Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://kugs.vipku.org/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12

Overview

General Information

Sample URL:http://kugs.vipku.org/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12
Analysis ID:1376332
Infos:

Detection

Phisher
Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected Phisher
Performs DNS queries to domains with low reputation
Creates files inside the system directory
Found iframes
HTML body contains low number of good links
HTML title does not match URL
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 7124 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://kugs.vipku.org/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 1268 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2036,i,5081529301769378248,128484250532948166,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
SourceRuleDescriptionAuthorStrings
dropped/chromecache_121JoeSecurity_Phisher_2Yara detected PhisherJoe Security
    dropped/chromecache_136JoeSecurity_Phisher_2Yara detected PhisherJoe Security
      No Sigma rule has matched
      No Snort rule has matched

      Click to jump to signature section

      Show All Signature Results

      Phishing

      barindex
      Source: Yara matchFile source: dropped/chromecache_121, type: DROPPED
      Source: Yara matchFile source: dropped/chromecache_136, type: DROPPED
      Source: https://nosotroda.com/e/tpl43/0?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=@@gtagManagerId
      Source: https://nosotroda.com/e/tpl43/0?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=@@gtagManagerId
      Source: https://nosotroda.com/e/tpl43/0?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: Iframe src: https://d2m2wsoho8qq12.cloudfront.net/iframe.html?token=87C8F5A3-F300-A87C-5859-7C0B65419DEA&apiurl=https%3A%2F%2Fcreate.leadid.com%2F2.11.9&lck=7DDFDDEA-887D-0AAD-A287-D1F0FA6BCFBD&lac=3395B01B-B79A-D8CF-A348-705B3C75A01D
      Source: https://nosotroda.com/e/tpl43/1?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=@@gtagManagerId
      Source: https://nosotroda.com/e/tpl43/1?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: Iframe src: https://d2m2wsoho8qq12.cloudfront.net/iframe.html?token=87C8F5A3-F300-A87C-5859-7C0B65419DEA&apiurl=https%3A%2F%2Fcreate.leadid.com%2F2.11.9&lck=7DDFDDEA-887D-0AAD-A287-D1F0FA6BCFBD&lac=3395B01B-B79A-D8CF-A348-705B3C75A01D
      Source: https://nosotroda.com/e/tpl43/0?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: Number of links: 0
      Source: https://nosotroda.com/e/tpl43/1?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: Number of links: 0
      Source: https://nosotroda.com/e/tpl43/0?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: Title: Gift Card does not match URL
      Source: https://nosotroda.com/e/tpl43/1?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: Title: Gift Card does not match URL
      Source: http://kugs.vipku.org/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12HTTP Parser: No favicon
      Source: http://kugs.vipku.org/t/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12HTTP Parser: No favicon
      Source: https://deviceid.trueleadid.com/iframe.html?token=87C8F5A3-F300-A87C-5859-7C0B65419DEA&apiurl=https%3A%2F%2Fcreate.leadid.com%2F2.11.9&lck=7DDFDDEA-887D-0AAD-A287-D1F0FA6BCFBD&lac=3395B01B-B79A-D8CF-A348-705B3C75A01DHTTP Parser: No favicon
      Source: https://d2m2wsoho8qq12.cloudfront.net/iframe.html?token=87C8F5A3-F300-A87C-5859-7C0B65419DEA&apiurl=https%3A%2F%2Fcreate.leadid.com%2F2.11.9&lck=7DDFDDEA-887D-0AAD-A287-D1F0FA6BCFBD&lac=3395B01B-B79A-D8CF-A348-705B3C75A01DHTTP Parser: No favicon
      Source: https://nosotroda.com/e/tpl43/0?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: No <meta name="author".. found
      Source: https://nosotroda.com/e/tpl43/0?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: No <meta name="author".. found
      Source: https://nosotroda.com/e/tpl43/1?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: No <meta name="author".. found
      Source: https://nosotroda.com/e/tpl43/0?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: No <meta name="copyright".. found
      Source: https://nosotroda.com/e/tpl43/0?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: No <meta name="copyright".. found
      Source: https://nosotroda.com/e/tpl43/1?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365HTTP Parser: No <meta name="copyright".. found
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
      Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49788 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49791 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49831 version: TLS 1.2

      Networking

      barindex
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: pushvisit.xyz
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: pushvisit.xyz
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: pushvisit.xyz
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: pushvisit.xyz
      Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
      Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
      Source: unknownTCP traffic detected without corresponding DNS query: 23.51.58.94
      Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
      Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
      Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
      Source: unknownTCP traffic detected without corresponding DNS query: 13.67.144.177
      Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
      Source: unknownTCP traffic detected without corresponding DNS query: 13.67.144.177
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.84
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
      Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
      Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
      Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
      Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.58
      Source: global trafficHTTP traffic detected: GET /4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12 HTTP/1.1Host: kugs.vipku.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: kugs.vipku.orgConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://kugs.vipku.org/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /t/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12 HTTP/1.1Host: kugs.vipku.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://kugs.vipku.org/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
      Source: unknownDNS traffic detected: queries for: kugs.vipku.org
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/plain; charset=utf-8X-Address: gin_throttle_mw_360000000000_154.16.192.193X-Ratelimit-Limit: 10X-Ratelimit-Remaining: 8X-Ratelimit-Reset: 1705526590Date: Wed, 17 Jan 2024 20:23:10 GMTContent-Length: 0
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
      Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49861
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
      Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
      Source: unknownNetwork traffic detected: HTTP traffic on port 49881 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
      Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
      Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
      Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
      Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
      Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
      Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
      Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
      Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
      Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
      Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
      Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
      Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
      Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
      Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
      Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
      Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
      Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
      Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
      Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
      Source: unknownNetwork traffic detected: HTTP traffic on port 49885 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
      Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
      Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
      Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49885
      Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49884
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49883
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49881
      Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49880
      Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49879
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49878
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49877
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49876
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49875
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49874
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49873
      Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49872
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
      Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49871
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49870
      Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
      Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49869
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
      Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49868
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49867
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
      Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49878 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49866 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49861 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49873 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
      Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
      Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49867 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
      Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
      Source: unknownNetwork traffic detected: HTTP traffic on port 49842 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49871 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
      Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
      Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49876 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
      Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
      Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
      Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
      Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49877 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49684 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49883 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49832 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
      Source: unknownHTTPS traffic detected: 173.222.162.58:443 -> 192.168.2.17:49788 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49791 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49831 version: TLS 1.2
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_7124_980298651
      Source: classification engineClassification label: mal52.phis.troj.win@19/115@78/410
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\Chrome\Application\Dictionaries
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://kugs.vipku.org/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2036,i,5081529301769378248,128484250532948166,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=2036,i,5081529301769378248,128484250532948166,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: Window RecorderWindow detected: More than 3 window changes detected
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
      1
      Drive-by Compromise
      Windows Management Instrumentation1
      Registry Run Keys / Startup Folder
      1
      Process Injection
      13
      Masquerading
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
      Encrypted Channel
      Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
      Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
      Registry Run Keys / Startup Folder
      1
      Process Injection
      LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
      Non-Application Layer Protocol
      SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
      Domain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
      Application Layer Protocol
      Data Encrypted for ImpactDNS ServerEmail Addresses
      Local AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureTraffic Duplication3
      Ingress Tool Transfer
      Data DestructionVirtual Private ServerEmployee Names

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      http://kugs.vipku.org/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b120%Avira URL Cloudsafe
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      SourceDetectionScannerLabelLink
      http://kugs.vipku.org/favicon.ico0%Avira URL Cloudsafe
      NameIPActiveMaliciousAntivirus DetectionReputation
      beacon.nosotroda.com
      45.55.126.207
      truefalse
        unknown
        g0-g3t-som3.com
        157.90.33.74
        truefalse
          unknown
          janiecera.com
          146.19.173.232
          truefalse
            unknown
            virtualpushplatform.com
            104.21.67.146
            truefalse
              unknown
              mobile-gtalk.l.google.com
              142.251.111.188
              truefalse
                high
                d2m2wsoho8qq12.cloudfront.net
                18.164.115.108
                truefalse
                  high
                  nosotroda.com
                  172.67.143.7
                  truefalse
                    unknown
                    pushvisit.xyz
                    20.50.64.3
                    truetrue
                      unknown
                      extension.trk-keingent.com
                      172.64.199.9
                      truefalse
                        unknown
                        www.google.com
                        142.250.72.100
                        truefalse
                          high
                          api.trustedform.com
                          52.6.216.19
                          truefalse
                            unknown
                            dw4luqp.ng.impervadns.net
                            45.223.17.68
                            truefalse
                              unknown
                              kugs.vipku.org
                              192.101.68.79
                              truefalse
                                unknown
                                jinxmux.com
                                185.140.54.135
                                truefalse
                                  unknown
                                  android.l.google.com
                                  142.250.72.110
                                  truefalse
                                    high
                                    a.nel.cloudflare.com
                                    35.190.80.1
                                    truefalse
                                      high
                                      accounts.google.com
                                      142.251.16.84
                                      truefalse
                                        high
                                        bledslab.win
                                        46.105.128.161
                                        truefalse
                                          unknown
                                          create.lidstatic.com
                                          104.22.39.182
                                          truefalse
                                            unknown
                                            trk-keingent.com
                                            172.64.198.9
                                            truefalse
                                              unknown
                                              cdn4image.com
                                              157.90.131.241
                                              truefalse
                                                unknown
                                                create.leadid.com
                                                52.203.168.17
                                                truefalse
                                                  unknown
                                                  cdn.pushdrop.club
                                                  172.67.217.134
                                                  truefalse
                                                    unknown
                                                    cdn.md-ace-b.online
                                                    104.21.83.123
                                                    truefalse
                                                      unknown
                                                      clients.l.google.com
                                                      142.250.65.174
                                                      truefalse
                                                        high
                                                        cdn.trustedform.com
                                                        13.226.34.80
                                                        truefalse
                                                          unknown
                                                          pushclk.com
                                                          104.21.29.105
                                                          truefalse
                                                            unknown
                                                            ka-f.fontawesome.com
                                                            unknown
                                                            unknownfalse
                                                              high
                                                              clients2.google.com
                                                              unknown
                                                              unknownfalse
                                                                high
                                                                clients1.google.com
