Edit tour

Windows Analysis Report
officeclicktorun.exe_Rules.xml

Overview

General Information

Sample name:officeclicktorun.exe_Rules.xml
Analysis ID:1382874
MD5:815172747c64e2f781505da8d849c0f6
SHA1:3d0ab653a45e7869a8f82bd711501616c3f7f367
SHA256:6898e40a8ef1d64e6314c438882814785719886b99d2560e6a59168c1b65ed8b
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Allocates memory in foreign processes
Changes memory attributes in foreign processes to executable or writable
Downloads suspicious files via Chrome
Writes to foreign memory regions
Creates a process in suspended mode (likely to inject code)
Potential browser exploit detected (process start blacklist hit)
Sigma detected: Use Short Name Path in Command Line
Uses insecure TLS / SSL version for HTTPS connection

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • MSOXMLED.EXE (PID: 356 cmdline: C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXE" /verb open "C:\Users\user\Desktop\officeclicktorun.exe_Rules.xml MD5: A2E6E2A1C125973A4967540FD08C9AF0)
    • iexplore.exe (PID: 6104 cmdline: "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\user\Desktop\officeclicktorun.exe_Rules.xml MD5: CFE2E6942AC1B72981B3105E22D3224E)
      • iexplore.exe (PID: 1068 cmdline: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6104 CREDAT:17410 /prefetch:2 MD5: 6F0F06D6AB125A99E43335427066A4A1)
        • ie_to_edge_stub.exe (PID: 3532 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe" --from-ie-to-edge=3 --ie-frame-hwnd=2038e MD5: 89CF8972D683795DAB6901BC9456675D)
          • msedge.exe (PID: 6596 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --from-ie-to-edge=3 --ie-frame-hwnd=2038e MD5: 69222B8101B0601CC6663F8381E7E00F)
            • msedge.exe (PID: 480 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2176 --field-trial-handle=2012,i,13106778062332849330,18246741884398805662,262144 /prefetch:3 MD5: 69222B8101B0601CC6663F8381E7E00F)
        • ssvagent.exe (PID: 5236 cmdline: "C:\PROGRA~2\Java\jre-1.8\bin\ssvagent.exe" -new MD5: F9A898A606E7F5A1CD7CFFA8079253A0)
  • msedge.exe (PID: 7152 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --from-ie-to-edge=3 --ie-frame-hwnd=2038e --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 6624 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1968 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:3 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 7244 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6236 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 8040 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.ProfileImport --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=6744 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
      • cookie_exporter.exe (PID: 1744 cmdline: cookie_exporter.exe --cookie-json=1128 MD5: 3DD7152D6D33725EA5958D7DE2586B97)
    • msedge.exe (PID: 8080 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6740 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 7652 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-handle=6120 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 3372 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=price_comparison_service.mojom.DataProcessor --lang=en-GB --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=7688 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
  • cleanup
No yara matches

System Summary

barindex
Source: Process startedAuthor: frack113, Nasreddine Bencherchali: Data: Command: "C:\PROGRA~2\Java\jre-1.8\bin\ssvagent.exe" -new, CommandLine: "C:\PROGRA~2\Java\jre-1.8\bin\ssvagent.exe" -new, CommandLine|base64offset|contains: w, Image: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe, NewProcessName: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe, OriginalFileName: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe, ParentCommandLine: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6104 CREDAT:17410 /prefetch:2, ParentImage: C:\Program Files (x86)\Internet Explorer\iexplore.exe, ParentProcessId: 1068, ParentProcessName: iexplore.exe, ProcessCommandLine: "C:\PROGRA~2\Java\jre-1.8\bin\ssvagent.exe" -new, ProcessId: 5236, ProcessName: ssvagent.exe
Source: Registry Key setAuthor: frack113: Data: Details: 1, EventID: 13, EventType: SetValue, Image: C:\Program Files\Internet Explorer\iexplore.exe, ProcessId: 6104, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\SecuritySafe
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: file:///C:/Users/user/Desktop/officeclicktorun.exe_Rules.xmlHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.1.237.25:443 -> 192.168.2.16:49737 version: TLS 1.0
Source: unknownHTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.16:49735 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.16:49782 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.28.12:443 -> 192.168.2.16:49834 version: TLS 1.2
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe
Source: unknownHTTPS traffic detected: 23.1.237.25:443 -> 192.168.2.16:49737 version: TLS 1.0
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.25
Source: unknownTCP traffic detected without corresponding DNS query: 40.71.99.188
Source: unknownTCP traffic detected without corresponding DNS query: 40.71.99.188
Source: unknownTCP traffic detected without corresponding DNS query: 40.71.99.188
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 40.71.99.188
Source: unknownTCP traffic detected without corresponding DNS query: 40.71.99.188
Source: unknownTCP traffic detected without corresponding DNS query: 40.71.99.188
Source: unknownTCP traffic detected without corresponding DNS query: 40.71.99.188
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.6.158
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49862
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49861
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49898 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49859
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
Source: unknownNetwork traffic detected: HTTP traffic on port 49881 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49893 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
Source: unknownNetwork traffic detected: HTTP traffic on port 49886 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
Source: unknownNetwork traffic detected: HTTP traffic on port 49904 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
Source: unknownNetwork traffic detected: HTTP traffic on port 49887 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49885 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49899
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49898
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49897
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49896
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49895
