Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.com

Overview

General Information

Sample URL:https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.com
Analysis ID:1375507

Detection

Score:2
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Creates files inside the system directory
Found iframes
HTML body contains password input but no form action
Stores files to the Windows start menu directory
URL contains potential PII (phishing indication)

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6608 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.com MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 6444 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2572 --field-trial-handle=2544,i,14601828975054631518,15686549178273406203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 3292 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5624 --field-trial-handle=2544,i,14601828975054631518,15686549178273406203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 5256 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4784 --field-trial-handle=2544,i,14601828975054631518,15686549178273406203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • chrome.exe (PID: 3760 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 3000 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=2032,i,14656047032145551079,2220650336726129832,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: Iframe src: https://accounts.youtube.com/accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=-1561588844&timestamp=1705421173244
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: Iframe src: /_/bscframe
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: Iframe src: https://accounts.youtube.com/accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=-1561588844&timestamp=1705421173244
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: Iframe src: /_/bscframe
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: Iframe src: https://accounts.youtube.com/accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=-1561588844&timestamp=1705421173244
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: Iframe src: /_/bscframe
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: Iframe src: https://accounts.youtube.com/accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=-1561588844&timestamp=1705421173244
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: Iframe src: /_/bscframe
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: Iframe src: https://accounts.youtube.com/accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=-1561588844&timestamp=1705421173244
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: Iframe src: /_/bscframe
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.comSample URL: PII: dscharge@magmutual.com
Source: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.comSample URL: PII: dscharge@magmutual.com
Source: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.comSample URL: PII: dscharge@magmutual.com
Source: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.comSample URL: PII: dscharge@magmutual.com
Source: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.comSample URL: PII: dscharge@magmutual.com
Source: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.comSample URL: PII: dscharge@magmutual.com
Source: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.comSample URL: PII: dscharge@magmutual.com
Source: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.comSample URL: PII: dscharge@magmutual.com
Source: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.comSample URL: PII: dscharge@magmutual.com
Source: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.comSample URL: PII: dscharge@magmutual.com
Source: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.comSample URL: PII: dscharge@magmutual.com
Source: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.comSample URL: PII: dscharge@magmutual.com
Source: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.comSample URL: PII: dscharge@magmutual.com
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: <input type="password" .../> found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No <meta name="author".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No <meta name="author".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No <meta name="author".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No <meta name="author".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No <meta name="author".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No <meta name="copyright".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No <meta name="copyright".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No <meta name="copyright".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No <meta name="copyright".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comHTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.17:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.17:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.17:49753 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49754 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.17:49762 version: TLS 1.2
Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.17:49766 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.237.254:443 -> 192.168.2.17:49770 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.140.48.131:443 -> 192.168.2.17:49772 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49777 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49778 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49779 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49780 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.7:443 -> 192.168.2.17:49784 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.7:443 -> 192.168.2.17:49790 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.123.128.254:443 -> 192.168.2.17:49791 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.138.254:443 -> 192.168.2.17:49794 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.161.157.233:443 -> 192.168.2.17:49797 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49800 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.7:443 -> 192.168.2.17:49801 version: TLS 1.2
Source: chrome.exeMemory has grown: Private usage: 16MB later: 29MB
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 13.67.144.177
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 13.67.144.177
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownDNS traffic detected: queries for: storage.cloud.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49683 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49684 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.17:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.51.58.94:443 -> 192.168.2.17:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.17:49753 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49754 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.17:49762 version: TLS 1.2
Source: unknownHTTPS traffic detected: 204.79.197.222:443 -> 192.168.2.17:49766 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.237.254:443 -> 192.168.2.17:49770 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.140.48.131:443 -> 192.168.2.17:49772 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49777 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49778 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49779 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49780 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.7:443 -> 192.168.2.17:49784 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.7:443 -> 192.168.2.17:49790 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.123.128.254:443 -> 192.168.2.17:49791 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.138.254:443 -> 192.168.2.17:49794 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.161.157.233:443 -> 192.168.2.17:49797 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49800 version: TLS 1.2
Source: unknownHTTPS traffic detected: 173.222.162.7:443 -> 192.168.2.17:49801 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_6608_580709992
Source: classification engineClassification label: clean2.win@25/58@24/184
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.com
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2572 --field-trial-handle=2544,i,14601828975054631518,15686549178273406203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5624 --field-trial-handle=2544,i,14601828975054631518,15686549178273406203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4784 --field-trial-handle=2544,i,14601828975054631518,15686549178273406203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2572 --field-trial-handle=2544,i,14601828975054631518,15686549178273406203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=2032,i,14656047032145551079,2220650336726129832,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=2032,i,14656047032145551079,2220650336726129832,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5624 --field-trial-handle=2544,i,14601828975054631518,15686549178273406203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4784 --field-trial-handle=2544,i,14601828975054631518,15686549178273406203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