                                                                unknown
                                                                unknownfalse
                                                                  high
                                                                  kit.fontawesome.com
                                                                  unknown
                                                                  unknownfalse
                                                                    high
                                                                    deviceid.trueleadid.com
                                                                    unknown
                                                                    unknownfalse
                                                                      unknown
                                                                      NameMaliciousAntivirus DetectionReputation
                                                                      http://kugs.vipku.org/favicon.icofalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      https://nosotroda.com/e/tpl43/3?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365false
                                                                        unknown
                                                                        https://deviceid.trueleadid.com/iframe.html?token=87C8F5A3-F300-A87C-5859-7C0B65419DEA&apiurl=https%3A%2F%2Fcreate.leadid.com%2F2.11.9&lck=7DDFDDEA-887D-0AAD-A287-D1F0FA6BCFBD&lac=3395B01B-B79A-D8CF-A348-705B3C75A01Dfalse
                                                                          unknown
                                                                          https://nosotroda.com/e/tpl43/1?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365false
                                                                            unknown
                                                                            http://kugs.vipku.org/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12false
                                                                              unknown
                                                                              http://kugs.vipku.org/t/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12false
                                                                                unknown
                                                                                https://nosotroda.com/e/tpl43/0?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23&ld=1&session_id=2c0f8fb9-4cc9-4ffd-bbec-c707ca7f7365false
                                                                                  unknown
                                                                                  https://d2m2wsoho8qq12.cloudfront.net/iframe.html?token=87C8F5A3-F300-A87C-5859-7C0B65419DEA&apiurl=https%3A%2F%2Fcreate.leadid.com%2F2.11.9&lck=7DDFDDEA-887D-0AAD-A287-D1F0FA6BCFBD&lac=3395B01B-B79A-D8CF-A348-705B3C75A01Dfalse
                                                                                    high
                                                                                    • No. of IPs < 25%
                                                                                    • 25% < No. of IPs < 50%
                                                                                    • 50% < No. of IPs < 75%
                                                                                    • 75% < No. of IPs
                                                                                    IPDomainCountryFlagASNASN NameMalicious
                                                                                    45.223.17.68
                                                                                    dw4luqp.ng.impervadns.netUnited States
                                                                                    19551INCAPSULAUSfalse
                                                                                    54.197.179.6
                                                                                    unknownUnited States
                                                                                    14618AMAZON-AESUSfalse
                                                                                    172.64.147.188
                                                                                    unknownUnited States
                                                                                    13335CLOUDFLARENETUSfalse
                                                                                    142.251.111.188
                                                                                    mobile-gtalk.l.google.comUnited States
                                                                                    15169GOOGLEUSfalse
                                                                                    18.164.115.108
                                                                                    d2m2wsoho8qq12.cloudfront.netUnited States
                                                                                    3MIT-GATEWAYSUSfalse
                                                                                    104.21.83.123
                                                                                    cdn.md-ace-b.onlineUnited States
                                                                                    13335CLOUDFLARENETUSfalse
                                                                                    46.105.128.161
                                                                                    bledslab.winFrance
                                                                                    16276OVHFRfalse
                                                                                    142.251.40.106
                                                                                    unknownUnited States
                                                                                    15169GOOGLEUSfalse
                                                                                    52.203.168.17
                                                                                    create.leadid.comUnited States
                                                                                    14618AMAZON-AESUSfalse
                                                                                    172.67.217.134
                                                                                    cdn.pushdrop.clubUnited States
                                                                                    13335CLOUDFLARENETUSfalse
                                                                                    185.140.54.135
                                                                                    jinxmux.comSweden
                                                                                    200514KNOWNSRVNLfalse
                                                                                    104.21.29.105
                                                                                    pushclk.comUnited States
                                                                                    13335CLOUDFLARENETUSfalse
                                                                                    20.50.64.3
                                                                                    pushvisit.xyzUnited States
                                                                                    8075MICROSOFT-CORP-MSN-AS-BLOCKUStrue
                                                                                    142.251.32.106
                                                                                    unknownUnited States
                                                                                    15169GOOGLEUSfalse
                                                                                    142.250.72.100
                                                                                    www.google.comUnited States
                                                                                    15169GOOGLEUSfalse
                                                                                    172.64.199.9
                                                                                    extension.trk-keingent.comUnited States
                                                                                    13335CLOUDFLARENETUSfalse
                                                                                    142.251.16.84
                                                                                    accounts.google.comUnited States
                                                                                    15169GOOGLEUSfalse
                                                                                    104.22.39.182
                                                                                    create.lidstatic.comUnited States
                                                                                    13335CLOUDFLARENETUSfalse
                                                                                    44.219.207.22
                                                                                    unknownUnited States
                                                                                    14618AMAZON-AESUSfalse
                                                                                    192.101.68.79
                                                                                    kugs.vipku.orgUnited States
                                                                                    12679ASN-MOLMoscowRussiaRUfalse
                                                                                    35.190.80.1
                                                                                    a.nel.cloudflare.comUnited States
                                                                                    15169GOOGLEUSfalse
                                                                                    172.64.198.9
                                                                                    trk-keingent.comUnited States
                                                                                    13335CLOUDFLARENETUSfalse
                                                                                    142.250.80.35
                                                                                    unknownUnited States
                                                                                    15169GOOGLEUSfalse
                                                                                    172.67.177.88
                                                                                    unknownUnited States
                                                                                    13335CLOUDFLARENETUSfalse
                                                                                    1.1.1.1
                                                                                    unknownAustralia
                                                                                    13335CLOUDFLARENETUSfalse
                                                                                    142.250.65.174
                                                                                    clients.l.google.comUnited States
                                                                                    15169GOOGLEUSfalse
                                                                                    157.90.131.241
                                                                                    cdn4image.comUnited States
                                                                                    766REDIRISRedIRISAutonomousSystemESfalse
                                                                                    172.67.143.7
                                                                                    nosotroda.comUnited States
                                                                                    13335CLOUDFLARENETUSfalse
                                                                                    157.90.33.74
                                                                                    g0-g3t-som3.comUnited States
                                                                                    766REDIRISRedIRISAutonomousSystemESfalse
                                                                                    13.226.34.80
                                                                                    cdn.trustedform.comUnited States
                                                                                    16509AMAZON-02USfalse
                                                                                    52.6.216.19
                                                                                    api.trustedform.comUnited States
                                                                                    14618AMAZON-AESUSfalse
                                                                                    239.255.255.250
                                                                                    unknownReserved
                                                                                    unknownunknownfalse
                                                                                    146.19.173.232
                                                                                    janiecera.comFrance
                                                                                    7726FITC-ASUSfalse
                                                                                    142.251.40.163
                                                                                    unknownUnited States
                                                                                    15169GOOGLEUSfalse
                                                                                    45.55.126.207
                                                                                    beacon.nosotroda.comUnited States
                                                                                    14061DIGITALOCEAN-ASNUSfalse
                                                                                    142.250.72.110
                                                                                    android.l.google.comUnited States
                                                                                    15169GOOGLEUSfalse
                                                                                    142.250.176.195
                                                                                    unknownUnited States
                                                                                    15169GOOGLEUSfalse
                                                                                    104.21.67.146
                                                                                    virtualpushplatform.comUnited States
                                                                                    13335CLOUDFLARENETUSfalse
                                                                                    172.64.165.7
                                                                                    unknownUnited States
                                                                                    13335CLOUDFLARENETUSfalse
                                                                                    IP
                                                                                    192.168.2.17
                                                                                    192.168.2.4
                                                                                    192.168.2.6
                                                                                    192.168.2.5
                                                                                    Joe Sandbox version:38.0.0 Ammolite
                                                                                    Analysis ID:1376332
                                                                                    Start date and time:2024-01-17 21:22:41 +01:00
                                                                                    Joe Sandbox product:CloudBasic
                                                                                    Overall analysis duration:
                                                                                    Hypervisor based Inspection enabled:false
                                                                                    Report type:full
                                                                                    Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                                    Sample URL:http://kugs.vipku.org/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12
                                                                                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                    Number of analysed new started processes analysed:7
                                                                                    Number of new started drivers analysed:0
                                                                                    Number of existing processes analysed:0
                                                                                    Number of existing drivers analysed:0
                                                                                    Number of injected processes analysed:0
                                                                                    Technologies:
                                                                                    • EGA enabled
                                                                                    Analysis Mode:stream
                                                                                    Analysis stop reason:Timeout
                                                                                    Detection:MAL
                                                                                    Classification:mal52.phis.troj.win@19/115@78/410
                                                                                    • Exclude process from analysis (whitelisted): SIHClient.exe
