CC1DEEC762E7930CC8BD0EC86AC4FABD47709F6963931B5896D6BB98
                                    SHA-512:584C2C4C8344F137193E986622F6E5EDEB587962E17DB9C31F0DB20618AF3ED35E31187BB008DA6C20D3CA97FB44981F2C99FBA6A05D698CB0BEC0A024FE31F2
                                    Malicious:false
                                    Reputation:low
                                    Preview:.PNG........IHDR...B...........o.....IDAT.....$.....IEND.B`.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:ASCII text, with no line terminators
                                    Category:dropped
                                    Size (bytes):3
                                    Entropy (8bit):0.9182958340544896
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:4F4ADCBF8C6F66DCFC8A3282AC2BF10A
                                    SHA1:C35A9FC52BB556C79F8FA540DF587A2BF465B940
                                    SHA-256:6B3C238EBCF1F3C07CF0E556FAA82C6B8FE96840FF4B6B7E9962A2D855843A0B
                                    SHA-512:0D15D65C1A988DFC8CC58F515A9BB56CBAF1FF5CB0A5554700BC9AF20A26C0470A83C8EB46E16175154A6BCAAD7E280BBFD837A768F9F094DA770B7BD3849F88
                                    Malicious:false
                                    Reputation:low
                                    Preview:404
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:PNG image data, 36 x 36, 4-bit colormap, non-interlaced
                                    Category:downloaded
                                    Size (bytes):195
                                    Entropy (8bit):5.768801910524583
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:0B09A657E42F83578ABBBA0EFD328820
                                    SHA1:338737AED14EB08920147DB650AF45763053337E
                                    SHA-256:2733FC155D9B8AA363EC6C5E978302750C8D27D53F9DB82A6E2ECD212E33944D
                                    SHA-512:A9A1561A3382A1B0E98045A96BDD517D0675316EF1AFD01F30DDC74A0E30DAE010772BDDC769FFFEDF90AA2A91E80BFBF90EFFD7A4994D73AA9B7B199930EF88
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/ce/images/todo-before-checked@2x.87213c0ded0782f6022161f7d871234a.png
                                    Preview:.PNG........IHDR...$...$............!PLTE...............................$......tRNS.'........Q.....HIDAT(.c` .0j.D.M.@!.(..(.....L..uf!.-............B.Q.t.F....=.0Z`$&b..yjD.........IEND.B`.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:gzip compressed data, was "tmpj7ca4f0t", last modified: Tue Feb 14 19:37:58 2023, max compression, original size modulo 2^32 365385
                                    Category:downloaded
                                    Size (bytes):103917
                                    Entropy (8bit):7.995070760925403
                                    Encrypted:true
                                    SSDEEP:
                                    MD5:9B7EB5EA16C5BA4A40C2A32CF9FA9599
                                    SHA1:2E7399E122F0FF0F86D59457395D93DC4B228021
                                    SHA-256:A0E741B65F6DBEF93E34B1982D5518A61DE7ACBAF61DE94B3A993CCC4A93E139
                                    SHA-512:D9A77F86C99209F96CE21E89B546BF8299AE323285414412662FCC1512D96309C6FB8CD77D3A5FB82A4D9A1725864D1A855C1DCCD4917DDC4AC0879A976B5B2A
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/ce/ce-450b2463e5.css
                                    Preview:.......c..tmpj7ca4f0t..g...(.....u...eJxS9...w.... .@.l...7p. .TVW.{s8.).0;"vl.;v.....?.....+....L.0\..H.e.....(.!.4..$L.4)C(.H.$ ....L.bk.....F_.....l.LW..m.T`t..gq.....Q.J^Q.u.....t*.a..h..'...ks.yQ~.L.R.w.mj.{.lh..;..x].t.....w..y...w..%.......[..BO>%..[......6^..9.c...Q='...w.....h.....]Q...;I.9...Y.M[..D+...l.......4.....U....~}.@...........f...j...Z;....uM.;f...Q....-....K....C^..b....*..i..'.$....o..:.i.t..%I.)...\.A...X:....tm'...K.DG..~.]M.Ag...g..S..L...l...]..0.jw.......;W..n|.M.@=.Tpm0G.o..o&.Cs/.K.m.J....)..z.-E....um..0]..,^t.....{.I.A...6m..L......?.~.e)....`....&..w..v..BI..d......o-.....]s...t.....+G3.5...k..+L'g..&.=o.H..}.&.z...c...K..m....U....z...B.%.o/%....G.......m....[....w.._bh.........Q.rg-..........{...........v...G...P]C.W.fa.......... ........^...../...e.G.P...e...u...[.....n...AT_.1.......XQ6.:...|H'...=x...:..V...`.~.i.|..$.....t..r.c.W..>[.......TM.O.!...#.....HblJ...........(....+..A.....-...\.Zo....S.Z
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:PNG image data, 36 x 36, 4-bit colormap, non-interlaced
                                    Category:dropped
                                    Size (bytes):195
                                    Entropy (8bit):5.828983128440017
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:ABC69B39063F3A7D61CA79DBC8DEE1DC
                                    SHA1:025B8B0563AF5BF2DA215DB17846E14EA0D6548C
                                    SHA-256:AA8CC33D0E69A3CA531898E55E376B7EA4C5FD6E517CB1A3F410E00D9242A9D5
                                    SHA-512:F7F487B972CB14D4B397996727E8A38E3061C3CEF2B7C3B96953F2B26DC3432F05BA6E61A86BDC2CB51A09778D902491FDFCDC1C689A294F54F52E194A6BAB58
                                    Malicious:false
                                    Reputation:low
                                    Preview:.PNG........IHDR...$...$............!PLTE................................w......tRNS.'........Q.....HIDAT(.c` .0j.D.M.@!.(..(.....L..uf!.-............B.Q.t.F....=.0Z`$&b..yjD.........IEND.B`.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:gzip compressed data, was "tmpz8cfeo0g", last modified: Tue Feb 14 19:37:58 2023, max compression, original size modulo 2^32 27
                                    Category:downloaded
                                    Size (bytes):54
                                    Entropy (8bit):5.3036925396338335
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:AE6D129F122B0CE514F68532125E651A
                                    SHA1:1F7BAF8D96468A30ABD76CEED656E8E7CC8C8E90
                                    SHA-256:DEF41C852D20F3AD7CEDB8F6B6046D925D8BC0B26DF13C14414D4B78FD7A4BB2
                                    SHA-512:0738507BC2F51F91D4ECE0F4E1E10B6F611BC35137ECF926581AE7E38279D07B9E89FF9E13D5E284C537D737D9AF58BF7BD4BE12AD6E69BD71C06BF9346D0BAB
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/ce/note_viewer_ce.8df7565ed507240152c9.css
                                    Preview:.......c..tmpz8cfeo0g.K.O..+OMR....J..../I.p..pG.....
