Windows Analysis Report


General Information

Sample name:20399201011-2023.jpg.html
Analysis ID:1358193


Range:0 - 100


Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
HTML file submission containing password form
Creates files inside the system directory
Detected hidden input values containing email addresses (often used in phishing pages)
HTML body contains low number of good links
HTML body contains password input but no form action
HTML page contains hidden URLs or javascript code
HTML page contains obfuscate script src
HTML title does not match URL
None HTTPS page querying sensitive user data (password, username or email)
Stores files to the Windows start menu directory
Uses insecure TLS / SSL version for HTTPS connection


  • System is w10x64_ra
  • chrome.exe (PID: 5276 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\20399201011-2023.jpg.html MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6700 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2052,i,9912628921689900689,5546769601433557711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

AV Detection

Source: euunclaimedpymt.comVirustotal: Detection: 6%Perma Link
Source: 20399201011-2023.jpg.htmlVirustotal: Detection: 33%Perma Link
Source: 20399201011-2023.jpg.htmlHTTP Parser: s.eggers@stadtwerke-husum.de
Source: 20399201011-2023.jpg.htmlHTTP Parser: Number of links: 0
Source: file:///C:/Users/user/Desktop/20399201011-2023.jpg.htmlHTTP Parser: Number of links: 0
Source: 20399201011-2023.jpg.htmlHTTP Parser: <input type="password" .../> found but no <form action="...
Source: file:///C:/Users/user/Desktop/20399201011-2023.jpg.htmlHTTP Parser: <input type="password" .../> found but no <form action="...
Source: 20399201011-2023.jpg.htmlHTTP Parser: Base64 decoded: var tnk = $("#tnk").val();$(document).bind('keydown', function(e) {if(e.ctrlKey && (e.which == 83)) {e.preventDefault();return false;}});document.addEventListener('contextmenu', event => event.preventDefault());document.onkeydown = funct...
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJCXZhciBkb2MgPSBkb2N1bWVudC5kb2N1bWVudEVsZW1lbnQ7CgkJCWRvYy5zZXRBdHRyaWJ1dGUoICdkYXRhLXVzZXJhZ2VudCcsIG5hdmlnYXRvci51c2VyQWdlbnQgKTsKCQk=
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gxIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gwIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gyIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,Ci8qIDwhW0NEQVRBWyAqLwoidXNlIHN0cmljdCI7dmFyIF9jcmVhdGVDbGFzcz1mdW5jdGlvbigpe2Z1bmN0aW9uIGRlZmluZVByb3BlcnRpZXModGFyZ2V0LHByb3BzKXtmb3IodmFyIGk9MDtpPHByb3BzLmxlbmd0aDtpKyspe3ZhciBkZXNjcmlwdG9yPXByb3BzW2ldO2Rlc2NyaXB0b3IuZW
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,Ci8qIDwhW0NEQVRBWyAqLwooZnVuY3Rpb24oKSB7CiJ1c2Ugc3RyaWN0Ijt2YXIgcj0iZnVuY3Rpb24iPT10eXBlb2YgU3ltYm9sJiYic3ltYm9sIj09dHlwZW9mIFN5bWJvbC5pdGVyYXRvcj9mdW5jdGlvbihlKXtyZXR1cm4gdHlwZW9mIGV9OmZ1bmN0aW9uKGUpe3JldHVybiBlJiYiZnVuY3
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJCXZhciBkb2MgPSBkb2N1bWVudC5kb2N1bWVudEVsZW1lbnQ7CgkJCWRvYy5zZXRBdHRyaWJ1dGUoICdkYXRhLXVzZXJhZ2VudCcsIG5hdmlnYXRvci51c2VyQWdlbnQgKTsKCQk=
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gxIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gwIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gyIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,Ci8qIDwhW0NEQVRBWyAqLwoidXNlIHN0cmljdCI7dmFyIF9jcmVhdGVDbGFzcz1mdW5jdGlvbigpe2Z1bmN0aW9uIGRlZmluZVByb3BlcnRpZXModGFyZ2V0LHByb3BzKXtmb3IodmFyIGk9MDtpPHByb3BzLmxlbmd0aDtpKyspe3ZhciBkZXNjcmlwdG9yPXByb3BzW2ldO2Rlc2NyaXB0b3IuZW