                                                                                    • Excluded IPs from analysis (whitelisted): 142.251.40.163, 34.104.35.123
                                                                                    • Excluded domains from analysis (whitelisted): edgedl.me.gvt1.com, clientservices.googleapis.com
                                                                                    • Not all processes where analyzed, report is missing behavior information
                                                                                    • VT rate limit hit for: http://kugs.vipku.org/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 17 19:23:10 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                                    Category:dropped
                                                                                    Size (bytes):2677
                                                                                    Entropy (8bit):3.9884206506111246
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:EB363FE22A0DED74CD25D6FE1A20CC9D
                                                                                    SHA1:6C08E4B574DCB0EE0DED4D24DB486096D8127BAB
                                                                                    SHA-256:9CEC296C80D6DE7AB11FF5959AFDA2964B9140DFC5A829A4C35DE397C64438E1
                                                                                    SHA-512:10885313C8A99A9608BEC0A047C3162EA02B139FAA129B8B5142BDF67B5C13A3EF520471C595529EE5042D583ADAFFBED6002FEBC8004FF1BA76741E7A7EE271
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:L..................F.@.. ...$+.,....~.:..I......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I1X.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V1X.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V1X.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V1X............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V1X............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 17 19:23:10 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                                    Category:dropped
                                                                                    Size (bytes):2679
                                                                                    Entropy (8bit):4.002664011287898
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:56E9482611F89A8711198233E6D5DD45
                                                                                    SHA1:50E947B6ACE905E86A631EBB844B2B9CD1539F92
                                                                                    SHA-256:1216B92598DA91C06CB69A0DF4A3B771462E694E22484673F814B4AB4164BD65
                                                                                    SHA-512:A4E349F0827C5FBB77DC76E82406EEFC83998C6EAC4280CEA46607B654BBF52E5EB5AA6B45FBC78251D33B42E047DF922E0CBC2182CD31A1339B5AEEE2488946
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:L..................F.@.. ...$+.,.....:/..I......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I1X.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V1X.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V1X.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V1X............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V1X............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                                    Category:dropped
                                                                                    Size (bytes):2693
                                                                                    Entropy (8bit):4.011852787061214
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:7FB72671D9CA5F97E5F84FB28A07E4EA
                                                                                    SHA1:EFE2E5AFF2FFCB20CC2CC2FB69C0EFF11B01F9AF
                                                                                    SHA-256:484355194C289C76D6A9C98DB78E76CE0F310198AA17A54D084EB968D4A0B3A8
                                                                                    SHA-512:9F8EB753D0600BF57B1A89F49F451E4793A9E721AED3450BDAEFA37B51EC2223D77CE2C7ACE93C0B29F45AB67B2B179D1121D5FDFE7D80076ECB899F2E18B75A
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:L..................F.@.. ...$+.,.....v. ;.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I1X.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V1X.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V1X.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V1X............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 17 19:23:10 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                                    Category:dropped
                                                                                    Size (bytes):2681
                                                                                    Entropy (8bit):4.0030418923439495
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:B34252C3C3E58C554C669839FBEF4B0E
                                                                                    SHA1:DE3C5B49056888BCA5E9F70539C63202A42F75D7
                                                                                    SHA-256:5DF1790445DBE1680931E59F48637070F10C55F0D651CC221F04393E3451A358
                                                                                    SHA-512:C9639999684C1C4F0113FED858F692DB027586E4D03EBFD272043BE6889D220F36415D3A6D1131ED2568D25908DDD59938D997FAA50692AEA5EB67CF759B69DD
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:L..................F.@.. ...$+.,.....)..I......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I1X.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V1X.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V1X.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V1X............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V1X............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 17 19:23:10 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                                    Category:dropped
                                                                                    Size (bytes):2681
                                                                                    Entropy (8bit):3.991881681082063
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:9201B74732AAE6A4ED1525C5B9916883
                                                                                    SHA1:06EA592081003B66C49EF7F12441031DE7048D29
                                                                                    SHA-256:CD2FFE400750DB75381B2EADE26580298BDF1451DAB42688699B263EC185FCD3
                                                                                    SHA-512:FCE9786B679E269DC83352A6AB12104316B76C8E974691D29031AEA1FD412775291139B78C2B23003E44B94A2EA1DFF0943A6707BBB8AF000971886725EE7BC6
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:L..................F.@.. ...$+.,....Y.4..I......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I1X.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V1X.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V1X.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V1X............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V1X............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 17 19:23:10 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                                                    Category:dropped
                                                                                    Size (bytes):2683
                                                                                    Entropy (8bit):4.0038798744621555
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:B9461AA53ADFC1F48D820BA89ABB0109
                                                                                    SHA1:9321CB3406854069F12A5BD3052789E487A0DDD8
                                                                                    SHA-256:928FCB033532397589A49E7986B7238FE0D8B6AC1691CE70D10BC3CD6220B0D0
                                                                                    SHA-512:58BD48A403DB1502A8124085A32150D3A37C0FC9FEB9E9C1B66247ADC8C6F2D90138D628A01C8F97B22DFF495F33A78C679DBC5AF75F186AEC7738373C033E06
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:L..................F.@.. ...$+.,....m.!..I......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I1X.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V1X.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V1X.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V1X............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V1X............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:PNG image data, 1001 x 1001, 8-bit/color RGBA, non-interlaced
                                                                                    Category:dropped
                                                                                    Size (bytes):472266
                                                                                    Entropy (8bit):7.993333072821621
                                                                                    Encrypted:true
                                                                                    SSDEEP:
                                                                                    MD5:BDF3A341855E42B28D395ADEBC72BA74
                                                                                    SHA1:DCC271AC7E28101F7A4FCFE4FAF7B4124B609E9C
                                                                                    SHA-256:19E6CC2A14A79EC633AFA888FB6141ED665119EDA949FA647D560F68541489B5
                                                                                    SHA-512:E18A63A6616704C3ED8F378D43F916600646F811D86D9C21CAF9BE5BDB13268B7E1C8B332506762C7DA68A150C1A87B2FE05963B6FD1A63B583F32C652C0729D
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:.PNG........IHDR.............i=l... .IDATx..y.#G..w=V...{.gy.gOf.P.P.F.Cz..y....E..v ........,.3,2.:?3.*.@ .....=.\c..B.!..B.!...D|..!..B.!..~@.N.!..B.!....tB.!..B.!.'P..B.!..B.!=."..B.!..B......B.!..BHO.H'..B.!..Bz.E:!..B.!....(..!..B.!...@.N.!..B.!....tB.!..B.!.'P..B.!..B.!=."..B.!..B......B.!..BHO.H'..B.!..Bz.E:!..B.!....(..!..B.!...@.N.!..B.!....tB.!..B.!.'P..B.!..B.!=."..B.!..B......B.!..BHO.H'..B.!..Bz.E:!..B.!....(..!..B.!...@.N.!..B.!....tB.!..B.!.'P..B.!..B.!=."..B.!..B......B.!..BHO.H'..B.!..Bz.E:!..B.!....(..!..B.!...@.N.!..B.!....tB.!..B.!.'P..B.!..B.!=."..B.!..B......B.!..BHO.H'..B.!..Bz.E:!..B.!....(..!..B.!...@.N.!..B.!....tB.!..B.!.'P..B.!..B.!=."..B.!..B......B.!..BHO.H'..B.!..Bz.E:!..B.!....(..!..B.!...@.N.!..B.!....tB.!..B.!.'P..B.!..B.!=."..B.!..B......B.!..BHO.H'..B.!..Bz.E:!..B.!....(..!..B.!...@.N.!..B.!....tB.!..B.!.'P..B.!..B.!=."..B.!..B......B.!..BHO.H'..B.!..Bz.E:!..B.!....(..!..B.!...@.N.!..B.!....tB.!..B.!.'P..B.!..B.!=."..B.!..B......B.!..B
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:JSON data
                                                                                    Category:downloaded
                                                                                    Size (bytes):6234
                                                                                    Entropy (8bit):4.981234752718146
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:98E719F4FF47A6B674C49CDF8A5084BA
                                                                                    SHA1:B0EB96CB3A96A89D33E9AD29B0F4D85E76D3F259
                                                                                    SHA-256:D29FAEB944A12DBFADE6689F72BF53B86F0289EB2DDA91303986F38F8CCCDB9A
                                                                                    SHA-512:0F2708E70C71F597CF31BF92ECFF03F2C571292E110E02D3F564885D443715019D19FE0A88BCA38BB3ECF7A2CFD5B72FE8FA94C0ADDF60847D47EAC97DC5277D
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://beacon.nosotroda.com/s/fc04f767-71d2-4ab9-b60f-8683c2559cbb?requestid=hI7kIhzieM&destinationid=2595812553&id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23
                                                                                    Preview:{"JsBlock":null,"SurveyBlocks":[{"Name":"EU-us-sf-tpl40-giftcard","AlternativeName":null,"CustomBlock":null,"IsWeighted":false,"Questions":[{"AnswerFieldType":2,"AnswerFieldTypeName":"Dropdown","Category":"Prize","CustomBlock":null,"Footer":null,"TcpaRequired":false,"IsAutocomplete":false,"Text":"Do you use cash?","OfferType":1,"OfferTypeName":"WarmUp","UniqueOfferUrl":null,"SubscribeUrl":null,"HostAndPostUrl":null,"ImpressionURL":"","CampaignId":"","Tag":"us-sf-41-use-cash","DeviceRestriction":0,"DeviceRestrictionName":"All","GenderRestriction":0,"GenderRestrictionName":"All","DependencyFormat":2,"DependencyFormatName":"Standalone","Options":[{"HostPostUrl":null,"UniqueOfferUrl":null,"DisableTrigger":false,"Optin":true,"HasTrigger":true,"Text":"Yes","Value":"Yes","ImageSelect":null,"OfferId":null,"NextQuestionTag":[],"SendSmsToClient":false,"Body":null},{"HostPostUrl":null,"UniqueOfferUrl":null,"DisableTrigger":false,"Optin":false,"HasTrigger":false,"Text":"No","Value":"No","ImageSele
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text, with very long lines (60130)
                                                                                    Category:downloaded
                                                                                    Size (bytes):60312
                                                                                    Entropy (8bit):4.72859504417617
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:A12EC7EBE75A4D59A5DD6B79E2BA2E16
                                                                                    SHA1:28F5DCC595EE6D4163481EF64170180502C8629B
                                                                                    SHA-256:FC5128DFDCDFA0C3A9967A6D2F19399D7BF1AAAE6AD7571B96B03915A1F30DDA
                                                                                    SHA-512:28B9EA5F3F95807259C2745162424ACEECAC2556BC1AB9A3B33E4E15B54C6970A4DF4A5892FE83C1155C82CA8D93AEBB173BE32F1A7F8B9D3CE038B2DD1E6FFE
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://ka-f.fontawesome.com/releases/v5.15.4/css/free.min.css?token=268a7048dd
                                                                                    Preview:/*!. * Font Awesome Free 5.15.4 by @fontawesome - https://fontawesome.com. * License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License). */.fa,.fab,.fad,.fal,.far,.fas{-moz-osx-font-smoothing:grayscale;-webkit-font-smoothing:antialiased;display:inline-block;font-style:normal;font-variant:normal;text-rendering:auto;line-height:1}.fa-lg{font-size:1.33333em;line-height:.75em;vertical-align:-.0667em}.fa-xs{font-size:.75em}.fa-sm{font-size:.875em}.fa-1x{font-size:1em}.fa-2x{font-size:2em}.fa-3x{font-size:3em}.fa-4x{font-size:4em}.fa-5x{font-size:5em}.fa-6x{font-size:6em}.fa-7x{font-size:7em}.fa-8x{font-size:8em}.fa-9x{font-size:9em}.fa-10x{font-size:10em}.fa-fw{text-align:center;width:1.25em}.fa-ul{list-style-type:none;margin-left:2.5em;padding-left:0}.fa-ul>li{position:relative}.fa-li{left:-2em;position:absolute;text-align:center;width:2em;line-height:inherit}.fa-border{border:.08em solid #eee;border-radius:.1em;padding:.2em .25em .15em}.fa-pul
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:JSON data
                                                                                    Category:dropped
                                                                                    Size (bytes):129
                                                                                    Entropy (8bit):4.613212127209274
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:1F13E69734EC6D934FD5F449C05E8AC7
                                                                                    SHA1:9CD22C3026CF99E64A2239D72A811925521F157F
                                                                                    SHA-256:89617E63A983178FEE68290DC76FD06475BFB6A8505FF79A2906E4D9A5E17504
                                                                                    SHA-512:A51BAB63F3A496AD49E1BD302A4219E8A2AD89E29CA5889E4CE9220FC126D646C26B94258E6058A838A233B09CBEEBE3C6456A0773FB8CD26754FFA846F15590
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:{"country":"United States","countryCode":"US","state":"New York","stateCode":"NY","zip":"10118","isp":null,"ip":"154.16.192.193"}
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:Web Open Font Format (Version 2), TrueType, length 22504, version 1.0
                                                                                    Category:downloaded
                                                                                    Size (bytes):22504
                                                                                    Entropy (8bit):7.9897727403675995
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:1C6C65523675ABC6FCD78E804325BD77
                                                                                    SHA1:898D9808304DC157F5DCB18CA169EC6E2B96B3D7
                                                                                    SHA-256:08664859BAAB5ED98F0BF818ED77E38464FF1826DC6406D5ECBD651409AFBD92
                                                                                    SHA-512:1505E8496C9BEE214C5F8815F8D88A31FFE2BAEB6FBA81A8228BD52220B9B2BB10464C1E1DBA11D6881583DFA478CDFB30A79CFA6F069C362FB65443FEB06918
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://fonts.gstatic.com/s/lato/v24/S6u9w4BMUTPHh50XSwiPGQ.woff2
                                                                                    Preview:wOF2......W..........W...........................z.p.`..D....e........Q..B..6.$..v. .....E.K...%...v.H$..F".... .ef ..D..[g..Nr"c.....U{AA.i.L.0.zkT.P.......BV.q.....`6.....>...[...E:4..d^.7..L......vL.\..xL..f.......T.....I......%.>+...95.N...<].....h.o7..).-....]R#..]....I..(W9..P........((...E....i}.eY.ys.y..^....k....9.s_....I...&D..Zf.C.1...CnfxQb....#.K..]....^.;3..~.@...V......:i..9...6.vU2+D.z...U......N.%..d..*..%...s.7...NM...I.i...<v....:.B...{..B..>.T$..@+....|Y.>........8..Wo......r./..r.hJ...a.Dm......f..Uk...F..k......f.\...L.....s..."M......k{Ib.%.E"C...J..Jj[.Y.;...d..@........A.}....+1). m.t~...-.f...J..Cu.Z]umgqZJ..IN........c.8"v.L.q.CzU..v...{.5U....WJ.:o..<...j}...J.Dif.f~.g....N.do.~.U......x....AJ"A.)..H.I.D......:...1X..~.....W.LE.......).q.Q......K.\..rw]p......)}xP...Zj.@...(B.8.!..9$Va.8...Q....o...k...LB*.j.......l.0.G.B|Q.o.j.U.vg+k.#.0.<8.....Z...xQ...m....x..s3.....d`....;.+..smW.8A.d..._........D...%..'.