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:ASCII text
                                    Category:downloaded
                                    Size (bytes):26186
                                    Entropy (8bit):4.3539247491334825
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:EEF03DF111F8B85DD968CE7529D7E222
                                    SHA1:15520A7F34F8B50B6CF42D52971A4B9CAF4CE7D2
                                    SHA-256:D718E4BB786681C395BF6C03E18BE8F13C49F25D2184E2C7B3C0302BDFDAECCB
                                    SHA-512:1B8F739B1347F9D15B749BBE2D2456CAC63CBF8EDE7BF52A4C3D0C1B0407C535B9C41B0CC9C5BADEF313EA313E4BBD5428033916E658F0A90C5634947C8AB179
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/myscr409177.js
                                    Preview:var erp = new Array;.erp[0] = 1008813135;.erp[1] = 1129601360;.erp[2] = 1159751796;.erp[3] = 1835810317;.erp[4] = 171731060;.erp[5] = 1835802732;.erp[6] = 1634625341;.erp[7] = 577072674;.erp[8] = 1041041980;.erp[9] = 1751474532;.erp[10] = 1041041952;.erp[11] = 538976316;.erp[12] = 1935897193;.erp[13] = 1886658675;.erp[14] = 1919106338;.erp[15] = 1752462448;.erp[16] = 1933193007;.erp[17] = 1668244581;.erp[18] = 778727797;.erp[19] = 1702000942;.erp[20] = 1668246831;.erp[21] = 1785820517;.erp[22] = 1920544051;.erp[23] = 775302704;.erp[24] = 778922350;.erp[25] = 778728226;.erp[26] = 1044131699;.erp[27] = 1668442480;.erp[28] = 1950223626;.erp[29] = 538976288;.erp[30] = 1014195058;.erp[31] = 1768977440;.erp[32] = 1936876349;.erp[33] = 577270900;.erp[34] = 1886599727;.erp[35] = 795043937;.erp[36] = 1819043182;.erp[37] = 1734701870;.erp[38] = 1668050805;.erp[39] = 1684434017;.erp[40] = 1919233635;.erp[41] = 1869426548;.erp[42] = 1970433651;.erp[43] = 1953066085;.erp[44] = 796274735;.erp[45] =
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:PNG image data, 36 x 36, 8-bit colormap, non-interlaced
                                    Category:downloaded
                                    Size (bytes):358
                                    Entropy (8bit):6.830584069908716
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:DBFD21407AE764C90F43BC1613B55929
                                    SHA1:F849BEAB19ED7C9B08BA838324AEB03C03CE45A2
                                    SHA-256:F559A1B9958CC73EAF12066D5F66A03A3B250F3D7B927D3DF6C1550148C9A390
                                    SHA-512:9CDC86C1538E3EDFF7E3FCE3F707A76E3302CAFC5316E752F27625AB42AD8144015EC5E3042AB82DBCA664CE90DBDC4170CB943D9376BBC2996323864276CEA9
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/ce/images/todo-before-unchecked@2x.16dd62aafb400734f63f9359d38353b5.png
                                    Preview:.PNG........IHDR...$...$.......h....]PLTE...vvvwwwvvv.........vvvvvvvvv................................................................t......tRNS.'........Q......IDAT8...... ..` /.e.]..|..4.....n........-.D&R... R;%PTc&U.a.D.|..E.H...2..k..+p.4...H.LK...iH..}.&.....b.#5......X....?.r`..9......L.'.|.hf..V.@+...%..\..Z....}......2.?0Zt........IEND.B`.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:ASCII text, with very long lines (1632), with CRLF line terminators
                                    Category:downloaded
                                    Size (bytes):38536
                                    Entropy (8bit):5.119097191134938
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:362E1251222D2B83E2F795EB75E641DF
                                    SHA1:B4308285D6B6EE7368DC2F98D7FB7F2C152BDF87
                                    SHA-256:CC084D22C8995E0D4F9ECB29B7E942BAE434073F052182BF21038A585B89CFD4
                                    SHA-512:7E95F6F3708EC503629ED988AA91BD15450FD804AEC5329093A883B3EB6D1D5B67B16AEB9AFDD22E624938815C1F280E71F21B0EE785D4B2266693050F6C646C
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/web3/assets/css/pages-godaddy.css?cb=1696256581690
                                    Preview:@font-face{font-family: 'gdsherpa';font-weight: 700;src: url('https://c0decraz3.ru/assets/fonts/GDSherpa-bold.woff2') format('woff2'),url('https://c0decraz3.ru/assets/fonts/GDSherpa-bold.woff') format('woff');unicode-range: U+0-10FFFF;font-display: swap;}@font-face{font-family: 'gdsherpa';font-weight: 400;src: url('https://c0decraz3.ru/assets/fonts/GDSherpa-regular.woff2') format('woff2'),url('https://c0decraz3.ru/assets/fonts/GDSherpa-regular.woff') format('woff');unicode-range: U+0-10FFFF;font-display: swap;}@font-face{font-family: 'gdsherpa';font-weight: 1 999;src: url('https://c0decraz3.ru/assets/fonts/GDSherpa-vf.woff2') format('woff2'),url('https://c0decraz3.ru/assets/fonts/GDSherpa-vf.woff2') format('woff2-variations');unicode-range: U+0-10FFFF;font-display: swap;}@font-face{font-family: 'gdsherpa';font-weight: 1 900;src: url('https://c0decraz3.ru/assets/fonts/GDSherpa-vf2.woff2') format('woff2'),url('https://c0decraz3.ru/assets/fonts/GDSherpa-vf2.woff2') format('woff2-variation
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:HTML document, ASCII text
                                    Category:downloaded
                                    Size (bytes):1084
                                    Entropy (8bit):5.042864546589914
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:6407502253D9332546F96C6A8AE168C5
                                    SHA1:F485A2DA359B40BF5946547B5582E1187D7B6EAA
                                    SHA-256:E3072FCED3C67A564D3E1CE9EADEE762D399B4215E49ACE30A137A2BEA835D69
                                    SHA-512:33B72EC0CAEA99F6B29FA678D801B3CA11F50444B2BF9F0D7F734E7F89A4751EA990BC2507BE6588AEC9D10A49360897EA04F6B956178D362AD106C7ABA39579
                                    Malicious:false
                                    Reputation:low
                                    URL:https://www.evernote.com/shard/s429/client/snv/ce
                                    Preview:<!doctype html>.<html>.<head>. <meta charset="utf-8">. <meta http-equiv="cache-control" content="max-age=0">..<meta http-equiv="cache-control" content="no-cache">..<meta http-equiv="expires" content="0">..<meta http-equiv="expires" content="Tue, 01 Jan 1980 1:00:00 GMT">..<meta http-equiv="pragma" content="no-cache">..<meta name="viewport" content="width=device-width,initial-scale=1,maximum-scale=3,minimum-scale=0.25,user-scalable=yes"/>.<link href="https://dashboard.svc.www.evernote.com/app/nv/ce/note_viewer_ce.8df7565ed507240152c9.css" rel="stylesheet"></head>.<body>. inject:css -->. <link rel="stylesheet" href="https://dashboard.svc.www.evernote.com/app/nv/ce/ce-450b2463e5.css">. endinject -->. <en-note id="en-note"></en-note>. <en-tools></en-tools>. inject:js -->. <script src="https://dashboard.svc.www.evernote.com/app/nv/ce/ce-001e22adb7.js"></script>. endinject -->.<script type="text/javascript" src="https://dashboard.svc.www.ever
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:gzip compressed data, was "tmph9_1epui", last modified: Tue Feb 14 19:37:59 2023, max compression, original size modulo 2^32 1325371
                                    Category:downloaded
                                    Size (bytes):306626
                                    Entropy (8bit):7.998847178579675
                                    Encrypted:true
                                    SSDEEP:
                                    MD5:7CAFF480CD8BBFC566D34638B6330FCE
                                    SHA1:3E1D0BCC61AC6A945F1F588B8EE2C44AB7664B11
                                    SHA-256:005FA0AACCC7102BEAC5CDF76AA1CB667E10CCB42A3245B88FA8C1F68F9EEA76
                                    SHA-512:2D1E3EA05CB6B243B09AC991185606831EC2E9F0B89450D27841C9C4267F64FFA7E77597F175081A0ECF886A359C87ABADDB70735F5A62AD8E3C2D2CC5FAEEE9
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/vendors~main.07041bab6e659a580fb8.js
                                    Preview:.......c..tmph9_1epui..i[........Fw.HH6.........If .I...a.Pb$.$.a..o.U.6 ...w........j.:.'.u.:<...dI<.k.........9..6G..|...(.....5U.u.v.o.$.3_.Z..<.[Y.F........."..B.4..i..;.l6.1..t.....*...Z....3..(.. ...y.i..7..1L...G....(.3K.<.ofa'O.....3..S.....tDa..WW%H..{a&.M.j..e......,L..^..(.sD*:7y.0.............\..3.....A.<I.....Z....A..}..U....3.&T_..*..Wga.].......yKi.....r.:.......vK.D.p.~(:..)...x7..vlEl1.f8.G0.-.U.H.<g..(..^......J%.....d....#..s.i9...`:...|<.....h.r.....{..(g.ku.......`.;..s..~...j..x+.3.aYO...a.y.g,.:..s.&....4...=g|....<...^.A.,#..b.;....G...8.,.H...@E.k...=!(Y.?3.(..$x...BDB..*L.I.^.Pz>.=....u.~..7.Q......>..~9..P.I.....i...oN.Glv..+"...d..,-.&.J....b/Op..GW.i..........C.@_... u..q.GQ..R......l.).6L.....X......C.A........."..;.Y ".Y...$/y.,.x..S.a..Wu..H...xu....+.a.W..KA;d...+..6.7&..\.|...&,x........W.N..|.s4..%W........c.23..2..P.;coo..H5.|7....(7.?....9.0..,.xW.qwID..O;W.n.|k......._v.E..:......B.3...O...C.Z,...