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,Ci8qIDwhW0NEQVRBWyAqLwooZnVuY3Rpb24oKSB7CiJ1c2Ugc3RyaWN0Ijt2YXIgcj0iZnVuY3Rpb24iPT10eXBlb2YgU3ltYm9sJiYic3ltYm9sIj09dHlwZW9mIFN5bWJvbC5pdGVyYXRvcj9mdW5jdGlvbihlKXtyZXR1cm4gdHlwZW9mIGV9OmZ1bmN0aW9uKGUpe3JldHVybiBlJiYiZnVuY3
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJCXZhciBkb2MgPSBkb2N1bWVudC5kb2N1bWVudEVsZW1lbnQ7CgkJCWRvYy5zZXRBdHRyaWJ1dGUoICdkYXRhLXVzZXJhZ2VudCcsIG5hdmlnYXRvci51c2VyQWdlbnQgKTsKCQk=
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gxIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gwIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gyIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,Ci8qIDwhW0NEQVRBWyAqLwoidXNlIHN0cmljdCI7dmFyIF9jcmVhdGVDbGFzcz1mdW5jdGlvbigpe2Z1bmN0aW9uIGRlZmluZVByb3BlcnRpZXModGFyZ2V0LHByb3BzKXtmb3IodmFyIGk9MDtpPHByb3BzLmxlbmd0aDtpKyspe3ZhciBkZXNjcmlwdG9yPXByb3BzW2ldO2Rlc2NyaXB0b3IuZW
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,Ci8qIDwhW0NEQVRBWyAqLwooZnVuY3Rpb24oKSB7CiJ1c2Ugc3RyaWN0Ijt2YXIgcj0iZnVuY3Rpb24iPT10eXBlb2YgU3ltYm9sJiYic3ltYm9sIj09dHlwZW9mIFN5bWJvbC5pdGVyYXRvcj9mdW5jdGlvbihlKXtyZXR1cm4gdHlwZW9mIGV9OmZ1bmN0aW9uKGUpe3JldHVybiBlJiYiZnVuY3
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJCXZhciBkb2MgPSBkb2N1bWVudC5kb2N1bWVudEVsZW1lbnQ7CgkJCWRvYy5zZXRBdHRyaWJ1dGUoICdkYXRhLXVzZXJhZ2VudCcsIG5hdmlnYXRvci51c2VyQWdlbnQgKTsKCQk=
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gxIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gwIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gyIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,Ci8qIDwhW0NEQVRBWyAqLwoidXNlIHN0cmljdCI7dmFyIF9jcmVhdGVDbGFzcz1mdW5jdGlvbigpe2Z1bmN0aW9uIGRlZmluZVByb3BlcnRpZXModGFyZ2V0LHByb3BzKXtmb3IodmFyIGk9MDtpPHByb3BzLmxlbmd0aDtpKyspe3ZhciBkZXNjcmlwdG9yPXByb3BzW2ldO2Rlc2NyaXB0b3IuZW
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,Ci8qIDwhW0NEQVRBWyAqLwooZnVuY3Rpb24oKSB7CiJ1c2Ugc3RyaWN0Ijt2YXIgcj0iZnVuY3Rpb24iPT10eXBlb2YgU3ltYm9sJiYic3ltYm9sIj09dHlwZW9mIFN5bWJvbC5pdGVyYXRvcj9mdW5jdGlvbihlKXtyZXR1cm4gdHlwZW9mIGV9OmZ1bmN0aW9uKGUpe3JldHVybiBlJiYiZnVuY3
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJCXZhciBkb2MgPSBkb2N1bWVudC5kb2N1bWVudEVsZW1lbnQ7CgkJCWRvYy5zZXRBdHRyaWJ1dGUoICdkYXRhLXVzZXJhZ2VudCcsIG5hdmlnYXRvci51c2VyQWdlbnQgKTsKCQk=
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gxIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gwIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gyIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,Ci8qIDwhW0NEQVRBWyAqLwoidXNlIHN0cmljdCI7dmFyIF9jcmVhdGVDbGFzcz1mdW5jdGlvbigpe2Z1bmN0aW9uIGRlZmluZVByb3BlcnRpZXModGFyZ2V0LHByb3BzKXtmb3IodmFyIGk9MDtpPHByb3BzLmxlbmd0aDtpKyspe3ZhciBkZXNjcmlwdG9yPXByb3BzW2ldO2Rlc2NyaXB0b3IuZW
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,Ci8qIDwhW0NEQVRBWyAqLwooZnVuY3Rpb24oKSB7CiJ1c2Ugc3RyaWN0Ijt2YXIgcj0iZnVuY3Rpb24iPT10eXBlb2YgU3ltYm9sJiYic3ltYm9sIj09dHlwZW9mIFN5bWJvbC5pdGVyYXRvcj9mdW5jdGlvbihlKXtyZXR1cm4gdHlwZW9mIGV9OmZ1bmN0aW9uKGUpe3JldHVybiBlJiYiZnVuY3
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJCXZhciBkb2MgPSBkb2N1bWVudC5kb2N1bWVudEVsZW1lbnQ7CgkJCWRvYy5zZXRBdHRyaWJ1dGUoICdkYXRhLXVzZXJhZ2VudCcsIG5hdmlnYXRvci51c2VyQWdlbnQgKTsKCQk=