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text, with very long lines (65536), with no line terminators
                                                                                    Category:downloaded
                                                                                    Size (bytes):86046
                                                                                    Entropy (8bit):5.716830995356198
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:F46641519EEE44FE450F02AE72E64A74
                                                                                    SHA1:AF388DAD525A6E17E8057BDD4E3ABBD6E165FC62
                                                                                    SHA-256:DAEC1D32A4F211884695930CBC2443467F28E7BD1B1AE1AFB7F2EB16349AACFE
                                                                                    SHA-512:8412390578D4326415F8294DE26E335B0881C72C085B1895C197145E7A79558FE168C0E0BC68E1E9232A57B2A8995BDADF46D6FDA95199CC35C49D894F661EB9
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://cdn.trustedform.com/trustedform-1.9.4.js
                                                                                    Preview:!function(){"use strict";function n(n,t){return"function"==typeof n?function(t){return n.bind(t)}:function(n){return t.bind(null,n)}}var t=Array.from||function(n){return Array.prototype.slice.call(n)};var r=n(Array.prototype.includes,e);function e(n,t){return-1!==n.indexOf(t)}var i=n(Array.prototype.flatMap,(function(n,t){for(var r=[],e=0;e<n.length;e++)Array.prototype.push.apply(r,t(n[e]));return r}));var o=n(Array.prototype.find,(function(n,t){for(var r=0;r<n.length;r++)if(t(n[r]))return n[r]}));var u=n(String.prototype.includes,e),a="undefined"!=typeof globalThis?globalThis:"undefined"!=typeof window?window:"undefined"!=typeof global?global:"undefined"!=typeof self?self:{};function c(n){return n&&n.__esModule&&Object.prototype.hasOwnProperty.call(n,"default")?n.default:n}function f(n,t){return n(t={exports:{}},t.exports),t.exports}function d(){throw new Error("Dynamic requires are not currently supported by @rollup/plugin-commonjs")}var s=c(f((function(n){function t(r){return"functi
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text, with very long lines (1211)
                                                                                    Category:downloaded
                                                                                    Size (bytes):3998
                                                                                    Entropy (8bit):4.922633165911299
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:85A00BDBC13FD231BCA4ACB87E88C83E
                                                                                    SHA1:89130B5324206302FC6B67F14949B4FDCCD87E1A
                                                                                    SHA-256:EB569FB4F2A140B98839CB4A7A5F99E6087513E24B30CE219FC0A60DFA599D16
                                                                                    SHA-512:3C7F9BF9D0A66CAF40191EA6CE3338DD14D777CB328502D03FAABF7C054EA96579CE5605BF8F851E5370CC99FC224A30D23D572CDB7E5BEF68B73FCCEDE10C38
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://virtualpushplatform.com/md-service-worker-content.js
                                                                                    Preview:let dbVersion=2;let DB=null;let displayStatus=4;let clickStatus=5;let nextSendoutDateKeyName='nextSendoutDate';let nextSendout=null;let minimumStatsForSendout=10;self.addEventListener('install',function(event){event.waitUntil(self.skipWaiting());});self.addEventListener('activate',function(event){event.waitUntil(self.clients.claim());});self.addEventListener('push',function(event){if(event.data){let payload=event.data.json();if(!payload.image||!payload.image.includes('http'))delete payload.image;if(!payload.badge||!payload.badge.includes('http'))delete payload.badge;if(!payload.icon||!payload.icon.includes('http'))delete payload.icon;event.waitUntil(self.registration.showNotification(payload.title,payload));payload.data.status=displayStatus;event.waitUntil(addStat(payload.data));if(payload.data.taboolaVisibleUrl){event.waitUntil(updateTaboolaVisible(payload.data.taboolaVisibleUrl));}}});self.addEventListener('notificationclick',function(event){event.waitUntil(onNotificationClick(event)
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text, with very long lines (12438)
                                                                                    Category:downloaded
                                                                                    Size (bytes):71503
                                                                                    Entropy (8bit):5.1259269022659
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:9234273EEDA1BF9914000ED35A6B3970
                                                                                    SHA1:9522B1AB3570D8077F4D0925DC2465CEB30C08C6
                                                                                    SHA-256:C56F9A877C81465BB3A9C3689E69E5EAD42C9B755F43061D0C0C50DC5071606F
                                                                                    SHA-512:EBA254A2B77BDE78D0E4A088C6A09AD943A990AED455C81D9A4A939E0FE0F9BA4745A5A54C1F732EC287D2498B0681443B05DCCB062DCB06D7C905FB777126AE
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://nosotroda.com/e/tpl43/bundle.d43d3461bfbb77e9dc90.css?t=1697733753352
                                                                                    Preview:@import url(https://fonts.googleapis.com/css2?family=Lato:wght@400;700;900&display=swap);....loader{position:fixed;top:0%;width:100%;height:100%;background:rgba(45,60,79,0.7)}.loader #loader{top:25%;height:100%;position:absolute;width:100%}@keyframes loader{0%{left:-100px}100%{left:110%}}.loader-wrapper{padding-top:2%;padding-bottom:4%;display:block;margin:0 auto;max-width:300px !important;width:100%}.loader-wrapper .loader-Header{display:none}.loader-wrapper .loader-Footer{display:none}#box{width:50px;height:50px;background:#539b3b;animation:animate 0.5s linear infinite;border-radius:3px;display:block;margin:8% auto 0}@keyframes animate{17%{border-bottom-right-radius:3px}25%{transform:translateY(9px) rotate(22.5deg)}50%{transform:translateY(18px) scale(1, 0.9) rotate(45deg);border-bottom-right-radius:40px}75%{transform:translateY(9px) rotate(67.5deg)}100%{transform:translateY(0) rotate(90deg)}}#shadow{width:50px;height:5px;background:#000;opacity:0.1;border-radius:50%;animation:shadow
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (64907)
                                                                                    Category:downloaded
                                                                                    Size (bytes):399031
                                                                                    Entropy (8bit):5.367407077998128
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:C23E7E1087E311B2107A66B76A78F4A9
                                                                                    SHA1:46AAE17643176D289FF2B42BD2B8B7C4A65DA309
                                                                                    SHA-256:84F91962C50A9F5A90FFC2463C3059FDD2BB217C437D68E2DD21F1EECB296FC5
                                                                                    SHA-512:38D5F2CCA912EFE98CEF8656207ADB7EBA0430971C7C1632AA592B66DF7F65AC3125694F470A1AC0098706FAD0CD0C926D231657487B84B2CE5201911333E9C3
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://nosotroda.com/e/tpl43/js/12.d4403009.chunk.js
                                                                                    Preview:(window.webpackJsonp=window.webpackJsonp||[]).push([[12],[,function(t,e,n){(function(t,r){var i;./**. * @license. * Lodash <https://lodash.com/>. * Copyright OpenJS Foundation and other contributors <https://openjsf.org/>. * Released under MIT license <https://lodash.com/license>. * Based on Underscore.js 1.8.3 <http://underscorejs.org/LICENSE>. * Copyright Jeremy Ashkenas, DocumentCloud and Investigative Reporters & Editors. */(function(){var o="Expected a function",a="__lodash_placeholder__",s=[["ary",128],["bind",1],["bindKey",2],["curry",8],["curryRight",16],["flip",512],["partial",32],["partialRight",64],["rearg",256]],u="[object Arguments]",c="[object Array]",f="[object Boolean]",l="[object Date]",h="[object Error]",d="[object Function]",p="[object GeneratorFunction]",v="[object Map]",g="[object Number]",m="[object Object]",y="[object RegExp]",b="[object Set]",w="[object String]",x="[object Symbol]",k="[object WeakMap]",S="[object ArrayBuffer]",_="[object DataView]",O="[object Fl
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text
                                                                                    Category:downloaded
                                                                                    Size (bytes):2299
                                                                                    Entropy (8bit):5.342321472470692
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:18612F12E33EFA4AF09AD301EF35F0D3
                                                                                    SHA1:811119D6A46CA0131A5ECC056175BABD776DC03D
                                                                                    SHA-256:0CEE972F52F443216ED569505738E89B08925201F31B5D7A51783EE9A0DCC785
                                                                                    SHA-512:2E0C71C6A2439D68A3112016A6AE6C11553795AD520C94C26F6DE2EC38588A6F87542431EF92F9F4FC13975B07FECEBEC9E8ED7D104BF11F065E75DE444F7569
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://fonts.googleapis.com/css2?family=Lato:wght@400;700;900&display=swap
                                                                                    Preview:/* latin-ext */.@font-face {. font-family: 'Lato';. font-style: normal;. font-weight: 400;. font-display: swap;. src: url(https://fonts.gstatic.com/s/lato/v24/S6uyw4BMUTPHjxAwXjeu.woff2) format('woff2');. unicode-range: U+0100-02AF, U+0304, U+0308, U+0329, U+1E00-1E9F, U+1EF2-1EFF, U+2020, U+20A0-20AB, U+20AD-20CF, U+2113, U+2C60-2C7F, U+A720-A7FF;.}./* latin */.@font-face {. font-family: 'Lato';. font-style: normal;. font-weight: 400;. font-display: swap;. src: url(https://fonts.gstatic.com/s/lato/v24/S6uyw4BMUTPHjx4wXg.woff2) format('woff2');. unicode-range: U+0000-00FF, U+0131, U+0152-0153, U+02BB-02BC, U+02C6, U+02DA, U+02DC, U+0304, U+0308, U+0329, U+2000-206F, U+2074, U+20AC, U+2122, U+2191, U+2193, U+2212, U+2215, U+FEFF, U+FFFD;.}./* latin-ext */.@font-face {. font-family: 'Lato';. font-style: normal;. font-weight: 700;. font-display: swap;. src: url(https://fonts.gstatic.com/s/lato/v24/S6u9w4BMUTPHh6UVSwaPGR_p.woff2) format('woff2');. unicode-range: U+0100-02
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text
                                                                                    Category:downloaded
                                                                                    Size (bytes):3834
                                                                                    Entropy (8bit):5.34081556409407
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:5E4E2012B2F18F872E014B258EC38680
                                                                                    SHA1:B6A0E2090CB41F86ED35D53BB3FAB2D261801347
                                                                                    SHA-256:A781901393BD19811BEF7EC44FE3715212110370A565CE384FF8A902DE5EAF3E
                                                                                    SHA-512:6067A84C781DCC26841769BE569D3056DD7EE3144776E5325B3C0024158FAC4D6BC0EED694F02E574689F709371B396E1CC54F8A9C1B32DF3AC0F6B63AC23FBF
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://fonts.googleapis.com/css2?family=Lato:wght@100;300;400;700;900&display=swap
                                                                                    Preview:/* latin-ext */.@font-face {. font-family: 'Lato';. font-style: normal;. font-weight: 100;. font-display: swap;. src: url(https://fonts.gstatic.com/s/lato/v24/S6u8w4BMUTPHh30AUi-qJCY.woff2) format('woff2');. unicode-range: U+0100-02AF, U+0304, U+0308, U+0329, U+1E00-1E9F, U+1EF2-1EFF, U+2020, U+20A0-20AB, U+20AD-20CF, U+2113, U+2C60-2C7F, U+A720-A7FF;.}./* latin */.@font-face {. font-family: 'Lato';. font-style: normal;. font-weight: 100;. font-display: swap;. src: url(https://fonts.gstatic.com/s/lato/v24/S6u8w4BMUTPHh30AXC-q.woff2) format('woff2');. unicode-range: U+0000-00FF, U+0131, U+0152-0153, U+02BB-02BC, U+02C6, U+02DA, U+02DC, U+0304, U+0308, U+0329, U+2000-206F, U+2074, U+20AC, U+2122, U+2191, U+2193, U+2212, U+2215, U+FEFF, U+FFFD;.}./* latin-ext */.@font-face {. font-family: 'Lato';. font-style: normal;. font-weight: 300;. font-display: swap;. src: url(https://fonts.gstatic.com/s/lato/v24/S6u9w4BMUTPHh7USSwaPGR_p.woff2) format('woff2');. unicode-range: U+01
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:PNG image data, 1000 x 749, 8-bit/color RGBA, non-interlaced
                                                                                    Category:downloaded
                                                                                    Size (bytes):347103
                                                                                    Entropy (8bit):7.9928402863767625
                                                                                    Encrypted:true
                                                                                    SSDEEP:
                                                                                    MD5:9C9B6882C819D6A29A19657624BE7E7B
                                                                                    SHA1:D113DA49689790196F8F645CDF19462036174D8A
                                                                                    SHA-256:9929C92C26C955A6F629A163BDA941AD2036323C12D6B5466F03410CF150FFD9
                                                                                    SHA-512:6EF82EB7ED6AC70EB069146C0E9DF72DE75574B4290D5B7416A6D7A9B96F2EF55B021EBA34B0107C1638F8998B3E13F9DCF92D9549EFA0DEFC187D6B420B436E
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://nosotroda.com/e/tpl43/public/mobile_CashApp.png
                                                                                    Preview:.PNG........IHDR...............N.....pHYs.................iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 6.0-c003 116.ddc7bc4, 2021/08/17-13:18:37 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmp:CreatorTool="Adobe Photoshop 21.2 (Windows)" xmp:CreateDate="2023-09-27T11:32:15+08:00" xmp:ModifyDate="2023-09-27T12:04:54+08:00" xmp:MetadataDate="2023-09-27T12:04:54+08:00" dc:format="image/png" photoshop:ColorMode="3" xmpMM:InstanceID="xmp.iid:4e99d270-9192-5d4e-a99d-9a3545a80c83" xmpMM:DocumentID="xmp.did:4e99d270-9192-5d4e-a99d-9a3545a80c83" xmpMM:OriginalDocumentID="xmp.did:4e99d270-9192-5d4e-
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:HTML document, ASCII text, with very long lines (398)
                                                                                    Category:downloaded
                                                                                    Size (bytes):458
                                                                                    Entropy (8bit):5.131460290374407
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:0A3E69B8B37A6DF0ACD7E7F5D9D3B854
                                                                                    SHA1:680DE96CFE2AFF1B030BFBD4A7CFA2529993EA61
                                                                                    SHA-256:0F3A07F36D6BDDEE418F7D7548BC165B09817E10764A359D2773388CDEC9FF8A
                                                                                    SHA-512:9C5C0679E082A5776536835110B90436CD6531E3B2C4FC7A15BDCE7F550D6647447C904E68D660FAF81E39C108E17198830E8B133E86D8559180FA6FB5CE25C7
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:http://kugs.vipku.org/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12
                                                                                    Preview:<script>.let e=new URL(window.location.href);e.pathname="/t"+e.pathname;let o=e.toString();navigator.cookieEnabled&&!function(e){for(var o=["googlebot","bingbot","yandexbot","duckduckbot","slurp","baiduspider","facebot","ia_archiver"],t=e.toLowerCase(),n=0;n<o.length;n++)if(t.indexOf(o[n])>-1)return!0;return!1}(navigator.userAgent)?setTimeout((function(){document.location.href=o}),1e3):console.log("bt");.</script>..<p style="color:gray;">redirect...</p>.