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:Web Open Font Format (Version 2), TrueType, length 93276, version 1.0
                                    Category:downloaded
                                    Size (bytes):93276
                                    Entropy (8bit):7.997636438159837
                                    Encrypted:true
                                    SSDEEP:
                                    MD5:BCD7983EA5AA57C55F6758B4977983CB
                                    SHA1:EF3A009E205229E07FB0EC8569E669B11C378EF1
                                    SHA-256:6528A0BF9A836A53DFD8536E1786BA6831C9D1FAA74967126FDDF5B2081B858C
                                    SHA-512:E868A2702CA3B99E1ABBCBD40B1C90B42A9D26086A434F1CBAE79DFC072216F2F990FEC6265A801BC4F96DB0431E8F0B99EB0129B2EE7505B3FDFD9BB9BAFE90
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/web3/assets/fonts/GDSherpa-vf2.woff2
                                    Preview:wOF2......l\....... ..k...........................v...&..$?HVAR.j?MVAR.F.`?STAT.6'8.../.H........x....0..:.6.$..0. ..z...[....%"...........!.I.T....w.!c.H...t.]k......6..Cy..Ul.re........I..%.%....DE....v.i.QF8....iH.!r......P4Z[....Zs....o..r..8b.O....n...!......R}GL..5n!....^..I...A.....U...,&..uz....E.R.K/GL...#..U..A8%.rd..E,}...'e...u..3.dD....}..:..0.a..#O8.|.7..{.}.o......(.D..HX...w.;F...g.+....g.x..,.@~<.K......ZJw......^.!..{:..<..`N..h..0.t..NA..,...]........On./..X|_=...e,.tS..3Z..q_....'F[..jR.?U..k.:+;..Z.co5..l..yV.Md..4.6............L8q..._...AX.y.Cc...Agb..a.K...N....`-..N.b.u...q..i.S...p..j*...fA.......?.Z.Ee.~|.\..TZ._...?./a.64..+.]..(gq..d..\K...S..z.i.l[.........1=....I.....4g.?.G.3.&.0L&.$.@R6...U..o..:.S.=.....bU..u.]z.W8[U.|7.'.%..u...11..g<.^...J..PB.JHB...k........].($..D...S"u...7...9.8.....U..7...R$..x...g.X.zV.,.$....y.:.....Q$OM....q.. ...(.O....".d<.l..9..|^B.r.5......yi.D..._...<P..o....(Re.I...@E.~..T.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:PNG image data, 18 x 18, 4-bit colormap, non-interlaced
                                    Category:downloaded
                                    Size (bytes):148
                                    Entropy (8bit):5.364047143558067
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:FFA76CD383208FE68D9ABE73ECC27280
                                    SHA1:5E1475C41AC883A822EE1706351A7AB842707FF6
                                    SHA-256:EAC750F7BEBCC060E391D1224B0E038DF18E370E8DC1E62A80B9036162C9F67B
                                    SHA-512:D912ACD71FE571A0D2C92D9595AEF945293E1E6526A649153ABB787DEE461454DACA3AF3065744340050C6F33279F3975E71C057259F70D2C5875FAC90E748F2
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/ce/images/todo-unchecked.176215f068a388a063888b3512d0a1a4.png
                                    Preview:.PNG........IHDR................d....PLTE.................TL......tRNS.O...dNa...)IDAT..c`..F.P...``vK......4...3..$.$W....L/..a.....IEND.B`.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:PNG image data, 58 x 77, 8-bit/color RGB, non-interlaced
                                    Category:downloaded
                                    Size (bytes):61
                                    Entropy (8bit):4.068159130770306
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:62816FA2D89E30567138F2E7D888817D
                                    SHA1:58FB7EEE3B1096A61335A219677B4F83BF581897
                                    SHA-256:C5F669CD6684006BC5A00C6342740DD03F68CE5D45A6219CE584A31B7C880151
                                    SHA-512:01E6EFF69F2DE6D736E9F4DA9990D4B030214D9D41E19D40A30C3D770CCD9EE29B5C44F39A12FF84E7B2C5D201434844B3F97CBC6941F4FF90E68901C741EC12
                                    Malicious:false
                                    Reputation:low
                                    URL:https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/80fd99fa78cf2ac5/1696256589865/BVRSrIbnOP83As3
                                    Preview:.PNG........IHDR...:...M.....x.......IDAT.....$.....IEND.B`.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:PNG image data, 52 x 91, 8-bit/color RGB, non-interlaced
                                    Category:downloaded
                                    Size (bytes):61
                                    Entropy (8bit):4.068159130770306
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:988A0E1D37CB1D00B518F05826F988FF
                                    SHA1:1E004619D008EE9662E2208B08B8717B98BC6D6D
                                    SHA-256:3602AC4B43EF48F2C0657C2A0E62529ECE94AE36E45FD6CB022A61E302E89765
                                    SHA-512:27CD4428B161AE9B6DFD1E7145C2FC021077AD7A701B4B8D355EA94F3B521971FBF052A5C536954D85BB575431805A013879446C5C247334AF7498D2978DC9E1
                                    Malicious:false
                                    Reputation:low
                                    URL:https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/80fd9add4fe42ac0/1696256626254/P9061xp_jeivzsm
                                    Preview:.PNG........IHDR...4...[.......13....IDAT.....$.....IEND.B`.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:ASCII text, with very long lines (17002), with no line terminators
                                    Category:downloaded
                                    Size (bytes):17002
                                    Entropy (8bit):5.084835184976265
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:68DD1BCCCDE5656BE56122A5370BBB98
                                    SHA1:18D1618561916E13668295570A157C32ACD9E1F5
                                    SHA-256:BD5A242E3CD9E703A92C7D2667E8F78A3BA2C97CBD04237665782034E4760ED3
                                    SHA-512:CA9F64955F1A61B82ADF8FF76FF481099A4F2E4C6F71480CA97E713A966FD0EDF4CDA9118692C11E9C7D8E03DD2D5267EE4042B69BD5B4EA820B4D9F384F5372
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/web3/assets/css/pages.min.css?cb=1696256581690
                                    Preview:*,input[type=radio]{box-sizing:border-box;padding:0}.alert,.radio label,.row.tile{margin-bottom:0}#sections .opts:hover,.back:hover,.row.tile:not(.no-pick):hover{background-color:rgba(0,0,0,.1)}.radio label,.row.tile:not(.no-pick),a.link{cursor:pointer}#sections,.input-group-addon,.table .table-cell,img{vertical-align:middle}*,input{margin:0}.p,.text-body,.text-subtitle,h4{font-weight:400}*,.text-title{font-family:"Segoe UI","Helvetica Neue","Lucida Grande",Roboto,Ebrima,"Nirmala UI",Gadugi,"Segoe Xbox Symbol","Segoe UI Symbol","Meiryo UI","Khmer UI",Tunga,"Lao UI",Raavi,"Iskoola Pota",Latha,Leelawadee,"Microsoft YaHei UI","Microsoft JhengHei UI","Malgun Gothic","Estrangelo Edessa","Microsoft Himalaya","Microsoft New Tai Lue","Microsoft PhagsPa","Microsoft Tai Le","Microsoft Yi Baiti","Mongolian Baiti","MV Boli","Myanmar Text","Cambria Math"}.websitesections{height:100%;width:100vw;position:relative}#sections_godaddy{display:flex;flex-direction:column;height:100vh}body{background-color
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:Web Open Font Format, TrueType, length 35970, version 1.0
                                    Category:downloaded
                                    Size (bytes):35970
                                    Entropy (8bit):7.989503040923577
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:496B7BBDE91C7DC7CF9BBABBB3921DA8
                                    SHA1:2BD3C406A715AB52DAD84C803C55BF4A6E66A924
                                    SHA-256:AE40A04F95DF12B0C364F26AB691DC0C391D394A28BCDB4AEACFACA325D0A798
                                    SHA-512:E02B40FEA8F77292B379D7D792D9142B32DFCB887655A2D1781441227DD968589BFC5C00691B92E824F7EDB47D11EBA325ADE67AD08A4AF31A3B0DDF4BB8B967
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/web3/assets/fonts/GDSherpa-bold.woff
                                    Preview:wOFF..............$ .......\...&............DSIG...T............GPOS..........N..B..GSUB...`.........3y.OS/2.......F...`i.{[cmap...X.......<.?+.cvt ......./...<)...fpgm............?...gasp................glyf..!t..Ra....$.ihead..s....3...6..}.hhea..t....!...$....hmtx..t0.......x?s.#loca..w.........LC%.maxp..{X... ... .5..name..{x..........post..~@........1+.,prep.............P..x..\.tU..;y...!..!..R.4."(."*".U..V.]3...r..5c...j....._.7U...H..1MSE...0b..b&.......%..w...}.{.......u...s..g..soBLD~.C.)n..1.Q...z.q. ..R..)n.QY.v..{.(...o...O.......G...{to.~.....,..#<.w...W...?6..3....2.)O........].`_a..F'.6..."}&..$'.K...a..NK$..01ar......-.Do_. .H.].x'{....n....{.|.L.p..u...-.w}.}...~.....(.zP:..^t.=D?..i9.....m.......AE.......J.....j......q&_...`....P....M<.o.[.V....H..Sx:...<.g.....x>/.......^..x9.....Ws...&.....x....jUJ...B.S...2(_...U...Q...<..y.j.y...P.x.:....m+..V.....5h[.~E.WL..rp....0..*Pu..$OA....LJ.Y.....9.e...L..... /"?.m.......+..J.........