1
Drive-by Compromise
Windows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
11
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
Encrypted Channel
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Non-Application Layer Protocol
SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
Domain AccountsAtLogon Script (Windows)1
Extra Window Memory Injection
1
Extra Window Memory Injection
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
Application Layer Protocol
Data Encrypted for ImpactDNS ServerEmail Addresses

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www3.l.google.com
142.251.41.14
truefalse
    high
    accounts.google.com
    172.253.63.84
    truefalse
      high
      play.google.com
      142.251.40.206
      truefalse
        high
        www.google.com
        142.251.41.4
        truefalse
          high
          clients.l.google.com
          142.251.40.238
          truefalse
            high
            clients1.google.com
            unknown
            unknownfalse
              high
              storage.cloud.google.com
              unknown
              unknownfalse
                high
                clients2.google.com
                unknown
                unknownfalse
                  high
                  accounts.youtube.com
                  unknown
                  unknownfalse
                    high
                    NameMaliciousAntivirus DetectionReputation
                    https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&followup=https%3A%2F%2Fstorage.cloud.google.com%2Fbuo00%2Fcloud.html&ifkv=ASKXGp3bh9bPAcwfGYKyRWWoMHrqP0S6VMmTpmmzofDxgdbMLEBf3KSbKQlZk5PnG3sHC6XyF2LvdQ&passive=1209600&service=cds&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-268335926%3A1705421170439572&theme=glif#dscharge@magmutual.comfalse
                      high
                      https://accounts.google.com/_/bscframefalse
                        high
                        https://accounts.youtube.com/accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=-1561588844&timestamp=1705421173244false
                          high
                          • No. of IPs < 25%
                          • 25% < No. of IPs < 50%
                          • 50% < No. of IPs < 75%
                          • 75% < No. of IPs
                          IPDomainCountryFlagASNASN NameMalicious
                          142.250.65.170
                          unknownUnited States
                          15169GOOGLEUSfalse
                          1.1.1.1
                          unknownAustralia
                          13335CLOUDFLARENETUSfalse
                          142.250.65.195
                          unknownUnited States
                          15169GOOGLEUSfalse
                          172.253.63.84
                          accounts.google.comUnited States
                          15169GOOGLEUSfalse
                          142.251.40.238
                          clients.l.google.comUnited States
                          15169GOOGLEUSfalse
                          142.251.40.206
                          play.google.comUnited States
                          15169GOOGLEUSfalse
                          172.253.62.84
                          unknownUnited States
                          15169GOOGLEUSfalse
                          172.253.122.84
                          unknownUnited States
                          15169GOOGLEUSfalse
                          142.250.81.227
                          unknownUnited States
                          15169GOOGLEUSfalse
                          142.251.40.142
                          unknownUnited States
                          15169GOOGLEUSfalse
                          142.251.40.132
                          unknownUnited States
                          15169GOOGLEUSfalse
                          142.251.41.14
                          www3.l.google.comUnited States
                          15169GOOGLEUSfalse
                          239.255.255.250
                          unknownReserved
                          unknownunknownfalse
                          142.251.40.163
                          unknownUnited States
                          15169GOOGLEUSfalse
                          142.250.72.99
                          unknownUnited States
                          15169GOOGLEUSfalse
                          142.251.41.4
                          www.google.comUnited States
                          15169GOOGLEUSfalse
                          142.250.31.84
                          unknownUnited States
                          15169GOOGLEUSfalse
                          IP
                          192.168.2.17
                          192.168.2.18
                          Joe Sandbox version:38.0.0 Ammolite
                          Analysis ID:1375507
                          Start date and time:2024-01-16 17:05:38 +01:00
                          Joe Sandbox product:CloudBasic
                          Overall analysis duration:
                          Hypervisor based Inspection enabled:false
                          Report type:light
                          Cookbook file name:defaultwindowsinteractivecookbook.jbs
                          Sample URL:https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.com
                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                          Number of analysed new started processes analysed:19
                          Number of new started drivers analysed:0
                          Number of existing processes analysed:0
                          Number of existing drivers analysed:0
                          Number of injected processes analysed:0
                          Technologies:
                          • EGA enabled
                          Analysis Mode:stream
                          Analysis stop reason:Timeout
                          Detection:CLEAN
                          Classification:clean2.win@25/58@24/184
                          • Exclude process from analysis (whitelisted): SgrmBroker.exe, MoUsoCoreWorker.exe, svchost.exe
                          • Excluded IPs from analysis (whitelisted): 142.250.72.99, 34.104.35.123, 142.250.65.195, 142.250.81.227
                          • Excluded domains from analysis (whitelisted): fs.microsoft.com, edgedl.me.gvt1.com, fonts.gstatic.com, clientservices.googleapis.com, www.gstatic.com
                          • Not all processes where analyzed, report is missing behavior information
                          • VT rate limit hit for: https://storage.cloud.google.com/buo00/cloud.html#dscharge@magmutual.com
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jan 16 15:06:10 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                          Category:dropped
                          Size (bytes):2677
                          Entropy (8bit):3.994864682955372
                          Encrypted:false
                          SSDEEP:
                          MD5:A391222E3B32754E4DC37D099589C6C7
                          SHA1:E3668320573773A98D1387FA3E2DBC1922A90D5A
                          SHA-256:08DA87C90A0C192D9B38E65BF0D81FD3B01E4A41CAEB358ADAF428271D4FF981
                          SHA-512:39E20030ABF249AFA523A6B36EEDE586D2A4EA3364B25B468C68AED8D85F2A85905ADFBEF9EC1EC2988E8A9771B21EAEB4CDA8FB7BF8EBE327DCB1C0CA241C71
                          Malicious:false
                          Reputation:low
                          Preview:L..................F.@.. ...$+.,....D...H......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I0X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V0X.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V0X.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V0X............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V0X............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jan 16 15:06:10 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                          Category:dropped
                          Size (bytes):2679
                          Entropy (8bit):4.0131006609273605
                          Encrypted:false
                          SSDEEP:
                          MD5:C7C77A2F8951531160FB5FC8AB974356
                          SHA1:3400AE81D80C2D2CB983AB0B855B066F1304C9C5
                          SHA-256:4B7E5224560BFEFCC558F07D775915C2D7278D168D29CFC8610EA679FD9CF9DC
                          SHA-512:7F5EF7DC613FB6C2E8B6348347470C663E7377A06A174048368170F6AAD8A0EEFC04F39EA122FE41638F1DFA8341845F2643C5B704ADBB50381B66B4B451E8B3