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:RIFF (little-endian) data, Web/P image
                                                                                    Category:downloaded
                                                                                    Size (bytes):5850
                                                                                    Entropy (8bit):7.959563766848594
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:B783152E3D5CB54FB0513E2F733B9C16
                                                                                    SHA1:A5A3563A418C42E2945C41B2BB10FBA2825CF38E
                                                                                    SHA-256:393C823927A7F5DE7D723181A1FDA8BDD866A48F8779317708ED561DA71CF372
                                                                                    SHA-512:5D36ACC643104655417ACF56F8096F6367EA518A9C54D40DB31173008FE53A7713DEB3443DA62071D1427161F3153CD9B944006680259CA0F7374F1F2C6A920D
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://cdn4image.com/creatives/602/284/192_2_1699540410118.webp
                                                                                    Preview:RIFF....WEBPVP8X..............ALPH.......m.Fp-...'.AD.' .. =..pW.I?.N.]...$..9..B.m.........t...$........#."Iz..#......Y..y..".h...X%m...P........p.f#MD@....$`...../........09.w.?}.*..EX..y.\.D.. .Pcs./...w..CY...j.4\U.8`t}e.....Z.L.....[...Je.*4...P.yS.B.... .Y.*`U.>M.:...5.V...."YW......E..-Q.....G...r.....*.e9.%...x*dS..L.nr.). .Y.G.V.C..'yj...,I..'....b...1.....4......h...x.1...%,M..h...f.....jt`X..\...e...o.j....I:.n=......Ib.....u'.rK.GQ...[...._o..(.&..y..........9.B<.+.&+.D......e..|.$.H\]..F@... .L..e.w'N{3.X...(..|.........Mo.6...=..#.....Vv"....|..6..D.@h.<..H..Xf....k@#.....#L...3.a.H..H\n...XI..1..%..u.V[0.;6_.'.m.9...V......y.].4.....2.=..p0...M....gqwd...k4.F...P..5.&j.L.#.....c....A....c...M'.f....\.....m.3.@....j.R..R^Z..W_...S..~6kg-..m......&Z?.....v6x<0.s.V..f..?wqD8....hS.j.E..8...J...Q%.;....>..].-.|.../........c.c.,&.........y.......?....DL.D..f.Ah.....y|y.-.A.+$...o...M..}D._>.....:<.&....B.6\z....ucc.fbE.e...)|.n
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:Web Open Font Format (Version 2), TrueType, length 23040, version 1.0
                                                                                    Category:downloaded
                                                                                    Size (bytes):23040
                                                                                    Entropy (8bit):7.990788476764561
                                                                                    Encrypted:true
                                                                                    SSDEEP:
                                                                                    MD5:DE69CF9E514DF447D1B0BB16F49D2457
                                                                                    SHA1:2AC78601179C3A63BA3F3F3081556B12DDCAF655
                                                                                    SHA-256:C447DD7677B419DB7B21DBDFC6277C7816A913FFDA76FD2E52702DF538DE0E49
                                                                                    SHA-512:4AEBB7E54D88827D4A02808F04901C0D09B756C518202B056A6C0F664948F5585221D16967F546E064187C6545ACEF15D59B68D0A7A59897BD899D3E9DDA37B1
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://fonts.gstatic.com/s/lato/v24/S6u9w4BMUTPHh6UVSwiPGQ.woff2
                                                                                    Preview:wOF2......Z........8..Y...........................B.p.`..D....e.....d.....B..6.$..v. .....E.K...5l\e.v.~S$}.".8.....5.E....s...ai`W.u..8a2C..JuBj....x.....%.u.C.......p..c...7...+.1.GS.3...F_....-..`#........]...T.....x*....&..{.....V..,..&~$D.#.P..|gzz...B.7..m.3....HH.l.....Dj.F.X.....U..+.Q...T.`...ST...1...0....io`zu@.J2....3]}0.X...,..+"...............(k.CGl......`.y.._....3.t!O.,X:t.3....lw..U../:..b.]....V.$.y....G....*.H..IN....bQ.+ \@....;...C3...c.l..i/....#..I.).Y...]...s..$K!..Tr...g%|r.D.#.Y{..R..We...X.?...*r.@...G.{..>..4^..b..,.z........T..[.ru#.7..{..G....J.3......Lz.C].of$Y2..^...>@L..P.........7..bB.....6f...ec.i..{._\...A.I.Lcy.Qm".....k.^.d.K(x7U...c.o.......}.T......iL..!.Z.......[O..*.%...*'?........^I./..;t.4%.....S...4....wY.b9.%.b...,.....tC..9.Z...V..CHnA.S.-.u$m.\....7{,..K{(.."....._...|{.VowE@E@@..Zg.....`8..b..Z...^....l+...R..%.L.b...._..E.j9\+.L.#J.........?&...&..scE..b..Jc.8...V....L 1./k.3..7w....x..-.....
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:PNG image data, 196 x 196, 8-bit/color RGBA, non-interlaced
                                                                                    Category:downloaded
                                                                                    Size (bytes):15966
                                                                                    Entropy (8bit):7.960724177548389
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:FFC3C1DE559EF26FD7848E10CEEF02B2
                                                                                    SHA1:3658DC00115A4A6D507E9D6910A22B6A5945EF3E
                                                                                    SHA-256:D8F649A56D616461B4DDA4748F937D9DE87EC4BB14A7E300E17F1D979E0FB448
                                                                                    SHA-512:A2D1626A222666E84BF6E42A2A61CE16731DFA6BEA4E11EAB96372779F5AB528FF806B85EA0F432BF816BA6700EDBEAD256612499260B39064DE0F80376F3E7F
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://cdn.md-ace-b.online/cdn/NEC_icon_4.png
                                                                                    Preview:.PNG........IHDR................k... cHRM..z&..............u0...`..:....p..Q<....bKGD..............tIME.....3.=.....=>IDATx..Y...y..;'.Z.....A.X).....II.$..Mm....l..3.37.>...s.&..n1...cyl..%...+Y.l..H....$.}_..h.RU.U..3..U]...z....G .]..y2.....Oh.5..$.@^..$H...."A.:$.H....!.$.CB....."A.:$.H....!.$.CB....."A.:$.H....!.$.CB....."A.:$.H....!.$.CB....."A.:$.H....!.$.CB....."A.:$.H....!....&)....@..h.R.0.......t.!..^.!^Q$.x."Z.5Ji.@.!..M..Wx.&T.Z).../hj. ....bH...^\X..Q..b._?...BD._..A....^<..M.(.Rh4j..D./...BB..B...FJY..R..J.h...B...........0.L.$... X..[..a.(.....2{U...g.......Dkk+.......).L.(.0..j...O].......~..o...!.L.l6KKs.B....R*.....z(.....n..n..fY...B...\.../..g.y......a.J..R2>>..:...:..P.T..F..RbY..L...V::;.......>......8..4... .............!......R...H).J16:.i....o..7.....$.C..tL...s...!..7o./../.........Fd.g..>.,J)Lsi....4M...0.\.".,.\.Ek]..i..Ri..<..]tww...CwO.....-.3i,..)...6.em.G..x.W'yD..@..b.2.....tw.L...477...R..U.T.Z...,a.....+....
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                    Category:downloaded
                                                                                    Size (bytes):548
                                                                                    Entropy (8bit):4.688532577858027
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:370E16C3B7DBA286CFF055F93B9A94D8
                                                                                    SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
                                                                                    SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
                                                                                    SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://nosotroda.com/e/tpl43/public/ahr/favicon/favicon.png
                                                                                    Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:HTML document, ASCII text, with no line terminators
                                                                                    Category:downloaded
                                                                                    Size (bytes):143
                                                                                    Entropy (8bit):5.026003900599222
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:2253817BED6A307BDE2D535275E39C0A
                                                                                    SHA1:0AFE452FFA0AA97A58F34E84D92DCA7FA21715D8
                                                                                    SHA-256:7886572037AA520BAC345E8B10406823A225E258CCC4F4EC0DC784C301F07E10
                                                                                    SHA-512:3BCDADB115ECF71596291DC72657854F7F0FB2CCE4847CB7C1FBEEAA9A6249A839634E5EF2C8438EBB32AAE98EA67A022051877557DB8E15D4B57896932BA89B
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://jinxmux.com/100835e4e5d854e4800/12/273-2979/14014-889062-9063
                                                                                    Preview:<script type="text/javascript">window.location.href="https://bledslab.win/r/ab349b6d-f4b1-4815-a82c-5813cf870fa4/473183/1436326885/12"</script>
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:PNG image data, 30 x 30, 8-bit/color RGBA, non-interlaced
                                                                                    Category:dropped
                                                                                    Size (bytes):1897
                                                                                    Entropy (8bit):7.74394838223016
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:AABE97F816BD1D09F2D5C817B75E8C52
                                                                                    SHA1:60D5E1A6A12497196DA425D3385A0CB7E308EA36
                                                                                    SHA-256:0DEB2955C0A55E069E2D8BDEA89EC03C597B1F2E4D7FF21D99BF2A68D19AE6FA
                                                                                    SHA-512:9AEF900FFE67133E98CC8555313FA20FB649D229F090391CC844F0CE3C9788EF1EED7803B12362A2BCF03C6D80A885D6A2B96DD744BE7BB3DDD305C92D165A41
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:.PNG........IHDR.............;0.....KiTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c138 79.159824, 2016/09/14-01:09:01 ">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about=""/>. </rdf:RDF>.</x:xmpmeta>.<?xpacket end="r"?> I.:....IDATH...K..E..._uu..cfv..B@.x..x..xEPHP.c}...1..$.B..j8x!....c...j D|....#aM$!A....;.....<..l...../.KU...^.U.13n$.... ...R_4....0.K.4..j.a)..;....`P...B..u.`.P*..m.A...,.y.0.@.....*#...e..S.....p.@.....j.cc...Y.>ul.c._..N.{Z........;..FW+.:..HL, j....YAPzjl.[o...D.U........>Z.>3....G......!..6l!.!...y............+.x^.P....!@.v..(...aX..y.C....~...{2...H....b@]..............>0.$hJ.oKx..l...}....w..w2CC...:.H..P.7.0@$.......;..;M.7.-..*!...!.A$.R...{D..!.<.........>t...d^.+.BA.....uc8....,...'"....P..\..1.y...ry. ..(..(.$.r".E.y..tz{".xG....$P..Wz^i.,...0.RB...2........;.....H6.R.o.y..0.Re._,
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text, with very long lines (26500)
                                                                                    Category:dropped
                                                                                    Size (bytes):26682
                                                                                    Entropy (8bit):4.82962335901065
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:76F34B71FC9FB641507FF6A822CC07F5
                                                                                    SHA1:73ED2F8F21CD40FB496E61306ACBB5849D4DBFF4
                                                                                    SHA-256:6DEA47458A4CD7CD7312CC780A53C62E0C8B3CCC8D0B13C1AC0EA6E3DFCECEA8
                                                                                    SHA-512:6C4002CE78247B50BFA835A098980AF340E4E9F05F7097C1E83301289051CE1282E647ABAB87DB28A32FBFE0263C7318D2444B7D57875873908D6D5ED2AF882F
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:/*!. * Font Awesome Free 5.15.4 by @fontawesome - https://fontawesome.com. * License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License). */.fa.fa-glass:before{content:"\f000"}.fa.fa-meetup{font-family:"Font Awesome 5 Brands";font-weight:400}.fa.fa-star-o{font-family:"Font Awesome 5 Free";font-weight:400}.fa.fa-star-o:before{content:"\f005"}.fa.fa-close:before,.fa.fa-remove:before{content:"\f00d"}.fa.fa-gear:before{content:"\f013"}.fa.fa-trash-o{font-family:"Font Awesome 5 Free";font-weight:400}.fa.fa-trash-o:before{content:"\f2ed"}.fa.fa-file-o{font-family:"Font Awesome 5 Free";font-weight:400}.fa.fa-file-o:before{content:"\f15b"}.fa.fa-clock-o{font-family:"Font Awesome 5 Free";font-weight:400}.fa.fa-clock-o:before{content:"\f017"}.fa.fa-arrow-circle-o-down{font-family:"Font Awesome 5 Free";font-weight:400}.fa.fa-arrow-circle-o-down:before{content:"\f358"}.fa.fa-arrow-circle-o-up{font-family:"Font Awesome 5 Free";font-weight:400}.fa.fa-arro
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text, with very long lines (2774)
                                                                                    Category:dropped
                                                                                    Size (bytes):2956
                                                                                    Entropy (8bit):5.124762572686671
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:F2E0B2680D9B0BCB6E0039C4424E5A59
                                                                                    SHA1:1EA995CEA90B79F3AD16C318572313A671718645
                                                                                    SHA-256:7F8B63BFF49FBA3C5BAE30F4EB39F2FD6D088FBE9D7292BDF37B0EF4A1EC68D6