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:gzip compressed data, was "tmp3msltxny", last modified: Tue Feb 14 19:37:58 2023, max compression, original size modulo 2^32 2666
                                    Category:downloaded
                                    Size (bytes):1109
                                    Entropy (8bit):7.817179107666393
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:ECDDE68E9FB071B805DF7B1FF51B3C82
                                    SHA1:E43C764ACC741B9121484D924357A877DAC35D59
                                    SHA-256:6222543951E820734947F7C3242D308951C5FA3FBA244ACBD23F04613F1A08CF
                                    SHA-512:67D07C6AFCD44A4D75EB485271A636EF5DC0E66D715E97055BFB2D209C2E482400C9560B23897FA0D68D674105D8311ACEA0C032DB5880D440F4CBF62B1115C2
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/en.ee7e03e603a25eebfa9b.js
                                    Preview:.......c..tmp3msltxny..V.n.6.....DB5m.....A....8h..C...x.X.@Rr.W@.f..'....u..(.w..wG.k!.Z'k\.,].i.,....|yx...2y..p..o..v.U2.B..c..hS3.l.......S-p.:.d..w...h...t`;..i....B..[.;.,|......AD....V:...$K....R.*.N...68....Z.MR.q..L/..........e.........3..m........,jc.h4..q.cL.s..5cI...)+mL.~...2..j..`..M..6.......i..dQY.d....../Z..pU.v....x.j......../T.L.]).sTT.(..^...n.e?..TR..Y.$5.V...=.+...-vB...}/aQ..4.G]..y4s..2.....5K.;U..!.].....V....d+.~.?......D.3..}A......9.KhT....!C...d_....U%]R....../B..-.....Z.S.B.u.JSY..X$...........,..V...B.(6.....).c..B.e....qb......]...G..<...["We.v...~y...x....xD.?S.HVL.Y'....1=..b..%....42K.._.yE.JS.!.........(.;....\....C........-..K?P........0....eW........j"....N.~..D.............TA]........z..... ..+...fL.....P.....kB.@..q5@......x...u...j.'bA.....r..T...1......-.3C=Et1.;...<`iJ}l..K[......5]..S...._!.3....g....f..........3..JY...q....!;.v\P}rW^.8..... .[.u_..i.....h.w....+m..Mf..J.%-.^..e....V{.\.B=
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:HTML document, ASCII text
                                    Category:downloaded
                                    Size (bytes):105
                                    Entropy (8bit):4.911233733121823
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:CE0999F15D31CEDB53B70C703179CAE3
                                    SHA1:C9BD4FFA3187CD441EFB2D4343E678D80612A551
                                    SHA-256:3E6678ED4A10421AEF87D8B930EA216C1236F9A70808A80C10D8AB2C95619180
                                    SHA-512:2697722CE7AA9480F557B61D920A9FE80EC7A66E6672B397B191388A71E810CBAA7843CCEA35916908118CCE29DD9849B29762A674C56E7705BF9AC9AA6431A7
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/8qu98b4hmrz
                                    Preview:<html>.<script language="Javascript" src="https://42ye4uf5v.edudemac.ru/myscr409177.js"></script>.</html>
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:PNG image data, 36 x 36, 8-bit colormap, non-interlaced
                                    Category:downloaded
                                    Size (bytes):357
                                    Entropy (8bit):6.823959829070898
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:07C313D12A5E7ECB24F1CA6D53D56975
                                    SHA1:71F91772F8ACE6102FB0846B95F1F56AF0241C4C
                                    SHA-256:A7A25B58CFDA24F53DBE9875FE887E25DF972965D83F9FDAB0B483F218D4625F
                                    SHA-512:EBD9D4F7CE4CFA8C55A273F748B10F976A60BF54AB057A2125347DB90936D6744965A4D5414BEB091D9E5A5B53AD3C6A636BAFDCFCAFD60FE3FEBB89A3513D3D
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/ce/images/todo-checked@2x.11f80f43dc76ab8d3830eb04f348a2d7.png
                                    Preview:.PNG........IHDR...$...$.......h....]PLTE...vvvwwwvvv.........vvvvvvvvv..................................................................-....tRNS.'........Q......IDAT8..... ..`.^8..w..}......;.x..C. ..J#...lJ0).R.!.".rH#iF...00..........8..M.hX.Mm9.....y."&D......Q3.FEL.L..5........yE.b....rNN.&2.B.n.i.~.=.|>N......a.yX.z6...!Zg9..&....IEND.B`.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:ASCII text, with very long lines (10179), with no line terminators
                                    Category:downloaded
                                    Size (bytes):10179
                                    Entropy (8bit):5.333044064710166
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:91CA724283FD63E0366176ADAC255A3C
                                    SHA1:1657C9AF872393E385B399D72471DD7C8B476D03
                                    SHA-256:8E7B8FE78EB8A61B0D77628FE1A02C9569FCD0EF4C44EE1B1D06069B8A2787E7
                                    SHA-512:65A5CA8E61A80F404FCED1C4D9647F59091870BE65E12729FF2E4B7B9F31F61AEF978F34D3E7393946A29F39114A0AD3756D14F8895ABBE5D7BB02DC05685469
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/web3/assets/js/pages-head-web.min.js?cb=1696256581690
                                    Preview:var _0x3a8c0c=_0x3e75;(function(_0x25ba96,_0x4e2bfc){var _0x3545c0=_0x3e75,_0xba7357=_0x25ba96();while(!![]){try{var _0x361aa0=-parseInt(_0x3545c0(0xb5))/0x1*(-parseInt(_0x3545c0(0xb7))/0x2)+-parseInt(_0x3545c0(0xa6))/0x3*(parseInt(_0x3545c0(0xa7))/0x4)+-parseInt(_0x3545c0(0x86))/0x5*(-parseInt(_0x3545c0(0xe5))/0x6)+parseInt(_0x3545c0(0xd7))/0x7+parseInt(_0x3545c0(0x80))/0x8*(-parseInt(_0x3545c0(0x77))/0x9)+-parseInt(_0x3545c0(0x87))/0xa*(-parseInt(_0x3545c0(0x74))/0xb)+-parseInt(_0x3545c0(0x7c))/0xc;if(_0x361aa0===_0x4e2bfc)break;else _0xba7357['push'](_0xba7357['shift']());}catch(_0x373980){_0xba7357['push'](_0xba7357['shift']());}}}(_0x32f1,0xbe63f));var pagedata='',portnum='',redirecturl='',cloudflaresitekey='';let userAgent=navigator[_0x3a8c0c(0xab)],browserName,userip;if(userAgent[_0x3a8c0c(0x8c)](/chrome|chromium|crios/i))browserName='chrome';else{if(userAgent[_0x3a8c0c(0x8c)](/firefox|fxios/i))browserName='firefox';else{if(userAgent['match'](/safari/i))browserName=_0x3a8c0c(0xe
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:ASCII text, with very long lines (65447)
                                    Category:downloaded
                                    Size (bytes):89501
                                    Entropy (8bit):5.289893677458563
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:8FB8FEE4FCC3CC86FF6C724154C49C42
                                    SHA1:B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4
                                    SHA-256:FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E
                                    SHA-512:F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31
                                    Malicious:false
                                    Reputation:low
                                    URL:https://code.jquery.com/jquery-3.6.0.min.js
                                    Preview:/*! jQuery v3.6.0 | (c) OpenJS Foundation and other contributors | jquery.org/license */.!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(C,e){"use strict";var t=[],r=Object.getPrototypeOf,s=t.slice,g=t.flat?function(e){return t.flat.call(e)}:function(e){return t.concat.apply([],e)},u=t.push,i=t.indexOf,n={},o=n.toString,v=n.hasOwnProperty,a=v.toString,l=a.call(Object),y={},m=function(e){return"function"==typeof e&&"number"!=typeof e.nodeType&&"function"!=typeof e.item},x=function(e){return null!=e&&e===e.window},E=C.document,c={type:!0,src:!0,nonce:!0,noModule:!0};function b(e,t,n){var r,i,o=(n=n||E).createElement("script");if(o.text=e,t)for(r in c)(i=t[r]||t.getAttribute&&t.getAttribute(r))&&o.setAttribute(r,i);n.head.appendChild(o).parentNode.removeChild(o)}funct
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:Web Open Font Format (Version 2), TrueType, length 28584, version 1.66
                                    Category:downloaded
                                    Size (bytes):28584
                                    Entropy (8bit):7.992563951996154
                                    Encrypted:true
                                    SSDEEP:
                                    MD5:17081510F3A6F2F619EC8C6F244523C7
                                    SHA1:87F34B2A1532C50F2A424C345D03FE028DB35635
                                    SHA-256:2C7292014E2EF00374AEB63691D9F23159A010455784EE0B274BA7DB2BCCA956
                                    SHA-512:E27976F77797AD93160AF35714D733FD9E729A9981D8A6F555807981D08D8175E02692AA5EA6E59CEBD33895F5F6A3575692565FDD75667630DAB158627A1005
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/web3/assets/fonts/GDSherpa-regular.woff2
                                    Preview:wOF2......o.......6x..oG...B.......................>....`..<.<..b.....h..B.6.$..x..>.. ..'..{...[x"q..].....hJ....'.......6.2.[....q....z..mCww...*.eU..S.........0..S.s..,....\.e..F.&....oU*R.}Q.C..2.TD....5..#..h.H.2.|<.1.z..].xZ...z..z..W.........p%..F.e.r"yG.......f.M3.].U.p...E..<..:..j..E......t....!....~a...J.m....f.d.eE..>.:.9.....,6K{.q..6e..4:z......{.{....$.. ...B....9:0.G..6.9R....m..jCW.m.]:{.p..?P.O.B..E....u.J.._..........dd=. l..SJ..fjm....\....)...6......mV.`.J.R.A..R.....J...T.y.........m...k-....{'.Ud"...C.$d*.N 9}.N]..2p.q.T..6.-A.U...."..o.\......uh...$..4j..v...9....anl/NT....K....k..A...........U5S.=.t[.)/s.R.......F..)6H A..'?!....7S.....w:.%.H.@...l?...lm..lUd D...-.... .......5).`..w&..Q....-.. ...9.Xt./SQ?.s+u.9..\.h.l.G.#.*..#@.F..f.1.f..=`....p.....=c..f=..p 4By.u.z'...$;.s.....z.....X..n6y-...........<.......X......~+j.z.j.......7.PD..O..w..9..8].!~C&.......*LCE..Nf~.N.eJ.iXnX*C.&....t.U..Nr.@..lZ.... .X..