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49894
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49893
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49892
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49891
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49890
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49897 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49905 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49889
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49888
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49887
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49886
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49885
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49884
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49883
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49882
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49881
Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49880
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49879
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49878
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49877
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49876
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49875
Source: unknownNetwork traffic detected: HTTP traffic on port 49891 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49874
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49873
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49872
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49871
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49870
Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49869
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49868
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49867
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
Source: unknownNetwork traffic detected: HTTP traffic on port 49890 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49878 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49889 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49866 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49861 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49901 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49873 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49856 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49895 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49867 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
Source: unknownNetwork traffic detected: HTTP traffic on port 49842 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49871 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49894 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 49902 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49876 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49882 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49877 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49883 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49899 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49832 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49905
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49904
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49903
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49902
Source: unknownNetwork traffic detected: HTTP traffic on port 49903 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49901
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49900
Source: unknownNetwork traffic detected: HTTP traffic on port 49888 -> 443
Source: unknownHTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.16:49735 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.16:49782 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.28.12:443 -> 192.168.2.16:49834 version: TLS 1.2

System Summary

barindex
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeFile dump: C:\Users\user\AppData\Local\Temp\scoped_dir7152_1312584184\CRX_INSTALL\page_embed_script.jsJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeFile dump: C:\Users\user\AppData\Local\Temp\scoped_dir7152_1312584184\CRX_INSTALL\eventpage_bin_prod.jsJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeFile dump: C:\Users\user\AppData\Local\Temp\scoped_dir7152_957790502\CRX_INSTALL\content.jsJump to dropped file
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeFile dump: C:\Users\user\AppData\Local\Temp\scoped_dir7152_957790502\CRX_INSTALL\content_new.jsJump to dropped file
Source: classification engineClassification label: mal56.evad.winXML@79/234@10/178
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeFile created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\69c03a09-e67a-4f51-ba0b-ed800f7847d7.tmp
Source: C:\Program Files\Internet Explorer\iexplore.exeFile created: C:\Users\user\AppData\Local\Temp\~DF38B13AA08B294768.TMP
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exeFile read: C:\Users\user\Desktop\desktop.ini
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXE C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXE" /verb open "C:\Users\user\Desktop\officeclicktorun.exe_Rules.xml
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXEProcess created: C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\user\Desktop\officeclicktorun.exe_Rules.xml
Source: C:\Program Files\Internet Explorer\iexplore.exeProcess created: C:\Program Files (x86)\Internet Explorer\iexplore.exe "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6104 CREDAT:17410 /prefetch:2
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe" --from-ie-to-edge=3 --ie-frame-hwnd=2038e
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exeProcess created: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe "C:\PROGRA~2\Java\jre-1.8\bin\ssvagent.exe" -new
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --from-ie-to-edge=3 --ie-frame-hwnd=2038e
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2176 --field-trial-handle=2012,i,13106778062332849330,18246741884398805662,262144 /prefetch:3
Source: unknownProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --from-ie-to-edge=3 --ie-frame-hwnd=2038e --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1968 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:3
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXEProcess created: C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\user\Desktop\officeclicktorun.exe_Rules.xml
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --from-ie-to-edge=3 --ie-frame-hwnd=2038e
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6236 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.ProfileImport --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=6744 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6740 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\cookie_exporter.exe cookie_exporter.exe --cookie-json=1128