                          Malicious:false
                          Reputation:low
                          Preview:L..................F.@.. ...$+.,.....-..H......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I0X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V0X.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V0X.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V0X............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V0X............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                          Category:dropped
                          Size (bytes):2693
                          Entropy (8bit):4.020161223677246
                          Encrypted:false
                          SSDEEP:
                          MD5:5A0E8BC32CB30445E60646CBFB556D85
                          SHA1:1D3C78AF481F6A9ED207D81D22ABF6F86670EC22
                          SHA-256:7CF1DA1978BDC454286E3EAD5A96FD11DF5AD7F310101E03935DAEE6A20621E2
                          SHA-512:C31090C1828B66B19DA0FD211932DA9DC244659907BA1EF62E1366E043246AAFE44226BF387B08A388C40861CC304D3D791AB9BEA2C1F0A86B112C936BFDB581
                          Malicious:false
                          Reputation:low
                          Preview:L..................F.@.. ...$+.,.....v. ;.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I0X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V0X.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V0X.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V0X............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jan 16 15:06:10 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                          Category:dropped
                          Size (bytes):2681
                          Entropy (8bit):4.008461998078777
                          Encrypted:false
                          SSDEEP:
                          MD5:7B9F4029B14B32DE8AB71CB8705DBA86
                          SHA1:88F594D2A8B0C77F96904B360BB6A72C04B445DB
                          SHA-256:51099B836F185FC366A7F73B21A25EEF8F52D3B73E46FEBBEAC0876A7FCD501D
                          SHA-512:AFB4DACE3939865CB729DC2DF4BDC03D7CC1C67CA5EB849803BB212CFC9B0E99664D6F96488D7AEAB01BCF29D95563607A46ED0E43E761967307A1B1C3D60409
                          Malicious:false
                          Reputation:low
                          Preview:L..................F.@.. ...$+.,.....e..H......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I0X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V0X.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V0X.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V0X............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V0X............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jan 16 15:06:10 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                          Category:dropped
                          Size (bytes):2681
                          Entropy (8bit):4.001165711868969
                          Encrypted:false
                          SSDEEP:
                          MD5:BE8E952E3E9C601BBDD51D06A3C5CB0E
                          SHA1:DE97BD986F39AF5BA46557FE514EE8BA67C01DE4
                          SHA-256:20BA3099C2988291E92A541567A6CA498F2D6EC46153062C820960C7F8D57509
                          SHA-512:3D70D077B488C724EC603FF628077687117443176F475B9EE7E316CDF4ED27409EC44AEA14AEBBE5EFBFF7420D4C7CC1547EC25D569EC25134759CC41FBA1C0C
                          Malicious:false
                          Reputation:low
                          Preview:L..................F.@.. ...$+.,.......H......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I0X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V0X.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V0X.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V0X............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V0X............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jan 16 15:06:10 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                          Category:dropped
                          Size (bytes):2683
                          Entropy (8bit):4.010667833957433
                          Encrypted:false
                          SSDEEP:
                          MD5:217738A022BCC2B9E8DEEF094E48AF15
                          SHA1:5C3D23D34C360768DA3368E71F0E4AB2FA925507
                          SHA-256:8D0632B5BE267870030839B2A6382BA0D1E5EAC13294C24CC178CD3696C75083
                          SHA-512:9249B68861AB3F41D00E932C1245DA4F4EE7C03733C98F8483BD510ADF629E752966511CDFB048AF3D94AA926EBD7531A7862BF6BE5C6892442799199771EF22
                          Malicious:false
                          Reputation:low
                          Preview:L..................F.@.. ...$+.,....+...H......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I0X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V0X.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V0X.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V0X............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V0X............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:ASCII text, with no line terminators
                          Category:downloaded
                          Size (bytes):52
                          Entropy (8bit):4.542000661265563
                          Encrypted:false
                          SSDEEP:
                          MD5:B3B89B9C275343BC6798E3A83564FDDB
                          SHA1:32367475C527C3F5E5DB0BF42C348816FF4D157B
                          SHA-256:900FB968F7FD9EA55F600AC9002A89E56AB56597DA7BDE04DEAAE6CC77AEB276
                          SHA-512:ADB6938104E802B0936630B216CDE732F21ECA6E60E7A31D1B9C8FF52B5A66A712A7ECDE3F8ED4915D15C0A71C33A9788060E1E22999094C39020A1F8C636874
                          Malicious:false
                          Reputation:low
                          URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xNDkSHgmA6QC9dWevzxIFDRkBE_oSBQ3oIX6GEgUN05ioBw==?alt=proto
                          Preview:CiUKDQ0ZARP6GgQIVhgCIAEKCw3oIX6GGgQISxgCCgcN05ioBxoA
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:ASCII text, with very long lines (663)
                          Category:downloaded
                          Size (bytes):3238
                          Entropy (8bit):5.364594322454931
                          Encrypted:false
                          SSDEEP:
                          MD5:65BA50756588185A6391E750B28B06BA
                          SHA1:E634CDDE8E44A7C3CA8D34FCC1F3235A72A7C9F7
                          SHA-256:325E5141A04513B760AC5CBB1A3AA21BCDF795616E76A81B199FECEBE46FF713
                          SHA-512:925DC827DB819A6B7AAAA27CB4CB52F808A64813220C8E3146C061DCBF4A31AA4808CA7D702111F2C22214F8FA20235E954EAC6E9F156AAEB9922289B26190B2
                          Malicious:false
                          Reputation:low
                          URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.nOJ7WSKZu4M.es5.O/ck=boq-identity.AccountsSignInUi.7fQcyxKRGI4.L.B1.O/am=P8BCEo4FQIyZ5Zy_Z5wcBgAAAAAAAAAAWAPYAQ/d=1/exm=AvtSve,Ctsu,EFQ78c,EGw7Od,EN3i8d,I6YDgd,IZ1fbc,IZT63,K0PMbc,KUM7Z,L1AAkb,LDQI,LEikZe,MpJwZc,NOeYWe,O6y8ed,PHUIyb,PrPYRd,Rkm0ef,RqjULd,Rusgnf,SCuOPb,STuCOe,SpsfSb,UPKV3d,UUJqVe,Uas9Hd,W2YXuc,YHI3We,YTxL4,ZUKRxc,_b,_tp,aW3pY,b3kMqb,bPkrc,bSspM,bTi8wc,byfTOb,eVCnO,fFzhe,fJpY1b,fqEYIb,hc6Ubd,hmHrle,inNHtf,kSPLL,lsjVmc,ltDFwf,lwddkf,mWLH9d,my67ye,n73qwf,njlZCf,oLggrd,pxq3x,qPfo0c,qmdT9,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,ws9Tlc,xBaz7b,xQtZb,yRXbo,ywOR5c,zbML3c,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlESPRnh-JZZP_yCycaEkysrUryWfw/ee=ASJRFf:LANRae;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:BDnJmb;EmZ2Bf:zr1jrb;Erl4fe:FloWmf;JsbNhc:Xd8iUd;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Oj465e:KG2eXe;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;UpnZUd:nnwwYc;XdiAjb:NLiXbe;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;eBAeSb:zbML3c;iFQyKf:vfuNJf;io8t5d:yDVVkb;kMFpHd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:fqEYIb;qddgKe:xQtZb;sP4Vbe:VwDzFe;uY49fb:COQbmf;ul9GGd:VDovNc;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=ZwDk9d,RMhBfe"
                          Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("ZwDk9d");.var ux=function(a){_.I.call(this,a.Ha)};_.z(ux,_.I);ux.Oa=_.I.Oa;ux.Ba=_.I.Ba;ux.prototype.cM=function(a){return _.Xe(this,{Xa:{pN:_.Yk}}).then(function(b){var c=window._wjdd,d=window._wjdc;return!c&&d?new _.cj(function(e){window._wjdc=function(f){d(f);e(wCa(f,b,a))}}):wCa(c,b,a)})};var wCa=function(a,b,c){return(a=a&&a[c])?a:b.Xa.pN.cM(c)};.ux.prototype.aa=function(a,b){var c=_.Zqa(b).Xg;if(c.startsWith("$")){var d=_.yn.get(a);_.ur[b]&&(d||(d={},_.yn.set(a,d)),d[c]=_.ur[b],delete _.ur[b],_.vr--);if(d)if(a=d[c])b=_.We(a);else throw Error("Kb`"+b);else b=null}else b=null;return b};_.ls(_.sca,ux);._.m();._.k("SNUn3");._.vCa=new _.Kl(_.og);._.m();._.k("RMhBfe");.var xCa=function(a,b){a=_.tpa(a,b);return 0==a.length?null:a[0].tb},yCa=function(){return Object.values(_.sq).reduce(function(a,b){return a+Object.keys(b).length},0)},zCa=function(){return Object.entries(_
