Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://ecv.microsoft.com/ss9eL9LgBE

Overview

General Information

Sample URL:https://ecv.microsoft.com/ss9eL9LgBE
Analysis ID:1373657

Detection

HTMLPhisher
Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Phishing site detected (based on favicon image match)
Yara detected HtmlPhish54
Phishing site detected (based on OCR NLP Model)
Phishing site detected (based on image similarity)
Phishing site or detected (based on various text indicators)
Creates files inside the system directory
Found iframes
HTML body contains low number of good links
HTML page contains hidden URLs or javascript code
HTML page contains obfuscate script src
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 1008 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://ecv.microsoft.com/ss9eL9LgBE MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 1964 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2032,i,11731082604981084967,18400594866956333796,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
SourceRuleDescriptionAuthorStrings
3.8.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
    4.9.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
      4.11.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
        No Sigma rule has matched
        No Snort rule has matched

        Click to jump to signature section

        Show All Signature Results

        Phishing

        barindex
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NWJmNDZhYmQtNDBiYS04OTRjLWQxN2EtMTljMzUxZTdhZDFiJnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODQwNjU0NTYxODE5NjE1Mi5iNDYzMDhmYS05ZDA4LTQ2OTItOTY1MS1iZmJmZjU4MmYwMGEmc3RhdGU9RGNzeEVvQXdDQUJCb3VOek1CQUI0VG5KT0xTV2ZsLUt2ZTRhQU94bEs0MHFjTnZsUXFhaXhzNWhyT05jWWhkNVRveUhITVZpWUpneXJseVo2aU9KWnF2MzZPODMtdzg=&sso_reload=trueMatcher: Template: microsoft matched with high similarity
        Source: Yara matchFile source: 3.8.pages.csv, type: HTML
        Source: Yara matchFile source: 4.9.pages.csv, type: HTML
        Source: Yara matchFile source: 4.11.pages.csv, type: HTML
        Source: Chrome DOMML Model on OCR Text: Matched 68.9% probability on "CLICK ON HERE TO VIEW THE DOCUMENT "
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NWJmNDZhYmQtNDBiYS04OTRjLWQxN2EtMTljMzUxZTdhZDFiJnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODQwNjU0NTYxODE5NjE1Mi5iNDYzMDhmYS05ZDA4LTQ2OTItOTY1MS1iZmJmZjU4MmYwMGEmc3RhdGU9RGNzeEVvQXdDQUJCb3VOek1CQUI0VG5KT0xTV2ZsLUt2ZTRhQU94bEs0MHFjTnZsUXFhaXhzNWhyT05jWWhkNVRveUhITVZpWUpneXJseVo2aU9KWnF2MzZPODMtdzg=&sso_reload=trueMatcher: Found strong image similarity, brand: MICROSOFT
        Source: Chrome DOMOCR Text: CLICK ON HERE TO VIEW THE DOCUMENT
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NWJmNDZhYmQtNDBiYS04OTRjLWQxN2EtMTljMzUxZTdhZDFiJnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODQwNjU0NTYxODE5NjE1Mi5iNDYzMDhmYS05ZDA4LTQ2OTItOTY1MS1iZmJmZjU4MmYwMGEmc3RhdGU9RGNzeEVvQXdDQUJCb3VOek1CQUI0VG5KT0xTV2ZsLUt2ZTRhQU94bEs0MHFjTnZsUXFhaXhzNWhyT05jWWhkNVRveUhITVZpWUpneXJseVo2aU9KWnF2MzZPODMtdzg=&sso_reload=trueHTTP Parser: Iframe src: https://outlook.office365.com/owa/prefetch.aspx
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NWJmNDZhYmQtNDBiYS04OTRjLWQxN2EtMTljMzUxZTdhZDFiJnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODQwNjU0NTYxODE5NjE1Mi5iNDYzMDhmYS05ZDA4LTQ2OTItOTY1MS1iZmJmZjU4MmYwMGEmc3RhdGU9RGNzeEVvQXdDQUJCb3VOek1CQUI0VG5KT0xTV2ZsLUt2ZTRhQU94bEs0MHFjTnZsUXFhaXhzNWhyT05jWWhkNVRveUhITVZpWUpneXJseVo2aU9KWnF2MzZPODMtdzg=&sso_reload=trueHTTP Parser: Iframe src: https://outlook.office365.com/owa/prefetch.aspx
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NWJmNDZhYmQtNDBiYS04OTRjLWQxN2EtMTljMzUxZTdhZDFiJnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODQwNjU0NTYxODE5NjE1Mi5iNDYzMDhmYS05ZDA4LTQ2OTItOTY1MS1iZmJmZjU4MmYwMGEmc3RhdGU9RGNzeEVvQXdDQUJCb3VOek1CQUI0VG5KT0xTV2ZsLUt2ZTRhQU94bEs0MHFjTnZsUXFhaXhzNWhyT05jWWhkNVRveUhITVZpWUpneXJseVo2aU9KWnF2MzZPODMtdzg=&sso_reload=trueHTTP Parser: Number of links: 0
        Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/rzhkc/0x4AAAAAAAPxmJm86dbLN-oP/auto/normalHTTP Parser: Base64 decoded: http://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/rzhkc/0x4AAAAAAAPxmJm86dbLN-oP/auto/normal
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuHTTP Parser: Script src: data:text/javascript;base64,ZnVuY3Rpb24gYygpe2lmKCFkb2N1bWVudC5xdWVyeVNlbGVjdG9yKCIuYiIpIHx8ICFkb2N1bWVudC5xdWVyeVNlbGVjdG9yKCIuZyIpKXtkb2N1bWVudC5oZWFkLmFwcGVuZENoaWxkKE9iamVjdC5hc3NpZ24oZG9jdW1lbnQuY3JlYXRlRWxlbWVudCgiZGl2Iikse2NsYXNzTGlzdDpbImIiXX
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuHTTP Parser: Script src: data:text/javascript;base64,ZnVuY3Rpb24gYygpe2lmKCFkb2N1bWVudC5xdWVyeVNlbGVjdG9yKCIuYiIpIHx8ICFkb2N1bWVudC5xdWVyeVNlbGVjdG9yKCIuZyIpKXtkb2N1bWVudC5oZWFkLmFwcGVuZENoaWxkKE9iamVjdC5hc3NpZ24oZG9jdW1lbnQuY3JlYXRlRWxlbWVudCgiZGl2Iikse2NsYXNzTGlzdDpbImIiXX
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuHTTP Parser: Script src: data:text/javascript;base64,ZnVuY3Rpb24gYygpe2lmKCFkb2N1bWVudC5xdWVyeVNlbGVjdG9yKCIuYiIpIHx8ICFkb2N1bWVudC5xdWVyeVNlbGVjdG9yKCIuZyIpKXtkb2N1bWVudC5oZWFkLmFwcGVuZENoaWxkKE9iamVjdC5hc3NpZ24oZG9jdW1lbnQuY3JlYXRlRWxlbWVudCgiZGl2Iikse2NsYXNzTGlzdDpbImIiXX
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NWJmNDZhYmQtNDBiYS04OTRjLWQxN2EtMTljMzUxZTdhZDFiJnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODQwNjU0NTYxODE5NjE1Mi5iNDYzMDhmYS05ZDA4LTQ2OTItOTY1MS1iZmJmZjU4MmYwMGEmc3RhdGU9RGNzeEVvQXdDQUJCb3VOek1CQUI0VG5KT0xTV2ZsLUt2ZTRhQU94bEs0MHFjTnZsUXFhaXhzNWhyT05jWWhkNVRveUhITVZpWUpneXJseVo2aU9KWnF2MzZPODMtdzg=&sso_reload=trueHTTP Parser: <input type="password" .../> found
        Source: https://27c7ebab.1883b22668b66be88b9070ff.workers.dev/HTTP Parser: No favicon
        Source: https://27c7ebab.1883b22668b66be88b9070ff.workers.dev/HTTP Parser: No favicon
        Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/rzhkc/0x4AAAAAAAPxmJm86dbLN-oP/auto/normalHTTP Parser: No favicon
        Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/rzhkc/0x4AAAAAAAPxmJm86dbLN-oP/auto/normalHTTP Parser: No favicon
        Source: https://27c7ebab.1883b22668b66be88b9070ff.workers.dev/HTTP Parser: No favicon
        Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/rzhkc/0x4AAAAAAAPxmJm86dbLN-oP/auto/normalHTTP Parser: No favicon
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NWJmNDZhYmQtNDBiYS04OTRjLWQxN2EtMTljMzUxZTdhZDFiJnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODQwNjU0NTYxODE5NjE1Mi5iNDYzMDhmYS05ZDA4LTQ2OTItOTY1MS1iZmJmZjU4MmYwMGEmc3RhdGU9RGNzeEVvQXdDQUJCb3VOek1CQUI0VG5KT0xTV2ZsLUt2ZTRhQU94bEs0MHFjTnZsUXFhaXhzNWhyT05jWWhkNVRveUhITVZpWUpneXJseVo2aU9KWnF2MzZPODMtdzg=HTTP Parser: No favicon
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NWJmNDZhYmQtNDBiYS04OTRjLWQxN2EtMTljMzUxZTdhZDFiJnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODQwNjU0NTYxODE5NjE1Mi5iNDYzMDhmYS05ZDA4LTQ2OTItOTY1MS1iZmJmZjU4MmYwMGEmc3RhdGU9RGNzeEVvQXdDQUJCb3VOek1CQUI0VG5KT0xTV2ZsLUt2ZTRhQU94bEs0MHFjTnZsUXFhaXhzNWhyT05jWWhkNVRveUhITVZpWUpneXJseVo2aU9KWnF2MzZPODMtdzg=&sso_reload=trueHTTP Parser: No favicon
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NWJmNDZhYmQtNDBiYS04OTRjLWQxN2EtMTljMzUxZTdhZDFiJnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODQwNjU0NTYxODE5NjE1Mi5iNDYzMDhmYS05ZDA4LTQ2OTItOTY1MS1iZmJmZjU4MmYwMGEmc3RhdGU9RGNzeEVvQXdDQUJCb3VOek1CQUI0VG5KT0xTV2ZsLUt2ZTRhQU94bEs0MHFjTnZsUXFhaXhzNWhyT05jWWhkNVRveUhITVZpWUpneXJseVo2aU9KWnF2MzZPODMtdzg=&sso_reload=trueHTTP Parser: No favicon
        Source: https://outlook.office365.com/owa/prefetch.aspxHTTP Parser: No favicon
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NWJmNDZhYmQtNDBiYS04OTRjLWQxN2EtMTljMzUxZTdhZDFiJnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODQwNjU0NTYxODE5NjE1Mi5iNDYzMDhmYS05ZDA4LTQ2OTItOTY1MS1iZmJmZjU4MmYwMGEmc3RhdGU9RGNzeEVvQXdDQUJCb3VOek1CQUI0VG5KT0xTV2ZsLUt2ZTRhQU94bEs0MHFjTnZsUXFhaXhzNWhyT05jWWhkNVRveUhITVZpWUpneXJseVo2aU9KWnF2MzZPODMtdzg=&sso_reload=trueHTTP Parser: No <meta name="author".. found
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NWJmNDZhYmQtNDBiYS04OTRjLWQxN2EtMTljMzUxZTdhZDFiJnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODQwNjU0NTYxODE5NjE1Mi5iNDYzMDhmYS05ZDA4LTQ2OTItOTY1MS1iZmJmZjU4MmYwMGEmc3RhdGU9RGNzeEVvQXdDQUJCb3VOek1CQUI0VG5KT0xTV2ZsLUt2ZTRhQU94bEs0MHFjTnZsUXFhaXhzNWhyT05jWWhkNVRveUhITVZpWUpneXJseVo2aU9KWnF2MzZPODMtdzg=&sso_reload=trueHTTP Parser: No <meta name="author".. found
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NWJmNDZhYmQtNDBiYS04OTRjLWQxN2EtMTljMzUxZTdhZDFiJnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODQwNjU0NTYxODE5NjE1Mi5iNDYzMDhmYS05ZDA4LTQ2OTItOTY1MS1iZmJmZjU4MmYwMGEmc3RhdGU9RGNzeEVvQXdDQUJCb3VOek1CQUI0VG5KT0xTV2ZsLUt2ZTRhQU94bEs0MHFjTnZsUXFhaXhzNWhyT05jWWhkNVRveUhITVZpWUpneXJseVo2aU9KWnF2MzZPODMtdzg=&sso_reload=trueHTTP Parser: No <meta name="copyright".. found
        Source: https://canadianshieldconsultant.com/redirect.cgi?ref=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvYXV0aG9yaXplP2NsaWVudF9pZD0wMDAwMDAwMi0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAmcmVkaXJlY3RfdXJpPWh0dHBzJTNhJTJmJTJmb3V0bG9vay5vZmZpY2UuY29tJTJmb3dhJTJmJnJlc291cmNlPTAwMDAwMDAyLTAwMDAtMGZmMS1jZTAwLTAwMDAwMDAwMDAwMCZyZXNwb25zZV9tb2RlPWZvcm1fcG9zdCZyZXNwb25zZV90eXBlPWNvZGUraWRfdG9rZW4mc2NvcGU9b3BlbmlkJm1zYWZlZD0xJm1zYXJlZGlyPTEmY2xpZW50LXJlcXVlc3QtaWQ9NWJmNDZhYmQtNDBiYS04OTRjLWQxN2EtMTljMzUxZTdhZDFiJnByb3RlY3RlZHRva2VuPXRydWUmY2xhaW1zPSU3YiUyMmlkX3Rva2VuJTIyJTNhJTdiJTIyeG1zX2NjJTIyJTNhJTdiJTIydmFsdWVzJTIyJTNhJTViJTIyQ1AxJTIyJTVkJTdkJTdkJTdkJm5vbmNlPTYzODQwNjU0NTYxODE5NjE1Mi5iNDYzMDhmYS05ZDA4LTQ2OTItOTY1MS1iZmJmZjU4MmYwMGEmc3RhdGU9RGNzeEVvQXdDQUJCb3VOek1CQUI0VG5KT0xTV2ZsLUt2ZTRhQU94bEs0MHFjTnZsUXFhaXhzNWhyT05jWWhkNVRveUhITVZpWUpneXJseVo2aU9KWnF2MzZPODMtdzg=&sso_reload=trueHTTP Parser: No <meta name="copyright".. found
        Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.17:49760 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.17:49782 version: TLS 1.2
        Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
        Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
        Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
        Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
        Source: unknownTCP traffic detected without corresponding DNS query: 13.67.144.177
        Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.222
        Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
        Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownTCP traffic detected without corresponding DNS query: 13.67.144.177
        Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
        Source: unknownTCP traffic detected without corresponding DNS query: 72.21.81.240
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
        Source: unknownDNS traffic detected: queries for: clients2.google.com
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
        Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
        Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
        Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
        Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
        Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
        Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49683 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
        Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
        Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
        Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
        Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
        Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
        Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
        Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
        Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
        Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
        Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
        Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
        Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49684 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
        Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.17:49760 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.17:49782 version: TLS 1.2
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_1008_1017340000
        Source: classification engineClassification label: mal68.phis.win@19/108@40/277
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
        Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://ecv.microsoft.com/ss9eL9LgBE
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2032,i,11731082604981084967,18400594866956333796,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2032,i,11731082604981084967,18400594866956333796,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: Window RecorderWindow detected: More than 3 window changes detected
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
        1
        Drive-by Compromise
        Windows Management Instrumentation1
        Registry Run Keys / Startup Folder
        1
        Process Injection
        11
        Masquerading
        OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
        Encrypted Channel
        Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
        Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
        Registry Run Keys / Startup Folder
        1
        Process Injection
        LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
        Non-Application Layer Protocol
        SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
        Domain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
        Application Layer Protocol
        Data Encrypted for ImpactDNS ServerEmail Addresses

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        https://ecv.microsoft.com/ss9eL9LgBE0%Avira URL Cloudsafe
        https://ecv.microsoft.com/ss9eL9LgBE0%VirustotalBrowse
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        part-0012.t-0009.t-msedge.net0%VirustotalBrowse
        27c7ebab.1883b22668b66be88b9070ff.workers.dev4%VirustotalBrowse
        canadianshieldconsultant.com2%VirustotalBrowse
        aadcdn.msftauth.net0%VirustotalBrowse
        cs1100.wpc.omegacdn.net0%VirustotalBrowse
        No Antivirus matches
        NameIPActiveMaliciousAntivirus DetectionReputation
        cs1100.wpc.omegacdn.net