                                                                                    SHA-512:DF7C65B3DF1A4F5AC7F697B1D6DCC264ECF3C177F9BD0375B5C52A4A124AC8CEA4FDE3429226875D3B39D1235623A0869230AF25E6028C452C9E7E417A53FAC3
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:/*!. * Font Awesome Free 5.15.4 by @fontawesome - https://fontawesome.com. * License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License). */@font-face{font-family:"FontAwesome";font-display:block;src:url(../webfonts/free-fa-solid-900.eot);src:url(../webfonts/free-fa-solid-900.eot?#iefix) format("embedded-opentype"),url(../webfonts/free-fa-solid-900.woff2) format("woff2"),url(../webfonts/free-fa-solid-900.woff) format("woff"),url(../webfonts/free-fa-solid-900.ttf) format("truetype"),url(../webfonts/free-fa-solid-900.svg#fontawesome) format("svg")}@font-face{font-family:"FontAwesome";font-display:block;src:url(../webfonts/free-fa-brands-400.eot);src:url(../webfonts/free-fa-brands-400.eot?#iefix) format("embedded-opentype"),url(../webfonts/free-fa-brands-400.woff2) format("woff2"),url(../webfonts/free-fa-brands-400.woff) format("woff"),url(../webfonts/free-fa-brands-400.ttf) format("truetype"),url(../webfonts/free-fa-brands-400.svg#fontawesome)
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:PNG image data, 300 x 223, 8-bit/color RGBA, non-interlaced
                                                                                    Category:downloaded
                                                                                    Size (bytes):120938
                                                                                    Entropy (8bit):7.993369624346691
                                                                                    Encrypted:true
                                                                                    SSDEEP:
                                                                                    MD5:97E46DDA6A0F93854D0FDA89B9244850
                                                                                    SHA1:0DA8C7CB6A6BA642A40ACBDE80466AE19433F891
                                                                                    SHA-256:76EDF3D1A24217B5F5A16A4B7836DA6FEFCF12F5DD80C8610B3C641A5AD759E8
                                                                                    SHA-512:91D0B04ADFFDF65DABCADFF8D765B1B2D8551C000137BF0001534D736A51539FBB2DE134EA5710967512E322396FFA4DD117B22E4C38C80ED3B740FC9728165B
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://cdn.pushdrop.club/cdn/NEC_banner_1.png
                                                                                    Preview:.PNG........IHDR...,.........L..v... cHRM..z&..............u0...`..:....p..Q<....bKGD..............tIME.....4#.......IDATx...-K........N...uo..nWUWUWu7.......P$@R..I.G.%z.....d..2.Q..H3.....b...j.n....d.."....=".>y........C...........o.U..B.x?.c...0..F....{.~`...~....c.5.*b.E.AD.PU....='...{L..=....j$......0.`D....@1.Q...o$.."...3f:.|....M.;..._y}...."B....H$.@...=.....<..j.D.......`....i.n;.2x...*.t..q..:.o..[|....q.1... ..|}.1v..Z....a.................G...}.7.*G............'?!`1..c...^r.2..}...x..h..]@..........".c....=..?b..w...-O..^i.z.rzv.f..Q,PU....m......<.f?........=...[...,.K.a.......H.....iMEM?U.b.....QU5u.R...X..4.......G....h/......P..7jN..{T._..&.../...o..7..9..a..7{...?..K^...?..o......%.>..;.....1O.n.........._...x........o.....F.....]7...?....g...0.}..........i.....$-.#..y5..=7.1.qA.C.... ..=P.ly>-...d.....PI..!...If.@f.A..F..........C#R~....+....#>x...b.P!....v.lD@@.xK6...JZ....4..j..../%R6........5.....0V.#.}....\gU..z-8k
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:downloaded
                                                                                    Size (bytes):113
                                                                                    Entropy (8bit):5.015209003384933
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:A2EFB081A7FB236CF4A51334D40DC365
                                                                                    SHA1:808B473EDC023D1D8140035711C490B921EEA307
                                                                                    SHA-256:8B1BA69C3414A25C833700EB8149CC68BA27B99F78C0C01B56986E7625B3DC0D
                                                                                    SHA-512:C9EBCD41F328A896BFD20CD13EDCC4F3F5B20DFE07C10E8DA1392CD10B6C545AC2658366602F83E60D4CC46FCCC32E2D2FF0410A2B8E93A5C30A4D1A2BBFCFE8
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://beacon.nosotroda.com/g/0e1dc196-5aa6-45bf-af51-e1ed42f37930?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23
                                                                                    Preview:https://beacon.nosotroda.com/s/fc04f767-71d2-4ab9-b60f-8683c2559cbb?requestid=hI7kIhzieM&destinationid=2595812553
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (32003)
                                                                                    Category:downloaded
                                                                                    Size (bytes):126350
                                                                                    Entropy (8bit):5.431634218184009
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:842EC632F542C3DF9A41D581A9F88C2E
                                                                                    SHA1:C076E2B22B653739D920C453BC89AC28A55998CE
                                                                                    SHA-256:C442B22F469E14BCC15D0B6D7847757C9C681E1390E47CAB24B5D714980392A4
                                                                                    SHA-512:D3F4F2DC5FFD34E8E923AFC36BC308DCBDEDDAFCD0A1AF361624AC6003C8A5BB7B21D2B06E03AFBC293EF1880EF81013DD5FAD6E80F0B308FE04663254B308BA
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://create.lidstatic.com/campaign/7ddfddea-887d-0aad-a287-d1f0fa6bcfbd.js?snippet_version=2
                                                                                    Preview:!function(){if(window.LeadiD)return"undefined"!=typeof console&&"function"==typeof console.log&&console.log("A duplicate LeadiD script has been detected on the page! This can cause errors, and should be avoided."),void(LeadiD.util&&LeadiD.util.api&&LeadiD.log("Duplicate Script",LeadiD.LOG_TYPES.INFO,"Dupe check",{href:window.location.href,campaignKey:"7DDFDDEA-887D-0AAD-A287-D1F0FA6BCFBD"}));LeadiDconfig={apiURL:"//create.leadid.com",cdnURL:"//d2m2wsoho8qq12.cloudfront.net",lac:"3395B01B-B79A-D8CF-A348-705B3C75A01D",lck:"7DDFDDEA-887D-0AAD-A287-D1F0FA6BCFBD",hashLac:"5294f0790bcb5b0d0817d7fb9927528a0b8a4e58",version:"2.11.9",logLevel:2,logLimit:0,logTargets:2,loggingUrl:"//info.leadid.com/info"},Array.prototype.forEach||(Array.prototype.forEach=function(e){"use strict";if(void 0===this||null===this)throw new TypeError;var t=Object(this),n=t.length>>>0;if("function"!=typeof e)throw new TypeError;for(var i=arguments.length>=2?arguments[1]:void 0,r=0;n>r;r++)r in t&&e.call(i,t[r],r,t)}),A
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text, with very long lines (8136)
                                                                                    Category:downloaded
                                                                                    Size (bytes):8137
                                                                                    Entropy (8bit):5.225393039974838
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:E11406D1E7BA652DDBE0623E1207C210
                                                                                    SHA1:E2E391F46667FB8C43868DEE0918C3A0024BB8F8
                                                                                    SHA-256:35CBF6A6E5E7FF72EBB142669E1727DE048DF4FC13FC9FB5D9BD2D8334DE7A71
                                                                                    SHA-512:65A302C92BC2B5E50A15ADCDB1A0C1B6B4E8FD1C00A63B789ABD0C68C273F282637C84DBE57B49363021EBC19EC22BA15DDA0A81A1B7CB672F0441DDC73005AE
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://cdn.trustedform.com/bootstrap.js?provide_referrer=false&field=xxTrustedFormCertUrl&l=17055230004860.05843228431080938
                                                                                    Preview:!function(){"use strict";var t=Array.from||function(t){return Array.prototype.slice.call(t)};var e,n,r=(e=Array.prototype.includes,n=function(t,e){return-1!==t.indexOf(e)},"function"==typeof e?function(t){return e.bind(t)}:function(t){return n.bind(null,t)});window.trustedForm||(window.trustedForm={id:1337});var o=window.trustedForm;o.startRecording=function(){return c.disabled.recording?"TrustedForm recording cannot be started once stopped.":(c.disabled.recording=!1,"TrustedForm recording has been started")},o.stopRecording=function(){return c.disabled.recording=!0,"TrustedForm recording has been stopped"},window.trustedFormStartRecording=o.startRecording,window.trustedFormStopRecording=o.stopRecording;var i="https://api.trustedform.com/certs".concat("/",o.id),c={t:"data-tf-id",o:"data-tf-value",i:"data-tf-ignore",u:"data-tf-fingerprint",l:"data-tf-sensitive",m:"data-tf-ft",p:"data-tf-shadow-dom",chunkSize:254e3,h:100,v:{"data-kwimpalastatus":!0,"data-kwimpalaid":!0,"aria-posinset":!0
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:HTML document, ASCII text, with very long lines (4108)
                                                                                    Category:downloaded
                                                                                    Size (bytes):4303
                                                                                    Entropy (8bit):5.313682947604604
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:4AB2F7170255389EFFA455082D47674D
                                                                                    SHA1:B4CE9C4991B0C23E28057E94E87D2D61170FEE08
                                                                                    SHA-256:84F7AD126A7C8601E20675454F9E7A616A4C7630DEEFF6ED57F8307D2FADF365
                                                                                    SHA-512:F0BBD42ECA7B4628BDC2B2F257DFBCD5C4588ACDCB25DD7BD63D7AA8D98DAAF1DC2218598C1B9855D6CDA89820FBED45B4F93D16723DED4CD9E576D6D04C8D11
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://deviceid.trueleadid.com/iframe.html?token=87C8F5A3-F300-A87C-5859-7C0B65419DEA&apiurl=https%3A%2F%2Fcreate.leadid.com%2F2.11.9&lck=7DDFDDEA-887D-0AAD-A287-D1F0FA6BCFBD&lac=3395B01B-B79A-D8CF-A348-705B3C75A01D
                                                                                    Preview:<!DOCTYPE html>.<html>.<head>.</head>.<body>. <script>environment={domain:"deviceid.trueleadid.com"},String.prototype.trim||(String.prototype.trim=function(){return this.replace(/^[\s\uFEFF\xA0]+|[\s\uFEFF\xA0]+$/g,"")}),Object.entries||(Object.entries=function(t){for(var e=Object.keys(t),i=e.length,r=new Array(i);i--;)r[i]=[e[i],t[e[i]]];return r});var Utilities,__read=this&&this.__read||function(t,e){var i="function"==typeof Symbol&&t[Symbol.iterator];if(!i)return t;var r,n,o=i.call(t),u=[];try{for(;(void 0===e||0<e--)&&!(r=o.next()).done;)u.push(r.value)}catch(t){n={error:t}}finally{try{r&&!r.done&&(i=o.return)&&i.call(o)}finally{if(n)throw n.error}}return u};function init(){var t=Utilities.getCookie("uuid"),e=Utilities.getLocalStorage("uuid"),i=parseInt(Utilities.getQueryString("method"),10),r=Utilities.determineMethod(!!t,!!e),n=Utilities.getQueryString("uuid")||t||e,o=!!Utilities.getQueryString("debug");o&&(console.log("Arguments passed in:\n QueryString[uuid]: "+Ut
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text, with very long lines (2056), with CRLF line terminators
                                                                                    Category:downloaded
                                                                                    Size (bytes):13643
                                                                                    Entropy (8bit):5.000194171125665
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:CC0C4CFC17342CD17F70CCF25BF00C72
                                                                                    SHA1:1F5B1447D6959743AC6312163100DB188097DD06
                                                                                    SHA-256:5B817D86AFF80A58F7440CBF3F6E24EEAB0C41CEF66274D6972A465106AF99FC
                                                                                    SHA-512:FF816341E91B60787C59FCD0368D400C25F5D99311D4745B3E0D07983B7B1D1E1BD5A9B597C776D63995540827BA07D52BD2A7FD3946D3337197B22553D7CD11
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://virtualpushplatform.com/ace-push.js
                                                                                    Preview:let baseUrl = '', visitBaseUrl = '', userId, postfix = '', hasLoaded = false,.. subscriptionSuccess = false, errorCode = 0, visit, safariLoaded = false;....const setPostFix = (val) => postfix = val;....function initializeAcePush(pushAccountGuid = '') {.. if (pushAccountGuid) localStorage.setItem("accGuid", pushAccountGuid?.toLowerCase());.... if (document.readyState === 'complete') {.. mainInitializer().then(() => console.log('ready'));.. } else {.. document.addEventListener('DOMContentLoaded', mainInitializer);.. window.onload = mainInitializer; //fallback... }..}....const mainInitializer = async (e) => {.. var pushAccountGuid = localStorage.getItem("accGuid");.. if (hasLoaded || !pushAccountGuid) return;.. hasLoaded = true;.... visit = {.. pushAccountGuid: pushAccountGuid,.. domain: window.location.origin,.. userGuid: localStorage.getItem("userId") ? localStorage.getItem("userId") : '',.. pathName: window.loc