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
                          Category:downloaded
                          Size (bytes):5430
                          Entropy (8bit):3.6534652184263736
                          Encrypted:false
                          SSDEEP:
                          MD5:F3418A443E7D841097C714D69EC4BCB8
                          SHA1:49263695F6B0CDD72F45CF1B775E660FDC36C606
                          SHA-256:6DA5620880159634213E197FAFCA1DDE0272153BE3E4590818533FAB8D040770
                          SHA-512:82D017C4B7EC8E0C46E8B75DA0CA6A52FD8BCE7FCF4E556CBDF16B49FC81BE9953FE7E25A05F63ECD41C7272E8BB0A9FD9AEDF0AC06CB6032330B096B3702563
                          Malicious:false
                          Reputation:low
                          URL:https://www.google.com/favicon.ico
                          Preview:............ .h...&... .... .........(....... ..... ............................................0...................................................................................................................................v.].X.:.X.:.r.Y........................................q.X.S.4.S.4.S.4.S.4.S.4.S.4...X....................0........q.W.S.4.X.:.................J...A...g.........................K.H.V.8..........................F..B.....................,.......................................B..............................................B..B..B..B..B...u..........................................B..B..B..B..B...{.................5.......k...........................................................7R..8F.................................................2........Vb..5C..;I..................R^.....................0................Xc..5C..5C..5C..5C..5C..5C..lv..........................................]i..<J..:G..Zf....................................................
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:HTML document, ASCII text, with very long lines (687)
                          Category:downloaded
                          Size (bytes):4134
                          Entropy (8bit):5.372195203947504
                          Encrypted:false
                          SSDEEP:
                          MD5:AD7B1FB9C8BC165B42508DC147796AC2
                          SHA1:36E3BC93E74FDFBB170B18EB865A65588EFCC04D
                          SHA-256:B8ABD62C93FD04D04FD699794D1FB3B3363BBE9EDB28068CC16511DA663DB315
                          SHA-512:C945A1442B50A01990464EE0C0D44782E6579B1BB110101951B9E488F40A7584D8ABE1925C7767CF905553A4C6F51F1DFC2B25CFB540684060C19E55CD48EEEA
                          Malicious:false
                          Reputation:low
                          URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.nOJ7WSKZu4M.es5.O/ck=boq-identity.AccountsSignInUi.7fQcyxKRGI4.L.B1.O/am=P8BCEo4FQIyZ5Zy_Z5wcBgAAAAAAAAAAWAPYAQ/d=1/exm=A7fCU,AvtSve,Ctsu,EFQ78c,EGw7Od,EN3i8d,I6YDgd,IZ1fbc,IZT63,K0PMbc,KUM7Z,L1AAkb,LDQI,LEikZe,MpJwZc,NOeYWe,O6y8ed,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,Rusgnf,SCuOPb,STuCOe,SpsfSb,UPKV3d,UUJqVe,Uas9Hd,VwDzFe,W2YXuc,YHI3We,YTxL4,ZUKRxc,ZwDk9d,_b,_tp,aW3pY,b3kMqb,bPkrc,bSspM,bTi8wc,bm51tf,byfTOb,eVCnO,fFzhe,fJpY1b,fqEYIb,hc6Ubd,hmHrle,inNHtf,kSPLL,lsjVmc,ltDFwf,lwddkf,mWLH9d,my67ye,n73qwf,njlZCf,oLggrd,pxq3x,qPfo0c,qmdT9,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,w9hDv,ws9Tlc,xBaz7b,xQtZb,yRXbo,ywOR5c,zbML3c,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlESPRnh-JZZP_yCycaEkysrUryWfw/ee=ASJRFf:LANRae;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:BDnJmb;EmZ2Bf:zr1jrb;Erl4fe:FloWmf;JsbNhc:Xd8iUd;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Oj465e:KG2eXe;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;UpnZUd:nnwwYc;XdiAjb:NLiXbe;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;eBAeSb:zbML3c;iFQyKf:vfuNJf;io8t5d:yDVVkb;kMFpHd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:fqEYIb;qddgKe:xQtZb;sP4Vbe:VwDzFe;uY49fb:COQbmf;ul9GGd:VDovNc;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=NTMZac,sOXFj,q0xTif,ZZ4WUe"
                          Preview:"use strict";_F_installCss(".N7rBcd{overflow-x:auto}sentinel{}");.this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.mg(_.lma);._.k("sOXFj");.var rs=function(a){_.I.call(this,a.Ha)};_.z(rs,_.I);rs.Oa=_.I.Oa;rs.Ba=_.I.Ba;rs.prototype.aa=function(a){return a()};_.ls(_.kma,rs);._.m();._.k("oGtAuc");._.Jra=new _.Kl(_.lma);._.m();._.k("q0xTif");.var Gsa=function(a){var b=function(d){_.vn(d)&&(_.vn(d).qc=null,_.Es(d,null));d.XyHi9&&(d.XyHi9=null)};b(a);a=a.querySelectorAll("[c-wiz]");for(var c=0;c<a.length;c++)b(a[c])},Qs=function(a){_.Oq.call(this,a.Ha);this.Ra=this.dom=null;if(this.Yh()){var b=_.Ml(this.Df(),[_.rm,_.qm]);b=_.ej([b[_.rm],b[_.qm]]).then(function(c){this.Ra=c[0];this.dom=c[1]},null,this);_.cs(this,b)}this.Ma=a.nh.f7};_.z(Qs,_.Oq);Qs.Ba=function(){return{nh:{f7:function(){return _.Wf(this)}}}};Qs.prototype.getContext=function(a){return this.Ma.getContext(a)};.Qs.prototype.getData=function(a){return this.Ma.getData(a)};Qs.protot
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:ASCII text, with very long lines (775)
                          Category:downloaded
                          Size (bytes):1479
                          Entropy (8bit):5.29976786498676
                          Encrypted:false
                          SSDEEP:
                          MD5:16FCE40330CC27A19E40EAF6EFF810F9
                          SHA1:0A7AAEE23F5602D78BA63CD165DA7CCB275268A3
                          SHA-256:AA1889B9FCAF667E32C3325B78B6759EAB8E05FC15A7D8528C49FEE623629904
                          SHA-512:06D7CE7A7999BCF9F61602C2784ACD76DA366F882346D33D332D9C179263C09E56D1BC8723DE699269A7F6FC5E146F0364B9BBF17FA03181EA38DF0068B5A5DA
                          Malicious:false
                          Reputation:low
                          URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.nOJ7WSKZu4M.es5.O/ck=boq-identity.AccountsSignInUi.7fQcyxKRGI4.L.B1.O/am=P8BCEo4FQIyZ5Zy_Z5wcBgAAAAAAAAAAWAPYAQ/d=1/exm=AvtSve,Ctsu,EFQ78c,EGw7Od,EN3i8d,I6YDgd,IZ1fbc,IZT63,K0PMbc,KUM7Z,L1AAkb,LDQI,LEikZe,MpJwZc,NOeYWe,O6y8ed,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,Rusgnf,SCuOPb,STuCOe,SpsfSb,UPKV3d,UUJqVe,Uas9Hd,W2YXuc,YHI3We,YTxL4,ZUKRxc,ZwDk9d,_b,_tp,aW3pY,b3kMqb,bPkrc,bSspM,bTi8wc,byfTOb,eVCnO,fFzhe,fJpY1b,fqEYIb,hc6Ubd,hmHrle,inNHtf,kSPLL,lsjVmc,ltDFwf,lwddkf,mWLH9d,my67ye,n73qwf,njlZCf,oLggrd,pxq3x,qPfo0c,qmdT9,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,ws9Tlc,xBaz7b,xQtZb,yRXbo,ywOR5c,zbML3c,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlESPRnh-JZZP_yCycaEkysrUryWfw/ee=ASJRFf:LANRae;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:BDnJmb;EmZ2Bf:zr1jrb;Erl4fe:FloWmf;JsbNhc:Xd8iUd;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Oj465e:KG2eXe;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;UpnZUd:nnwwYc;XdiAjb:NLiXbe;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;eBAeSb:zbML3c;iFQyKf:vfuNJf;io8t5d:yDVVkb;kMFpHd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:fqEYIb;qddgKe:xQtZb;sP4Vbe:VwDzFe;uY49fb:COQbmf;ul9GGd:VDovNc;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=bm51tf"
                          Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("kMFpHd");._.YSa=new _.Kl(_.fm);._.m();._.k("bm51tf");.var aTa=!!(_.$g[0]>>21&1);var cTa=function(a,b,c,d,e){this.ea=a;this.ta=b;this.ja=c;this.Ca=d;this.Fa=e;this.aa=0;this.da=bTa(this)},dTa=function(a){var b={};_.Ma(a.xM(),function(e){b[e]=!0});var c=a.jM(),d=a.qM();return new cTa(a.jJ(),1E3*c.aa(),a.RL(),1E3*d.aa(),b)},bTa=function(a){return Math.random()*Math.min(a.ta*Math.pow(a.ja,a.aa),a.Ca)},nF=function(a,b){return a.aa>=a.ea?!1:null!=b?!!a.Fa[b]:!0};var oF=function(a){_.I.call(this,a.Ha);this.Bc=null;this.ea=a.Ea.LP;this.ja=a.Ea.metadata;a=a.Ea.P9;this.da=a.ea.bind(a)};_.z(oF,_.I);oF.Oa=_.I.Oa;oF.Ba=function(){return{Ea:{LP:_.ZSa,metadata:_.YSa,P9:_.RSa}}};oF.prototype.aa=function(a,b){if(1!=this.ja.getType(a.Cd()))return _.ym(a);var c=this.ea.aa;return(c=c?dTa(c):null)&&nF(c)?_.Fra(a,eTa(this,a,b,c)):_.ym(a)};.var eTa=function(a,b,c,d){return c.then(function(e){r
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:Web Open Font Format (Version 2), TrueType, length 21464, version 1.0
                          Category:downloaded
                          Size (bytes):21464
                          Entropy (8bit):7.991635778215233
                          Encrypted:true
                          SSDEEP:
                          MD5:923A543CC619EA568F91B723D9FB1EF0
                          SHA1:6F4ADE25559645C741D7327C6E16521E43D7E1F9
                          SHA-256:BF7344209EDB1BE5A2886C425CF6334A102D76CBEA1471FD50171E2EE92877CD