        152.199.4.44
        truefalseunknown
        accounts.google.com
        172.253.122.84
        truefalse
          high
          challenges.cloudflare.com
          104.17.2.184
          truefalse
            high
            27c7ebab.1883b22668b66be88b9070ff.workers.dev
            172.67.140.162
            truefalseunknown
            canadianshieldconsultant.com
            5.230.67.136
            truefalseunknown
            www.google.com
            172.253.115.147
            truefalse
              high
              part-0012.t-0009.t-msedge.net
              13.107.246.40
              truefalseunknown
              clients.l.google.com
              172.253.62.102
              truefalse
                high
                MNZ-efz.ms-acdc.office.com
                52.96.109.242
                truefalse
                  high
                  clients1.google.com
                  unknown
                  unknownfalse
                    high
                    r4.res.office365.com
                    unknown
                    unknownfalse
                      high
                      aadcdn.msftauth.net
                      unknown
                      unknownfalseunknown
                      cdn.forms.office.net
                      unknown
                      unknownfalse
                        high
                        lists.office.com
                        unknown
                        unknownfalse
                          high
                          outlook.office365.com
                          unknown
                          unknownfalse
                            high
                            clients2.google.com
                            unknown
                            unknownfalse
                              high
                              identity.nel.measure.office.net
                              unknown
                              unknownfalse
                                high
                                NameMaliciousAntivirus DetectionReputation
                                https://27c7ebab.1883b22668b66be88b9070ff.workers.dev/false
                                  unknown
                                  https://outlook.office365.com/owa/prefetch.aspxfalse
                                    high
                                    https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/rzhkc/0x4AAAAAAAPxmJm86dbLN-oP/auto/normalfalse
                                      high
                                      • No. of IPs < 25%
                                      • 25% < No. of IPs < 50%
                                      • 50% < No. of IPs < 75%
                                      • 75% < No. of IPs
                                      IPDomainCountryFlagASNASN NameMalicious
                                      52.96.109.242
                                      MNZ-efz.ms-acdc.office.comUnited States
                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      13.107.246.40
                                      part-0012.t-0009.t-msedge.netUnited States
                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      13.107.21.200
                                      unknownUnited States
                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      52.178.17.2
                                      unknownUnited States
                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      5.230.67.136
                                      canadianshieldconsultant.comGermany
                                      12586ASGHOSTNETDEfalse
                                      172.253.122.84
                                      accounts.google.comUnited States
                                      15169GOOGLEUSfalse
                                      104.17.3.184
                                      unknownUnited States
                                      13335CLOUDFLARENETUSfalse
                                      104.21.62.242
                                      unknownUnited States
                                      13335CLOUDFLARENETUSfalse
                                      23.212.249.91
                                      unknownUnited States
                                      16625AKAMAI-ASUSfalse
                                      172.253.115.147
                                      www.google.comUnited States
                                      15169GOOGLEUSfalse
                                      13.107.213.40
                                      unknownUnited States
                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      20.190.190.194
                                      unknownUnited States
                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      20.110.205.119
                                      unknownUnited States
                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      172.253.62.102
                                      clients.l.google.comUnited States
                                      15169GOOGLEUSfalse
                                      1.1.1.1
                                      unknownAustralia
                                      13335CLOUDFLARENETUSfalse
                                      52.109.16.40
                                      unknownUnited States
                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      13.107.246.57
                                      unknownUnited States
                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      172.253.63.95
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      142.251.111.94
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      172.253.63.102
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      172.253.122.94
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      13.107.213.57
                                      unknownUnited States
                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      20.50.73.13
                                      unknownUnited States
                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                      172.67.140.162
                                      27c7ebab.1883b22668b66be88b9070ff.workers.devUnited States
                                      13335CLOUDFLARENETUSfalse
                                      23.62.230.25
                                      unknownUnited States
                                      20940AKAMAI-ASN1EUfalse
                                      239.255.255.250
                                      unknownReserved
                                      unknownunknownfalse
                                      142.251.16.95
                                      unknownUnited States
                                      15169GOOGLEUSfalse
                                      104.17.2.184
                                      challenges.cloudflare.comUnited States
                                      13335CLOUDFLARENETUSfalse
                                      IP
                                      192.168.2.17
                                      Joe Sandbox version:38.0.0 Ammolite
                                      Analysis ID:1373657
                                      Start date and time:2024-01-12 12:07:35 +01:00
                                      Joe Sandbox product:CloudBasic
                                      Overall analysis duration:
                                      Hypervisor based Inspection enabled:false
                                      Report type:full
                                      Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                      Sample URL:https://ecv.microsoft.com/ss9eL9LgBE
                                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                      Number of analysed new started processes analysed:7
                                      Number of new started drivers analysed:0
                                      Number of existing processes analysed:0
                                      Number of existing drivers analysed:0
                                      Number of injected processes analysed:0
                                      Technologies:
                                      • EGA enabled
                                      Analysis Mode:stream
                                      Analysis stop reason:Timeout
                                      Detection:MAL
                                      Classification:mal68.phis.win@19/108@40/277
                                      • Exclude process from analysis (whitelisted): SIHClient.exe
                                      • Excluded IPs from analysis (whitelisted): 142.251.111.94, 34.104.35.123, 13.107.246.57, 13.107.213.57, 13.107.213.51, 13.107.246.41, 13.107.246.51, 13.107.253.57, 13.107.246.69, 13.107.213.40, 23.62.230.25, 23.62.230.15, 20.110.205.119, 13.107.21.200, 204.79.197.200, 13.107.226.57, 13.107.213.41, 13.107.213.69, 142.251.16.95, 172.253.63.95, 172.253.62.95, 142.251.163.95, 172.253.122.95, 142.251.167.95, 172.253.115.95, 52.109.16.40, 20.50.73.13, 52.178.17.2
                                      • Excluded domains from analysis (whitelisted): onedscolprdweu02.westeurope.cloudapp.azure.com, content-autofill.googleapis.com, slscr.update.microsoft.com, c-msn-com-nsatc.trafficmanager.net, c-bing-com.a-0001.a-msedge.net, dual-a-0001.a-msedge.net, cdn.forms.office.net.edgesuite.net, clientservices.googleapis.com, customervoice-prod.forms.office.com.akadns.net, onedscolprdneu10.northeurope.cloudapp.azure.com, ecv.microsoft.com, firstparty-azurefd-prod.trafficmanager.net, eu.events.data.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, a1894.dscms.akamai.net, customervoice.microsoft.com, edgedl.me.gvt1.com, star-azurefd-prod.trafficmanager.net, c.bing.com, prod.lists.office.com.akadns.net, csp.microsoft.com, c1.microsoft.com, eu-mobile.events.data.microsoft.com
                                      • Not all processes where analyzed, report is missing behavior information
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Jan 12 10:08:11 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2677
                                      Entropy (8bit):3.98642588204987
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:042CF735A4E5C52116B02CE2430BD9BE
                                      SHA1:93E991B7123D7F205264A5FAAF2377321D7B0420
                                      SHA-256:7C795E65BE019AA1B454ED478C8A5DC0406582125513FA090A1C6A6F49AE0DFE
                                      SHA-512:7AD1AED0DB1B0A651A47113559CF04FAB88D7A5541F5B814515C98A146E2BDB9E01D038762CAC41D8925AE70F5479EB53F89FFD503CDE9DECBA45F666F6407AE
                                      Malicious:false
                                      Reputation:low
                                      Preview:L..................F.@.. ...$+.,....kpk.GE......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I,X.X....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,X.Y....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V,X.Y....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V,X.Y...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V,X.Y...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............VRs.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Jan 12 10:08:11 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2679
                                      Entropy (8bit):4.001950197402793
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:1C069CA23F97BCA399FFA34932282228
                                      SHA1:74280FF53270BF9444D6AC624B123C3A87284E76
                                      SHA-256:C0DC6E74368827DEB20FF76A193B085ECE50F363142A2E63F31055A94CA230D7
                                      SHA-512:13C3AAD176F1EC423D00479C92AAF5788634229672E9EEBE1772B989E5C5751B2B9596ED7B6346CBF9F2C1ED9AD1EA888C6C5E7B2CDA110B61B1A30ABE2BF734
                                      Malicious:false
                                      Reputation:low
                                      Preview:L..................F.@.. ...$+.,....=.\.GE......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I,X.X....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,X.Y....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V,X.Y....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V,X.Y...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V,X.Y...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............VRs.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2693
                                      Entropy (8bit):4.014713503191854
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:20592F74AA4053EE4F24BE0B96C2FC39
                                      SHA1:4EB1C038EAE41391492D0D87F828FA2243BADD05
                                      SHA-256:3F18D40C142DCCFBB8C820DAF4995B4DC2863597D08EEAE394B263C762CF6EB6
                                      SHA-512:73C2CE4820E66012C9AD8EF9C329C3A84D94C86CD6B807FCE11618FDE1C9F06DB28309F1BEF02255337DE6F7B3F604ACFBBBB18329FCA688E8CE821A132D20CA
                                      Malicious:false
                                      Reputation:low
                                      Preview:L..................F.@.. ...$+.,.....v. ;.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I,X.X....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,X.Y....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V,X.Y....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V,X.Y...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............VRs.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Jan 12 10:08:11 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2681
                                      Entropy (8bit):4.002964855104947
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2C9B206F33261018C3DDF58BC860F298
                                      SHA1:90348ABE31B60B88682D44ED100C91E989F3E084
                                      SHA-256:2924681F7B61B69FCAEA04C8594D9F07213D85EEF305F7AD486ED9AF215DD838
                                      SHA-512:649862289B73361C75E7FB2912FCFDE4AF21B4EEA938E024430B63779D72F8E0B794BD8B8A56272FC7560B7A1C1DE23EE1909F4B8B1128B63FE48C8488613DCA
                                      Malicious:false