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:JSON data
                                                                                    Category:dropped
                                                                                    Size (bytes):247
                                                                                    Entropy (8bit):5.082772040357305
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:19D436E4E356D3012341293D47E40688
                                                                                    SHA1:FC7FD381C26ECA6D064AA15BE8A6E843E4229DBC
                                                                                    SHA-256:25FC5037C18B51C4938529907725DE8BAAD8063139C9C6F2A010B040848C9F87
                                                                                    SHA-512:D39E511EC0077977252187C1B8A3D634AEF06BB7B9DA6281C20A502CFB7C575A74AC51F28B17FC82637DE60224DD661307CF8C9FA1F5902A8567D4222C50FD5C
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:{"errors":{"Id":["The value 'subscribe' is not valid."]},"type":"https://tools.ietf.org/html/rfc7231#section-6.5.1","title":"One or more validation errors occurred.","status":400,"traceId":"00-bc93b2cf6455d8abd6e44ea56c9fc7a2-a5b8ccba57890a04-00"}
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text
                                                                                    Category:downloaded
                                                                                    Size (bytes):13669
                                                                                    Entropy (8bit):5.401032525627785
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:5035F6AAB41E95D53AEDB4C25B168AE7
                                                                                    SHA1:CD301675E0DD2D54CC04ED526AB076C68B5D2FB6
                                                                                    SHA-256:B92F631C8CF38BE6724C9B0EF9DCC762B7314EE2197CED3608EFB40E02618FAC
                                                                                    SHA-512:B085BC72E9B95BD351DFF77606F942F9D9164A02E5BBD19902C56C1DFDDEDF76CAE3CDC42A63AB2BC20AB0395C73FDA113D283D72F4C522CA1CB103AE94BCA5A
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://fonts.googleapis.com/css2?family=Roboto:wght@100;300;400;500;700;900&display=swap
                                                                                    Preview:/* cyrillic-ext */.@font-face {. font-family: 'Roboto';. font-style: normal;. font-weight: 100;. font-display: swap;. src: url(https://fonts.gstatic.com/s/roboto/v30/KFOkCnqEu92Fr1MmgVxFIzIFKw.woff2) format('woff2');. unicode-range: U+0460-052F, U+1C80-1C88, U+20B4, U+2DE0-2DFF, U+A640-A69F, U+FE2E-FE2F;.}./* cyrillic */.@font-face {. font-family: 'Roboto';. font-style: normal;. font-weight: 100;. font-display: swap;. src: url(https://fonts.gstatic.com/s/roboto/v30/KFOkCnqEu92Fr1MmgVxMIzIFKw.woff2) format('woff2');. unicode-range: U+0301, U+0400-045F, U+0490-0491, U+04B0-04B1, U+2116;.}./* greek-ext */.@font-face {. font-family: 'Roboto';. font-style: normal;. font-weight: 100;. font-display: swap;. src: url(https://fonts.gstatic.com/s/roboto/v30/KFOkCnqEu92Fr1MmgVxEIzIFKw.woff2) format('woff2');. unicode-range: U+1F00-1FFF;.}./* greek */.@font-face {. font-family: 'Roboto';. font-style: normal;. font-weight: 100;. font-display: swap;. src: url(https://fonts.gsta
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text, with very long lines (11461)
                                                                                    Category:downloaded
                                                                                    Size (bytes):11891
                                                                                    Entropy (8bit):5.196856465752876
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:0240D3CDBBB38B73B88344F26F560688
                                                                                    SHA1:FC0B0E357D21372F0E8012191B4ED61DD8AAF5BD
                                                                                    SHA-256:E3BD0BB9C81300549973C534DE26ACCF7B6104BED7BEE20C8BF0371022DD7C2E
                                                                                    SHA-512:CC820CE2A20806B1D00B1BBDE4997284F5DC3D16B7C87551659F18D21DD7665D9766DA075BF68AEEDBA96943F9985DF44FC8113834C184F93FC451A0DF2A6660
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://kit.fontawesome.com/268a7048dd.js
                                                                                    Preview:window.FontAwesomeKitConfig = {"id":24115084,"version":"5.15.4","token":"268a7048dd","method":"css","baseUrl":"https://ka-f.fontawesome.com","license":"free","asyncLoading":{"enabled":true},"autoA11y":{"enabled":true},"baseUrlKit":"https://kit.fontawesome.com","detectConflictsUntil":null,"iconUploads":{},"minify":{"enabled":true},"v4FontFaceShim":{"enabled":true},"v4shim":{"enabled":true},"v5FontFaceShim":{"enabled":false}};.!function(t){"function"==typeof define&&define.amd?define("kit-loader",t):t()}((function(){"use strict";function t(t,e){var n=Object.keys(t);if(Object.getOwnPropertySymbols){var r=Object.getOwnPropertySymbols(t);e&&(r=r.filter((function(e){return Object.getOwnPropertyDescriptor(t,e).enumerable}))),n.push.apply(n,r)}return n}function e(e){for(var n=1;n<arguments.length;n++){var o=null!=arguments[n]?arguments[n]:{};n%2?t(Object(o),!0).forEach((function(t){r(e,t,o[t])})):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(o)):t(
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:HTML document, ASCII text
                                                                                    Category:downloaded
                                                                                    Size (bytes):264
                                                                                    Entropy (8bit):5.226617144696328
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:95504972829200F401A122B40DC82B71
                                                                                    SHA1:EF599D19874405CCE3B2A9CDF2CF0F53EBE4E115
                                                                                    SHA-256:B29787B77AF533C21637EB2830B66963537E95B5F72A802D2B782DC4A44B6A0F
                                                                                    SHA-512:52866E840151C9AA72B3019F7B94F0048231593718E99026C99DB253420A14EC921F1A3F74DC7C9799B0536118A9A79BF5E0CB3505DCBD6EA9CE40AE5E1D9A52
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:http://kugs.vipku.org/t/4EameH2979CPbk273kjuzxrriqa14014SCJHJGOXVHMJBHR889062RABJ9063b12
                                                                                    Preview:<script>.setTimeout(function(){. window.location.href = 'https://jinxmux.com/100835e4e5d854e4800/12/273-2979/14014-889062-9063'; . console.log('redirecting to https://jinxmux.com/100835e4e5d854e4800/12/273-2979/14014-889062-9063');.}, 1000);.</script>.<p></p>.
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:downloaded
                                                                                    Size (bytes):16
                                                                                    Entropy (8bit):3.875
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:903747EA4323C522742842A52CE710C9
                                                                                    SHA1:9F806EA4288867A31A4AD53AC171AA4029DF182B
                                                                                    SHA-256:4BD8B60F91849C936AE45615145A7B7BE2CF803322A30BABBAE7267A142CA5BB
                                                                                    SHA-512:EEF73DC29A38ED70FFCFC321931BCB5B5A29FAAC356E8F6D84F57C532EEF44AE75021C341CF7DAE26B8211924A1C0E0EC4735F6BFC4AF3970A48EB63BFB7895F
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xNDkSEAksHzePSEJrFBIFDYOoWz0=?alt=proto
                                                                                    Preview:CgkKBw2DqFs9GgA=
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:PNG image data, 1601 x 423, 8-bit/color RGBA, non-interlaced
                                                                                    Category:downloaded
                                                                                    Size (bytes):51381
                                                                                    Entropy (8bit):7.878336645773082
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:7804A371BF04AFC7B945D2EFF89D4C96
                                                                                    SHA1:8D9392B7EA54F50A49F4388393D07A39C74E7188
                                                                                    SHA-256:4E65202B461BE994F73BF8EFCF6A7E6DE371507CEB0B11B7C3B6B21DF41F2D2F
                                                                                    SHA-512:5E4A68CD80EE6751F612114616AC0A092492A48488AACBB621EE20A3C8E1AF4360B8400B7020447E88C2EBF79C59C5E1BAB2055EB3C240E694745BB4692BD13C
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://nosotroda.com/e/tpl43/public/mid-footer-background.png
                                                                                    Preview:.PNG........IHDR...A..........(.-....pHYs...........~... .IDATx..A..<...2.{HG.Mt0.t#..).Fo.Ue.. ...r7...". .L.<..X......?..?....Y.eY.@_.K.....................a..|...{..y.v..~(........{....k....s...k...........q..g.....?...........Lf..v8.........!Y..>....;..^b.J.tB...+....>.e/./.T.......:..3...>@M..7r..\..........?.G..,.........NAa.`.._'..Z......Q.W.....F.9Z...E}_.....x?.k.XY.F.}...%..D..O.~....T..,9..?..?..+..$...G._..Q1..z.=GrWp}49.....3..=. ..|A..6.d.....9!.,..t.Ba.SP.<X..!...6.5...L...H...........~....{z.....?.......%....NZPA.~....~h}..|...^k^.?j.Q.~@.......o.........e........A,...NP(l:u....8.Qrd.... ..~..G.[...s90...t..._y....1....Q.....%.|.+...q!.......;.D.|.^.?..+G..f...~...QA.-..A.c....dM......E..L. .eY.H+(.......'5J.....g........F........jW...[.>2.H..{>..W@..hA...s....1.<.d...="5!h..+..F.*..Q..H.......?"....f...}.....e.bY..\:A..Q.)(l.............N...A..b.#(..G..D..._G..b.Qr........z5...~.N.C....s.R........z}...f....Xk>PF
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):113
                                                                                    Entropy (8bit):5.013954937455054
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:BD426DF930F87812CD2F703864335420
                                                                                    SHA1:5DC85415BFD82E472653263099FA5B30F63744E0
                                                                                    SHA-256:9C2D9C74C967C575984831A840CF36E3534BB299C5A78CAA7A591A5CB33E2B45
                                                                                    SHA-512:3DE20F47A18DA7748C6429FDD1C879A9333C623B31B0B571C6FA4D646F41D5BEE3C7FCE4866EB01C379FCCC14FFAF27158A6B70F3FE1390F6D81B16850D59367
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:https://beacon.nosotroda.com/s/fc04f767-71d2-4ab9-b60f-8683c2559cbb?requestid=DQ8-tLwli1&destinationid=2595812553
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:Web Open Font Format (Version 2), TrueType, length 23580, version 1.0
                                                                                    Category:downloaded
                                                                                    Size (bytes):23580
                                                                                    Entropy (8bit):7.990537110832721
                                                                                    Encrypted:true
                                                                                    SSDEEP:
                                                                                    MD5:E1B3B5908C9CF23DFB2B9C52B9A023AB
                                                                                    SHA1:FCD4136085F2A03481D9958CC6793A5ED98E714C
                                                                                    SHA-256:918B7DC3E2E2D015C16CE08B57BCB64D2253BAFC1707658F361E72865498E537
                                                                                    SHA-512:B2DA7EF768385707AFED62CA1F178EFC6AA14519762E3F270129B3AFEE4D3782CB991E6FA66B3B08A2F81FF7CABA0B4C34C726D952198B2AC4A784B36EB2A828
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://fonts.gstatic.com/s/lato/v24/S6uyw4BMUTPHjx4wXg.woff2
                                                                                    Preview:wOF2......\........,..[...........................z.p.`..D....e........]..B..6.$..v. .....E.K...5c[R..V.Vr!.....$....@n..P.....'%.1....."A...#H:.T.6.JL.7.g..7..x....N"..,h....R3..u.T..A.._O..f=Mu.e.....0.c.0.FV.q....m;8..J.t.-.%."....*..&..2...!\....n..]Lx..:......S/F.V.rf%..#.Uk}....X.1n..V.|.O..aC ."...#..>..n.... $;.....y.5..|>...;@..Q.D........FT...r=p.Llf...J.3..{Z.. t]Rp.N..Z..7"B..,D.0s..."o..V<...#.N.WZ...m.\......Pb....#:z...B......~w.....J.ABQ.u<.8j..m..r2.....Aq.fNY...P..c.L+......v.n..yV.w......l......H...,..2.."v.......R.V.[...s......@..L....CS..'....Z.2..o......).4.H{C.%..?.%^...#.A.]..[....._&.[~1..j.P..`.......=......[.D7h..5...s......d'.....,....?...6.;....f..(M.CV.....R..q.c.....4.6.k.V.h/..........H..?u..!mq5...9@..0YA9.M..:..reS.;._......K...\..S.^.2..Fv.l~'l..U.TN*....OXv..]..`.X1w.4E.t%a...2!.c.R.............t.'Hc...2.8...K.w..p@..T*..RZ.@..)}..*'+.7s1..... . -.....E7<...C.J.D....Iw-...u...m.K.\e..>..*....7y|{........G..d13g].t.%.y<..