                          SHA-512:A4153751761CD67465374828B0514D7773B8C4ED37779D1ECFD4F19BE4FAA171585C8EE0B4DB59B556399D5D2B9809BA87E04D4715E9D090E1F488D02219D555
                          Malicious:false
                          Reputation:low
                          URL:https://fonts.gstatic.com/s/googlesans/v14/4UaGrENHsxJlGDuGo1OIlL3Owp4.woff2
                          Preview:wOF2......S...........St.............................*....`..~..<..u.....H........6.$..|. ..r..K..........V...@yF#b...>.[<;P..@*.....OINd(...T...C..T.w.s.b..$.....6+. ....R8E$..o..f."MD.@T"...fH..fX..O....AA..F*....+v.Q(KpXF..U"..x@...3|l..E..<.O..~..5M}.".q.#Y9....c.o.s...M.Cr..Dt.,..CtI.O..{D......H..*.+>*K..:.Y..-.l.v......'.....^.Y.k..E..c..~..S..P0.@.....<.!(.P.u.g.2....y..y..Z...v.^..lu.dC.a..o....{.o....h3A.K.I..-.O,..}.c>....Q1]....($..........s..b.X..........CJ.+..4.gE4T.S.*{g......(^...bA,...~..R..p...<G."..y.G...k..*'...i.u....I..S....\.......e$..m.2...{K........V......{me.%.}...P3...{.T..i..Av...K..g.... ...R..n..{m....t@Z....1A.H.2...^..R5)..4}..(...T......=...Pg...Y....y..e.$...]U..0.....8..Fs.(..O.....&..f,g..5..1.yo9..:cy...e..A.......i...i...G..4`)..#j.<+..{ai..[..[~.(,......X......3.f.m+3...B......_D.F.X.i.Y#.X......}_.d..`.i..i......T...7v..A.......?..c..~..g..w.D.H)%..B.!.......:.....ZE{........m.FN.....k...0.X...
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:ASCII text, with very long lines (1299)
                          Category:downloaded
                          Size (bytes):114724
                          Entropy (8bit):5.551213200680841
                          Encrypted:false
                          SSDEEP:
                          MD5:5A4453E9E3E19DE3FBABC55106F72397
                          SHA1:7DCACF570ADA05AD90A3C19A59ED5443121DA6E6
                          SHA-256:2E0DB94DBC625420B47C18DBE0CCD34D4A9AA08D15023E51F938AEDC753B0E2B
                          SHA-512:ABCC8E5C5D4B5988F0AC5B47AAD04A137E26A315F6E5CE577A2227B350ABDB62AAC14A447F0DBD6EFB6DF43C9573DCDCAF1DD862AABA6667F612B3448E305B9B
                          Malicious:false
                          Reputation:low
                          URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.nOJ7WSKZu4M.es5.O/ck=boq-identity.AccountsSignInUi.7fQcyxKRGI4.L.B1.O/am=P8BCEo4FQIyZ5Zy_Z5wcBgAAAAAAAAAAWAPYAQ/d=1/exm=AvtSve,EFQ78c,EGw7Od,EN3i8d,I6YDgd,IZT63,K0PMbc,KUM7Z,L1AAkb,LDQI,LEikZe,MpJwZc,NOeYWe,O6y8ed,PrPYRd,Rkm0ef,SCuOPb,STuCOe,SpsfSb,UUJqVe,Uas9Hd,YHI3We,YTxL4,ZUKRxc,_b,_tp,aW3pY,b3kMqb,bSspM,byfTOb,eVCnO,fFzhe,fJpY1b,fqEYIb,hc6Ubd,hmHrle,inNHtf,lsjVmc,lwddkf,mWLH9d,my67ye,n73qwf,njlZCf,oLggrd,qmdT9,siKnQd,t2srLd,tUnxGc,vHEMJe,vfuNJf,ws9Tlc,xBaz7b,xQtZb,zbML3c,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlESPRnh-JZZP_yCycaEkysrUryWfw/ee=ASJRFf:LANRae;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:BDnJmb;EmZ2Bf:zr1jrb;Erl4fe:FloWmf;JsbNhc:Xd8iUd;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Oj465e:KG2eXe;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;UpnZUd:nnwwYc;XdiAjb:NLiXbe;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;eBAeSb:zbML3c;iFQyKf:vfuNJf;io8t5d:yDVVkb;kMFpHd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:fqEYIb;qddgKe:xQtZb;sP4Vbe:VwDzFe;uY49fb:COQbmf;ul9GGd:VDovNc;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=ltDFwf,Rusgnf,Ctsu,UPKV3d,bPkrc,W2YXuc,pxq3x,IZ1fbc,soHxf,kSPLL,qPfo0c,yRXbo,bTi8wc,ywOR5c,PHUIyb"
                          Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("ltDFwf");.var Krb=_.w("ltDFwf");var jV=function(a){_.J.call(this,a.Ha);var b=this.oa();this.pb=this.Qa("P1ekSe");this.mb=this.Qa("cQwEuf");this.da=b.getData("progressvalue").number(0);this.ja=b.getData("buffervalue").number(1);this.Ca=b.yb("B6Vhqe");this.Ma=b.yb("juhVM");this.ta=b.yb("D6TUi");this.aa=b.yb("qdulke");this.La=0!==this.da;this.Ka=1!==this.ja;this.Fa=[];this.ea=_.It(this).Yb(function(){this.Fa.length&&(this.Fa.forEach(this.o8,this),this.Fa=[]);this.La&&(this.La=!1,_.as(this.pb,"transform","scaleX("+this.da+")"));this.Ka&&.(this.Ka=!1,_.as(this.mb,"transform","scaleX("+this.ja+")"));_.As(b,"B6Vhqe",this.Ca);_.As(b,"D6TUi",this.ta);_.As(b,"juhVM",this.Ma);_.As(b,"qdulke",this.aa)}).build();this.ea();_.Uh&&_.It(this).Yb(function(){b.ob("ieri7c")}).ze().build()();_.mA(this.oa().el(),this.Sa.bind(this))};_.z(jV,_.J);jV.Ba=_.J.Ba;.jV.prototype.Sa=function(a,b){Lrb(
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:ASCII text, with very long lines (405)
                          Category:downloaded
                          Size (bytes):1600
                          Entropy (8bit):5.232577190477029
                          Encrypted:false
                          SSDEEP:
                          MD5:9893B7BF270B6040B21043437BE2F99A
                          SHA1:FC78C7464AC25475BC1A6E0B88B8AABD781B4D28
                          SHA-256:C0857956EA6D45C6C6CEE3A976C5FABBD2960E2CF30F1692C974C43E56A49FF3
                          SHA-512:38198C8F65A585FF67EB9CD1BC843EF3A24D5EA80B1F8CB2B00FE9A3891667B142B2F6A85529BB7441CCF86D256A83A835AAC1F6CD5F6A9378B2B71DB0F2F71A
                          Malicious:false
                          Reputation:low
                          URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.nOJ7WSKZu4M.es5.O/ck=boq-identity.AccountsSignInUi.7fQcyxKRGI4.L.B1.O/am=P8BCEo4FQIyZ5Zy_Z5wcBgAAAAAAAAAAWAPYAQ/d=1/exm=AvtSve,Ctsu,EFQ78c,EGw7Od,EN3i8d,I6YDgd,IZ1fbc,IZT63,K0PMbc,KUM7Z,L1AAkb,LDQI,LEikZe,MpJwZc,NOeYWe,O6y8ed,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,Rusgnf,SCuOPb,STuCOe,SpsfSb,UPKV3d,UUJqVe,Uas9Hd,W2YXuc,YHI3We,YTxL4,ZUKRxc,ZwDk9d,_b,_tp,aW3pY,b3kMqb,bPkrc,bSspM,bTi8wc,bm51tf,byfTOb,eVCnO,fFzhe,fJpY1b,fqEYIb,hc6Ubd,hmHrle,inNHtf,kSPLL,lsjVmc,ltDFwf,lwddkf,mWLH9d,my67ye,n73qwf,njlZCf,oLggrd,pxq3x,qPfo0c,qmdT9,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,ws9Tlc,xBaz7b,xQtZb,yRXbo,ywOR5c,zbML3c,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlESPRnh-JZZP_yCycaEkysrUryWfw/ee=ASJRFf:LANRae;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:BDnJmb;EmZ2Bf:zr1jrb;Erl4fe:FloWmf;JsbNhc:Xd8iUd;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Oj465e:KG2eXe;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;UpnZUd:nnwwYc;XdiAjb:NLiXbe;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;eBAeSb:zbML3c;iFQyKf:vfuNJf;io8t5d:yDVVkb;kMFpHd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:fqEYIb;qddgKe:xQtZb;sP4Vbe:VwDzFe;uY49fb:COQbmf;ul9GGd:VDovNc;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=w9hDv,VwDzFe,A7fCU"
                          Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("w9hDv");._.mg(_.lha);_.sx=function(a){_.I.call(this,a.Ha);this.aa=a.Xa.cache};_.z(_.sx,_.I);_.sx.Oa=_.I.Oa;_.sx.Ba=function(){return{Xa:{cache:_.Hq}}};_.sx.prototype.execute=function(a){_.wb(a,function(b){var c;_.Ve(b)&&(c=b.Za.Pb(b.fb));c&&this.aa.lC(c)},this);return{}};_.ls(_.Gha,_.sx);._.m();._.k("VwDzFe");.var HF=function(a){_.I.call(this,a.Ha);this.aa=a.Ea.Kq;this.ea=a.Ea.metadata;this.da=a.Ea.Cq};_.z(HF,_.I);HF.Oa=_.I.Oa;HF.Ba=function(){return{Ea:{Kq:_.hF,metadata:_.YSa,Cq:_.dF}}};HF.prototype.execute=function(a){var b=this;a=this.da.create(a);return _.wb(a,function(c){var d=2===b.ea.getType(c.Cd())?b.aa.Yb(c):b.aa.aa(c);return _.jl(c,_.iF)?d.then(function(e){return _.hd(e)}):d},this)};_.ls(_.Lha,HF);._.m();._.k("sP4Vbe");._.XSa=new _.Kl(_.Hha);._.m();._.k("A7fCU");.var mF=function(a){_.I.call(this,a.Ha);this.aa=a.Ea.wK};_.z(mF,_.I);mF.Oa=_.I.Oa;mF.Ba=function(){r
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:Web Open Font Format (Version 2), TrueType, length 21700, version 1.0
                          Category:downloaded
                          Size (bytes):21700
                          Entropy (8bit):7.989666631701204
                          Encrypted:false
                          SSDEEP:
                          MD5:7D75A9EB3B38B5DD04B8A7CE4F1B87CC
                          SHA1:68F598C84936C9720C5FFD6685294F5C94000DFF
                          SHA-256:6C24799E77B963B00401713A1DBD9CBA3A00249B9363E2C194D01B13B8CDB3D7
                          SHA-512:CF0488C34A1AF36B1BB854DEA2DECFC8394F47831B1670CAB3EED8291B61188484CC8AB0A726A524ECDD20B71D291BCCCBC2CE999FD91662ACA63D2D22ED0D9F
                          Malicious:false
                          Reputation:low
                          URL:https://fonts.gstatic.com/s/googlesans/v14/4UabrENHsxJlGDuGo1OIlLU94YtzCwY.woff2
                          Preview:wOF2......T...........T_..........................4..*....`..~..d..u.....,..$.....6.$..|. ..V..K..^.=...sp.f.m../....l\.....T.9.n..A...........2x.{P[V..v%..M...f.7..+c.cM.'...$..u.H4[?i.'..T..+.(...L...inV.@.dd....T.. }b...c.ghRA..I$.su.....`....Q.OB..S.{.#.3..o.{v.........n...]f#b.J_.......}# ..1... F........=?O.|._p........X.6.VQ.*.E..rU...}....dK.$...0.W..2i..Y...9.Y.............f{..6'....C:%.(........}.....W..._....k...|.........Y8./..e..........L......_.9..v...2F..$..y)....UWu_..T.]qE.H.b..OP...B@.4.!,F..._............z.3.*.A,h.M.(...6~_[U$.....uM2.*..qz.v.........hV\|?.......M-.h..by.A,.}.....?...52.g.,....<..s..k....h.U.]1.1..O......m......j...}6.j.v.a..R....Fj...).fO3........GSM....... ...GL..({A....$O..&'..\....:.x....{N.p8..q..iF..k...b.>....<..M..`.....d.I.5... .x...mo.L.?A(..F }./.._V.e.A.Z3.....C...h...f......(,..3....%.h'.?sG..&x..W.......b].'34.S#s...wiG.O....J.ADDDDBw.m;.....K.ti).....?.6.\.M..d.....[.z....4..D.b...6..F.....F..D.r
