Windows
Analysis Report
https://web1.zixmail.net/s/e?b=mnbsf&
Overview
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64_ra
chrome.exe (PID: 6728 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// web1.zixma il.net/s/e ?b=mnbsf& MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA) chrome.exe (PID: 6052 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2044 --fi eld-trial- handle=195 6,i,162946 7971648793 0389,17745 4556211460 04636,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: |
Source: | Classification label: |
Source: | File created: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Window detected: |
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 11 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 2 Encrypted Channel | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Abuse Accessibility Features | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 1 Non-Application Layer Protocol | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 2 Application Layer Protocol | Data Encrypted for Impact | DNS Server | Email Addresses |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 142.250.138.84 | true | false | high | |
web1.zixmail.net | 63.71.15.50 | true | false | high | |
www.google.com | 142.250.114.106 | true | false | high | |
clients.l.google.com | 142.250.138.113 | true | false | high | |
clients1.google.com | unknown | unknown | false | high | |
clients2.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.251.116.100 | unknown | United States | 15169 | GOOGLEUS | false | |
1.1.1.1 | unknown | Australia | 13335 | CLOUDFLARENETUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
63.71.15.50 | web1.zixmail.net | United States | 13380 | ASN-CUSTUS | false | |
142.250.138.113 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.114.106 | www.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.138.94 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.115.94 | unknown | United States | 15169 | GOOGLEUS | false | |
142.251.116.95 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.138.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.14 |
192.168.2.18 |
Joe Sandbox version: | 38.0.0 Ammolite |
Analysis ID: | 1368993 |
Start date and time: | 2024-01-02 20:51:57 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://web1.zixmail.net/s/e?b=mnbsf& |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 5 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | stream |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean2.win@14/64@12/113 |
- Exclude process from analysis
(whitelisted): SIHClient.exe - Excluded IPs from analysis (wh
itelisted): 72.21.81.200, 142. 250.138.94, 34.104.35.123, 142 .251.116.95, 142.250.113.95, 1 42.250.114.95, 142.250.138.95, 142.250.115.95 - Excluded domains from analysis
(whitelisted): wildcardtlu.az ureedge.net, cdp-tlu-shim.traf ficmanager.net, edgedl.me.gvt1 .com, content-autofill.googlea pis.com, msedge.b.tlu.dl.deliv ery.mp.microsoft.com, clientse rvices.googleapis.com, wildcar dtlu.ec.azureedge.net, dns.msf tncsi.com, cs9.wpc.v0cdn.net - Not all processes where analyz
ed, report is missing behavior information
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.979162247943638 |
Encrypted: | false |
SSDEEP: | |
MD5: | 7834607A5E9B4D63258E46BE03D7BB33 |