                                      Reputation:low
                                      Preview:L..................F.@.. ...$+.,......V.GE......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I,X.X....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,X.Y....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V,X.Y....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V,X.Y...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V,X.Y...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............VRs.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Jan 12 10:08:11 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2681
                                      Entropy (8bit):3.9917026826819697
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:2A9FB68B87624C895E0CF28E58A41A01
                                      SHA1:19E1197F08892B21B0EBD9C8123CC66C811EB7DC
                                      SHA-256:10BD84211B989B79AECB8DF1B6F1A5F402093D5B41E7B6B3379207BB55D1E8E1
                                      SHA-512:3F237A30222A1036F3CB91A9785BAAA54C4CB865F19C523D371AAB023CC9951EEFCE128F248280C2FA2CF60BFE688A43FD3EF003BB37D01793F0026DD4929428
                                      Malicious:false
                                      Reputation:low
                                      Preview:L..................F.@.. ...$+.,....7.e.GE......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I,X.X....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,X.Y....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V,X.Y....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V,X.Y...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V,X.Y...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............VRs.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Jan 12 10:08:11 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                      Category:dropped
                                      Size (bytes):2683
                                      Entropy (8bit):4.001997372940184
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:D0C849833231F77908A1A353099888B6
                                      SHA1:825A725FB477BEB4BF19C7EC37C1155652D67997
                                      SHA-256:B5A6DD42AA0B50A74B1368850C5A55C5E2ADF6348792AD7A1F6F70A20E1E48DE
                                      SHA-512:B3302D30E6F23DDD30D6542934FE6CA8C75BEB69E9CED5382BCA0B1890D984B582473D28B4CC1B2379B66CC7B908469518B21E93FE6F7B93F7B6133BAB8241D9
                                      Malicious:false
                                      Reputation:low
                                      Preview:L..................F.@.. ...$+.,....^eK.GE......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I,X.X....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V,X.Y....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V,X.Y....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V,X.Y...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V,X.Y...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............VRs.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
                                      Category:dropped
                                      Size (bytes):17174
                                      Entropy (8bit):2.9129715116732746
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:12E3DAC858061D088023B2BD48E2FA96
                                      SHA1:E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5
                                      SHA-256:90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21
                                      SHA-512:C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01
                                      Malicious:false
                                      Reputation:low
                                      Preview:..............h(..f...HH...........(..00......h....6.. ...........=...............@..........(....A..(....................(....................................."P.........................................."""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333""""""""""""""""""""""""""
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:downloaded
                                      Size (bytes):28
                                      Entropy (8bit):4.307354922057605
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9F9FA94F28FE0DE82BC8FD039A7BDB24
                                      SHA1:6FE91F82974BD5B101782941064BCB2AFDEB17D8
                                      SHA-256:9A37FDC0DBA8B23EB7D3AA9473D59A45B3547CF060D68B4D52253EE0DA1AF92E
                                      SHA-512:34946EF12CE635F3445ED7B945CF2C272EF7DD9482DA6B1A49C9D09A6C9E111B19B130A3EEBE5AC0CCD394C523B54DD7EB9BF052168979A9E37E7DB174433F64
                                      Malicious:false
                                      Reputation:low
                                      URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xNDkSFwmurOez5MwOKRIFDdFbUVISBQ1Xevf9?alt=proto
                                      Preview:ChIKBw3RW1FSGgAKBw1Xevf9GgA=
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:JSON data
                                      Category:dropped
                                      Size (bytes):72
                                      Entropy (8bit):4.241202481433726
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9E576E34B18E986347909C29AE6A82C6
                                      SHA1:532C767978DC2B55854B3CA2D2DF5B4DB221C934
                                      SHA-256:88BDF5AF090328963973990DE427779F9C4DF3B8E1F5BADC3D972BAC3087006D
                                      SHA-512:5EF6DCFFD93434D45760888BF4B95FF134D53F34DA9DC904AD3C5EBEDC58409073483F531FEA4233869ED3EC75F38B022A70B2E179A5D3A13BDB10AB5C46B124
                                      Malicious:false
                                      Reputation:low
                                      Preview:{"Message":"The requested resource does not support http method 'GET'."}
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
                                      Category:downloaded
                                      Size (bytes):61
                                      Entropy (8bit):3.990210155325004
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9246CCA8FC3C00F50035F28E9F6B7F7D
                                      SHA1:3AA538440F70873B574F40CD793060F53EC17A5D
                                      SHA-256:C07D7D29E3C20FA6CA4C5D20663688D52BAD13E129AD82CE06B80EB187D9DC84
                                      SHA-512:A2098304D541DF4C71CDE98E4C4A8FB1746D7EB9677CEBA4B19FF522EFDD981E484224479FD882809196B854DBC5B129962DBA76198D34AAECF7318BD3736C6B
                                      Malicious:false
                                      Reputation:low
                                      URL:https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
                                      Preview:.PNG........IHDR...............s....IDAT.....$.....IEND.B`.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text
                                      Category:downloaded
                                      Size (bytes):689017
                                      Entropy (8bit):4.210697599646938
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3E89AE909C6A8D8C56396830471F3373
                                      SHA1:2632F95A5BE7E4C589402BF76E800A8151CD036B
                                      SHA-256:6665CA6A09F770C6679556EB86CF4234C8BDB0271049620E03199B34B4A16099
                                      SHA-512:E7DBE4E95D58F48A0C8E3ED1F489DCF8FBF39C3DB27889813B43EE95454DECA2816AC1E195E61A844CC9351E04F97AFA271B37CAB3FC522809CE2BE85CC1B8F0
                                      Malicious:false
                                      Reputation:low
                                      URL:https://canadianshieldconsultant.com/aadcdn.msauth.net/~/shared/1.0/content/js/ConvergedLogin_PCore_rBkXYjh21YAKS8SjeOJwmw2.js
                                      Preview:.!(function (e) {. function n(n) {. for (var t, i, o = n[0], r = n[1], s = 0, c = []; s < o.length; s++). (i = o[s]),. Object.prototype.hasOwnProperty.call(a, i) && a[i] && c.push(a[i][0]),. (a[i] = 0);. for (t in r) Object.prototype.hasOwnProperty.call(r, t) && (e[t] = r[t]);. for (d && d(n); c.length; ) c.shift()();. }. var t,. i = {},. a = { 22: 0 };. function o(n) {. if (i[n]) return i[n].exports;. var t = (i[n] = { i: n, l: !1, exports: {} });. return e[n].call(t.exports, t, t.exports, o), (t.l = !0), t.exports;. }. Function.prototype.bind ||. ((t = Array.prototype.slice),. (Function.prototype.bind = function (e) {. if ("function" != typeof this). throw new TypeError(. "Function.prototype.bind - what is trying to be bound is not callable". );. var n = t.call(arguments, 1),. i = n.length,. a = this,. o = function () {},. r = function () {. return (.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=4, xresolution=62, yresolution=70, resolutionunit=2, software=paint.net 4.2.9], baseline, precision 8, 50x28, components 3
                                      Category:dropped
                                      Size (bytes):987
                                      Entropy (8bit):6.922003634904799
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E58AAFC980614A9CD7796BEA7B5EA8F0
                                      SHA1:D4CAC92DCDE0CAF7C571E6D791101DA94FDBD2CA
                                      SHA-256:8B34A475187302935336BF43A2BF2A4E0ADB9A1E87953EA51F6FCF0EF52A4A1D
                                      SHA-512:2DAC06596A11263DF1CFAB03EDA26D0A67B9A4C3BAA6FB6129CDBF0A157C648F5B0F5859B5CA689EFDF80F946BF4D854BA2B2C66877C5CE3897D72148741FCC9
                                      Malicious:false
                                      Reputation:low
                                      Preview:......JFIF.....H.H.....fExif..MM.*.................>...........F.(...........1.........N.......H.......H....paint.net 4.2.9....C....................................................................C.........................................................................2..!............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?......[.4..lz.....K.S..p.>.9.r9j..'.\.qrW..mo...X9ZV<./x...EX...m.Prj..A.EtG...K..mr....Lc.T.*8...nlY.V.{6...*R...]..(.y...)^.5V.IVO.W.B.19.R\...f.U.....'..S:..k.6..*).f.n._3*....}.y.8.EusH..y.`.mA...W.}...bL..:..b.<f..(lH#R....v._...........9N~S..
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:JSON data
                                      Category:downloaded
                                      Size (bytes):6365
                                      Entropy (8bit):5.264097418086229
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:249F13E6C9C30281171C96CB96CEFEC7
                                      SHA1:5FBCE37F6393DEA792DAF49D2E95B5CC552824DD
                                      SHA-256:A1D7E7B66585792AF61C453741EF99F4E225628BFD5CBDD28E724991A8CA4015
                                      SHA-512:4D35EAB4C8A8269988AC5C6E538ECA038AE46D92589CD8339D68D5B47BDA23575875B74503D07BFB83D2DD42E1FB1477E14D9D529D402385E307E80C6D6EB0B5
                                      Malicious:false
                                      Reputation:low
                                      URL:https://customervoice.microsoft.com/formapi/api/6daf35a0-4831-4835-b9b8-052b8949a8ca/users/edcc657b-1606-4e4f-8b3b-7d63563d0eed/light/runtimeForms('oDWvbTFINUi5uAUriUmoyntlzO0GFk9Oizt9Y1Y9Du1UNFpJWlBKSFg1OTdFQ0pCS0tPMUdSRUgxUy4u')?$expand=questions($expand=choices)
                                      Preview:{"description":null,"onlineSafetyLevel":0,"reputationTier":1,"background":{"altText":null,"contentType":null,"fileIdentifier":null,"originalFileName":null,"resourceId":null,"resourceUrl":null,"height":null,"width":null,"size":null},"header":{"altText":null,"contentType":"image/png","fileIdentifier":"439ef38c-a76f-4855-be20-a3ba7abe1d35","originalFileName":"277dd6dc-83e6-49f0-90e8-68ecc5f2a693","resourceId":"a3344f4c-cf55-44a8-875d-2dd06a5ba41b","resourceUrl":"https://lists.office.com/Images/6daf35a0-4831-4835-b9b8-052b8949a8ca/edcc657b-1606-4e4f-8b3b-7d63563d0eed/T4ZIZPJHX597ECJBKKO1GREH1S/a3344f4c-cf55-44a8-875d-2dd06a5ba41b","height":null,"width":null,"size":null},"logo":{"altText":null,"contentType":null,"fileIdentifier":null,"originalFileName":null,"resourceId":null,"resourceUrl":null,"height":null,"width":null,"size":null},"tableId":"T4ZIZPJHX597ECJBKKO1GREH1S","otherInfo":"{\"PrimaryCustomizedThemeColor\":\"#745942\",\"SecondaryCustomizedThemeColor\":\"#5a4533\",\"TertiaryCustomi
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                      Category:dropped
                                      Size (bytes):4286
                                      Entropy (8bit):5.790142327810594
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:EE2B357FA5FBA69AF238168E3A1A27E1
                                      SHA1:B5DD4606BEDBF1D705A01F833802248E03D01518
                                      SHA-256:0FD813BAE48835570858A2508D9C29900B8A4CDDEBFF4A250E79AD12F8ACBDCB
                                      SHA-512:EC00810F1DAD54D6036359386C7A205953CF1E8F81909471376EA7F77786BAABCF2EBB37A68CEB63531147A92080195EF64D93FE750380038E0AA00797DFCBDA
                                      Malicious:false
                                      Reputation:low
                                      Preview:...... .... .........(... ...@..... .......................................................................................................................................................................................................p...{@..|o..x...x...w...wo..s@..........................................................................................`..}...}...|...{...{...y...x...x...v...w ........]e.`\d..[b..Ze.`......................................................`...........~...~...}...p...^...R...W...]...V.^f..^f..\e..]e..\d..[d..Zd............................................ ....................[...1...!... ...!...!...!.]f.._h..^g..^g..]e..]e..\e..\d..\d....................................0.................|...E...!...!..."...!..."..."... .Zb.._h..^g..^g..^g..^g..]f..]e..\e..\f.P..........................0.....................3...#...#...#...#...#...#...$.x...`i..`i..`i..`i.._h.._h.._h..^g..]f..^g..`h .................. ....................G...