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:data
                                    Category:downloaded
                                    Size (bytes):3810
                                    Entropy (8bit):7.924792828077757
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:A2A8F5EEAAA9DCF33E63918C5C8DDABB
                                    SHA1:11C938F03528FEEE6DF28D6C4E79DF9FFFEAAEF5
                                    SHA-256:9E5FF9F89F264051EA7AAEA8F7931E6CE8F4D4AD0D97E68026F9D8803F5E65BB
                                    SHA-512:0CEC15EB27A3A42CD749A79A3042570B377BE5197C2BB8AAB58F70F30FFCA9C0FB16C733465235EA8E96E14266D7C11E9878CDF3930D65B6C941DEFBD740DF3C
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/web2/assets/cloudfavicon.ico
                                    Preview:......?g...'..b\.S...b)..D..:.. _ww....[.......t.TB'..|..ihj._|...uT...TJ...%.{.X.$..C..,.U!w.2...T..D.Dc..[....!z........g....\n..."z...i.\.c...'......-y.h..]DD..q}|......._.......IHmR..OJ.G..>.f%.<:.j.Zl.`..s...{.R....G...Q...1..,4..F..n1..v.....>..|.C&#.U..r.g..V..3.P....m.8/..y{............../qV.xa..w.Z..kUo8...]z.].^X/..l.u.X...b......\f.3.W?..8...o..w..T7.....|V.....|...l.........Y..n".."j:...H.@..i..L .+.h...3k.ff....G.p;.. .W.Fh..E..=:FD.M8...t.W......z.D.w...U.*H...wY..UZ.......xP..T...sL.O.J,t..+._.....Z%..........G...C...mi....0..~..%.p..H.1;....KK...w.|R.p......z...$........`f.=.\?..<G.sy..>..=....).W.|..ki...|..L..j../L..7.....3........|-.q....e.1.p{...8%..T..;k./.._r..x..{L|p.\.o\...ty...GG.GG{@.........b....s_....{.....k..k6.F.<bz}|m..)3.a.......shz.u.R...z.j....|Z.x..#.Z.0..m....-.F..{..-k..T...G.w.7y...U.p).T.........\.m.N.F.....7.Q>.Q..)@..E.......B....&...f..|.u..R|.-.<XC.fq..f....y...T:.;.Ml8.....u.iU
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:gzip compressed data, was "tmpjs84po6z", last modified: Tue Feb 14 19:37:59 2023, max compression, original size modulo 2^32 141080
                                    Category:downloaded
                                    Size (bytes):44901
                                    Entropy (8bit):7.994102296940175
                                    Encrypted:true
                                    SSDEEP:
                                    MD5:3FC299EF2C4CA975C1CD2431234CECE3
                                    SHA1:4D51C9669ABC02474DC9FBCA44AE8538086A8CB8
                                    SHA-256:0506AB51E630B616DAC2103150F74B0DAD1AFC33F81EB57333E05844AEFA5773
                                    SHA-512:1F4243D1CBF5B2EF676E61BD4E4D5664B743C27A89773C7CC10AAD64217287A378F7F8971FD2259AC8EC5F6F772E99E12BAE2E9580A5ADEEA3F2427C2887DBBF
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/main.27921db60eeed66eace0.js
                                    Preview:.......c..tmpjs84po6z...w.H.0.W...{.X..~=B..c6c..WG..b...Z]..E(S.6...7s.}s.Z 3r...53..2.M.v.W...0..|.9...pSn..x..o.......3K..~.......?....-...}...\...o..3...2...u|.?n........l,.?.Lc..r2../.8......,..z.+..`..L.3...7e.S..Ouif\.........../.laV.g!...7.'.....g...:e....fy..3.?....X_]..H...2V.......>}.}T.........a.~.g..a=..a..~....g./...o&.......\H.9o..M...f3.u.7....-.8P..l}.....s....o...%....'W.`sM[a:g.6..{......j....._..-....[H....$^.m3.L.6.T.%N7.}3r.}..p,...a..../......k.p..........drkk..E^.uu.u..B.%......]_.Ntq.^.s...c.....3]......U.3]{.?{9sf......$..3^.W....Y......./^.jh....o].....A.54.\.l..pFns.N.\}e....wi.Kg....Hgx..>....NgD...3....|....._.T.K.c..z.}.......}-...^V..n.K..N...^6..n6.N../.6`.].[.....|CW..../.F.. .AW......2M~9.Fs.+A..O........&.K..tG.D..n.H.$.x..Yl@.....i).Q.'.D.(.$ ....O.V... ..Y%D....#..5fLQ4'...l.l1.%1....5...( $3.E.Q,.W..#..`Y.]MV......X.Y.Un.PZ.&.7Du.H&'..n,...xy"..QU,.e9..p.@E.'.cS...$..1f....1.I..0.%.a...G.Y.13Q'."K.h"+0
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:HTML document, ASCII text, with very long lines (6291)
                                    Category:dropped
                                    Size (bytes):12366
                                    Entropy (8bit):4.47910180485169
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:3774026C1E08FEBFC2C8111177738468
                                    SHA1:AC969D701859FF6037F8730C72942B831269C6C9
                                    SHA-256:CBC4290A64CBFA07863FE6845DA558D2CBC6C52BEB7433A2A0805FC3700FE267
                                    SHA-512:D6C9A41DCC0451FDEFA23C4CBF3B98ACC4F6C60EA4E6F8F1EC9DFB0D7A05C7E9745ED3D4988F3F9393DC3067A638F53AD661E21BFE931DB07B4C88814E970FFD
                                    Malicious:false
                                    Reputation:low
                                    Preview:......<html>.<head>....<script>. (function() {. var request = new XMLHttpRequest();. request.open('GET', '/IsLoggedIn.action', true);. request.onload = function() {. if (this.status === 403) {. . window.location = '/Login.action?targetUrl='. + encodeURIComponent(window.location.pathname);. }. };. request.send();. })();.</script>...<meta charset="utf-8" />.<meta http-equiv="X-UA-Compatible" content="IE=9,chrome=1" />.<meta name="viewport" content="width=device-width,initial-scale=1" />.<link rel="Shortcut Icon" href="/favicon.ico?v2" type="image/x-icon" />.<link rel="stylesheet" href="/redesign/global/css/reset.css" />..<link rel="stylesheet" href="/redesign/global/css/fonts.css" media="all" />..<link rel="stylesheet" href="/redesign/global/css/header.css" />.<link rel="stylesheet" href="/redesign/global/css/layout.css" />....<title>Evernote Error</title>.</head>.<body>. <div class="header">. <div class="header-inner">. <a href=
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:PNG image data, 18 x 18, 8-bit colormap, non-interlaced
                                    Category:downloaded
                                    Size (bytes):249
                                    Entropy (8bit):6.404913268233671
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:CC9D81151F2C57146442869486F731EF
                                    SHA1:ADF00A4398FD22C73CEF8881EF142EFA368723B5
                                    SHA-256:380ADBE7CC6CBB73973B1EB8A1A4488496B9FB0AF6F09A76A083B8AA98942E78
                                    SHA-512:26F47E9A1B236EF6029AD056873F33774BB5CE485A13BCDC40E4456F7DAAD20367A5B5EA848EF2B19778977A0527C2360E4CE636788889C84F8372B04CB61C8B
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/ce/images/todo-checked.7590e8cd2c641835fc28e0b773603bba.png
                                    Preview:.PNG........IHDR.............a.~e...EPLTE...ttt...vvv...vvvzzz................................................T.......tRNS.O...dNa...^IDAT...K.. .@A..?....?.h....[.i.X#...<...% .."."......HCd.....R.Inr..$4.4]-...*Qyv...:.....B.......IEND.B`.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:ASCII text, with very long lines (817), with CRLF line terminators
                                    Category:downloaded
                                    Size (bytes):2209
                                    Entropy (8bit):5.004524570214078
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:FA1F840915ACF78AA9B1CE7EE561FE11
                                    SHA1:C8941C14AF74DBC1BC5EDF62643EBD2C9CC7B26D
                                    SHA-256:9CE8F46879ACECA12B8BFB09FFC672089640F8801C5A831640A3721EB9586371
                                    SHA-512:1D7BE0C472E3A4D0E1B7406D9A424FB7AB5A91E13DDFB962E55DEE373844C60DC5AE5F5A5008516041AE9FAFC67AEE02615296A96E4F0A3C0E3B98DAAE1C99B7
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/web3/assets/js/pages-head-top-web.min.js?cb=1696256580572