SHA1: | 3E52981BD49FCBC1FC29CF90025816E5A8E6387D |
SHA-256: | 0AACC150CB9FB78CBABB603E6F54AA748213DC546D3361FC00140F06829A6724 |
SHA-512: | 76B91298A2C2FD0D77F3D16EE435F8E2919FA7F27D40A9538299CFF2D3E993710F00180C86978AFC048CE8693815F8CB4022358D87CB21414B3EEC75F3B9CA22 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.993388099895696 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5EB27CB39580137445F7E5EDB442BDDF |
SHA1: | 4F1B67E67386391A01CDE800215F8FD0C074A116 |
SHA-256: | DE34790017DFD6247CC0546BEA4897BCB390C4002002E1A0746AAFB563ADF76C |
SHA-512: | 96980A1A507CDB7D935D86429972B6A3ECE3B42289F18F6C02B107B8A7A614A19EC04D1367606104466AC67013EE2C5A75E2D8BF13DB348B6B89AB263E069909 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2691 |
Entropy (8bit): | 4.001880042340615 |
Encrypted: | false |
SSDEEP: | |
MD5: | A61EA5416EFE9643EC02EDAF64314749 |
SHA1: | 1DF7F701A667FFE4FFF053C51FF6E9E033A2138D |
SHA-256: | 301DBD9A602B7BAD8EF967A037B575C46614592EB134DF9804E7418649340EDF |
SHA-512: | 2DCB3B8D1C462BFA9A26E48259BF7F7BB6B1B5B44E7760C3CA62DD853D5CC6963F1B1072EB3D5D3F577813FD4D597C1F1E40102AD9DC491FD8F103DE47C5E12A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9906425988984164 |
Encrypted: | false |
SSDEEP: | |
MD5: | B269CFABA87E9E71E2B00B785A774F17 |
SHA1: | 074142DCE65DB117B7FCBFDFFA376A2B1ADFE29D |
SHA-256: | 9D7E23AB872601E12233275EA60CDEF6B69219A8379F7EBB93F65E223ACF22C2 |
SHA-512: | E72439AD873BB632780D8A266DFBEB3A36791E46E4735A21B393F00FBCE3036D2D1398CB4668B544F23A682F40488AA05728E82CDEA3727D81462AC57F12782B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9813439922308413 |
Encrypted: | false |
SSDEEP: | |
MD5: | C763448F57D7C7295CCC56A8F48E9012 |
SHA1: | 6B7CBACAD373D901CBA2BDA6FC00C00626623993 |
SHA-256: | 706635618767121F871669295C6FCEFBDC2A665E7E556FA9DD96382D7BA737A7 |
SHA-512: | F4ED3CCE1A27493AA3A764F9F94744B5DA9229D15ACC4DFB33C68BCD8ECCDD0941B619A7A6CF9172A07475F01488B05952B3014A471CFC15A626605713F934B8 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.990464153724291 |
Encrypted: | false |
SSDEEP: | |
MD5: | 043C2647CF6F4AB1EDACA6DF3F89EBD0 |
SHA1: | 5A2F0E416C4B2DC868CF9EC7AC65AA4DCFDFEDFE |
SHA-256: | 58CEB5C0AE6CD9540A686BEF5440F1013AB63C19450DD8FA799CE95A5C0FE289 |
SHA-512: | 8FC2DE1539FA5A5B6AD9DE246FC42C5CAE578F16C2B598C477E1EB2DBFCF78DF1787766A347D11D649D2F18EDF854A28D1E83FD48378AA25D4C6B3AF66BC855D |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2926 |
Entropy (8bit): | 6.839978812802928 |
Encrypted: | false |
SSDEEP: | |
MD5: | D48F93267419F13EE0F3A775FA48EE6A |
SHA1: | CD3924AB285A897E452054ADB8D187108BDD3824 |
SHA-256: | D674FFCC6A5CE458811EC06A6E5CBD2574D2C1FA9390E4CE55927187EF1E5C6C |
SHA-512: | 0CA798B19601BE00038956E17B89C7D8EED9F75B4F2F63D42C2EAEE41D37B2C67E9E977428B82E50B84B9EDC09C1DD55FA1A508EE4F1C905820B33E0DC410959 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/i/mnbsf/top_20160531_0714.gif |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 288580 |
Entropy (8bit): | 5.066983843372853 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2849239B95F5A9A2AEA3F6ED9420BB88 |
SHA1: | AF32F706407AB08F800C5E697CCE92466E735847 |
SHA-256: | 1FE2BB5390A75E5D61E72C107CAB528FC3C29A837D69AAB7D200E1DBB5DCD239 |