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (13671)
                                      Category:downloaded
                                      Size (bytes):13901
                                      Entropy (8bit):5.195074233002772
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F825FAE8AB6AF0E2839B97703162292B
                                      SHA1:3FAD1A6AE487367311BBAE110F1B37E52D93D93F
                                      SHA-256:45012E7515A8515A8FECB0622FA769203766183655B791B5E05DA8EB5D2583B6
                                      SHA-512:7C9039B855314908C84143ADA8CE3D903801CBCDDAB93EAA42B8D6755CF80A86A150B881146E1223B1ABA0BF8DFC49DDACEECAEDF2E9091E1E292FBCF838F489
                                      Malicious:false
                                      Reputation:low
                                      URL:https://cdn.forms.office.net/forms/scripts/dists/response-page-pro.chunk.ir.71be336.js
                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[166],{55055:function(e,t,n){n.r(t),n.d(t,{TitleOverflowMenu:function(){return E}});var o=n(59312),r=n(87363),i=n(60211),s=n(29559),u=n(10836),a=n(7645),l=n(54740),p=n(31442),c=n(3424),d=n(12611),h=n(262),m=n(38174),f=n(54496),M=n(64290),g=n(23112),b=n(93387);var v=function(e){function t(t){var n=e.call(this,t)||this;return n.menuTriggerRef=r.createRef(),n.subMenuTriggerRef=r.createRef(),n.menuTableRef=r.createRef(),n.resizeTimeId=null,n.blurTimeId=null,n.triggerFocused=!1,n.selectedElement=null,n.controlId=d.uniqueId("menu"),n.allowScrollBar=!n.props.SubMenu,n.state={MenuExpanded:!1,DisableButtonFocused:!1},n.getRoot=n.getRoot.bind(n),n.onMenuBlur=n.onMenuBlur.bind(n),n.onKeyDownForMenuTriggerButton=n.onKeyDownForMenuTriggerButton.bind(n),n.handleKeyUpOnTable=n.handleKeyUpOnTable.bind(n),n.resizeWindowCallback=n.resizeWindowCallback.bind(n),n.focusOnMenuItem=n.focusOnMenuItem.bind(n),n.setSelectedElement=n.setSelectedElement
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:JSON data
                                      Category:downloaded
                                      Size (bytes):89
                                      Entropy (8bit):5.2701129259535024
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:F18ADA791F9B65557545AD7D7B6DDC07
                                      SHA1:1588605AD72CA8C25EB524382582DFB7B3DDD763
                                      SHA-256:F485283B373F38247245B056EAF55B9D39EC1AA1A2139D64C059CB956AC0F0D2
                                      SHA-512:ECAD851F668967F8EE685FCF299A4CA204AF0E85D6C14AD9E6BE96ABEF2F4EA650FC03F19B8DFA820A0407D6D50C09FA7ECA59BBB77C7021A994FB1C52491F43
                                      Malicious:false
                                      Reputation:low
                                      URL:"https://customervoice.microsoft.com/formapi/api/6daf35a0-4831-4835-b9b8-052b8949a8ca/users/edcc657b-1606-4e4f-8b3b-7d63563d0eed/light/runtimeForms('oDWvbTFINUi5uAUriUmoyntlzO0GFk9Oizt9Y1Y9Du1UNFpJWlBKSFg1OTdFQ0pCS0tPMUdSRUgxUy4u')?$select=id,customCssFileName,customCSSInLineHeaderToggle,footerText"
                                      Preview:{"id":"oDWvbTFINUi5uAUriUmoyntlzO0GFk9Oizt9Y1Y9Du1UNFpJWlBKSFg1OTdFQ0pCS0tPMUdSRUgxUy4u"}
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (63096)
                                      Category:downloaded
                                      Size (bytes):63350
                                      Entropy (8bit):5.119568293747089
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9D2DD1DCF2590DE6A481BE4226B489B3
                                      SHA1:14DECCA6CC19A8E7F1FEA02BF53FB30166531414
                                      SHA-256:8436F0E7540FC0A0D15D2470979A7E624B2505B32BC93AF741BA7380D2DCFB2B
                                      SHA-512:C184BE78C958B762EF49C464319AACD935D0C3E0A764F56319271E2F82343B1F904EC013F56AACE1848F1B19FDE70769123FD24CC9A87DC6BAF95210115C301D
                                      Malicious:false
                                      Reputation:low
                                      URL:https://cdn.forms.office.net/forms/scripts/dists/response-page-pro.cachegroup-nerve.min.52db3c7.js
                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[527],{41293:function(n,t,r){function i(n,t){n||(console.assert(n,"Nerve - "+t),s("assert failed: ".concat(t)))}function e(n){return s("TODO: ".concat(n))}function u(){return s("to be overridden.")}function o(n){if(n="Nerve - warning: ".concat(n),console.warn(n),c){var t=new Error(n).stack;c(t)}}r.d(t,{ZK:function(){return o},_y:function(){return s},ct:function(){return u},hu:function(){return i},ys:function(){return e}});var c=null;function s(n){throw Error("Nerve - "+n)}},42874:function(n,t,r){r.d(t,{k:function(){return e},s:function(){return u}});var i=r(36630),e=function(){return function(n){void 0===n&&(n={}),u(this,n)}}();function u(n,t,r){void 0===r&&(r=!1),(0,i.zO)(n,"__nerve__",t,r)}},39923:function(n,t,r){r.d(t,{J4:function(){return w},bn:function(){return a},f4:function(){return h},u9:function(){return l}});var i=r(26203),e=r(41293),u=r(42874),o=r(36630),c="Spec",s=Object.freeze({IsKeyField:!1,IsLocalField:!1,IsNum
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (47421), with CRLF line terminators
                                      Category:downloaded
                                      Size (bytes):369103
                                      Entropy (8bit):5.381338995618774
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6E9386843C22345A256F324692D627F2
                                      SHA1:FEF7FADB3A27032695AAB726682A340D583BFC51
                                      SHA-256:D40E9F33813211AA5DFABEEBF4A1571D488E56878954DE4D513A25B3525B3988
                                      SHA-512:C90E8A26A10AFA84C74C1D4828466E75D0FB24E826BB984EE0C50C96E44488031D4F43068614559A77967BE58E63E5BB12D3BF0999F763725BC7E1C0BF75C6BB
                                      Malicious:false
                                      Reputation:low
                                      URL:https://cdn.forms.office.net/forms/scripts/vendors/combinedmin/basics_osi_v5_j3.min.3997ff6.js
                                      Preview:!function(e,t){if("object"==typeof exports&&"object"==typeof module)module.exports=t();else if("function"==typeof define&&define.amd)define([],t);else{var i=t();for(var n in i)("object"==typeof exports?exports:e)[n]=i[n]}}(this,function(){return function(e){function t(n){if(i[n])return i[n].exports;var r=i[n]={i:n,l:!1,exports:{}};return e[n].call(r.exports,r,r.exports,t),r.l=!0,r.exports}var i={};return t.m=e,t.c=i,t.i=function(e){return e},t.d=function(e,i,n){t.o(e,i)||Object.defineProperty(e,i,{configurable:!1,enumerable:!0,get:n})},t.n=function(e){var i=e&&e.e?function(){return e.default}:function(){return e};return t.d(i,"a",i),i},t.o=function(e,t){return Object.prototype.hasOwnProperty.call(e,t)},t.p="",t(t.s=30)}([function(e,t,i){"use strict";Object.defineProperty(t,"__esModule",{value:!0});!function(e){e[e.Unspecified=0]="Unspecified",e[e.String=1]="String",e[e.Int64=2]="Int64",e[e.Double=3]="Double",e[e.Boolean=4]="Boolean",e[e.Date=5]="Date"}(t.AWTPropertyType||(t.AWTProperty
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Unicode text, UTF-8 text, with very long lines (39764)
                                      Category:downloaded
                                      Size (bytes):787773
                                      Entropy (8bit):5.373695057050899
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:75922DF2F340E5134E5AC68882C7C8D6
                                      SHA1:B432004EF339F4AD783B272EB17D11B4584715F7
                                      SHA-256:52935E90B2AF319D774B4064E1E0C60D05EA87903652145B8F56E762E6748D80
                                      SHA-512:F995B4E14EEC0CF57E12724CB1D2AAAEA808657F2C7BEA01D2DA01212C409AA4B65C66B50F92E5E5A2702AA1C60C3AE8174104039B5B04454678D93806D8AF5A
                                      Malicious:false
                                      Reputation:low
                                      URL:https://cdn.forms.office.net/forms/scripts/dists/response-page-pro.min.b0ff380.js
                                      Preview:(function(){var __webpack_modules__={26261:function(n,t,e){"use strict";e.d(t,{Vw:function(){return h},cS:function(){return c},cl:function(){return p},gV:function(){return d},iH:function(){return v},n5:function(){return f},oe:function(){return l},z_:function(){return m}});var r=e(63061);function i(n,t){return n?n+"."+t:t}function o(n,t,e,o,u){void 0===u&&(u=4),o&&n.push((0,r.dt)("".concat(i(t,e)),o,u))}function u(n,t,e,o){"boolean"==typeof o&&n.push((0,r.UL)("".concat(i(t,e)),o))}function s(n,t,e,o){"number"==typeof o&&n.push((0,r.Kq)("".concat(i(t,e)),o))}var a=function(n){var t="Activity.Result",e=[];return s(e,t,"Code",n.code),o(e,t,"Type",n.type),s(e,t,"Tag",n.tag),u(e,t,"IsExpected",n.isExpected),e.push((0,r.dt)("zC.Activity.Result","Office.System.Result")),e},c={contractName:"Office.System.Activity",getFields:function(n){var t="Activity",e=[];return o(e,t,"CV",n.cV),s(e,t,"Duration",n.duration),s(e,t,"Count",n.count),s(e,t,"AggMode",n.aggMode),u(e,t,"Success",n.success),n.result&
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (65536), with no line terminators
                                      Category:downloaded
                                      Size (bytes):232394
                                      Entropy (8bit):5.54543362321178
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:AF8D946B64D139A380CF3A1C27BDBEB0
                                      SHA1:C76845B6FFEAF14450795C550260EB618ABD60AB
                                      SHA-256:37619B16288166CC76403F0B7DF6586349B2D5628DE00D5850C815D019B17904
                                      SHA-512:C5CFB514F993310676E834C8A5477576BD57C82A8665387F9909BA0D4C3C2DE693E738ACAA74E7B4CA20894EA2FEEA5CF9A2428767D03FE1DE9C84538FDC3EE9
                                      Malicious:false
                                      Reputation:low
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7159.25/resources/styles/0/boot.worldwide.mouse.css