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gxIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gwIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,CgkJKGZ1bmN0aW9uKCQpIHsKCgkJCSQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCkgewoKCQkJCSQoIiNtaW9fY2FsY19ib3gyIC50YWJzLWNvbnRlbnQgLnR5cGUgYSIpLmNsaWNrKCBmdW5jdGlvbiAoKSB7CgkJCQkJdmFyIHRhYkNvbnRlbnQgPSAkKHRoaXMpLmF0dHIoJ2hyZWYnKTsKCQ
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,Ci8qIDwhW0NEQVRBWyAqLwoidXNlIHN0cmljdCI7dmFyIF9jcmVhdGVDbGFzcz1mdW5jdGlvbigpe2Z1bmN0aW9uIGRlZmluZVByb3BlcnRpZXModGFyZ2V0LHByb3BzKXtmb3IodmFyIGk9MDtpPHByb3BzLmxlbmd0aDtpKyspe3ZhciBkZXNjcmlwdG9yPXByb3BzW2ldO2Rlc2NyaXB0b3IuZW
Source: https://www.stadtwerke-husum.de/HTTP Parser: Script src: data:text/javascript;base64,Ci8qIDwhW0NEQVRBWyAqLwooZnVuY3Rpb24oKSB7CiJ1c2Ugc3RyaWN0Ijt2YXIgcj0iZnVuY3Rpb24iPT10eXBlb2YgU3ltYm9sJiYic3ltYm9sIj09dHlwZW9mIFN5bWJvbC5pdGVyYXRvcj9mdW5jdGlvbihlKXtyZXR1cm4gdHlwZW9mIGV9OmZ1bmN0aW9uKGUpe3JldHVybiBlJiYiZnVuY3
Source: 20399201011-2023.jpg.htmlHTTP Parser: Title: PDF | stadtwerke-husum.de Document Previewer does not match URL
Source: file:///C:/Users/user/Desktop/20399201011-2023.jpg.htmlHTTP Parser: Title: PDF | stadtwerke-husum.de Document Previewer does not match URL
Source: file:///C:/Users/user/Desktop/20399201011-2023.jpg.htmlHTTP Parser: Has password / email / username input fields
Source: 20399201011-2023.jpg.htmlHTTP Parser: <input type="password" .../> found
Source: file:///C:/Users/user/Desktop/20399201011-2023.jpg.htmlHTTP Parser: <input type="password" .../> found
Source: 20399201011-2023.jpg.htmlHTTP Parser: No favicon
Source: file:///C:/Users/user/Desktop/20399201011-2023.jpg.htmlHTTP Parser: No favicon
Source: file:///C:/Users/user/Desktop/20399201011-2023.jpg.htmlHTTP Parser: No favicon
Source: 20399201011-2023.jpg.htmlHTTP Parser: No <meta name="author".. found
Source: file:///C:/Users/user/Desktop/20399201011-2023.jpg.htmlHTTP Parser: No <meta name="author".. found
Source: file:///C:/Users/user/Desktop/20399201011-2023.jpg.htmlHTTP Parser: No <meta name="author".. found
Source: 20399201011-2023.jpg.htmlHTTP Parser: No <meta name="copyright".. found
Source: file:///C:/Users/user/Desktop/20399201011-2023.jpg.htmlHTTP Parser: No <meta name="copyright".. found
Source: file:///C:/Users/user/Desktop/20399201011-2023.jpg.htmlHTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: -> version: TLS 1.0
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: chrome.exeMemory has grown: Private usage: 0MB later: 29MB
Source: unknownHTTPS traffic detected: -> version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownUDP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownTCP traffic detected without corresponding DNS query:
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: unknownHTTPS traffic detected: -> version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_5276_1323492214
Source: classification engineClassification label: mal60.phis.winHTML@17/6@26/148
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: 20399201011-2023.jpg.htmlVirustotal: Detection: 33%
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\20399201011-2023.jpg.html
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2052,i,9912628921689900689,5546769601433557711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2052,i,9912628921689900689,5546769601433557711,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk

Stealing of Sensitive Information

Source: file:///C:/Users/user/Desktop/20399201011-2023.jpg.htmlHTTP Parser: file:///C:/Users/user/Desktop/20399201011-2023.jpg.html
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
Valid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
Encrypted Channel
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Non-Application Layer Protocol
SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
Domain AccountsAtLogon Script (Windows)1
Extra Window Memory Injection
Extra Window Memory Injection
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
Application Layer Protocol
Data Encrypted for ImpactDNS ServerEmail Addresses

file:///C:/Users/user/Desktop/20399201011-2023.jpg.html0%Avira URL Cloudsafe
about:blank0%Avira URL Cloudsafe
                • Avira URL Cloud: safe
                • Avira URL Cloud: safe
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    unknownUnited States
                    i.gyazo.comUnited States
                    unknownUnited States
                    unknownUnited States
                    unknownUnited States
                    unknownUnited States
                    unknownUnited States
                    code.jquery.comUnited States
                    clients.l.google.comUnited States
                    www.google.comUnited States
                    euunclaimedpymt.comCroatia (LOCAL Name: Hrvatska)
                    accounts.google.comUnited States
                    Joe Sandbox version:38.0.0 Ammolite
                    Analysis ID:1358193
                    Start date and time:2023-12-11 10:05:56 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:defaultwindowsinteractivecookbook.jbs
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:8
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    • EGA enabled
                    Analysis Mode:stream
                    Analysis stop reason:Timeout
                    Sample name:20399201011-2023.jpg.html
                    Cookbook Comments:
                    • Found application associated with file extension: .html
                    • Exclude process from analysis (whitelisted): dllhost.exe
                    • Excluded IPs from analysis (whitelisted):,
                    • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, clientservices.googleapis.com
                    • Not all processes where analyzed, report is missing behavior information
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Dec 11 08:06:26 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Size (bytes):2673
                    Entropy (8bit):3.98644084550774
                    Preview:L..................F.@.. ...$+.,....)W0R.,..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.W.H....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.>......CW.V.W.H....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.W.H....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.W.H..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.W.H...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............|.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Dec 11 08:06:26 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Size (bytes):2675
                    Entropy (8bit):4.002133647909013
                    Preview:L..................F.@.. ...$+.,....l/'R.,..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.W.H....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.>......CW.V.W.H....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.W.H....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.W.H..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.W.H...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............|.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Size (bytes):2689
                    Entropy (8bit):4.0134454624335545
                    Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.W.H....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.>......CW.V.W.H....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.W.H....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.W.H..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............|.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Dec 11 08:06:26 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Size (bytes):2677
                    Entropy (8bit):4.002066578043301
                    Preview:L..................F.@.. ...$+.,......#R.,..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.W.H....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.>......CW.V.W.H....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.W.H....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.W.H..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.W.H...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............|.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Dec 11 08:06:26 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Size (bytes):2677
                    Entropy (8bit):3.990966348385927
                    Preview:L..................F.@.. ...$+.,......,R.,..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.W.H....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.>......CW.V.W.H....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.W.H....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.W.H..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.W.H...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............|.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Dec 11 08:06:26 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                    Size (bytes):2679
                    Entropy (8bit):4.0015266579255515
                    Preview:L..................F.@.. ...$+.,....^..R.,..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.W.H....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.>......CW.V.W.H....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.W.H....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.W.H..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.W.H...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............|.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                    File type:HTML document, ISO-8859 text, with very long lines (3648), with CRLF line terminators
                    Entropy (8bit):5.943956448801516
                    • HyperText Markup Language (12001/1) 18.75%
                    • HyperText Markup Language (12001/1) 18.75%
                    • HyperText Markup Language (11501/1) 17.97%
                    • HyperText Markup Language (11501/1) 17.97%
                    • HyperText Markup Language (11001/1) 17.19%
                    File name:20399201011-2023.jpg.html
                    File size:9'142 bytes
                    File Content Preview:<html>..<head>...<meta name="viewport" content="width=device-width, initial-scale=1">...<meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1" />...<title>PDF | stadtwerke-husum.de Document Previewer</title>...<script src="https://code.jquery.com/j
                    Icon Hash:173149cccc490307