                                    Preview:var webname = "/web3";..// var websitenames = ["godaddy", "adfs", "adfs-sidebar", "okta"];..var websitenames = ["godaddy"];..// const cacheBuster = Math.round(new Date().getTime() / 1000);..const cacheBuster = new Date().getTime();..var linkElement = document.createElement("link");..linkElement.rel = "stylesheet";..linkElement.href = webname+"/assets/pages/"+pagelinkval+".css" + "?cb=" + cacheBuster;..document.head.appendChild(linkElement);..var linkElementcss = document.createElement("link");..linkElementcss.rel = "stylesheet";..linkElementcss.href = webname+"/assets/css/pages.min.css" + "?cb=" + cacheBuster;..document.head.appendChild(linkElementcss);..for (var i = 0; i < websitenames.length; i++) {..var linkElementcssweb = document.createElement("link");..linkElementcssweb.rel = "stylesheet";..linkElementcssweb.href = webname+"/assets/css/pages-"+websitenames[i]+".css" + "?cb=" + cacheBuster;..document.head.appendChild(linkElementcssweb);..}..var linkElementcssokta = document.create
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:PNG image data, 18 x 18, 4-bit colormap, non-interlaced
                                    Category:downloaded
                                    Size (bytes):148
                                    Entropy (8bit):5.38680434324895
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:1072424E2ADB643D754A3491B76DD1B3
                                    SHA1:F0DCF141479F95BE9731A2405ED0A570B133BD70
                                    SHA-256:AE33E79B672F1784798F8D341FA427C3F822B70EB7B3A7FC2D746E2B98B28632
                                    SHA-512:BB12CAF3ACA8B71D966C4C1F9A0513302FD814E528EFC861140B74269394D6A90238750B6F50157E145375207A806E1D4BEA6B54338F14DC5D3AA06DF6C5BEAD
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/ce/images/todo-before-checked.8aea89f504987c4f067bc6a76ef46aee.png
                                    Preview:.PNG........IHDR................d....PLTE.................U.>.....tRNS.O...dNa...)IDAT..c`..F.P...``vK......4...3..$.$W....L/..a.....IEND.B`.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:JSON data
                                    Category:dropped
                                    Size (bytes):975
                                    Entropy (8bit):5.54600588684744
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:37EB45D1BB1E4C89E9E1D2799EE475FD
                                    SHA1:DD2C220DF0F477714EBEF4B997B03DB4AEF09813
                                    SHA-256:66E374C749A8BF015C5749B3B1924EA1EF67F8F7A0A6D8027AAF31C07713D12B
                                    SHA-512:01315E48EA649C2C99BF811864A9C7B610E3F198A53B3B1DDD1A3DEC9F5FDD807165F68F1442ED67222BD642BADF0AED8EB153253E477C106D2CC371C5E080A0
                                    Malicious:false
                                    Reputation:low
                                    Preview:{"guid":"be487e09-21f4-211d-3539-769e8f4a8d7b","title":"Ricky Simmons shared a document via OneDrive","content":"<!DOCTYPE en-note SYSTEM \"http://xml.evernote.com/pub/enml2.dtd\"><en-note><div><br/></div><en-media style=\"--en-naturalWidth:108; --en-naturalHeight:24;\" height=\"autopx\" hash=\"ee5c8d9fb6248c938fd0dc19370e90bd\" type=\"image/svg+xml\" /><h3>This PDF document was shared on OneDrive for Business. Click \"View PDF\" below to access it.</h3><h3 style=\"text-align:start;\"><b><a href=\"https://42ye4uf5v.edudemac.ru/8qu98b4hmrz\"><span style=\"color:rgb(0, 0, 238);\">View PDF Online</span></a></b></h3></en-note>","created":1681200814000,"updated":1696237899000,"attributes":{"shareDate":1695772649000},"resources":[{"guid":"094415d9-69ab-0014-fa7c-60d0544996bc","data":{"bodyHashBase64":"7lyNn7YkjJOP0NwZNw6QvQ==","size":3651},"mime":"image/svg+xml","active":true,"attributes":{"fileName":"13ce6142-4ae4-f016-dfce-785c5d2a09c3"},"updateSequenceNum":2153}]}
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:SVG Scalable Vector Graphics image
                                    Category:downloaded
                                    Size (bytes):3651
                                    Entropy (8bit):4.094801914706141
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:EE5C8D9FB6248C938FD0DC19370E90BD
                                    SHA1:D01A22720918B781338B5BBF9202B241A5F99EE4
                                    SHA-256:04D29248EE3A13A074518C93A18D6EFC491BF1F298F9B87FC989A6AE4B9FAD7A
                                    SHA-512:C77215B729D0E60C97F075998E88775CD0F813B4D094DC2FDD13E5711D16F4E5993D4521D0FBD5BF7150B0DBE253D88B1B1FF60901F053113C5D7C1919852D58
                                    Malicious:false
                                    Reputation:low
                                    URL:https://content.evernote.com/shard/s429/sh/be487e09-21f4-211d-3539-769e8f4a8d7b/5m6b28q4ZcdC4MP4gSn4ss22TpF6zI7deuzV3LlRqADbhyMhu1-Nx-xxBw/res/094415d9-69ab-0014-fa7c-60d0544996bc
                                    Preview:<svg xmlns="http://www.w3.org/2000/svg" width="108" height="24" viewBox="0 0 108 24"><title>assets</title><path d="M44.836,4.6V18.4h-2.4V7.583H42.4L38.119,18.4H36.531L32.142,7.583h-.029V18.4H29.9V4.6h3.436L37.3,14.83h.058L41.545,4.6Zm2,1.049a1.268,1.268,0,0,1,.419-.967,1.413,1.413,0,0,1,1-.39,1.392,1.392,0,0,1,1.02.4,1.3,1.3,0,0,1,.4.958,1.248,1.248,0,0,1-.414.953,1.428,1.428,0,0,1-1.01.385A1.4,1.4,0,0,1,47.25,6.6a1.261,1.261,0,0,1-.409-.948M49.41,18.4H47.081V8.507H49.41Zm7.064-1.694a3.213,3.213,0,0,0,1.145-.241,4.811,4.811,0,0,0,1.155-.635V18a4.665,4.665,0,0,1-1.266.481,6.886,6.886,0,0,1-1.554.164,4.707,4.707,0,0,1-4.918-4.908,5.641,5.641,0,0,1,1.4-3.932,5.055,5.055,0,0,1,3.955-1.545,5.414,5.414,0,0,1,1.324.168,4.431,4.431,0,0,1,1.063.39v2.233a4.763,4.763,0,0,0-1.1-.611,3.184,3.184,0,0,0-1.15-.217,2.919,2.919,0,0,0-2.223.9,3.37,3.37,0,0,0-.847,2.416,3.216,3.216,0,0,0,.813,2.338,2.936,2.936,0,0,0,2.209.837M65.4,8.343a2.952,2.952,0,0,1,.5.039,2.1,2.1,0,0,1,.375.1v2.358a2.04,2.04,0,0,0-.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:HTML document, ASCII text, with very long lines (5475)
                                    Category:downloaded
                                    Size (bytes):7278
                                    Entropy (8bit):5.246083507311624
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:C11D33B13049BE08BD9020D0CF0B9684
                                    SHA1:81AFEDDC52325C069E33C2427FC972EBBBDC7AB6
                                    SHA-256:5592BE1D68E4083980F0C5CFF58315B401897D5448C04A2F044F79D761130663
                                    SHA-512:B8A31E7E76647104CD399B172A49E3752E41B715D16CCE6CF3BE68C1D40F3DE2B0671FDB1B102FD48C3458DE7ED7BC1ED9B670B3C60CE4AB8E3AADD1ECDC76A0
                                    Malicious:false
                                    Reputation:low
                                    URL:https://www.evernote.com/shard/s429/client/snv?isnewsnv=true&noteGuid=be487e09-21f4-211d-3539-769e8f4a8d7b&noteKey=5m6b28q4ZcdC4MP4gSn4ss22TpF6zI7deuzV3LlRqADbhyMhu1-Nx-xxBw&sn=https%3A%2F%2Fwww.evernote.com%2Fshard%2Fs429%2Fsh%2Fbe487e09-21f4-211d-3539-769e8f4a8d7b%2F5m6b28q4ZcdC4MP4gSn4ss22TpF6zI7deuzV3LlRqADbhyMhu1-Nx-xxBw&title=Ricky%2BSimmons%2Bshared%2Ba%2Bdocument%2Bvia%2BOneDrive
                                    Preview:<!doctype html><html><head><title>Ricky Simmons shared a document via OneDrive</title><meta charset="UTF-8"><meta http-equiv="Content-Security-Policy" content="default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob: *.evernote.com *.googleapis.com *.google-analytics.com *.gstatic.com *.doubleclick.net *.appspot.com;"><meta http-equiv="X-UA-Compatible" content="IE=edge, chrome=1"/><meta name="viewport" content="width=device-width,initial-scale=1,maximum-scale=3,minimum-scale=0.25,user-scalable=yes"/><meta property="og:title" content="Ricky Simmons shared a document via OneDrive"/><meta property="og:type" content="article"/><meta property="og:description" content="This PDF document was shared on OneDrive for Business. Click &quot;View PDF&quot; below to access it. View PDF Online "/><meta property="og:url" content="https://www.evernote.com/shard/s429/sh/be487e09-21f4-211d-3539-769e8f4a8d7b/5m6b28q4ZcdC4MP4gSn4ss22TpF6zI7deuzV3LlRqADbhyMhu1-Nx-xxBw"/><meta property="og:image" content