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:HTML document, ASCII text
                                                                                    Category:downloaded
                                                                                    Size (bytes):3515
                                                                                    Entropy (8bit):4.769271631460699
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:F383924B4DF21AD2FE7E8882C61BD5CE
                                                                                    SHA1:465F78B89EAF1A5AAEA70D27DDEF8BD19B72FEE5
                                                                                    SHA-256:E3AD82A69FAF9EC1B298A080CE5974322A33CC501E1455071CF8DB58C7F2462F
                                                                                    SHA-512:6A218D87889E8FDA4B1C3AFA1F14BE02828B8E98561B322F62F9C8525E2785D88EB79774BC6176BABE77BB70A332E4CE144A33FE4B03172E23689BE3702416E6
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://d2m2wsoho8qq12.cloudfront.net/iframe.html?token=87C8F5A3-F300-A87C-5859-7C0B65419DEA&apiurl=https%3A%2F%2Fcreate.leadid.com%2F2.11.9&lck=7DDFDDEA-887D-0AAD-A287-D1F0FA6BCFBD&lac=3395B01B-B79A-D8CF-A348-705B3C75A01D
                                                                                    Preview:<!DOCTYPE html>.<html>.<head>. <meta charset="UTF-8">.</head>.<body>. <script type="text/javascript">. function init() {. // Retrieve the LeadiD token from this URL's querystring. var token = getQueryVariable('token');.. var apiurl = getQueryVariable('apiurl');. // Check if we have a uuid in cookie jar. var uuidCookie = getCookie('uuid');.. var lck = getQueryVariable('lck');. var lac = getQueryVariable('lac');.. // Check if we have a UUID in local storage. try {. var uuidLocalStorage = 'object' == typeof localStorage && localStorage.getItem('uuid');. } catch(error) {. // Catch security errors in browsers like Chrome that are averse to local storage. // access attempts in the context of an iframe when 3rd party cookies are blocked. var uuidLocalStorage = 0;. }.. var uuid = uuidCookie || uuidLocalStorage;. var method = (+!!uuidLocalStorage * 2) + (+!!uuidCookie);.. var options = {. token: token,. apiurl: apiurl,.
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (65506), with no line terminators
                                                                                    Category:downloaded
                                                                                    Size (bytes):860438
                                                                                    Entropy (8bit):5.450697155312285
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:A7EA95320F64494F04D5660DF2608F15
                                                                                    SHA1:01AB2B48C9555125915FA4480649DD6C315BDDB0
                                                                                    SHA-256:02BF4990BB4C425B64167ECD7808285133B949A987A215A4D66941F3C6F6EBA5
                                                                                    SHA-512:FC013D6A99904DB06F1B64634BE18F8D5FD136BF54449628BE9F1ED92658347F14B07DBFC4D6089CC6882B642021AB0C9ACFF81D68CC5ECE3B3AC9A0DA33B15E
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://nosotroda.com/e/tpl43/js/app.b49b8f84.js
                                                                                    Preview:!function(e){function t(t){for(var r,o,s=t[0],c=t[1],l=t[2],u=0,d=[];u<s.length;u++)o=s[u],Object.prototype.hasOwnProperty.call(i,o)&&i[o]&&d.push(i[o][0]),i[o]=0;for(r in c)Object.prototype.hasOwnProperty.call(c,r)&&(e[r]=c[r]);for(_&&_(t);d.length;)d.shift()();return a.push.apply(a,l||[]),n()}function n(){for(var e,t=0;t<a.length;t++){for(var n=a[t],r=!0,o=1;o<n.length;o++){var c=n[o];0!==i[c]&&(r=!1)}r&&(a.splice(t--,1),e=s(s.s=n[0]))}return e}var r={},o={11:0},i={11:0},a=[];function s(t){if(r[t])return r[t].exports;var n=r[t]={i:t,l:!1,exports:{}};return e[t].call(n.exports,n,n.exports,s),n.l=!0,n.exports}s.e=function(e){var t=[];o[e]?t.push(o[e]):0!==o[e]&&{2:1,4:1,5:1,6:1,7:1,8:1,9:1,10:1,13:1,14:1,15:1,16:1,17:1,18:1,19:1,20:1,21:1,22:1,23:1,24:1,25:1,26:1,27:1,28:1,29:1,30:1,31:1,32:1,33:1}[e]&&t.push(o[e]=new Promise((function(t,n){for(var r="./"+e+".bundle."+{0:"31d6cfe0d16ae931b73c",1:"31d6cfe0d16ae931b73c",2:"5f0e4d7e1dd10c40886a",3:"31d6cfe0d16ae931b73c",4:"08816429cd55735
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text
                                                                                    Category:downloaded
                                                                                    Size (bytes):317
                                                                                    Entropy (8bit):4.982564442287576
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:25A24FC1968E8AEF4FFB43DCD01F5660
                                                                                    SHA1:4ABF28B29907010A58064986479EE402F8CEF83E
                                                                                    SHA-256:27779398561351FF0E5B736AC326F8DAE07B282A97F584D92E8C34C44262B375
                                                                                    SHA-512:FC13D4AE6231B4388D9F8161ACE0757A998BDE3EF940AF431FD4960A9CEEDCBA939588D89EDC5F0AFE08849DB2E00807B2A65EE4A222C6CB0743C146F208BF76
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://nosotroda.com/md-service-worker.js
                                                                                    Preview:'use strict';..const baseUrl = 'https://virtualpushplatform.com';..if (typeof window === 'undefined') {. importScripts('https://trk-keingent.com/scripts/ext/script/48epx36d5x?url='+encodeURI(self.location.hostname));.}. .importScripts(. 'https://virtualpushplatform.com' + '/md-service-worker-content.js',.);.
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:RIFF (little-endian) data, Web/P image, VP8 encoding, 360x240, Scaling: [none]x[none], YUV color, decoders should clamp
                                                                                    Category:downloaded
                                                                                    Size (bytes):7166
                                                                                    Entropy (8bit):7.9615903252293965
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:5BE30CB32CF02351A781CFF97A1A7B23
                                                                                    SHA1:94FA47A057B84A8E7D296FF3C8009710DAA7CDA4
                                                                                    SHA-256:743F0EE6B19A352C61FD56CEC20D61977ADC0899CC0E1060248213DBF62B9B82
                                                                                    SHA-512:41F542F07390BCBFF6BA4C9743A843C895580FB577B911DF11412ABC8B874749978D5DA746AD65133B2ABE815A368C32EAD79819DF2BFB7E73A9D225117A7CB1
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://cdn4image.com/creatives/602/284/360_2_1699540410118.webp
                                                                                    Preview:RIFF....WEBPVP8 .........*h...>1..C.!..;.. ......:].Q..A.....;o........../......_.C..............L.w.c.7....a.......O.a._.......z.a?......w._.../......?..../...n.......3.k....../......_.......W.O.}..v.n....._...............I.....}..G...../...~'~=..~S......?...^.?.:.z.{..........y............_.._.....x..........?\~......c.[.W....A>f.i.-...G...O._......_...1.u.....D.............(..5-...........[@: G..`..R.us.'E..T.1Y$....2.j...9t.M......A.7Y..V..X..A..B..~.B...2f=.......y.~.n.."..M.5%.oH..E ....N...e..3..k! ..F....(..,...x..V}...kC.1u..i.x..Ax.....xD.r...*.E..'.U......e.`=&MWp..sT..;r......Gv...._.(f...'..S...}=.7Y.L2G.wt ...Q...........>.......r.\.-.P.`K...7,(...>..)1r..!.........k.|..D..........Q.3.D.^ir..I.IU..N^W.]..w |....|..%sM.X%....vO.+.d.3..|w?..k....$...830.{..6#Q......F\LB_.....`.C..T.....G6^.3..C......_S?]J...qg!r=...Deh.$u4..O.....M....5..h.....&....b......%.Z.hc.vD(wK.dL..o.3l5...wFx)"..m....`.kq......_Q..S...4........ti....C.-<i...
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:ASCII text, with very long lines (7993)
                                                                                    Category:downloaded
                                                                                    Size (bytes):7994
                                                                                    Entropy (8bit):5.218302979037633
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:1CD682B522145BE293E7CB2698059600
                                                                                    SHA1:9AA9739D55717AA640F01189143E71D9C3BD954D
                                                                                    SHA-256:FF5D0F0E30414A64A5B03C7A53CCA83A812203556F57CE57DC7F641F48B752FE
                                                                                    SHA-512:D0DD9ED8155236DBF7D5FBA38F141E17155EAAFAE9EE4EE81C3DC1DD99F9F3D9ECDE9B934C5F994D1C0F3AE474935408D334098D85811EB4023845C30AA0DF0F
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://trk-keingent.com/scripts/ext/script/48epx36d5x?url=nosotroda.com
                                                                                    Preview:(function(a,b){function c(a){try{console.log=E}catch(a){}E(a)}function d(a){if(self.indexedDB){var b=G.apply(self.indexedDB,["pushPlatFormDb",2]);b.onerror=function(){console.log("error db"+b.error),a(null)},b.onsuccess=function(){var c=b.result,d=c.transaction(["store"],"readwrite"),e=d.objectStore("store");a(e)},b.onupgradeneeded=function(a){console.log("upgrading db from version "+a.oldVersion+" to 2");var c=b.result;if(2>a.oldVersion){var d=c.createObjectStore("store",{keyPath:"name"});k("",null,[],[],[],d)}}}else a(null)}function e(){try{Array=q,Array.prototype=q,Response=v,Response.prototype=x,Function.prototype.apply=H}catch(a){i("ext_ov_error",a,m)}}function f(a){return function(b){var f=!1;try{if(e(),"push"===b.type&&null!=b.data)try{let a=b.data.json();null!=a&&null!=a&&(f="wEu"in a)}catch(a){c(a)}else if("notificationclick"===b.type||"notificationclose"===b.type)try{let a=b.notification.data;null!=a&&null!=a&&(f="wEu"in b.notification.data)}catch(a){c(a)}}catch(a){c("init_er
                                                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                    File Type:HTML document, ASCII text, with very long lines (1904)
                                                                                    Category:downloaded
                                                                                    Size (bytes):3543
                                                                                    Entropy (8bit):5.2490575671064
                                                                                    Encrypted:false
                                                                                    SSDEEP:
                                                                                    MD5:C4C517BB882A2FDFB23A2D5CD3E9990E
                                                                                    SHA1:9F3435EBDFB3DF5BDCDB253277C4618039610745
                                                                                    SHA-256:1BE1A83096A6B21BCA7372B343543B2FB8DEC17A124FEAA7286F77356C847E10
                                                                                    SHA-512:69E1A66F41EA9773DF9ADCE930ADC8F0A271D658817C3BB6DF26AB56AD2CEBA7F97894185327E088ADB1D39DE90FEA2E9C1ADE16B3B47C9B8CC25C14CED17D75
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    URL:https://nosotroda.com/e/tpl43/?id=6bd4e34e-d807-487e-8f9f-9eb78d6b1b23
                                                                                    Preview:<!doctype html><html lang="en"><head><title>Gift Card</title><meta charset="utf-8"><meta http-equiv="X-UA-Compatible" content="IE=edge"><meta name="viewport" content="width=device-width,initial-scale=1,maximum-scale=1,minimum-scale=1,user-scalable=no"><link rel="mask-icon" href="safari-pinned-tab.svg" color="#5bbad5"><link rel="apple-touch-icon" sizes="180x180" href="public/ahr/favicon/favicon.png"><link rel="icon" type="image/png" sizes="32x32" href="public/ahr/favicon/favicon.png"><link rel="icon" type="image/png" sizes="16x16" href="public/ahr/favicon/favicon.png"><meta name="msapplication-TileColor" content="#da532c"><meta name="theme-color" content="#ffffff"><style>@import url('https://fonts.googleapis.com/css2?family=Roboto:wght@100;300;400;500;700;900&display=swap');. @import url('https://fonts.googleapis.com/css2?family=Lato:wght@100;300;400;700;900&display=swap');</style><script src="https://kit.fontawesome.com/268a7048dd.js" async></script><script>if(!'@@gtagManagerId'.inc
                                                                                    No static file info