SHA-512: | 9FFE201D6DDAB4CDD0A9171B0A7E9EC26A7170B00719A0E3A4406EE3165DE3B3745B6A10FBAABBA1CDCF5ECB6B2585DC6CD535387750D53EE900FFA08B962EF2 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/REL-6.3.11-release.1.39489/scripts/jquery/jquery.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 109 |
Entropy (8bit): | 4.682630221661915 |
Encrypted: | false |
SSDEEP: | |
MD5: | 56A5BB37719239FD5EA38C789FBC0E39 |
SHA1: | 079B63878CBDA4DF4B9534257E36F3734D3B13BD |
SHA-256: | 5F180D55F25EAEBF710C3ADF71EEC2D704C42EAEA452AA3120126D873F281509 |
SHA-512: | 10DA22386141936B82350D0083FA4D1E42FF51D9DD7808FEE0963E6A05B2D4AA571AA82DBD4BC6C58FEDA9E6130BFD3F285FD58E7EFBB1F4C1266D22DC8E4F32 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/CON-566f38d3/mnbsf_stylesheet_mobile.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2795 |
Entropy (8bit): | 4.998137030841464 |
Encrypted: | false |
SSDEEP: | |
MD5: | EC2CE98C11C47F6E4FEC84470A74011D |
SHA1: | C3092CAB18EA755A164E1ADC888C9F0D17FBE097 |
SHA-256: | 9067BAB2250174B292E6970C58650C11096A29887FD47FB716355AEB50F8F0EF |
SHA-512: | E72AD9740358F9C93D3612BCD9CC91F3C084F02D4CA6CED4C7B89D3A887DA7C3FCAFEC23DD50FBFD656EC30E1749B5844A9E8B5A71D270B93D0891F20B0CAE96 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/CON-596d78f3/mnbsf_stylesheet.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3872 |
Entropy (8bit): | 5.46034012764402 |
Encrypted: | false |
SSDEEP: | |
MD5: | 1BB76B6E62A47BD8E54BAAF5DA382B78 |
SHA1: | EEEF314B661E68472400BBD9D477E86D77FCAAE5 |
SHA-256: | B0C0E3C8FCF8160433ADE6287C7022FE3E8AE2F9D473762238977712791629D2 |
SHA-512: | F4E1D3A6AFA901C23D779914DB5BB77D65C72EF8CE112BDCE098B874BBC072C168FF71C549A92C9B650A687A676290D53EE7ECF64A7540F111AC5BEE31BF0AA7 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/REL-6.3.11-release.1.39489/default_validatorconstants_en.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2552 |
Entropy (8bit): | 4.878673329767581 |
Encrypted: | false |
SSDEEP: | |
MD5: | 372E5E534B2F2DD81AD3647ACA4782D4 |
SHA1: | CFAFD72458521B6896D16B17F47C31B5B20009D2 |
SHA-256: | FE8E6E29FD6FF507EB4320931B53996D1D20EB33CB2A3BE0DBA694AF8796EE06 |
SHA-512: | CA82CF38065B81B93109069F781299949AC4467119AFA2A5EDBD3F36A00A1E03156300783F52C11B9A3EA84312455CE8CC41EA53F1AC5C6068BA5942BD2CE064 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/REL-6.3.11-release.1.39489/userNotifier.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16544 |
Entropy (8bit): | 5.096884809716413 |
Encrypted: | false |
SSDEEP: | |
MD5: | D3C4BE0F7308A19FB17DB9376D7DEC7A |
SHA1: | EE16C49C9B804EB7EE2988B38F5611AB85026678 |
SHA-256: | 81103F073BE555414136AEA440D8F6272A80F08CE513607CB76040453712E25C |
SHA-512: | EC82276ACA0BC62B8C72D69A401D7762A2975A07A81F1F3AF765AD0EDC658C745B0433A5AC90990DEFB87BF5FF7625FAA65B74B4D6E4C95607EE68F0D7EC1DA9 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/REL-6.3.11-release.1.39489/2ndGen/base/stylesheet_tablet.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 48 |
Entropy (8bit): | 4.13442806519115 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9EBA26905B967E18022E3F736C43F402 |
SHA1: | 5A51FA0EEFEDAB14E18ED6F17B440F0BAEC6F6C7 |
SHA-256: | 5C923FF6E174473E797D78A5D3EDCA01965AC435A1E01260419E5D4CB8D6E93D |
SHA-512: | 909C0F2BADA25CC37038D13FCAF9D593F330F67025E0669984EFCFA6FCB0B0C03EEB2C7BA784DB2EE41B7CDDBC39E7981B27616FDF05C14A823A7354AEBCEF4D |