Source: C:\Program Files\Internet Explorer\iexplore.exeProcess created: C:\Program Files (x86)\Internet Explorer\iexplore.exe "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6104 CREDAT:17410 /prefetch:2
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe "C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exe" --from-ie-to-edge=3 --ie-frame-hwnd=2038e
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exeProcess created: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe "C:\PROGRA~2\Java\jre-1.8\bin\ssvagent.exe" -new
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2176 --field-trial-handle=2012,i,13106778062332849330,18246741884398805662,262144 /prefetch:3
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6236 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.ProfileImport --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=6744 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6740 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-handle=6120 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-handle=6120 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=price_comparison_service.mojom.DataProcessor --lang=en-GB --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=7688 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=price_comparison_service.mojom.DataProcessor --lang=en-GB --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=7688 --field-trial-handle=1940,i,7518944280599086167,12736008309264696502,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exeProcess information set: NOOPENFILEERRORBOX

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory allocated: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5E90000 protect: page read and write
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory allocated: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EA0000 protect: page read and write
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory allocated: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB0000 protect: page no access
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory allocated: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB0000 protect: page execute and read and write
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory allocated: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EC0000 protect: page read and write
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D930 protect: page write copy
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D930 protect: page execute read
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2F5A0 protect: page write copy
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2F5A0 protect: page execute read
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D4B0 protect: page write copy
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D4B0 protect: page execute read
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2F4E0 protect: page write copy
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2F4E0 protect: page execute read
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D6D0 protect: page write copy
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D6D0 protect: page execute read
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D190 protect: page write copy
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D190 protect: page execute read
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D470 protect: page write copy
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D470 protect: page execute read
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D5F0 protect: page write copy
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D5F0 protect: page execute read
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D5D0 protect: page write copy
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D5D0 protect: page execute read
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D4F0 protect: page write copy
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D4F0 protect: page execute read
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D530 protect: page write copy
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D530 protect: page execute read
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory protected: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB0400 protect: page execute read
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5E90000
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 888155A2D8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EA0000
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB0420
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D930
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB0460
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2F5A0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB04A0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D4B0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB04E0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2F4E0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB0520
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D6D0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB0560
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D190
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB05A0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D470
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB05E0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D5F0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB0620
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D5D0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB0660
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D4F0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB06A0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FFDF4D2D530
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EB0400
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FF672693E50
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FF6726918E8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FF6726910E0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 228F5EC0000
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FF6726918F0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FF672691860
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FF672691868
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FF6726910D8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FF672685038
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FF6726918F8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FF672691900