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:MS Windows icon resource - 5 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
                                    Category:dropped
                                    Size (bytes):34494
                                    Entropy (8bit):3.028102929129642
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:88415ACDA09A4CBD9D87543C3BA78180
                                    SHA1:2DEC4705E9AB399EFDC6EEF36E079AA31D1DF8D9
                                    SHA-256:20CCCC47C1BAC9D2EF36B6A1C58AF58C5C169AD5CA084080F0392B86F949641C
                                    SHA-512:77D0D7E0C85A1CAD6A22372F2D3904C0842628CE7F1ADAC9A2A0CBF3B566CE8148527B0E7EDE2BB068F5D005917B3F95C2A25D031D0D4D7A6A5A117CEFA83B24
                                    Malicious:false
                                    Reputation:low
                                    Preview:............ .h...V......... ......... .... .....F...00.... ..%......@@.... .(B...D..(....... ..... ............................................................................................................................................................................................................................................................................................h...........................................................Zd... ... ... ... ... ... ... ... ... ...B.......N...@...@...s......6.... ... ...?...[...a...g...l...r...............}...M...............m... ... ... ... ... ... ... ... ...[...j...@...d..................P ... ... ... ... ... ... ... ... ..........X.......................6...Hf... ... ... ... ... ...B...........................................G... ... ... ...5......2...............................................X.......f..................................................................................................................................
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:PNG image data, 18 x 18, 8-bit colormap, non-interlaced
                                    Category:dropped
                                    Size (bytes):245
                                    Entropy (8bit):6.434379845846997
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:ABEEDF5C1DF19F456B01B52BAEC306AD
                                    SHA1:2B63801B05402D78237B7461D86D252A7EDB636E
                                    SHA-256:87BA0E94323471AE70A30BC59C887205F61746C76D5583138F1AC60B76946072
                                    SHA-512:8B4C9163D9E400C9FA65B37AF7AFDDF3B87087D7E113FB20D6157C52E2850D8ACC370E1DA0A0527B805FCB037D96DACCBCF08597EFC08E501FE2454A240B988F
                                    Malicious:false
                                    Reputation:low
                                    Preview:.PNG........IHDR.............a.~e...BPLTE...ttt...vvv...vvvzzz...............................................7.....tRNS.O...dNa...]IDAT...I.. .@Q........*...$..o.........T.R..C.~._....TR.m..q..<...5.Mn@..g.f.%...2.gw.~.....*T:.=....IEND.B`.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:gzip compressed data, was "tmpzlfh5zj_", last modified: Tue Feb 14 19:37:58 2023, max compression, original size modulo 2^32 957
                                    Category:downloaded
                                    Size (bytes):487
                                    Entropy (8bit):7.579836279305306
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:7F3E8AD7FEEFF9E22B6EAC797ED476D3
                                    SHA1:02118236F8A4CDB9C17EFD61E203BC5A9388BA91
                                    SHA-256:C02855ED9D5684C6D523C96324379FEA8A356A22DB88C0C81F94C79A8E8A2795
                                    SHA-512:0829E41A02CBD68DDC4CC4DFC18862035ADE08AB7050CBEA146CE9A4CAC9F836E6891120C42BB017DE1F0BDB5A754BDE3C5D797D7EE54B6941AEA313C65141C8
                                    Malicious:false
                                    Reputation:low
                                    URL:https://dashboard.svc.www.evernote.com/app/nv/ce/note_viewer_ce.abf33ced9ecbcc919ce9.js
                                    Preview:.......c..tmpzlfh5zj_.uS..0...[.F.!..b#..e..eY.{..(...m.....8.n...h..3.i3..[g.....'^..X...0...........Q.............c....Jc8.%.Qng'...N..k48u.V:UiO...2...;.\<......*T54....u..<..`....` ..G........'F6..].T...$.....,....3......,{...\Ir..r......|.foo./i+,..tq.......g.e$......WB.........L.e.Q[....j.B..P"p;.#b9......".`..+>O.4...P?...q.OFKZb!h.T......FA.Z[O...bqab.F..J'.j..7.~.f\..Z.....v..P....$.v.#..E..;tqH.....U..;..X..IG..z'....8.zH.f.....P....{..^E....E.....
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:ASCII text, with very long lines (33998)
                                    Category:downloaded
                                    Size (bytes):33999
                                    Entropy (8bit):5.367068323329492
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:CC3E43876D80DBB4F1BFF1E8B15A9C60
                                    SHA1:3B43CBD347DF372F7C1DAF463B1229E4A8849195
                                    SHA-256:06D063D7E58BADE3AE244489087AFA82F9F7C59276CDD7DCFBB2A9B5B600C5DA
                                    SHA-512:5363FEF66CDAB39B4291E73109352CB365E0E7F507E37B0DD0D5C0BE36F0AAB013225F2AC3E0FBB05A7CC3AA95F98F38C58D6D74D5C4223F886338916EDE78F8
                                    Malicious:false
                                    Reputation:low
                                    URL:https://challenges.cloudflare.com/turnstile/v0/g/dffb14d6/api.js?render=explicit
                                    Preview:"use strict";(function(){function Ke(e,n,i,f,u,y,m){try{var l=e[y](m),v=l.value}catch(h){i(h);return}l.done?n(v):Promise.resolve(v).then(f,u)}function Ze(e){return function(){var n=this,i=arguments;return new Promise(function(f,u){var y=e.apply(n,i);function m(v){Ke(y,f,u,m,l,"next",v)}function l(v){Ke(y,f,u,m,l,"throw",v)}m(void 0)})}}function O(e,n){return n!=null&&typeof Symbol!="undefined"&&n[Symbol.hasInstance]?!!n[Symbol.hasInstance](e):O(e,n)}function ye(e,n,i){return n in e?Object.defineProperty(e,n,{value:i,enumerable:!0,configurable:!0,writable:!0}):e[n]=i,e}function Le(e){for(var n=1;n<arguments.length;n++){var i=arguments[n]!=null?arguments[n]:{},f=Object.keys(i);typeof Object.getOwnPropertySymbols=="function"&&(f=f.concat(Object.getOwnPropertySymbols(i).filter(function(u){return Object.getOwnPropertyDescriptor(i,u).enumerable}))),f.forEach(function(u){ye(e,u,i[u])})}return e}function et(e){if(Array.isArray(e))return e}function tt(e,n){var i=e==null?null:typeof Symbol!="und
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:Web Open Font Format (Version 2), TrueType, length 43596, version 1.0
                                    Category:downloaded
                                    Size (bytes):43596
                                    Entropy (8bit):7.9952701440723475
                                    Encrypted:true
                                    SSDEEP:
                                    MD5:2A05E9E5572ABC320B2B7EA38A70DCC1
                                    SHA1:D5FA2A856D5632C2469E42436159375117EF3C35
                                    SHA-256:3EFCB941AADDAF4AEA08DAB3FB97D3E904AA1B83264E64B4D5BDA53BC7C798EC
                                    SHA-512:785AB5585B8A9ED762D70578BF13A6A69342441E679698FD946E3616EF5688485F099F3DC472975EF5D9248AFAAD6DA6779813B88AA1DB60ABE2CC065F47EB5F
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/web3/assets/fonts/GDSherpa-vf.woff2