                                      Preview:.feedbackList{-webkit-animation-duration:.17s;-moz-animation-duration:.17s;animation-duration:.17s;-webkit-animation-name:feedbackListFrames;-moz-animation-name:feedbackListFrames;animation-name:feedbackListFrames;-webkit-animation-fill-mode:both;-moz-animation-fill-mode:both;animation-fill-mode:both}@-webkit-keyframes feedbackListFrames{from{-webkit-transform:scale(1,1);transform:scale(1,1);-webkit-animation-timing-function:cubic-bezier(.33,0,.67,1);animation-timing-function:cubic-bezier(.33,0,.67,1)}to{-webkit-transform:scale(1.03,1.03);transform:scale(1.03,1.03)}}@-moz-keyframes feedbackListFrames{from{-moz-transform:scale(1,1);transform:scale(1,1);-moz-animation-timing-function:cubic-bezier(.33,0,.67,1);animation-timing-function:cubic-bezier(.33,0,.67,1)}to{-moz-transform:scale(1.03,1.03);transform:scale(1.03,1.03)}}@keyframes feedbackListFrames{from{-webkit-transform:scale(1,1);-moz-transform:scale(1,1);transform:scale(1,1);-webkit-animation-timing-function:cubic-bezier(.33,0,.67,
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (59783), with CRLF line terminators
                                      Category:downloaded
                                      Size (bytes):663451
                                      Entropy (8bit):5.3635307555313165
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:761CE9E68C8D14F49B8BF1A0257B69D6
                                      SHA1:8CF5D714D35EFFA54F3686065CB62CCE028E2C77
                                      SHA-256:BEAA65AD34340E61E9E701458E2CCFF8F9073FDEBBC3593A2C7EC8AFEACB69C1
                                      SHA-512:CEC948666FBA0F56D3DA27A931033C3A581C9C00FEC4D3DDCF41324525B5B5321AE3AB89581ECC7F497DE85EF684AB277C8A2DB393D526416CEB76C91A1B9263
                                      Malicious:false
                                      Reputation:low
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7159.25/scripts/boot.worldwide.0.mouse.js
                                      Preview:.window.scriptsLoaded = window.scriptsLoaded || {}; window.scriptProcessStart = window.scriptProcessStart || {}; window.scriptProcessStart['boot.worldwide.0.mouse.js'] = (new Date()).getTime();../* Empty file */;Function.__typeName="Function";Function.__class=!0;Function.createCallback=function(n,t){return function(){var r=arguments.length;if(r>0){for(var u=[],i=0;i<r;i++)u[i]=arguments[i];u[r]=t;return n.apply(this,u)}return n.call(this,t)}};Function.prototype.bind=Function.prototype.bind||function(n){if(typeof this!="function")throw new TypeError("bind(): we can only bind to functions");var u=Array.prototype.slice.call(arguments,1),r=this,t=function(){},i=function(){return r.apply(this instanceof t?this:n,u.concat(Array.prototype.slice.call(arguments)))};this.prototype&&(t.prototype=this.prototype);i.prototype=new t;return i};Function.createDelegate=function(n,t){return function(){return t.apply(n,arguments)}};Function.emptyFunction=Function.emptyMethod=function(){};Error.__typeNam
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (65339), with CRLF line terminators
                                      Category:downloaded
                                      Size (bytes):660449
                                      Entropy (8bit):5.4121922690110535
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:D9E3D2CE0228D2A5079478AAE5759698
                                      SHA1:412F45951C6AEDA5F3DF2C52533171FC7BDD5961
                                      SHA-256:7041D585609800051E4F451792AEC2B8BD06A4F2D29ED6F5AD8841AAE5107502
                                      SHA-512:06700C65BEF4002EBFBFF9D856C12E8D71F408BACA2D2103DDE1C28319B6BD3859FA9D289D8AEB6DD484E802040F6EE537F31F97B4B60A6B120A6882C992207A
                                      Malicious:false
                                      Reputation:low
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7159.25/scripts/boot.worldwide.3.mouse.js
                                      Preview:.window.scriptsLoaded = window.scriptsLoaded || {}; window.scriptProcessStart = window.scriptProcessStart || {}; window.scriptProcessStart['boot.worldwide.3.mouse.js'] = (new Date()).getTime();..;_n.a.jR=function(n){return n.dS()};_n.a.jZ=function(n){return n.eh()};_n.a.jP=function(n){return n.cC()};_n.a.jQ=function(n){return n.ca()};_n.a.hZ=function(n){return n.dO};_n.a.jU=function(n){return n.ed()};_n.a.jT=function(n){return n.ea()};_n.a.kb=function(n){return n.ej()};_n.a.hM=function(n){return 300};_n.a.fh=function(n){return n.V};_n.a.jV=function(n){return n.bI()};_n.a.ie=function(n){return n.mh()};_n.a.km=function(n){return n.bl()};_n.a.ka=function(n){return n.ei()};_n.a.ko=function(n){return n.cV()};_n.a.eX=function(n){return _y.E.isInstanceOfType(n)?n.y:null};_n.a.jN=function(n){return n.c()};_n.a.gm=function(n){return n.b()};_n.a.jM=function(n){return n.b()};_n.a.ib=function(n){return n.jM()};_n.a.iq=function(n){return n.bG};_n.a.iX=function(n){return _n.V.isInstanceOfType(n)?n
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
                                      Category:downloaded
                                      Size (bytes):1435
                                      Entropy (8bit):7.8613342322590265
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9F368BC4580FED907775F31C6B26D6CF
                                      SHA1:E393A40B3E337F43057EEE3DE189F197AB056451
                                      SHA-256:7ECBBA946C099539C3D9C03F4B6804958900E5B90D48336EEA7E5A2ED050FA36
                                      SHA-512:0023B04D1EEC26719363AED57C95C1A91244C5AFF0BB53091938798FB16E230680E1F972D166B633C1D2B314B34FE0B9D7C18442410DB7DD6024E279AAFD61B0
                                      Malicious:false
                                      Reputation:low
                                      URL:https://canadianshieldconsultant.com/aadcdn.msauth.net/~/shared/1.0/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd.svg
                                      Preview:...........WMo.7..+..uV.HJ...{..........&..v...(Q.F.....aW.Q.|..~.|{~...b{8...zv.....8|...b.gxb.y{.x<\lS...p...p..l7...o.}.v.....t.........r..r.|9?.......HP...r.4.aGA.j....7.!....K.n.B.Z.C.]....kj..A..p...xI...b..I!K..><.B..O....#...$.]h.bU.;.Y...).r.u....g*.-w.2..vPh....q....4_..N\..@y).t{.2pj.f..4h.....NC.....x.R..P..9.....".4.`%N..&...a.@.......fS)A4.F..8e9KHE....8d.CR.K..g..Q.......a....f.....dg*N.N.k..#w..........,.".%..I.q.Y.R]..7.!.:.Ux...T.qI..{..,b..2..B...Bh...[o..[4....dZ.z.!.l....E.9$..Y.'...M.,p..$..8Ns3.B.....{.....H..Se3....%.Ly...VP{.Bh.D.+....p..(..`....t....U.e....2......j...%..0.f<...q...B.k..N....03...8....l.....bS...vh..8..Q..LWXW..C.......3..Pr.V.l...^=VX\,d9f.Y;1!w.d,.qvs....f*;.....Zhrr.,.U....6.Y....+Zd.*R...but....".....4.L...z........L.Q......)....,.].Y.&....*ZsIVG.^...#...e..r....Z..F..c..... .QDCmV..1.~...J9..b_Oov\..X.R..._.TqH.q.5G.0{ZphQ..k...s..\.../.Dp..d`#......8.#Y...Mb.j.Q......=n4.c....p.[.SI.....0.N.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (14182)
                                      Category:downloaded
                                      Size (bytes):14434
                                      Entropy (8bit):5.41253474392622
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:39FE53EB9274BE422813B6756D3951E8
                                      SHA1:5E7E1AA6347DD66A7B52BB3AC94EC50BB0BEC9E5
                                      SHA-256:E91EBC90763C7B778FC6FD26FC0524D9D8584DE71A1A6E2ABB6D54492D3472D8
                                      SHA-512:AFD23FA265FBE11DFF9750901524E272E6261AFBDE6B680C005F67BCBBBF8F3D96E594D4C7381C6652BF1E70871AE37C5D0D9B4F084AAAD0E5D377645CC12227
                                      Malicious:false
                                      Reputation:low
                                      URL:https://cdn.forms.office.net/forms/scripts/dists/response-page-pro.chunk.cvtitlerender.65b951b.js
                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[581],{22184:function(e,o,t){t.d(o,{D4:function(){return c},K9:function(){return r},O8:function(){return m},YR:function(){return i},cL:function(){return u},el:function(){return l},f8:function(){return p},pP:function(){return a},t3:function(){return n}});var r=.5,i=1.5,a=4.5,n=3,l=1.5,s=[{BackgroundColor:"#eee6f2",BackgroundImage:null,Name:"CV_HBG_Professional",PrimaryColor:"#21052e",SecondaryColor:"#0f0214",Thumbnail:null},{BackgroundColor:"#e6eff2",BackgroundImage:null,Name:"CV_HBG_Friendly",PrimaryColor:"#185b75",SecondaryColor:"#13475b",Thumbnail:null},{BackgroundColor:"#e6f2eb",BackgroundImage:null,Name:"CV_HBG_Playful",PrimaryColor:"#237547",SecondaryColor:"#1b5b38",Thumbnail:null},{BackgroundColor:"#f2ece6",BackgroundImage:null,Name:"CV_HBG_Relaxed",PrimaryColor:"#68503c",SecondaryColor:"#4f3c2d",Thumbnail:null},{BackgroundColor:"#e6ecf2",BackgroundImage:null,Name:"CV_HBG_3DMolecules",PrimaryColor:"#416083",SecondaryCol
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:PNG image data, 800 x 173, 8-bit/color RGBA, non-interlaced
                                      Category:dropped
                                      Size (bytes):261535
                                      Entropy (8bit):7.9085465292915815
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:0A6E902C8D66A342F2D02F6E1E1EF5F8
                                      SHA1:58BF954EE9A0638438D47F636442C99F10756FDD
                                      SHA-256:F3D149EB9C86028C97D56B729BC9939F6ECDC27168BE475BC2B6FCD0F67E51B2
                                      SHA-512:CC570F5FADC00107F7528FE029A59225A6DE9686A233DA4177FB10EFDF22928F90918172A12D8C9B784217CB98D6B3F85958820F7498D9D590062771F9A8ED97
                                      Malicious:false
                                      Reputation:low
                                      Preview:.PNG........IHDR... .........H.......sRGB.........gAMA......a.....pHYs.........].......IDATx^...{....|~.A.....v.....Q2.d1Z.d.L2J.....bffffN..w.....}..Y}.].9.......x`NM..z~..1...&_.#.....}......Z......9c`./0~...._i.5.R#...2.....|!...8?.7....7.2..9Z...........=..k..f5$.YM....9#.........N.[}/)...4DF..\..A.....?JV..dP..2.s...RW..C...(..Y...,E=..^.4..i(#.6..dL.&26.....X..6....4.%..4...6...j$..E)..[k.....+t.J.Rq=.......4.OGpDT.....2...k|....?.....#..\.P.4.ih..k....J....`.^...[.".y.yeZ..]4.q3.I...O.h!S..i.5.e..Gf+...R&g.zfK.[...M..0.9..,-.&;*...."9..DNn.*...3;..]...era.*9.h...B.._).0.zl.\?.Kn../7.......+'...Sr......<.y^.......yv...xxS^?./o_>.w.."..../..........u............8.k(>|. .?~.=.i...{......U....F>.{..^......k{.......Yy...>.+................~................{.?.^.l(........L(.!.J..E.rj.d.zp..9.U.^.+O....N.....3...y..y.........yv..<.{^^b|q.4.;-/.^.wo..o............<.^......r..~9.y...$9i.%%.......%.w..9.c.\;...g.<8...i.<.rP.]9$On..