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FF6726911E0
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeMemory written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe base: 7FF6726911E8
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXEProcess created: C:\Program Files\Internet Explorer\iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\user\Desktop\officeclicktorun.exe_Rules.xml
Source: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.47\BHO\ie_to_edge_stub.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --from-ie-to-edge=3 --ie-frame-hwnd=2038e
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
Exploitation for Client Execution
Path Interception311
Process Injection
1
Masquerading
OS Credential Dumping1
File and Directory Discovery
Remote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts311
Process Injection
LSASS Memory2
System Information Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
officeclicktorun.exe_Rules.xml0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
file:///C:/Users/user/Desktop/officeclicktorun.exe_Rules.xml0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
chrome.cloudflare-dns.com
162.159.61.3
truefalse
    unknown
    clients.l.google.com
    142.251.15.102
    truefalse
      high
      googlehosted.l.googleusercontent.com
      172.217.215.132
      truefalse
        high
        sni1gl.wpc.nucdn.net
        152.195.19.97
        truefalse
          unknown
          clients2.googleusercontent.com
          unknown
          unknownfalse
            high
            clients2.google.com
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              file:///C:/Users/user/Desktop/officeclicktorun.exe_Rules.xmlfalse
              • Avira URL Cloud: safe
              low
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              13.107.6.158
              unknownUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              13.107.246.41
              unknownUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              13.107.246.40
              unknownUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              204.79.197.200
              unknownUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              23.96.180.189
              unknownUnited States
              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              4.227.249.197
              unknownUnited States
              3356LEVEL3USfalse
              23.223.31.33
              unknownUnited States
              16625AKAMAI-ASUSfalse
              152.195.19.97
              sni1gl.wpc.nucdn.netUnited States
              15133EDGECASTUSfalse
              13.107.21.200
              unknownUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              96.7.224.17
              unknownUnited States
              20940AKAMAI-ASN1EUfalse
              162.159.61.3
              chrome.cloudflare-dns.comUnited States
              13335CLOUDFLARENETUSfalse
              13.107.213.41
              unknownUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              40.71.99.188
              unknownUnited States
              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              13.107.213.40
              unknownUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              96.7.225.160
              unknownUnited States
              20940AKAMAI-ASN1EUfalse
              204.79.197.239
              unknownUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              20.110.205.119
              unknownUnited States
              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              142.251.15.102
              clients.l.google.comUnited States
              15169GOOGLEUSfalse
              172.64.41.3
              unknownUnited States
              13335CLOUDFLARENETUSfalse
              96.7.225.184
              unknownUnited States
              20940AKAMAI-ASN1EUfalse
              13.107.5.80
              unknownUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              172.217.215.132
              googlehosted.l.googleusercontent.comUnited States
              15169GOOGLEUSfalse
              1.1.1.1
              unknownAustralia
              13335CLOUDFLARENETUSfalse
              13.107.21.239
              unknownUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              96.7.224.26
              unknownUnited States
              20940AKAMAI-ASN1EUfalse
              52.237.183.121
              unknownUnited States
              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              18.67.65.40
              unknownUnited States
              3MIT-GATEWAYSUSfalse
              13.107.42.16
              unknownUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              20.40.24.37
              unknownUnited States
              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              23.63.205.212
              unknownUnited States
              16625AKAMAI-ASUSfalse
              239.255.255.250
              unknownReserved
              unknownunknownfalse
              13.107.22.239
              unknownUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              23.49.5.229
              unknownUnited States
              35994AKAMAI-ASUSfalse
              20.50.73.9
              unknownUnited States
              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              204.79.197.203
              unknownUnited States
              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              20.44.10.122
              unknownUnited States
              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              IP
              192.168.2.16
              Joe Sandbox version:39.0.0 Ruby
              Analysis ID:1382874
              Start date and time:2024-01-29 18:20:59 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:defaultwindowsinteractivecookbook.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:22
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • EGA enabled
              Analysis Mode:stream
              Analysis stop reason:Timeout
              Sample name:officeclicktorun.exe_Rules.xml
              Detection:MAL
              Classification:mal56.evad.winXML@79/234@10/178
              Cookbook Comments:
              • Found application associated with file extension: .xml
              • Exclude process from analysis (whitelisted): dllhost.exe
              • Excluded IPs from analysis (whitelisted): 23.63.205.212
              • Excluded domains from analysis (whitelisted): e11290.dspg.akamaiedge.net, go.microsoft.com, go.microsoft.com.edgekey.net
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtAllocateVirtualMemory calls found.