Malicious: | false |
Reputation: | low |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xNDkSFwm05Uv8Ynr_uBIFDcPxAUESBQ3iWAvg?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1414 |
Entropy (8bit): | 4.994494585610974 |
Encrypted: | false |
SSDEEP: | |
MD5: | 738806F6615E2BD7730F0E97EB375C98 |
SHA1: | F91D847E78830D8278B9F1CED3907AC13501EF98 |
SHA-256: | A63577E7A4896B28D2FF18374539681D675B6D6E815846315E51EAD479FE6B89 |
SHA-512: | 4A3F1C1FE2BF5E9D5CF8322E1651EC0D91DDF57D3060C12512F940C3AFCFC49366AE3AFBBCF10FFD9FBF8CCA41F3E8BF29C7D6917B0DE3A68DA86EA23BCC9490 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/REL-6.3.11-release.1.39489/fieldvalue.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4168 |
Entropy (8bit): | 4.364207777843192 |
Encrypted: | false |
SSDEEP: | |
MD5: | C5E7A96D9F08831036AF7261F519F8EF |
SHA1: | 13F265BBBEAEAED4E6D43995A7553893F514FB0A |
SHA-256: | 2EC8BFF74CFFA23AFAD4C372398FF59B7BDEA6C07DCE9B511112D9A4B743A560 |
SHA-512: | BB1132DACCAA7E5FDEDF21DF9DFFB3381787D7379C485159E8D1E66080C8D2160F85E3356A0B4395EB98031798518532FCA0905E0884E140AC78B09D30D1A8EC |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/i/securedbyzix.svg |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2731 |
Entropy (8bit): | 4.918169128272672 |
Encrypted: | false |
SSDEEP: | |
MD5: | 78E5C476E160DC0D2F1E219A1AC54D12 |
SHA1: | 64AA415D7522DA1BCF3581239B61EC2591E3097E |
SHA-256: | BF714B969A60F049145EB5C2879309AE27CB4D4D6C557D1D71F1233E12F1755D |
SHA-512: | 5079D07CB4C3F8FDF6F8584CEE391EC944BBD3F89A49C2E5179CC9FDEC07EA8C9DE4FB058810D6878DE1BFE6F1D27E7980526AE32965B80DF4679443BC05F8B4 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/REL-6.3.11-release.1.39489/2ndGen/base/stylesheet_print.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2271 |
Entropy (8bit): | 7.773250653947018 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0D73550368E86F17746F226BA187787E |
SHA1: | 6BE228080DCACE16D88AB71843DC5EB224D49C94 |
SHA-256: | 689CFB629C8055246958A87D01CCB1D7B11E5474B6B8AC5F40A2A9F251A9EA89 |
SHA-512: | 080A0D6F5D69EF54F7C2ADA5B227AD825275592ECA5FECB775944CBEF32BCF08300DFD53C62CCE2C51657FF95480B31B678245007EFFBFA5FECCB694A71B04D4 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 65 |
Entropy (8bit): | 4.439139114250231 |
Encrypted: | false |
SSDEEP: | |
MD5: | 496D4CD5A824E776DED961247841A2D6 |
SHA1: | 57CAF10F2500D036438421A6196D359686B28B2C |
SHA-256: | 1CD23F829A9FDA20D675E4B312DE0F6C6D1E4E207EC60084C1DA519D6CF3CA62 |
SHA-512: | 731026E71FB459995B9D8AE73B974B15B4DA475DFA700B8D268886CB7626DBE6BCFC0B8DF5EA058FCA4F82541D445FF16C14CF5B6BED1280B036C591CD2978A9 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/REL-6.3.11-release.1.39489/2ndGen/base/stylesheet_desktop.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 36108 |
Entropy (8bit): | 5.176033132020104 |
Encrypted: | false |
SSDEEP: | |
MD5: | 32E9D431BD7BA52AACDAA3988B7A47DC |
SHA1: | 538C7ADBFA8E1588AC59931B3387462F116304D8 |
SHA-256: | 7D110159015B3BF23A9F8D78E5D9DFC0AB06769988599213DC0417E6FE2A4CDC |
SHA-512: | 178186194061CCB950FBF514D45E64BFE60C5A7E18CDD8E36F07BD0AD202D80B0F367C106DD8297DBE2B201708BCA3B2CF877FABFDC44EA133966E6A6C61921E |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/REL-6.3.11-release.1.39489/2ndGen/base/stylesheet_mobile.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 6055 |