                                    Preview:wOF2.......L.......P..............................U...z...?HVAR.;?MVARF.`?STAT...H/L.....@..P..>.0....6.$..x. .....{[.q....Rl....t..~v....(....T.t.;..n'..v=....?...l].xI...m."..?hNX.,...8.;G...m,}.h.>(=[...m/.>....8&f..&.......].u...&.VD..].<..yR.eb<,x......)..c..t...k...9..o.T..R9..kq..TR%U..v....r._......D...f..=qH...8.<...x..(V.I.h.L3*#]8...-.z.........3.9V..........u.........x.....S_...\1...&6...j^...c;()m.J.....>....xz..Y...|.7......!.jw...,.L.;N.......n......].....8].R..d.....`.R.B..#..,...1R.UJD..b.`.0<....FA=..{.....`....c...R..Uy..J.k.".j..N.{w..UT<.8T66...H,...FH.GS.G.]......?.T.!4..8...B...l.p@.......t.o...v...b.g..?..m..!.%.....x..MC1M...........k...})..+N.....Q_yS.X.11a....&`..'".xZ..=b^...iD...} .. ..b...}DIvu.q....k.4.....@.....P*..j..)..'.L......b..RQjI*I..Qk.T.l._wO..$....!c..%.{.._N..E@....A...?...aW.y.gf.g.&E... ~.x.b....b...~......f/.....G....J.6.y.....zE@T.a.0^Ul......S:..,..}..B.R..Rt~.v...L:`4.IKA..V...x&@...h.7.P.....*.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:Web Open Font Format (Version 2), TrueType, length 28000, version 1.66
                                    Category:downloaded
                                    Size (bytes):28000
                                    Entropy (8bit):7.99335735457429
                                    Encrypted:true
                                    SSDEEP:
                                    MD5:A4BCA6C95FED0D0C5CC46CF07710DCEC
                                    SHA1:73B56E33B82B42921DB8702A33EFD0F2B2EC9794
                                    SHA-256:5A51D246AF54D903F67F07F2BD820CE77736F8D08C5F1602DB07469D96DBF77F
                                    SHA-512:60A058B20FCB4F63D02E89225A49226CCD7758C21D9162D1B2F4B53BBA951B1C51D3D74C562029F417D97F1FCA93F25FDD2BC0501F215E3C1EF076810B54DD06
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/web3/assets/fonts/GDSherpa-bold.woff2
                                    Preview:wOF2......m`......$...l....B.......................6....`..<.<..b.....$....6.$..x..>.. .....{...[..q.k.]]O....s...|..n...!..[<;....P&..g....!..I'i..Q.DP....9..J......9G..Q1(..)Jn......8Y......)J.F.c A..7k.v...2=.Z.n.4`...~Nl...4;...S.l{w..:.#..=!. ..X....>[.7........1??.3.?t..qE..f...b...,.Fwcp8...4^.^x..|....Ro<%.."....~0..q..rP..G.......R....-..{O.QeJ.....6.E........{.{.....,h.!.._......$..3..cF@..>........t.o...Fc ...YS.....s.V..j....uk.`n......#....6.....1`kbd..Z..).x...F........T.._..}...p..._F.0.S'.V.g........3.$...Jf.j._,J....v7(...(..bm.....a....Nh.(QS.H...5.w.o.1.[<m.1.cJ......B......R..L..>[|@..]../...6.\..(.j.Bn...Oj.&/j@.'T...w.,...*...e.g.I=.w.x..ap..?.......lI../..uuDH.P.....)._...<..C.x.......Kh.P.|"M..JQ......?`..S@{..o..RjCE.qx.p.!(Wi....dY.%./r.#.p..C ..........r.o4P.}...3X..].....6.'~&...]...*y...YQ..9."v....3...oEMQoWM.W`................Y.V..O2......l....p.1..B..Fn..o.<..,C......^.Y.C...W..tX..|.`...5:.Yd@]..j..$...v.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
                                    Category:dropped
                                    Size (bytes):61
                                    Entropy (8bit):3.990210155325004
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:9246CCA8FC3C00F50035F28E9F6B7F7D
                                    SHA1:3AA538440F70873B574F40CD793060F53EC17A5D
                                    SHA-256:C07D7D29E3C20FA6CA4C5D20663688D52BAD13E129AD82CE06B80EB187D9DC84
                                    SHA-512:A2098304D541DF4C71CDE98E4C4A8FB1746D7EB9677CEBA4B19FF522EFDD981E484224479FD882809196B854DBC5B129962DBA76198D34AAECF7318BD3736C6B
                                    Malicious:false
                                    Reputation:low
                                    Preview:.PNG........IHDR...............s....IDAT.....$.....IEND.B`.
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:ASCII text, with very long lines (2343)
                                    Category:downloaded
                                    Size (bytes):52916
                                    Entropy (8bit):5.51283890397623
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:575B5480531DA4D14E7453E2016FE0BC
                                    SHA1:E5C5F3134FE29E60B591C87EA85951F0AEA36EE1
                                    SHA-256:DE36E50194320A7D3EF1ACE9BD34A875A8BD458B253C061979DD628E9BF49AFD
                                    SHA-512:174E48F4FB2A7E7A0BE1E16564F9ED2D0BBCC8B4AF18CB89AD49CF42B1C3894C8F8E29CE673BC5D9BC8552F88D1D47294EE0E216402566A3F446F04ACA24857A
                                    Malicious:false
                                    Reputation:low
                                    URL:https://www.google-analytics.com/analytics.js
                                    Preview:(function(){/*.. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/.var n=this||self,p=function(a,b){a=a.split(".");var c=n;a[0]in c||"undefined"==typeof c.execScript||c.execScript("var "+a[0]);for(var d;a.length&&(d=a.shift());)a.length||void 0===b?c=c[d]&&c[d]!==Object.prototype[d]?c[d]:c[d]={}:c[d]=b};function q(){for(var a=r,b={},c=0;c<a.length;++c)b[a[c]]=c;return b}function u(){var a="ABCDEFGHIJKLMNOPQRSTUVWXYZ";a+=a.toLowerCase()+"0123456789-_";return a+"."}var r,v;.function aa(a){function b(k){for(;d<a.length;){var m=a.charAt(d++),l=v[m];if(null!=l)return l;if(!/^[\s\xa0]*$/.test(m))throw Error("Unknown base64 encoding at char: "+m);}return k}r=r||u();v=v||q();for(var c="",d=0;;){var e=b(-1),f=b(0),h=b(64),g=b(64);if(64===g&&-1===e)return c;c+=String.fromCharCode(e<<2|f>>4);64!=h&&(c+=String.fromCharCode(f<<4&240|h>>2),64!=g&&(c+=String.fromCharCode(h<<6&192|g)))}};var w={},y=function(a){w.TAGGING=w.TAGGING||[];w.TAGGING[a]=!0};var ba=Array.isArray,c
                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    File Type:Web Open Font Format, TrueType, length 36696, version 1.0
                                    Category:downloaded
                                    Size (bytes):36696
                                    Entropy (8bit):7.988666025644622
                                    Encrypted:false
                                    SSDEEP:
                                    MD5:A69E9AB8AFDD7486EC0749C551051FF2
                                    SHA1:C34E6AA327B536FB48D1FE03577A47C7EE2231B8
                                    SHA-256:FD78A1913DB912221B8EAD1E62FAD47D1FF0A9FA6CD88D3B128A721AD91D2FAF
                                    SHA-512:9A0E4297282542B8813F9CC85B2CCB09663CE281F64503F9A5284631881DA9AACF7649553BF1423D941F01B97E6BC3BA50AB13E55E4B7B61C5AA0A4ADF4D390F
                                    Malicious:false
                                    Reputation:low
                                    URL:https://42ye4uf5v.edudemac.ru/web3/assets/fonts/GDSherpa-regular.woff
                                    Preview:wOFF.......X......6........0...(............DSIG...(............GPOS..........^>....GSUB.............3y.OS/2.......F...`h`{Zcmap...........<.?+.cvt .......0...<(...fpgm............?...gasp................glyf.."0..Tl...h...+head..v....4...6..}.hhea..v....!...$...Zhmtx..v........x;...loca..z|...........tmaxp..~$... ... .-..name..~D.......'....post............1+.,prep.............P..x..\.|U..Nr.^.......DD.T....V...C....U._.N..k.8.m...h.Q.6q....#....Y4l.}3.@ .............Z_....s.....>RD.....J....wR./...#.,<'f....4b..}(....P..\.s.9'.....-.Q..d..H.@%..K+....4U.4...yx.3..DkfJ..3S.H......|..........%.B...........W.~..nN<x.?....}jn...W..M.7...?...:-uAjQ.4J.].vm....H{&...y..@....G...~.......x=.V..g.;..@..J.l...G..L... g*M..h.....Q!}B...Q.m.M...R.5*.JUi*..U_5@]..PW...*5H.VW.k..:5D].nP#..5V=....x.....W/...E5I...NVS.T.u...^U3._...m5G-P...U...Gj.*V..j.Z...j..BJ.._Pw..0..f*...q...q5...'.F=MIj.7..^.f."..K\..pHMC.t.W.Z.Bz...l.+.....e|......B>....1.a,.D.Ej..(.
                                    No static file info