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:ASCII text, with very long lines (826)
                          Category:downloaded
                          Size (bytes):8035
                          Entropy (8bit):5.300204980570846
                          Encrypted:false
                          SSDEEP:
                          MD5:D16ECF77068D5E88B61422A1516459D8
                          SHA1:C0B52A386A611E349B1AF59773768CCBE8D7F095
                          SHA-256:CEA9A8CCE7EBBD78FC18DE0183D1F55CC0E3F2B3984E6DCEEE422D04AFD63D2B
                          SHA-512:199276BDA86C44AC94026EE65A4FA90772E2313E7F946AF7F370AB2D19443B9A1B333520499134A3D72D37A0EAC17CBCD0B5B6E2F739DDD9495B9A599FA54295
                          Malicious:false
                          Reputation:low
                          URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.nOJ7WSKZu4M.es5.O/ck=boq-identity.AccountsSignInUi.7fQcyxKRGI4.L.B1.O/am=P8BCEo4FQIyZ5Zy_Z5wcBgAAAAAAAAAAWAPYAQ/d=1/exm=A7fCU,AvtSve,Ctsu,EFQ78c,EGw7Od,EN3i8d,I6YDgd,IZ1fbc,IZT63,K0PMbc,KUM7Z,L1AAkb,LDQI,LEikZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,Rusgnf,SCuOPb,STuCOe,SpsfSb,UPKV3d,UUJqVe,Uas9Hd,VwDzFe,W2YXuc,YHI3We,YTxL4,ZUKRxc,ZZ4WUe,ZwDk9d,_b,_tp,aW3pY,b3kMqb,bPkrc,bSspM,bTi8wc,bm51tf,byfTOb,eVCnO,fFzhe,fJpY1b,fqEYIb,hc6Ubd,hmHrle,inNHtf,kSPLL,lsjVmc,ltDFwf,lwddkf,mWLH9d,my67ye,n73qwf,njlZCf,oLggrd,pxq3x,q0xTif,qPfo0c,qmdT9,sOXFj,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,w9hDv,ws9Tlc,xBaz7b,xQtZb,yRXbo,ywOR5c,zbML3c,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlESPRnh-JZZP_yCycaEkysrUryWfw/ee=ASJRFf:LANRae;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:BDnJmb;EmZ2Bf:zr1jrb;Erl4fe:FloWmf;JsbNhc:Xd8iUd;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Oj465e:KG2eXe;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;UpnZUd:nnwwYc;XdiAjb:NLiXbe;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;eBAeSb:zbML3c;iFQyKf:vfuNJf;io8t5d:yDVVkb;kMFpHd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:fqEYIb;qddgKe:xQtZb;sP4Vbe:VwDzFe;uY49fb:COQbmf;ul9GGd:VDovNc;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=wg1P6b"
                          Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.iKa=_.w("wg1P6b",[_.Xy,_.en]);._.k("wg1P6b");.var $Za=function(a,b){b=b||_.La;for(var c=0,d=a.length,e;c<d;){var f=c+(d-c>>>1);var g=b(0,a[f]);0<g?c=f+1:(d=f,e=!g)}return e?c:-c-1},a_a=function(a,b){for(;b=b.previousSibling;)if(b==a)return-1;return 1},b_a=function(a,b){var c=a.parentNode;if(c==b)return-1;for(;b.parentNode!=c;)b=b.parentNode;return a_a(b,a)},c_a=function(a,b){if(a==b)return 0;if(a.compareDocumentPosition)return a.compareDocumentPosition(b)&2?1:-1;if(_.Uh&&!(9<=Number(_.ii))){if(9==a.nodeType)return-1;if(9==b.nodeType)return 1}if("sourceIndex"in.a||a.parentNode&&"sourceIndex"in a.parentNode){var c=1==a.nodeType,d=1==b.nodeType;if(c&&d)return a.sourceIndex-b.sourceIndex;var e=a.parentNode,f=b.parentNode;return e==f?a_a(a,b):!c&&_.Wi(e,b)?-1*b_a(a,b):!d&&_.Wi(f,a)?b_a(b,a):(c?a.sourceIndex:e.sourceIndex)-(d?b.sourceIndex:f.sourceIndex)}d=_.Ii(a);c=d.createRange
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:ASCII text, with very long lines (4199)
                          Category:downloaded
                          Size (bytes):19219
                          Entropy (8bit):5.387735925560776
                          Encrypted:false
                          SSDEEP:
                          MD5:9E1C91CD2BCAB1C001E94C6961649A42
                          SHA1:06CD3C26EFB2BD546193768730887FE5DCE88E84
                          SHA-256:C1C9E96932CBF5E8BDDB5787C253F98A44E47430FBF5D05ADE4641E8A1B71FE9
                          SHA-512:DDFE2C92C3CAF3FED225128831651C40935D900F43EDF4F6D3F2AE0C855D62417C13952DEF9A96D766065F41ADE471550EEDE1736A1B9B0EF060B00B05C4E8F0
                          Malicious:false
                          Reputation:low
                          URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.nOJ7WSKZu4M.es5.O/ck=boq-identity.AccountsSignInUi.7fQcyxKRGI4.L.B1.O/am=P8BCEo4FQIyZ5Zy_Z5wcBgAAAAAAAAAAWAPYAQ/d=1/exm=AvtSve,Ctsu,EFQ78c,EGw7Od,EN3i8d,I6YDgd,IZ1fbc,IZT63,K0PMbc,KUM7Z,L1AAkb,LDQI,LEikZe,MpJwZc,NOeYWe,O6y8ed,PHUIyb,PrPYRd,Rkm0ef,Rusgnf,SCuOPb,STuCOe,SpsfSb,UPKV3d,UUJqVe,Uas9Hd,W2YXuc,YHI3We,YTxL4,ZUKRxc,_b,_tp,aW3pY,b3kMqb,bPkrc,bSspM,bTi8wc,byfTOb,eVCnO,fFzhe,fJpY1b,fqEYIb,hc6Ubd,hmHrle,inNHtf,kSPLL,lsjVmc,ltDFwf,lwddkf,mWLH9d,my67ye,n73qwf,njlZCf,oLggrd,pxq3x,qPfo0c,qmdT9,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,ws9Tlc,xBaz7b,xQtZb,yRXbo,ywOR5c,zbML3c,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlESPRnh-JZZP_yCycaEkysrUryWfw/ee=ASJRFf:LANRae;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:BDnJmb;EmZ2Bf:zr1jrb;Erl4fe:FloWmf;JsbNhc:Xd8iUd;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Oj465e:KG2eXe;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;UpnZUd:nnwwYc;XdiAjb:NLiXbe;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;eBAeSb:zbML3c;iFQyKf:vfuNJf;io8t5d:yDVVkb;kMFpHd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:fqEYIb;qddgKe:xQtZb;sP4Vbe:VwDzFe;uY49fb:COQbmf;ul9GGd:VDovNc;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=RqjULd"
                          Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.sw=function(a){this.Ga=_.t(a)};_.z(_.sw,_.v);_.tw=function(a,b){return _.sd(a,3,b,_.vc)};_.sw.Gb=[1,2,3,4];.var wAa=_.da.URL,xAa,yAa,AAa,zAa;try{new wAa("http://example.com"),xAa=!0}catch(a){xAa=!1}yAa=xAa;.AAa=function(a){var b=_.Si("A");try{_.ue(b,_.pe(a));var c=b.protocol}catch(e){throw Error("dc`"+a);}if(""===c||":"===c||":"!=c[c.length-1])throw Error("dc`"+a);if(!zAa.has(c))throw Error("dc`"+a);if(!b.hostname)throw Error("dc`"+a);var d=b.href;a={href:d,protocol:b.protocol,username:"",password:"",hostname:b.hostname,pathname:"/"+b.pathname,search:b.search,hash:b.hash,toString:function(){return d}};zAa.get(b.protocol)===b.port?(a.host=a.hostname,a.port="",a.origin=a.protocol+"//"+a.hostname):(a.host=.b.host,a.port=b.port,a.origin=a.protocol+"//"+a.hostname+":"+a.port);return a};._.BAa=function(a){if(yAa){try{var b=new wAa(a)}catch(d){throw Error("dc`"+a);}var c=zAa.get(b
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:ASCII text, with very long lines (15990)
                          Category:downloaded
                          Size (bytes):670506
                          Entropy (8bit):5.734945947279104
                          Encrypted:false
                          SSDEEP:
                          MD5:14B09FBBD54D23643BB62856CCA0CE1D
                          SHA1:59F0388EBC9872EDDB4E680F27A989413461498F
                          SHA-256:3DC5B8F6AD05B487BBEF49C42C3FFF488ABF47D75CD2D62BB50DA2A02D1082B9
                          SHA-512:074939AB026F704363BB586FF029C2B8D54B0228C88573B69DD40EA63EAFD1220CCD7C368EB8132BF039DFC4A4C007E565B76760D720EEE4F04588C2C50CD476
                          Malicious:false
                          Reputation:low
                          URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.nOJ7WSKZu4M.es5.O/ck=boq-identity.AccountsSignInUi.7fQcyxKRGI4.L.B1.O/am=P8BCEo4FQIyZ5Zy_Z5wcBgAAAAAAAAAAWAPYAQ/d=1/exm=LEikZe,_b,_tp,byfTOb,lsjVmc/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlESPRnh-JZZP_yCycaEkysrUryWfw/ee=ASJRFf:LANRae;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:BDnJmb;EmZ2Bf:zr1jrb;Erl4fe:FloWmf;JsbNhc:Xd8iUd;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Oj465e:KG2eXe;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;UpnZUd:nnwwYc;XdiAjb:NLiXbe;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;eBAeSb:zbML3c;iFQyKf:vfuNJf;io8t5d:yDVVkb;kMFpHd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:fqEYIb;qddgKe:xQtZb;sP4Vbe:VwDzFe;uY49fb:COQbmf;ul9GGd:VDovNc;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=n73qwf,SCuOPb,IZT63,vfuNJf,UUJqVe,ws9Tlc,siKnQd,STuCOe,njlZCf,fJpY1b,b3kMqb,EGw7Od,ZUKRxc,my67ye,t2srLd,EN3i8d,hmHrle,mWLH9d,NOeYWe,O6y8ed,fqEYIb,PrPYRd,MpJwZc,hc6Ubd,Rkm0ef,KUM7Z,oLggrd,inNHtf,L1AAkb,lwddkf,SpsfSb,fFzhe,tUnxGc,aW3pY,EFQ78c,xQtZb,I6YDgd,zbML3c,zr1jrb,vHEMJe,YHI3We,YTxL4,bSspM,Uas9Hd,zy0vNb,K0PMbc,AvtSve,qmdT9,xBaz7b,eVCnO,LDQI"