              • Report size getting too big, too many NtCreateKey calls found.
              • Report size getting too big, too many NtOpenFile calls found.
              • Report size getting too big, too many NtOpenKeyEx calls found.
              • Report size getting too big, too many NtProtectVirtualMemory calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              • Report size getting too big, too many NtSetValueKey calls found.
              • Report size getting too big, too many NtWriteVirtualMemory calls found.
              • Timeout during stream target processing, analysis might miss dynamic analysis data
              • VT rate limit hit for: officeclicktorun.exe_Rules.xml
              Process:C:\Program Files\Internet Explorer\iexplore.exe
              File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
              Category:dropped
              Size (bytes):4286
              Entropy (8bit):3.8046022951415335
              Encrypted:false
              SSDEEP:
              MD5:DA597791BE3B6E732F0BC8B20E38EE62
              SHA1:1125C45D285C360542027D7554A5C442288974DE
              SHA-256:5B2C34B3C4E8DD898B664DBA6C3786E2FF9869EFF55D673AA48361F11325ED07
              SHA-512:D8DC8358727590A1ED74DC70356AEDC0499552C2DC0CD4F7A01853DD85CEB3AEAD5FBDC7C75D7DA36DB6AF2448CE5ABDFF64CEBDCA3533ECAD953C061A9B338E
              Malicious:false
              Reputation:low
              Preview:...... .... .........(... ...@..... ...................................................................................................................................................................................................N...Sz..R...R...P...N..L..H..DG..........................................................................................R6..U...U...S...R...P...N..L..I..F..B...7...............................................................................S6..V...V...U...S...R...P...N..L..I..F..C...?..:z......................................................................O...W...V...V...U...S...R...P...N..L..I..E..C...?...;..{7..q2$..............................................................T..D..]...S)..p6..J...R...P...N..L..I..E..B..>..;..z7..p2..f,X.........................................................A..O#..N!..N!..N!..P$..q:...P...N..K..I..E..A..=..9..x5..n0..e,...5...................................................Ea.Z,..T$..T$..T
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):63648
              Entropy (8bit):6.105123796427434
              Encrypted:false
              SSDEEP:
              MD5:F4F8E308D9F698F19DC98DD4040C66C1
              SHA1:C18D715305210293F312355EF019A7C3FC67DF43
              SHA-256:44A6F4BCAB6236E259B2C6FE55A20E9F2AE28194B6440FF9F0A2F624E19D8495
              SHA-512:577A06BCB3DE94E83E5D8BFE8802DC5D8E26D44EA337CEB99465318FA9B7C8F6FBB07539DF489ACB71425FBC79141B1D97CB2374754C422C06E9C7578AE7035B