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (65339), with CRLF line terminators
                                      Category:downloaded
                                      Size (bytes):659798
                                      Entropy (8bit):5.352921769071548
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:9786D38346567E5E93C7D03B06E3EA2D
                                      SHA1:23EF8C59C5C9AA5290865933B29C9C56AB62E3B0
                                      SHA-256:263307E3FE285C85CB77CF5BA69092531CE07B7641BF316EF496DCB5733AF76C
                                      SHA-512:4962CDF483281AB39D339A7DA105A88ADDB9C210C9E36EA5E36611D7135D19FEC8B3C9DBA3E97ABB36D580F194F1860813071FD6CBEDE85D3E88952D099D6805
                                      Malicious:false
                                      Reputation:low
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7159.25/scripts/boot.worldwide.1.mouse.js
                                      Preview:.window.scriptsLoaded = window.scriptsLoaded || {}; window.scriptProcessStart = window.scriptProcessStart || {}; window.scriptProcessStart['boot.worldwide.1.mouse.js'] = (new Date()).getTime();..;_a.d.G=function(n,t){this.b=n;this.a=t};_a.d.G.prototype={b:0,a:0};_a.fo=function(n){this.s=n};_a.fo.prototype={s:null,t:null,i:function(){return this.s.currentTarget},e:function(){return this.t?this.t.x:this.s.pageX},f:function(){return this.t?this.t.y:this.s.pageY},o:function(){return this.s.relatedTarget},b:function(){return this.s.target},n:function(){return this.s.timeStamp||+new Date},a:function(){var n=this.s.which;!n&&_a.o.a().K&&this.s.type==="keypress"&&(n=this.u());return n},u:function(){return this.s.keyCode},m:function(){return this.s.originalEvent},j:function(){return this.s.type},k:function(){return this.s.originalEvent.touches},q:function(){return this.s.isDefaultPrevented()},g:function(){return this.s.shiftKey},h:function(){return _j.G.a().P?this.s.metaKey:this.s.ctrlKey},l:
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (994), with no line terminators
                                      Category:downloaded
                                      Size (bytes):994
                                      Entropy (8bit):4.934955158256183
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E2110B813F02736A4726197271108119
                                      SHA1:D7AC10CC425A7B67BF16DDA0AAEF1FEB00A79857
                                      SHA-256:6D1BE7ED96DD494447F348986317FAF64728CCF788BE551F2A621B31DDC929AC
                                      SHA-512:E79CF6DB777D62690DB9C975B5494085C82E771936DB614AF9C75DB7CE4B6CA0A224B7DFB858437EF1E33C6026D772BE9DBBB064828DB382A4703CB34ECEF1CF
                                      Malicious:false
                                      Reputation:low
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7159.25/resources/images/0/sprite1.mouse.css
                                      Preview:.image-loading_blackbg-gif{background:url('loading_blackbg.gif');width:16px;height:16px}.image-loading_whitebg-gif{background:url('loading_whitebg.gif');width:16px;height:16px}.image-thinking16_blue-gif{background:url('thinking16_blue.gif');width:16px;height:16px}.image-thinking16_grey-gif{background:url('thinking16_grey.gif');width:16px;height:16px}.image-thinking16_white-gif{background:url('thinking16_white.gif');width:16px;height:16px}.image-thinking24-gif{background:url('thinking24.gif');width:24px;height:24px}.image-thinking32_blue-gif{background:url('thinking32_blue.gif');width:32px;height:32px}.image-thinking32_grey-gif{background:url('thinking32_grey.gif');width:32px;height:32px}.image-thinking32_white-gif{background:url('thinking32_white.gif');width:32px;height:32px}.image-clear1x1-gif{width:1px;height:1px;background:url('sprite1.mouse.png') -0 -0}.csimg{padding:0;border:none;background-repeat:no-repeat;-webkit-touch-callout:none}span.csimg{-ms-high-contrast-adjust:none}
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:HTML document, ASCII text, with very long lines (2345), with CRLF line terminators
                                      Category:downloaded
                                      Size (bytes):2347
                                      Entropy (8bit):5.290031538794594
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E86EF8B6111E5FB1D1665BCDC90888C9
                                      SHA1:994BF7651CB967CD9053056AF2D69ACB74DB7F29
                                      SHA-256:3410242720DE50B090D07A23AEE2DAD879B31D36F2615732962EC4CFA8A9D458
                                      SHA-512:2486B491681EE91A9CD1ECC9AA011A3FB34B48358C5D7A4D503A5357BC5CE4CA22999F918D40AC60A3063940D5F326FC7E4E5713D89D5C102DE68824E371B3AB
                                      Malicious:false
                                      Reputation:low
                                      URL:https://login.live.com/Me.htm?v=3
                                      Preview:<script type="text/javascript">!function(n,t){for(var e in t)n[e]=t[e]}(this,function(n){function t(i){if(e[i])return e[i].exports;var s=e[i]={exports:{},id:i,loaded:!1};return n[i].call(s.exports,s,s.exports,t),s.loaded=!0,s.exports}var e={};return t.m=n,t.c=e,t.p="",t(0)}([function(n,t){function e(n){for(var t=g[c],e=0,i=t.length;e<i;++e)if(t[e]===n)return!0;return!1}function i(n){if(!n)return null;for(var t=n+"=",e=document.cookie.split(";"),i=0,s=e.length;i<s;i++){var o=e[i].replace(/^\s*(\w+)\s*=\s*/,"$1=").replace(/(\s+$)/,"");if(0===o.indexOf(t))return o.substring(t.length)}return null}function s(n,t,e){if(n)for(var i=n.split(":"),s=null,o=0,a=i.length;o<a;++o){var l=null,c=i[o].split("$");if(0===o&&(s=parseInt(c.shift()),!s))return;var p=c.length;if(p>=1){var f=r(s,c[0]);if(!f||e[f])continue;l={signInName:f,idp:"msa",isSignedIn:!0}}if(p>=3&&(l.firstName=r(s,c[1]),l.lastName=r(s,c[2])),p>=4){var g=c[3],m=g.split("|");l.otherHashedAliases=m}if(p>=5){var h=parseInt(c[4],16);h&&(l.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Unicode text, UTF-8 text, with very long lines (33648), with no line terminators
                                      Category:downloaded
                                      Size (bytes):33672
                                      Entropy (8bit):4.794966424719676
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:6FEC042B5183775D05DE6BC036BCEC52
                                      SHA1:9E048EDEDC3F5486CABA12B69C826EED487B4C71
                                      SHA-256:0E8EF55464F75E593347AF74DBDE1B7E4E9156EC2A37549512897690925F97C8
                                      SHA-512:0F124047D046166BDDE19CE6FBBE2F0DDE636FBCC10FB1387E9B344CDA0D4CBEAB0CCB01551F0DC6074BAF58FA950B4A468A555B84D5A19C1FCBC760ABA63BB6
                                      Malicious:false
                                      Reputation:low
                                      URL:https://cdn.forms.office.net/forms/scripts/dists/ls-response.en-us.dbf1f0e78.js
                                      Preview:window.FormsLsMap = (window.FormsLsMap || {});window.FormsLsMap["en-us"]={"mdbicgo":"Required to answer","lbnbnjb":"Please share your comments here","jchpiio":"Help improve phishing detection","hkplpef":"It's not collecting sensitive info","lifjakb":"It needs to collect sensitive info","eackega":"Other","mnpehin":"Did this form trigger a false positive? Click to provide details.","amlalmd":"Why did you unblock this form?","acmngdo":"This user is not currently restricted from using Microsoft Forms. No further action is needed..","pdnfcop":"Correct","gplbmcp":"Print response","pfjnaob":"Required","efmefee":"To access the full range of AI capabilities, please click \"Allow\" and allow access in the popup window.","jcamdkj":"Allow access to continue","dlogacb":"Pause background music","oancfdj":"Play background music","pjgjcee":"Pause live background","dplcjia":"Play live background","giamlmc":"Please select at least {0} options.","ggbmbok":"Please select at most {0} options.","mbpambh":
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (65339), with CRLF line terminators
                                      Category:downloaded
                                      Size (bytes):662286
                                      Entropy (8bit):5.315860951951661
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:12204899D75FC019689A92ED57559B94
                                      SHA1:CCF6271C6565495B18C1CED2F7273D5875DBFB1F
                                      SHA-256:39DAFD5ACA286717D9515F24CF9BE0C594DFD1DDF746E6973B1CE5DE8B2DD21B
                                      SHA-512:AA397E6ABD4C54538E42CCEDA8E3AA64ACE76E50B231499C20E88CF09270AECD704565BC9BD3B27D90429965A0233F99F27697F66829734FF02511BD096CF030
                                      Malicious:false
                                      Reputation:low
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7159.25/scripts/boot.worldwide.2.mouse.js
                                      Preview:.window.scriptsLoaded = window.scriptsLoaded || {}; window.scriptProcessStart = window.scriptProcessStart || {}; window.scriptProcessStart['boot.worldwide.2.mouse.js'] = (new Date()).getTime();.._y.lC=function(){};_y.lC.registerInterface("_y.lC");_y.jw=function(){};_y.jw.registerInterface("_y.jw");_y.lA=function(){};_y.lA.registerInterface("_y.lA");var IDelayedSendEvent=function(){};IDelayedSendEvent.registerInterface("IDelayedSendEvent");var IIsShowingComposeInReadingPaneEvent=function(){};IIsShowingComposeInReadingPaneEvent.registerInterface("IIsShowingComposeInReadingPaneEvent");var ISendFailedO365Event=function(){};ISendFailedO365Event.registerInterface("ISendFailedO365Event");var ISendFailureRemoveO365Event=function(){};ISendFailureRemoveO365Event.registerInterface("ISendFailureRemoveO365Event");_y.gw=function(){};_y.gw.registerInterface("_y.gw");_y.iB=function(){};_y.iB.registerInterface("_y.iB");_y.ih=function(){};_y.ih.registerInterface("_y.ih");_y.jy=function(){};_y.jy.regis
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:PNG image data, 600 x 1, 8-bit/color RGBA, non-interlaced
                                      Category:downloaded
                                      Size (bytes):132
                                      Entropy (8bit):4.945787382366693
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:3EDA15637AFEAC6078F56C9DCC9BBDB8
                                      SHA1:97B900884183CB8CF99BA069EEDC280C599C1B74
                                      SHA-256:68C66D144855BA2BC8B8BEE88BB266047367708C1E281A21B9D729B1FBD23429
                                      SHA-512:06B21827589FCAF63B085DB2D662737B24A39A697FF9138BDF188408647C3E90784B355F2B8390160CA487992C033CE735599271EE35873E1941812AB6C34B52
                                      Malicious:false
                                      Reputation:low
                                      URL:https://r4.res.office365.com/owa/prem/15.20.7159.25/resources/images/0/sprite1.mouse.png
                                      Preview:.PNG........IHDR...X..........x......sRGB.........gAMA......a.....pHYs..........o.d....IDATHK..1......Om.O ...j.a...\BW....IEND.B`.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:PNG image data, 578 x 125, 8-bit/color RGBA, non-interlaced
                                      Category:downloaded
                                      Size (bytes):151603
                                      Entropy (8bit):7.944193899035669
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:DC36913090BB4878BF58F016D586C8CC
                                      SHA1:A7B7B5EF71362D1DEC721078FCD12F7FA97B56B4
                                      SHA-256:B4019E4040472B8FFBBDFCB3ADE293657233DC6479C483E0336D7B02AEB3CB1D
                                      SHA-512:AA4F8DD1AE2EE65717BDDC4B9B2EB9E176EAA987D03AF6421B710233C48258E4077376EAFB1F00EDAB56B187A4F915ADD8F332FA58AB60BB94DE142F687D24C4
                                      Malicious:false
                                      Reputation:low
                                      URL:https://lists.office.com/Images/6daf35a0-4831-4835-b9b8-052b8949a8ca/edcc657b-1606-4e4f-8b3b-7d63563d0eed/T4ZIZPJHX597ECJBKKO1GREH1S/a3344f4c-cf55-44a8-875d-2dd06a5ba41b_mo
                                      Preview:.PNG........IHDR...B...}.....N..Q....gAMA......a.....pHYs...........2.....IDATx^..w{UW.6z.Gx........s. ....(.3....9.mr.9..3.D..vUu..W...\s.%.?.:..k...V...1...b.}.....$~...........$...f...B"{~.1..g2...?..^.4"....G..s.k;....K.c.u4sD.$v..1..0.[I...$..^..~'....H..I...#..,...3....&...0........$.........2%..L..W*#.IUT.....R.;Hjb..X.7...C<Q.0T....1.c.P.`iH."S........a..R..h..y...w..N..q...p....q.?.&<.9..sFc. ..4.....2-e..:O.$.S...ef.`...H."3..KS. .C.....LO.,.sF..H9..TNmn.....].....r..:.x.q`.\>.A.O..........r....y^......UiypCZ..7/...W.......+..y...'~......;...w.q..'>|...~is....{..~.......O.......y~...{.@~.}}._....g..|.`F}.|..O..q.4_.+......R.. K.b..)r..r..~.<.~D..:-..... .....9..>.....y....y.H~....>...._?..O..cke..dI....Q...Q.oj..G..s........!y.|L..:%-7OK.>o..O...c..[.._~....*.>.........,o...Hqv....,[9M~........_..../.Y................]G.1.....7..#.~o..{&o_.....u|..z|Y^>..?..{..;9#Oo....G.......Qy.rD.\<(w...gv..[....r..Z....\.R.b....+.p..