                          Preview:"use strict";_F_installCss(".Mh0NNb{background-color:#323232;bottom:0;box-sizing:border-box;box-shadow:0px 6px 10px 0px rgba(0,0,0,.14),0px 1px 18px 0px rgba(0,0,0,.12),0px 3px 5px -1px rgba(0,0,0,.2);color:#fff;display:flex;-webkit-box-orient:vertical;-webkit-box-direction:normal;flex-direction:column;font-size:14px;left:0;min-height:48px;position:fixed;right:0;transform:translate(0,100%);visibility:hidden;z-index:99999}.M6tHv{-webkit-box-align:center;box-align:center;align-items:center;align-content:center;display:flex;-webkit-box-orient:horizontal;-webkit-box-direction:normal;flex-direction:row;min-height:inherit;padding:0}.aGJE1b{box-flex:1;flex-grow:1;flex-shrink:1;line-height:normal;overflow:hidden;padding:14px 24px;text-overflow:ellipsis;word-break:break-word}.x95qze{align-self:center;color:#eeff41;box-flex:0;flex-grow:0;flex-shrink:0;float:right;text-transform:uppercase;font-weight:500;display:inline-block;cursor:pointer;outline:none;padding:14px 24px}.KYZn9b{background-color:#
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:ASCII text, with very long lines (1631)
                          Category:downloaded
                          Size (bytes):38524
                          Entropy (8bit):5.380933182606575
                          Encrypted:false
                          SSDEEP:
                          MD5:7609CFFA24A53E65D4B74577DE272F4B
                          SHA1:59543F04A0DCA6B1056D174AC44B821CE4FD6BB3
                          SHA-256:2CE110DF6BA65C666F65D2090D9FC8A343811389AA458B4E76BA7C7C309E4D37
                          SHA-512:B66B19DDE83E01D88FE76185D42EF4E7BBB5BDD92D1FF89E1B9420239288978A38CBB29263969867B7B0F075287D04DEB8F43E52B19AAE957FC6AA6B9BA0EC72
                          Malicious:false
                          Reputation:low
                          URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.nOJ7WSKZu4M.es5.O/ck=boq-identity.AccountsSignInUi.7fQcyxKRGI4.L.B1.O/am=P8BCEo4FQIyZ5Zy_Z5wcBgAAAAAAAAAAWAPYAQ/d=1/exm=_b,_tp/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlESPRnh-JZZP_yCycaEkysrUryWfw/ee=ASJRFf:LANRae;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:BDnJmb;EmZ2Bf:zr1jrb;Erl4fe:FloWmf;JsbNhc:Xd8iUd;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Oj465e:KG2eXe;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;UpnZUd:nnwwYc;XdiAjb:NLiXbe;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;eBAeSb:zbML3c;iFQyKf:vfuNJf;io8t5d:yDVVkb;kMFpHd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:fqEYIb;qddgKe:xQtZb;sP4Vbe:VwDzFe;uY49fb:COQbmf;ul9GGd:VDovNc;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=byfTOb,lsjVmc,LEikZe"
                          Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.ona=function(a){var b=0,c;for(c in a)b++;return b};_.pna=function(a){return a.Vg&&"function"==typeof a.Vg?a.Vg():_.ma(a)||"string"===typeof a?a.length:_.ona(a)};_.Vo=function(a){if(a.Mg&&"function"==typeof a.Mg)return a.Mg();if("undefined"!==typeof Map&&a instanceof Map||"undefined"!==typeof Set&&a instanceof Set)return Array.from(a.values());if("string"===typeof a)return a.split("");if(_.ma(a)){for(var b=[],c=a.length,d=0;d<c;d++)b.push(a[d]);return b}return _.xb(a)};._.qna=function(a){if(a.Lg&&"function"==typeof a.Lg)return a.Lg();if(!a.Mg||"function"!=typeof a.Mg){if("undefined"!==typeof Map&&a instanceof Map)return Array.from(a.keys());if(!("undefined"!==typeof Set&&a instanceof Set)){if(_.ma(a)||"string"===typeof a){var b=[];a=a.length;for(var c=0;c<a;c++)b.push(c);return b}return _.yb(a)}}};.var rna,una,tna,sna,kp,mp,Gna,xna,zna,yna,Cna,Ana;rna=function(a,b,c){if(b)re
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:ASCII text, with very long lines (3004)
                          Category:downloaded
                          Size (bytes):219321
                          Entropy (8bit):5.458246897095534
                          Encrypted:false
                          SSDEEP:
                          MD5:6E83EB8FBB6A4F0B8F31564F50C64B18
                          SHA1:6883B22EF5FA9CE6C3AAA4BB3CB1A2E7E7A47BFA
                          SHA-256:7A0FF46AB40684EE9C354325A5D615624F95DE1AB77D1D52657198BBD63EC405
                          SHA-512:3BF02210ABACFD55803F7D36BADC2BE29681A01B16F1312B51B5CAE051A89F880504CE1530A7ADD9BEBE3156A46D0C1A04FFF124635E0069184B98046E50C138
                          Malicious:false
                          Reputation:low
                          URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.nOJ7WSKZu4M.es5.O/am=P8BCEo4FQIyZ5Zy_Z5wcBgAAAAAAAAAAWAPYAQ/d=1/excm=_b,_tp,identifierview/ed=1/dg=0/wt=2/ujg=1/rs=AOaEmlGkhXcT7V5ecQz4-OJohhQZUSpX5A/m=_b,_tp"
                          Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._._F_toggles_initialize=function(a){("undefined"!==typeof globalThis?globalThis:"undefined"!==typeof self?self:this)._F_toggles=a||[]};(0,_._F_toggles_initialize)([0x1242c03f, 0x31001638, 0x39ce5998, 0x72719ef, 0x6, 0x0, 0x358000, 0x76, ]);./*.. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/./*.. SPDX-License-Identifier: Apache-2.0.*/./*.. Copyright 2013 Google LLC.. SPDX-License-Identifier: Apache-2.0.*/.var baa,daa,Pa,haa,Za,bb,cb,db,eb,iaa,fb,jb,jaa,kaa,ob,naa,paa,qaa,taa,vaa,Kb,zaa,Ob,Aaa,Baa,Tb,Eaa,Gaa,Haa,jc,Iaa,Maa,Naa,Lc,Paa,Qaa,Raa,Qc,Uaa,Taa,Waa,Yc,Xc,Xaa,Zc,Zaa,bd,fd,$aa,aba,qd,pd,ad,Id,iba,kba,lba,gba,mba,oba,pba,Ed,ke,le,ne,ve,zba,Ie,Le,Me,Oe,Cba,Eba,Gba,Hba,Iba,Jba,Mba,Oba,Qba,Rba,Uba,bca,Yba,cca,Ff,Gf,dca,eca,gca,ica,jca,kca,Uf,lca,mca,bg,oca,pca,rca,tca,uca,aaa,vca,ug,wca,wg,xca,yg,Ag,yca,Hg,Ig,Dca,Qg,Rg,Fca;_.aa=function(a){ret
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:HTML document, Unicode text, UTF-8 text, with very long lines (1136)
                          Category:dropped
                          Size (bytes):1555
                          Entropy (8bit):5.249530958699059
                          Encrypted:false
                          SSDEEP:
                          MD5:FBE36EB2EECF1B90451A3A72701E49D2
                          SHA1:AE56EA57C52D1153CEC33CEF91CF935D2D3AF14D
                          SHA-256:E8F2DED5D74C0EE5F427A20B6715E65BC79ED5C4FC67FB00D89005515C8EFE63
                          SHA-512:7B1FD6CF34C26AF2436AF61A1DE16C9DBFB4C43579A9499F4852A7848F873BAC15BEEEA6124CF17F46A9F5DD632162364E0EC120ACA5F65E7C5615FF178A248F
                          Malicious:false
                          Reputation:low
                          Preview:<!DOCTYPE html>.<html lang=en>. <meta charset=utf-8>. <meta name=viewport content="initial-scale=1, minimum-scale=1, width=device-width">. <title>Error 400 (Bad Request)!!1</title>. <style>. *{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html{background:#fff;color:#222;padding:15px}body{margin:7% auto 0;max-width:390px;min-height:180px;padding:30px 0 15px}* > body{background:url(//www.google.com/images/errors/robot.png) 100% 5px no-repeat;padding-right:205px}p{margin:11px 0 22px;overflow:hidden}ins{color:#777;text-decoration:none}a img{border:0}@media screen and (max-width:772px){body{background:none;margin-top:0;max-width:none;padding-right:0}}#logo{background:url(//www.google.com/images/branding/googlelogo/1x/googlelogo_color_150x54dp.png) no-repeat;margin-left:-5px}@media only screen and (min-resolution:192dpi){#logo{background:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat 0% 0%/100% 100%;-moz-border-image:url(//ww
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:Web Open Font Format (Version 2), TrueType, length 15552, version 1.0
                          Category:downloaded
                          Size (bytes):15552
                          Entropy (8bit):7.983966851275127
                          Encrypted:false
                          SSDEEP:
                          MD5:285467176F7FE6BB6A9C6873B3DAD2CC
                          SHA1:EA04E4FF5142DDD69307C183DEF721A160E0A64E
                          SHA-256:5A8C1E7681318CAA29E9F44E8A6E271F6A4067A2703E9916DFD4FE9099241DB7
                          SHA-512:5F9BB763406EA8CE978EC675BD51A0263E9547021EA71188DBD62F0212EB00C1421B750D3B94550B50425BEBFF5F881C41299F6A33BBFA12FB1FF18C12BC7FF1
                          Malicious:false
                          Reputation:low
                          URL:https://fonts.gstatic.com/s/roboto/v18/KFOlCnqEu92Fr1MmEU9fBBc4.woff2
                          Preview:wOF2......<...........<Z.........................d..z..J.`..L.\..<.....<.....^...x.6.$..6. .... ..S..}%.......|....x..[j.E...d..-A...]=sjf$X.o.5......V....i?}.\...;...V......5..mO=,[.B..d'..=..M...q...8..U'..N..G...[..8....Jp..xP...'.?....}.-.1F.C.....%z..#...Q...~.~..3.............r.Xk..v.*.7t.+bw...f..b...q.W..'E.....O..a..HI.....Y.B..i.K.0.:.d.E.Lw....Q..~.6.}B...bT.F.,<./....Qu....|...H....Fk.*-..H..p4.$......{.2.....".T'..........Va.6+.9uv....RW..U$8...p...........H5...B..N..V...{.1....5}p.q6..T...U.P.N...U...!.w..?..mI..8q.}.... >.Z.K.....tq..}.><Ok..w.. ..v....W...{....o...."+#+,..vdt...p.WKK:.p1...3`. 3.......Q.].V.$}.......:.S..bb!I...c.of.2uq.n.MaJ..Cf.......w.$.9C...sj.=...=.Z7...h.w M.D..A.t.....]..GVpL...U(.+.)m..e)..H.}i.o.L...S.r..m..Ko....i..M..J..84.=............S..@......Z.V.E..b...0.....@h>...."$.?....../..?.....?.J.a,..|..d...|`.m5..b..LWc...L...?.G.].i...Q..1.:..LJV.J...bU.2.:\.kt.......t.....k....B..i.z+...........A.....