Entropy (8bit): | 5.179218892050803 |
Encrypted: | false |
SSDEEP: | |
MD5: | F7C582BEF0D90EC28C1500B05F62EC63 |
SHA1: | 79B2276C5C9D1131347EBC7183AC65EC6E2AD920 |
SHA-256: | A57E6E8ACE4AF732A75BE722FF22CAC47EC4253DE7220FCFF4881604FCCB2EAA |
SHA-512: | D02D3458738F3AFA59B2A8551F4C061185E0EDE1BB2CBE5F96CE6A8215115E6775E76108B48BB11BAEF91036EF17A6F822B0D1FD25F999ABE3B068BAE2F2074D |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/REL-6.3.11-release.1.39489/2ndGen/base/stylesheet_desktopFallthrough.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3324 |
Entropy (8bit): | 4.9057442951405115 |
Encrypted: | false |
SSDEEP: | |
MD5: | 1EE901EA2968D580CB3DBFC0D576A60E |
SHA1: | D34381C10C8130EBAB70E589825FEEC7341DEE44 |
SHA-256: | E967764F603B517699D3C4AB4C8722211E0ACA5A5C3C8B55D666B2CA7FA44E8B |
SHA-512: | 01E1E54060AD4CBB6BE7C406DAB69C7786409B9A1A342611F650ECD2F69AEE99F4CA562FD1393EC4078AEBD7AAEF346D7A96096D8BAD83FB1CDAADDD16CCC737 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/REL-6.3.11-release.1.39489/2ndGen/base/stylesheet_mobileLandscape.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1593 |
Entropy (8bit): | 4.95506566766411 |
Encrypted: | false |
SSDEEP: | |
MD5: | 23C3006AA2306EF65A982F0E135F5B85 |
SHA1: | 939B9E69FFD2588166B871E0643EC67AC407524D |
SHA-256: | 425533232E1245EEBF4FFE8E82F8831280064E0207046B609218F99B5A56D60C |
SHA-512: | B09F96C2F2509A2277314D3EA48CC2FF62F7C0D55A35E9078286AFABDEDD3D063E6E5195B7F48B5FF0637D5604B05BE8398BCD0A0B4405FF4790AA9C0E0036D3 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/CON-1bf86621/mnbsf_stylesheet_HandHeld.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 492 |
Entropy (8bit): | 4.673424200155852 |
Encrypted: | false |
SSDEEP: | |
MD5: | 37F0A98FA1E40956308C3FCAEE929744 |
SHA1: | 39467A9D2ED951F9461F51032F354F3F03974776 |
SHA-256: | 2A07A12EC6607580E1C9BD6BFE4EEC68A495563A224F82EB56CCE72BFC8348A4 |
SHA-512: | 28C8ADF0A026BCB49993AF9A94BAEFB040B610DA9BDC2CA914D817783C47FCADD96437ACDFA7887C6461CE13A9906C497C2C35EC149BC3F478B4205F6A48BB38 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/stylesheets/skipnav.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4171 |
Entropy (8bit): | 4.617307131461832 |
Encrypted: | false |
SSDEEP: | |
MD5: | BF9A0EAE8529030C24FB3E19C86E4FD0 |
SHA1: | 788BB1FD37EE9C29D2FCE24F18B4697D25B5CF98 |
SHA-256: | 50982BA9961B6C3F2BE89BC0C20948DDAD27AF428A44AA21B123AB5007BE8309 |
SHA-512: | 7740863F1D149AB5374E176D6A1FD5FB39AC551EDBFE037497F2D0D4A55F02C63E779DA091CFC3A56E4137022CA887CD7470B1BED687FAFB3B417DB6C9A34DA6 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/REL-6.3.11-release.1.39489/emailfieldvalue.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1005 |
Entropy (8bit): | 4.872768633004354 |
Encrypted: | false |
SSDEEP: | |
MD5: | A2F6081C877AD62CFA117EBBEA517DC0 |
SHA1: | C859B3D693B568355D71CEC52B11B851F2AE050F |
SHA-256: | 7C09CDA7E306B74834E26C300055B1DC45FDD393E176297E9C60F5F1258545EE |
SHA-512: | C5DD7967A0EB0002CD95B8584AFFA37313B7D487AB3EAABA73867ED997B18D333B18E368F0EFB4742EBFAD63F6A167BDE5BA57D6F0522B54A4BBE93C09A4B8E7 |
Malicious: | false |
Reputation: | low |
URL: | https://web1.zixmail.net/s/REL-6.3.11-release.1.39489/default_loginview_validator.js |
Preview: |