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with no line terminators
                                      Category:downloaded
                                      Size (bytes):16
                                      Entropy (8bit):3.875
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:46DF3E5E2D15256CA16616EBFDA5427F
                                      SHA1:BE8F9B307E458075DA0D43585A05F1D451469182
                                      SHA-256:AF3248D0B278571EFF9A22F8ED1CEB54B70D202B44FD70ECA4CA13A5771CECC3
                                      SHA-512:88FBCC0A92317A0BADE7D4B72C023A16792F3728443075BF4B1767C8A55258836B54D56B24EABE36AE4EF240F796B58B8F1EA10C7E3C146BDE89882FC9ADE302
                                      Malicious:false
                                      Reputation:low
                                      URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xNDkSEAlVXKuvvAsoeBIFDZFhlU4=?alt=proto
                                      Preview:CgkKBw2RYZVOGgA=
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Unicode text, UTF-8 text, with very long lines (19569), with CRLF line terminators
                                      Category:downloaded
                                      Size (bytes):52547
                                      Entropy (8bit):5.360332468600038
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:162890ADA98A5DEF6640BBE57DA52EB9
                                      SHA1:06A3D551F9718164171E7517F18577B73F13B390
                                      SHA-256:DA599489D3F86D69769A1D310A5E59838D7E72EAD0BCFE94851D0084318FCDC2
                                      SHA-512:DDA7B8F4C63FABFCA8646CC059E6B3D50298985AFEE866680106B4610ADAFA58D078AF31EA8F81C2AE9FB2AD8BC579E64B7F4EC3B23987F278ADB410E24DBBBA
                                      Malicious:false
                                      Reputation:low
                                      URL:https://cdn.forms.office.net/forms/scripts/vendors/combinedmin/response_v2.min.5234a19.js
                                      Preview:/*!.. * linkify.js v2.1.8.. * https://github.com/SoapBox/linkifyjs.. * Copyright (c) 2014 SoapBox Innovations Inc... * Licensed under the MIT license.. */..!function(){"use strict";var n="function"==typeof Symbol&&"symbol"==typeof Symbol.iterator?function(n){return typeof n}:function(n){return n&&"function"==typeof Symbol&&n.constructor===Symbol&&n!==Symbol.prototype?"symbol":typeof n};!function(e){function a(n,e){var a=arguments.length>2&&void 0!==arguments[2]?arguments[2]:{},t=Object.create(n.prototype);for(var o in a)t[o]=a[o];return t.constructor=e,e.prototype=t,e}function t(n){n=n||{},this.defaultProtocol=n.hasOwnProperty("defaultProtocol")?n.defaultProtocol:h.defaultProtocol,this.events=n.hasOwnProperty("events")?n.events:h.events,this.format=n.hasOwnProperty("format")?n.format:h.format,this.formatHref=n.hasOwnProperty("formatHref")?n.formatHref:h.formatHref,this.nl2br=n.hasOwnProperty("nl2br")?n.nl2br:h.nl2br,this.tagName=n.hasOwnProperty("tagName")?n.tagName:h.tagName,this.targ
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (23932)
                                      Category:downloaded
                                      Size (bytes):24184
                                      Entropy (8bit):5.319074041419613
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:245EBB579CD738B1264FDC870B7E2187
                                      SHA1:57F686C66F2C184BA1AE2079DC9C95CF4E4E653C
                                      SHA-256:A26333C5F6065955E82B3E54442DE3ECB2DCF9AE27890D232FAC5839ADE037DB
                                      SHA-512:1CB349A3000CA015FF206DE6DF090F928FD282906DC2F390566529EC9211378CE20F4A3AF5628699D05A86C73C43EA8EEE2835914A5A7350D40520E1DD252E25
                                      Malicious:false
                                      Reputation:low
                                      URL:https://cdn.forms.office.net/forms/scripts/dists/response-page-pro.chunk.cvheadertheme.ce22c68.js
                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[264],{22184:function(o,e,r){r.d(e,{D4:function(){return m},K9:function(){return t},O8:function(){return d},YR:function(){return i},cL:function(){return l},el:function(){return f},f8:function(){return p},pP:function(){return c},t3:function(){return n}});var t=.5,i=1.5,c=4.5,n=3,f=1.5,a=[{BackgroundColor:"#eee6f2",BackgroundImage:null,Name:"CV_HBG_Professional",PrimaryColor:"#21052e",SecondaryColor:"#0f0214",Thumbnail:null},{BackgroundColor:"#e6eff2",BackgroundImage:null,Name:"CV_HBG_Friendly",PrimaryColor:"#185b75",SecondaryColor:"#13475b",Thumbnail:null},{BackgroundColor:"#e6f2eb",BackgroundImage:null,Name:"CV_HBG_Playful",PrimaryColor:"#237547",SecondaryColor:"#1b5b38",Thumbnail:null},{BackgroundColor:"#f2ece6",BackgroundImage:null,Name:"CV_HBG_Relaxed",PrimaryColor:"#68503c",SecondaryColor:"#4f3c2d",Thumbnail:null},{BackgroundColor:"#e6ecf2",BackgroundImage:null,Name:"CV_HBG_3DMolecules",PrimaryColor:"#416083",SecondaryCol
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1592
                                      Category:downloaded
                                      Size (bytes):621
                                      Entropy (8bit):7.673946009263606
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4761405717E938D7E7400BB15715DB1E
                                      SHA1:76FED7C229D353A27DB3257F5927C1EAF0AB8DE9
                                      SHA-256:F7ED91A1DAB5BB2802A7A3B3890DF4777588CCBE04903260FBA83E6E64C90DDF
                                      SHA-512:E8DAC6F81EB4EBA2722E9F34DAF9B99548E5C40CCA93791FBEDA3DEBD8D6E401975FC1A75986C0E7262AFA1B9D1475E1008A89B92C8A7BEC84D8A917F221B4A2
                                      Malicious:false
                                      Reputation:low
                                      URL:https://canadianshieldconsultant.com/aadcdn.msauth.net/~/shared/1.0/content/images/signin-options_4e48046ce74f4b89d45037c90576bfac.svg
                                      Preview:..........}UMo"1..+.....G; .8l...M..$.U.AW......UaX..`'.=......|..z3...Ms>..Y...QB..W..y..6.......?..........L.W=m....=..w.)...nw...a.z......#.y.j...m...P...#...6....6.u.u...OF.V..07b..\...s.f..U..N..B...>.d.-z..x.2..Lr.Rr)....JF.z.;Lh.....q.2.A....[.&".S..:......]........#k.U#57V..k5.tdM.j.9.FMQ2..H:.~op..H.......hQ.#...r[.T.$.@........j.xc.x0..I.B:#{iP1.e'..S4.:...mN.4)<W.A.).g.+..PZ&.$.#.6v.+.!...x*...}.._...d...#.Cb..(..^k..h!..7.dx.WHB......(.6g.7.Wwt.I<.......o.;.....Oi$}f.6.....:P..!<5.(.p.e.%et.)w8LA.l9r..n.....?.F.DrK...H....0F...{.,.......{E.."....*...x.@..?u......../....8...
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:PNG image data, 100 x 35, 8-bit/color RGB, non-interlaced
                                      Category:dropped
                                      Size (bytes):61
                                      Entropy (8bit):4.035372245524405
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:C60E583F6E0BA715A7D50581BF1768B9
                                      SHA1:2B83E430D125C3FFBB966A647F5DBDC5714101CA
                                      SHA-256:CFD7749689008B63A44F3FBBB2C131BA7908213EF1D4C31894A975D19484BD46
                                      SHA-512:2806E04FFD7C73E54431460BF76789CCAB5D0F549ED873BC0781A5BA9432996404A16602E310BD2C882EC0A6D63436CF18EB2BACC4CE8915307CBBA68DACA528
                                      Malicious:false
                                      Reputation:low
                                      Preview:.PNG........IHDR...d...#.......8.....IDAT.....$.....IEND.B`.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:Unicode text, UTF-8 text, with very long lines (64954), with CRLF line terminators
                                      Category:downloaded
                                      Size (bytes):213684
                                      Entropy (8bit):5.088387120690259
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:E6A02F503963DFDD398C620D4AB0B735
                                      SHA1:D586B2D9A5C0ECE4DBF2B5B29CA970EC3CD0BE99
                                      SHA-256:2C75BB8BFE3B9C39FA2FEBB0B4A310E9563AE4FE2025DC3065A37C61C8330F5D
                                      SHA-512:4030921B3916E90D8BF461BD2DAB8807E2818DEEB3417577998F98B09A491CABFB840FDBC6BC3CC8EADB9D42BE4AF21575517C85318B1C0C1D4B39E0E803FB81
                                      Malicious:false
                                      Reputation:low
                                      URL:https://cdn.forms.office.net/forms/css/dist/cv-response-page.min.be80eab.css
                                      Preview:@charset 'UTF-8';/*!.. * Generated using the Bootstrap Customizer (https://getbootstrap.com/docs/3.4/customize/).. *//*!.. * Bootstrap v3.4.1 (https://getbootstrap.com/).. * Copyright 2011-2019 Twitter, Inc... * Licensed under MIT (https://github.com/twbs/bootstrap/blob/master/LICENSE).. *//*! normalize.css v3.0.3 | MIT License | github.com/necolas/normalize.css */html{font-family:sans-serif;-ms-text-size-adjust:100%;-webkit-text-size-adjust:100%}body{margin:0}article,aside,details,figcaption,figure,footer,header,hgroup,main,menu,nav,section,summary{display:block}audio,canvas,progress,video{display:inline-block;vertical-align:baseline}audio:not([controls]){display:none;height:0}[hidden],template{display:none}a{background-color:transparent}a:active,a:hover{outline:0}abbr[title]{border-bottom:none;text-decoration:underline;text-decoration:underline dotted}b,strong{font-weight:700}dfn{font-style:italic}h1{font-size:2em;margin:.67em 0}mark{background:#ff0;color:#000}small{font-size:80%}sub
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 111831
                                      Category:downloaded
                                      Size (bytes):20226
                                      Entropy (8bit):7.978342463026624
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:71C96C3706B26B7003D1C8B6706067AF
                                      SHA1:3EDB40999A956FE71B1A2E7D08EB6D92F4706061
                                      SHA-256:9DA5D4E9E1ED57EFF4368A7DF52597D6903F4E82ADD83C061DAEC12335DED5D3
                                      SHA-512:E164AA2394189D09BDC99B1404D2655D9B3FA872B8F4630894610205DC245CA6E2FE6BF6A2EE90E249572187A1DF7A451BCAF080999F0A4A68C31F3A09E565A8
                                      Malicious:false
                                      Reputation:low
                                      URL:https://canadianshieldconsultant.com/aadcdn.msauth.net/~/ests/2.1/content/cdnbundles/converged.v2.login.min_chy_qb6g1qbjbxlng2ytiq2.css