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
                          Category:downloaded
                          Size (bytes):15344
                          Entropy (8bit):7.984625225844861
                          Encrypted:false
                          SSDEEP:
                          MD5:5D4AEB4E5F5EF754E307D7FFAEF688BD
                          SHA1:06DB651CDF354C64A7383EA9C77024EF4FB4CEF8
                          SHA-256:3E253B66056519AA065B00A453BAC37AC5ED8F3E6FE7B542E93A9DCDCC11D0BC
                          SHA-512:7EB7C301DF79D35A6A521FAE9D3DCCC0A695D3480B4D34C7D262DD0C67ABEC8437ED40E2920625E98AAEAFBA1D908DEC69C3B07494EC7C29307DE49E91C2EF48
                          Malicious:false
                          Reputation:low
                          URL:https://fonts.gstatic.com/s/roboto/v18/KFOmCnqEu92Fr1Mu4mxK.woff2
                          Preview:wOF2......;........H..;..........................d..@..J.`..L.T..<.....x.....^...x.6.$..6. ..t. ..I.h|.l....A....b6........(......@e.]...*:..-.0..r.)..hS..h...N.).D.........b.].......^..t?.m{...."84...9......c...?..r3o....}...S]....zbO.../z..{.....~cc....I...#.G.D....#*e.A..b...b`a5P.4........M....v4..fI#X.z,.,...=avy..F.a.\9.P|.[....r.Q@M.I.._.9..V..Q..]......[ {u..L@...]..K......]C....l$.Z.Z...Zs.4........ x.........F.?.7N..].|.wb\....Z{1L#..t....0.dM...$JV...{..oX...i....6.v.~......)|.TtAP&).KQ.]y........'...:.d..+..d..."C.h..p.2.M..e,.*UP..@.q..7..D.@...,......B.n. r&.......F!.....\...;R.?-.i...,7..cb../I...Eg...!X.)5.Aj7...Ok..l7.j.A@B`".}.w.m..R.9..T.X.X.d....S..`XI..1... .$C.H.,.\. ..A(.AZ.................`Wr.0]y..-..K.1.............1.tBs..n.0...9.F[b.3x...*$....T..PM.Z-.N.rS?I.<8eR'.3..27..?;..OLf*.Rj.@.o.W...........j~ATA....vX.N:.3dM.r.)Q.B...4i.f..K.l..s....e.U.2...k..a.GO.}..../.'..%$..ed.*.'..qP....M..j....../.z&.=...q<....-..?.A.%..K..
                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                          File Type:ASCII text, with very long lines (574)
                          Category:downloaded
                          Size (bytes):3448
                          Entropy (8bit):5.474195960044918
                          Encrypted:false
                          SSDEEP:
                          MD5:D060B5371249E859D5F80FFF961E1F50
                          SHA1:6A33183CF9369184DFA814E1D7122A3943716238
                          SHA-256:F68A40AEE0FAC282C6599CCAC9C0375F9CAAE4CA0AD16F87C662C64597689367
                          SHA-512:3B8A93C6A848C255F35B81FDDFD8791E2CF32C4C892B67EEE231914D79131FB254C424922707A1266910CBDD9493EA20B57EF3C8B7CEF3C32C925E8783E86538
                          Malicious:false
                          Reputation:low
                          URL:"https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en_US.nOJ7WSKZu4M.es5.O/ck=boq-identity.AccountsSignInUi.7fQcyxKRGI4.L.B1.O/am=P8BCEo4FQIyZ5Zy_Z5wcBgAAAAAAAAAAWAPYAQ/d=1/exm=A7fCU,AvtSve,Ctsu,EFQ78c,EGw7Od,EN3i8d,I6YDgd,IZ1fbc,IZT63,K0PMbc,KUM7Z,L1AAkb,LDQI,LEikZe,MpJwZc,NOeYWe,NTMZac,O6y8ed,PHUIyb,PrPYRd,RMhBfe,Rkm0ef,RqjULd,Rusgnf,SCuOPb,STuCOe,SpsfSb,UPKV3d,UUJqVe,Uas9Hd,VwDzFe,W2YXuc,YHI3We,YTxL4,ZUKRxc,ZZ4WUe,ZwDk9d,_b,_tp,aW3pY,b3kMqb,bPkrc,bSspM,bTi8wc,bm51tf,byfTOb,eVCnO,fFzhe,fJpY1b,fqEYIb,hc6Ubd,hmHrle,inNHtf,kSPLL,lsjVmc,ltDFwf,lwddkf,mWLH9d,my67ye,n73qwf,njlZCf,oLggrd,pxq3x,q0xTif,qPfo0c,qmdT9,sOXFj,siKnQd,soHxf,t2srLd,tUnxGc,vHEMJe,vfuNJf,w9hDv,wg1P6b,ws9Tlc,xBaz7b,xQtZb,yRXbo,ywOR5c,zbML3c,zr1jrb,zy0vNb/excm=_b,_tp,identifierview/ed=1/wt=2/ujg=1/rs=AOaEmlESPRnh-JZZP_yCycaEkysrUryWfw/ee=ASJRFf:LANRae;Al0B8:kibjWe;DaIJ8c:iAskyc;EVNhjf:pw70Gc;EkYFhd:BDnJmb;EmZ2Bf:zr1jrb;Erl4fe:FloWmf;JsbNhc:Xd8iUd;LBgRLc:XVMNvd;Me32dd:MEeYgc;NPKaK:PVlQOd;NSEoX:lazG7b;Oj465e:KG2eXe;Pjplud:EEDORb;QGR0gd:Mlhmy;SMDL4c:K0PMbc;SNUn3:ZwDk9d;UpnZUd:nnwwYc;XdiAjb:NLiXbe;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;eBAeSb:zbML3c;iFQyKf:vfuNJf;io8t5d:yDVVkb;kMFpHd:OTA3Ae;nAFL3:NTMZac;nTuGK:JKNPM;oGtAuc:sOXFj;oSUNyd:K0PMbc;oXZmbc:tUnxGc;pXdRYb:fqEYIb;qddgKe:xQtZb;sP4Vbe:VwDzFe;uY49fb:COQbmf;ul9GGd:VDovNc;vNjB7d:YTxL4;wR5FRb:siKnQd;yxTchf:KUM7Z/m=Wt6vjf,hhhU8,FCpbqb,WhJNk"
                          Preview:"use strict";this.default_AccountsSignInUi=this.default_AccountsSignInUi||{};(function(_){var window=this;.try{._.k("Wt6vjf");.var nra=function(){var a=_.je();return _.ek(a,1)};var Qr=function(a){this.Ga=_.t(a,0,Qr.messageId)};_.z(Qr,_.v);Qr.prototype.Ja=function(){return _.Kj(this,1)};Qr.prototype.Wa=function(a){return _.qk(this,1,a)};Qr.messageId="f.bo";var Rr=function(){_.am.call(this)};_.z(Rr,_.am);Rr.prototype.Sc=function(){this.QN=!1;ora(this);_.am.prototype.Sc.call(this)};Rr.prototype.aa=function(){pra(this);if(this.xz)return qra(this),!1;if(!this.TP)return Sr(this),!0;this.dispatchEvent("p");if(!this.nJ)return Sr(this),!0;this.cH?(this.dispatchEvent("r"),Sr(this)):qra(this);return!1};.var rra=function(a){var b=new _.dp(a.RZ);null!=a.tK&&b.aa("authuser",a.tK);return b},qra=function(a){a.xz=!0;var b=rra(a),c="rt=r&f_uid="+_.Ai(a.nJ);_.Hm(b,(0,_.kg)(a.ea,a),"POST",c)};.Rr.prototype.ea=function(a){a=a.target;pra(this);if(_.Km(a)){this.dF=0;if(this.cH)this.xz=!1,this.dispatchEvent("
                          No static file info