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"1B94E5024015A307769363A60E0D5B42FA1F9C3BB6A108D492D64D1251C4F3D1\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL1dW5PctrH+K6p9SlIerHZ1s5wnH1mOXSeyXY5Srjqp1BYIYkgsQYDCZWY4Kf/30w3O3jQEZpryOQ9xVhw2bmx0f93obvzngm+uboStpbhZSx6ikzeilaK7sRvpnKrlxTf/ueDDoJXgQVnjL7751+GBrG8GC8/Hi28ufh7CzzFcfHVR254rA0+MDGutdkzY/uL3rygkPsRaWT9R/vuri0Sh5NSz4b18TBzGAf/97ebqHU7i+2kO73AKh3ewCZiLh8FffHP1+1cXou6pszN6fL8brJe/aD7+Knk9Ph6318o0hYneU/8GPW6UkY+Jg40sbJZQ9nwHf0sGs1hAzSuxeMgbhhRyKb3mb5gKSyh3a2VUGJd2vOVBtDB6YUt8WWxCNTAACW042wBTLW2m0lGK6DbYkm/5lgm+pJlW4hbbwC82OGuWjkY4mJMD/hctN0bqpe2YwEOLLLn0+9jt4KSXJvhBx8WLu2l3C7dUG3Vc2iu8zj5FJTr4KMPSRr5Tvv3WjNtWOlkWgLMi6SAN8ZFLj3AIRxSPOj4Q3D85FpZJNdDE5Q/w5of1D3IjkkymiY4CsVEmSFPb4sIc0x/m+PjhzDR7XJkbZUCWyy9WfsgLjeN9z50uSasjQpAFTg4WJrqMalWvSRrX4rSYt+cSaLUp7e6j9+16rQSNwsjaLesF8ANpHoT3g+S9Z70Sznq7XvhxWPTnEkH7vTXIRtY1p1DQDDf
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):64531
              Entropy (8bit):6.104830357284618
              Encrypted:false
              SSDEEP:
              MD5:CF4784F6DDD490A98BA314F43A02DA93
              SHA1:B43C80B5C0F9451A42E675BCB04D89D1B39A47A0
              SHA-256:38BF3A1336F2540E536451F4BA12514473A3C480600748E728AFD051743D1051
              SHA-512:8350D921D4A5B96850CF375B673B82BC05B2A430D4FB814AD428F9BF076CB45DD093F899C423F1C81405722B1564F7F50282C05A303395C3ACA3B4B1812BF246
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"1B94E5024015A307769363A60E0D5B42FA1F9C3BB6A108D492D64D1251C4F3D1\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"desktop_session_duration_tracker":{"last_session_end_timestamp":"1706548905"},"domain_actions_config":"H4sIAAAAAAAAAL1dW5PctrH+K6p9SlIerHZ1s5wnH1mOXSeyXY5Srjqp1BYIYkgsQYDCZWY4Kf/30w3O3jQEZpryOQ9xVhw2bmx0f93obvzngm+uboStpbhZSx6ikzeilaK7sRvpnKrlxTf/ueDDoJXgQVnjL7751+GBrG8GC8/Hi28ufh7CzzFcfHVR254rA0+MDGutdkzY/uL3rygkPsRaWT9R/vuri0Sh5NSz4b18TBzGAf/97ebqHU7i+2kO73AKh3ewCZiLh8FffHP1+1cXou6pszN6fL8brJe/aD7+Knk9Ph6318o0hYneU/8GPW6UkY+Jg40sbJZQ9nwHf0sGs1hAzSuxeMgbhhRyKb3mb5gKSyh3a2VUGJd2vOVBtDB6YUt8WWxCNTAACW042wBTLW2m0lGK6DbYkm/5lgm+pJlW4hbbwC82OGuWjkY4mJMD/hctN0bqpe2YwEOLLLn0+9jt4KSXJvhBx8WLu2l3C7dUG3Vc
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):58458
              Entropy (8bit):6.10344102847642
              Encrypted:false
              SSDEEP:
              MD5:3F47A8EC3A6E3241F633F4F8B4D1E1BA
              SHA1:555A963F91D2D1BEE9F8E1DC60BFC74AB39974D9
              SHA-256:445699D3D8EFB04F5F6BE942A4B3AE8F8CCD0FD01DAE043BF667AC7B9D64AD1D
              SHA-512:401C18B4AD1A9AB151FEA09ACBE25B1346BF8D51F48D385799E38A94D7F040C5B751A0B13A50AF90D90ACAE417E9CFABE0E7F5E0A97708088A4E7A41DE652CBB
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):58938
              Entropy (8bit):6.1064581073027115
              Encrypted:false
              SSDEEP:
              MD5:29E57CFDB93E0242C1F1EE60DA881316
              SHA1:D0D877579D3130D1738A302D50346ABF2D5B631D
              SHA-256:8E5B75B4CA512814859135C24BF22C305AC120FDBAF9182CA431436CF02BA994