                                      Preview:...........}ks.6.....\.R;.J.H=-WR;..&>g^53.G.R[.DY<C..$e.WG..... )...{+'g...l............bw_f7.:x..<x.-.*V5)/wE..Y...gy.0.*(.*-o.e.|..._..I.....?<{.!x...W..._..^..p..E..'..Y...<.....*]..6(. ..D..*...Y.......:.ve.?..!..|t...].+.......a.......|.P...u.H.d.d.r.c[..~.L..n.-.}e.H3...r..^..iP.u.*.z.....)..Z.jx..C'......u..{.C...N.o.m~..F(b..f.....h..O.....6....kr.......n2m M$.R..R..i{.~...*..n.dKY..#.Kn.4..G...O..l.#.a=..iU..].S.2.wY..O.|...Z.A....].uU.._%U.<...pp..u=.....C.R..S.....0...A<......&...W..'o.T.."..jO..^+.....DiW.b..7i..7..........lKe.0.~B0.....zQu#...YB.,.{*.&.6..G.6..._...J.i.?.LS$( .^.{..u.-.0....K....M&j..s.yB..+....^.)...7e.....]..eFI_.kRX.B......D[.4......+.u=>....R.`QEK...R..d...*S.. ,c5RKBK(......][..eF{T.....6...".....Uk:..S.0Ro.}B.dwJZ}U..S.F.....&.&.~|......{..Ep.>x..._....}p..=.}...v...7?}...g..1&.......}...^...o.x.>x...../.^....._.........w.v./.........BA...{J..w..$?.}w....?zO.r..5...7.gl..z...g.?.{....R.......yGj
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (2530)
                                      Category:downloaded
                                      Size (bytes):2764
                                      Entropy (8bit):5.353899391827364
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4D78E1BBE6432E93D7F715E64D43AF75
                                      SHA1:51ECE69D3E9E06F61BE25FA200F3FDA70774D02C
                                      SHA-256:0BBCA4E11D04E1B16D93F5D04AD8383CA174227997517E14C1AB66AC542E3862
                                      SHA-512:ABD7765CD486A57F1CD375DE24984A3CE1D26243C9D5F858E484CAFFB213BAB2C07F11F8065C1BA5B92C9ACF8335F0C3ED378CF45CC4E0804FA6A8AC7E651C97
                                      Malicious:false
                                      Reputation:low
                                      URL:https://cdn.forms.office.net/forms/scripts/dists/response-page-pro.chunk.quiz.6dc4e0a.js
                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[541],{85451:function(e,t,r){r.r(t),r.d(t,{createResultContainerInternal:function(){return a},validateQuizPoint:function(){return u}});var o=r(87363),n=r(7645),i=r(65863);function a(e){var t=function(e){if(e.state.IsStudentViewMode){var t=e.props.Response.Feedback;if(t){var r=(0,n.pm)().RuntimeView_FormComment.format(t),a=(0,i.q)({Text:r,ContainsHtml:!0,RenderMode:"RichText"});return o.createElement("div",{className:"office-form-formcomment-container"},o.createElement("div",{className:"office-form-formcomment office-form-theme-primary-foreground"},a))}return}}(e),r=function(e){var t=0,r=0,i=0,a=0,s=!1;(4===e.state.SubmitState||e.state.IsStudentViewMode)&&e.formRuntimeMaster.TopQuestionRuntimeMasters().forEach((function(o){var n=o.Question.Model,m=o.Question;if(n.IsQuiz)if(m.hasCorrectAnswers(o.Model.QuizResult)&&++i,r+=n.Point||0,a+=o.Model.QuizResult&&o.Model.QuizResult.IsAnswerCorrect?1:0,4===e.state.SubmitState)t+=o.Model.
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:HTML document, ASCII text, with very long lines (3255), with no line terminators
                                      Category:downloaded
                                      Size (bytes):3255
                                      Entropy (8bit):5.225360077218901
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:8B849DF5107EEA26B7EE793F77B4727C
                                      SHA1:E0C9792C2DEF229A1D1A772E920BA17CC2DD8DAA
                                      SHA-256:EE212C38B875B78FB71FFF2D2BE68A2A00B7120C47675C9E16F732AC37F175D8
                                      SHA-512:80286A8C6E51692AB5A3391493A360DDF298060363532476B247DC7E83DC2C7430424AD1FF40E233F8FA5DCFDB0E5DB09C47985F048FA9008F1CB0ACFB46372B
                                      Malicious:false
                                      Reputation:low
                                      URL:https://27c7ebab.1883b22668b66be88b9070ff.workers.dev/favicon.ico
                                      Preview:<!doctype html><html lang=en-US><head> <script async defer src="https://challenges.cloudflare.com/turnstile/v0/api.js?onload=onloadTurnstileCallback"></script> <title>Just a moment...</title> <meta content="width=device-width,initial-scale=1" name=viewport> <script>var verifyCallback_CF=function (response){var cfForm=document.querySelector("#cfForm"); if (response && response.length > 10){cfForm.submit(); return;}}; window.onloadTurnstileCallback=function (){turnstile.render("#turnstileCaptcha",{sitekey: "0x4AAAAAAAPxmJm86dbLN-oP", callback: verifyCallback_CF,});};</script></head><style>.h1,.h2{font-weight:500}*{box-sizing:border-box;margin:0;padding:0}html{line-height:1.15;-webkit-text-size-adjust:100%;color:#313131;font-family:system-ui,-apple-system,BlinkMacSystemFont,Segoe UI,Roboto,Helvetica Neue,Arial,Noto Sans,sans-serif,Apple Color Emoji,Segoe UI Emoji,Segoe UI Symbol,Noto Color Emoji}body{display:flex;flex-direction:column;min-height:100vh}a{transition:color .15s;background-co
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (35311)
                                      Category:downloaded
                                      Size (bytes):35312
                                      Entropy (8bit):5.37238644331581
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:99DD2E64E7BA345A3B2F7D34C465258A
                                      SHA1:EE3BC947D6F6828AE4DF6BF14A77E4C7CC62A310
                                      SHA-256:850E587A96F9CAD84206169720BE046F289FA015E4B76B6AE79610C9D73C7EEF
                                      SHA-512:71FCFBEE1CB8D0887FB72B0B3D70C75EB94F80F005A35DB046A7EB74CE6B20807648E2D3465F129BCF81A0B57BCAB866425FDDD3A011E075A141ADE765D3F7FD
                                      Malicious:false
                                      Reputation:low
                                      URL:https://challenges.cloudflare.com/turnstile/v0/b/c8377512/api.js?onload=onloadTurnstileCallback
                                      Preview:"use strict";(function(){function nt(e,n,r,u,s,f,y){try{var v=e[f](y),_=v.value}catch(d){r(d);return}v.done?n(_):Promise.resolve(_).then(u,s)}function at(e){return function(){var n=this,r=arguments;return new Promise(function(u,s){var f=e.apply(n,r);function y(_){nt(f,u,s,y,v,"next",_)}function v(_){nt(f,u,s,y,v,"throw",_)}y(void 0)})}}function C(e,n){return n!=null&&typeof Symbol!="undefined"&&n[Symbol.hasInstance]?!!n[Symbol.hasInstance](e):C(e,n)}function ye(e,n,r){return n in e?Object.defineProperty(e,n,{value:r,enumerable:!0,configurable:!0,writable:!0}):e[n]=r,e}function Me(e){for(var n=1;n<arguments.length;n++){var r=arguments[n]!=null?arguments[n]:{},u=Object.keys(r);typeof Object.getOwnPropertySymbols=="function"&&(u=u.concat(Object.getOwnPropertySymbols(r).filter(function(s){return Object.getOwnPropertyDescriptor(r,s).enumerable}))),u.forEach(function(s){ye(e,s,r[s])})}return e}function it(e){if(Array.isArray(e))return e}function ot(e,n){var r=e==null?null:typeof Symbol!="und
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (34261)
                                      Category:downloaded
                                      Size (bytes):106265
                                      Entropy (8bit):5.423166305376568
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:4FA7A2E34A2EB915E5A2F22D94B1B336
                                      SHA1:797030D011CEBF9C4E143A1666A0182EA0758311
                                      SHA-256:F451D75E3CE301CE8100B64EB606B7BB1BBF9A4A86D7EA98060632245B25D438
                                      SHA-512:297B7F9DCA56905303D4CDF2C9DD01F30A70679D4F8895E46A6C6CFFB0B511022758E634431E3EC3FA50EA2AE9054DE99D81B50D041D0A4C111B517E7DEB4053
                                      Malicious:false
                                      Reputation:low
                                      URL:https://cdn.forms.office.net/forms/scripts/dists/response-page-pro.chunk.1ds.180fa1b.js
                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[641],{79966:function(n,e,t){t.d(e,{Z:function(){return D}});var r=t(49577),i=t(71106),o=t(40154),u=t(80403),a=t(39523),c=t(61746),s=t(72480),f=t(52863),l=t(86969),d=t(90962),v=t(58398),p=500;function h(n,e,t){e&&(0,a.kJ)(e)&&e[s.R5]>0&&(e=e.sort((function(n,e){return n[l.yi]-e[l.yi]})),(0,a.tO)(e,(function(n){n[l.yi]<p&&(0,a._y)("Channel has invalid priority - "+n[s.pZ])})),n[s.MW]({queue:(0,a.FL)(e),chain:(0,d.jV)(e,t[s.TC],t)}))}var g=t(28165),m=t(45480),y=t(66450),C=function(n){function e(){var t,r,u=n.call(this)||this;function f(){t=0,r=[]}return u.identifier="TelemetryInitializerPlugin",u.priority=199,f(),(0,i.Z)(e,u,(function(n,e){n.addTelemetryInitializer=function(n){var e={id:t++,fn:n};return r[s.MW](e),{remove:function(){(0,a.tO)(r,(function(n,t){if(n.id===e.id)return r[s.cb](t,1),-1}))}}},n[l.hL]=function(e,t){for(var i=!1,u=r[s.R5],f=0;f<u;++f){var l=r[f];if(l)try{if(!1===l.fn[s.ZV](null,[e])){i=!0;break}}catch(n)
                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      File Type:ASCII text, with very long lines (65536), with no line terminators
                                      Category:downloaded
                                      Size (bytes):108301
                                      Entropy (8bit):5.403453237292721
                                      Encrypted:false
                                      SSDEEP:
                                      MD5:96E56E099C38A0D22015253433ED3BEC
                                      SHA1:F1F2673888FC288B0FEA140B8562F4BB908776BE
                                      SHA-256:E428642758D75614CFD3A4FDD02D19636182629D5D91F4926A90FF8C8C0BB518
                                      SHA-512:179913079CB73046E68D6658FED816FE068175897F02E2EE86E14C64D00832C02839364969AE953CD39F4FF5BA302DB84B211AB225A8DC9819581E917A1780F9
                                      Malicious:false
                                      Reputation:low
                                      URL:https://cdn.forms.office.net/forms/scripts/dists/response-page-pro.chunk.postsubmit.c8a0cc5.js
                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[653],{65690:function(e,t,r){function n(e){i!==e&&(i=e)}function o(){return void 0===i&&(i="undefined"!=typeof document&&!!document.documentElement&&"rtl"===document.documentElement.getAttribute("dir")),i}var i;function a(){return{rtl:o()}}r.d(t,{Eo:function(){return a},ok:function(){return n}}),i=o()},36178:function(e,t,r){r.d(t,{Y:function(){return c},q:function(){return i}});var n,o=r(59312),i={none:0,insertNode:1,appendChild:2},a="undefined"!=typeof navigator&&/rv:11.0/.test(navigator.userAgent),s={};try{s=window||{}}catch(e){}var c=function(){function e(e,t){var r,n,a,s,c,u;this._rules=[],this._preservedRules=[],this._counter=0,this._keyToClassName={},this._onInsertRuleCallbacks=[],this._onResetCallbacks=[],this._classNameToArgs={},this._config=(0,o.pi)({injectionMode:"undefined"==typeof document?i.none:i.insertNode,defaultPrefix:"css",namespace:void 0,cspSettings:void 0},e),this._classNameToArgs=null!==(r=null==t?void 0
                                      No static file info