              SHA-512:FA0DFE62C494B4B1497BAC291C3D23C926CC8DB8CD70D153573311C0D1A7FC995D238BC6371CB93DBCBADB4DA16B623934274026D486A62BCA669B2175DF4C4A
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):100396
              Entropy (8bit):4.631218093626774
              Encrypted:false
              SSDEEP:
              MD5:03811A31AD3132022E98AF7561D5A753
              SHA1:4FA717319F4EF7D3E3AA39CA44E9DF30C29F4F42
              SHA-256:0B47D6A978AE18EE557F07A7D8C3F9F54D40EDF1C6149115018884CDB4017705
              SHA-512:C30D1AAE6C4B49ED69544133BC919FF4D2D9B325B3D26F2AE737F1380A9D2A5364331E4F2683DCC53A9D367DFE5FCC18C383DDA2618A14BA12A1C88F200B60F5
              Malicious:false
              Reputation:low
              Preview:{"sites":[{"url":"24video.be"},{"url":"7dnifutbol.bg"},{"url":"6tv.dk"},{"url":"9kefa.com"},{"url":"aculpaedoslb.blogspot.pt"},{"url":"aek-live.gr"},{"url":"arcadepunk.co.uk"},{"url":"acidimg.cc"},{"url":"aazah.com"},{"url":"allehensbeverwijk.nl"},{"url":"amateurgonewild.org"},{"url":"aindasoudotempo.blogspot.com"},{"url":"anorthosis365.com"},{"url":"autoreview.bg"},{"url":"alivefoot.us"},{"url":"arbitro10.com"},{"url":"allhard.org"},{"url":"babesnude.info"},{"url":"aysel.today"},{"url":"animepornx.com"},{"url":"bahisideal20.com"},{"url":"analyseindustrie.nl"},{"url":"bahis10line.org"},{"url":"apoel365.net"},{"url":"bahissitelerisikayetleri.com"},{"url":"bambusratte.com"},{"url":"banzaj.pl"},{"url":"barlevegas.com"},{"url":"baston.info"},{"url":"atomcurve.com"},{"url":"atascadocherba.com"},{"url":"astrologer.gr"},{"url":"adultpicz.com"},{"url":"alleporno.com"},{"url":"beaver-tube.com"},{"url":"beachbabes.info"},{"url":"bearworldmagazine.com"},{"url":"bebegimdensonra.com"},{"url":"autoy
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):100396
              Entropy (8bit):4.631218093626774
              Encrypted:false
              SSDEEP:
              MD5:03811A31AD3132022E98AF7561D5A753
              SHA1:4FA717319F4EF7D3E3AA39CA44E9DF30C29F4F42
              SHA-256:0B47D6A978AE18EE557F07A7D8C3F9F54D40EDF1C6149115018884CDB4017705
              SHA-512:C30D1AAE6C4B49ED69544133BC919FF4D2D9B325B3D26F2AE737F1380A9D2A5364331E4F2683DCC53A9D367DFE5FCC18C383DDA2618A14BA12A1C88F200B60F5
              Malicious:false
              Reputation:low
              Preview:{"sites":[{"url":"24video.be"},{"url":"7dnifutbol.bg"},{"url":"6tv.dk"},{"url":"9kefa.com"},{"url":"aculpaedoslb.blogspot.pt"},{"url":"aek-live.gr"},{"url":"arcadepunk.co.uk"},{"url":"acidimg.cc"},{"url":"aazah.com"},{"url":"allehensbeverwijk.nl"},{"url":"amateurgonewild.org"},{"url":"aindasoudotempo.blogspot.com"},{"url":"anorthosis365.com"},{"url":"autoreview.bg"},{"url":"alivefoot.us"},{"url":"arbitro10.com"},{"url":"allhard.org"},{"url":"babesnude.info"},{"url":"aysel.today"},{"url":"animepornx.com"},{"url":"bahisideal20.com"},{"url":"analyseindustrie.nl"},{"url":"bahis10line.org"},{"url":"apoel365.net"},{"url":"bahissitelerisikayetleri.com"},{"url":"bambusratte.com"},{"url":"banzaj.pl"},{"url":"barlevegas.com"},{"url":"baston.info"},{"url":"atomcurve.com"},{"url":"atascadocherba.com"},{"url":"astrologer.gr"},{"url":"adultpicz.com"},{"url":"alleporno.com"},{"url":"beaver-tube.com"},{"url":"beachbabes.info"},{"url":"bearworldmagazine.com"},{"url":"bebegimdensonra.com"},{"url":"autoy
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):4194304
              Entropy (8bit):0.0
              Encrypted:false
              SSDEEP:
              MD5:B5CFA9D6C8FEBD618F91AC2843D50A1C
              SHA1:2BCCBD2F38F15C13EB7D5A89FD9D85F595E23BC3
              SHA-256:BB9F8DF61474D25E71FA00722318CD387396CA1736605E1248821CC0DE3D3AF8
              SHA-512:BD273BF4E10ED6E305ECB7B781CB065545FCE9BE9F1E2968DF22C3A98F82D719855AAFE5FF303D14EA623A5C55E51E924E10033A92A7A6B07725D7E9692B74F5
              Malicious:false
              Reputation:low
              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):4194304
              Entropy (8bit):0.0
              Encrypted:false
              SSDEEP:
              MD5:B5CFA9D6C8FEBD618F91AC2843D50A1C
              SHA1:2BCCBD2F38F15C13EB7D5A89FD9D85F595E23BC3
              SHA-256:BB9F8DF61474D25E71FA00722318CD387396CA1736605E1248821CC0DE3D3AF8
              SHA-512:BD273BF4E10ED6E305ECB7B781CB065545FCE9BE9F1E2968DF22C3A98F82D719855AAFE5FF303D14EA623A5C55E51E924E10033A92A7A6B07725D7E9692B74F5
              Malicious:false
              Reputation:low
              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):4194304
              Entropy (8bit):0.5333689336454512
              Encrypted:false
              SSDEEP:
              MD5:B964610502EE517B199094B442F25D47
              SHA1:18E0DDBF492450AE416596FFDED5AA54BC999F2E
              SHA-256:EF632B826249C404441A81693DC31B684858EC50ED102638D7D81C2E41449603
              SHA-512:BDC60A0E29DB81914244583899143E97A963512212A120D5816F46F5F38E301A2FC4C7083198F4576BCD77F7EC386CC43B49003F12799CD67896F745D8ABCAEF
              Malicious:false
              Reputation:low
              Preview:...@..@...@.....C.].....@...................................`... ...i.y.........BrowserMetrics......i.y..Yd. .......A...................v.0.....UV&K.k<................UV&K.k<................UMA.PersistentHistograms.InitResult.....8...i.y.[".................................................i.y.Pq.30..............117.0.2045.47-64..".en-GB*...Windows NT..10.0.190452l..x86_64..?........".ubssyk20,1(.0..8..B.......2.:.M..BU..Be...?j...GenuineIntel... .. ..........x86_64...J....k..^o..J..l.zL.^o..J....\.^o..J.....f.^o..J....?.^o..P.Z...b.INBXj....... .8.@..............2......................w..U?:K....&..`v.>.........."....."...24.."."vfSn8LvoRR6x9HfN//24V2w+A0djSL3uj44qFpD7tBM="*.:............B)..1.3.177.11.. .*.RegKeyNotFound2.windowsR...Z....+....W@..$...SF@.......Y@.......4@.......Y@........?........?.........................Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......4@.......Y@................Y@.......Y@.......Y@........?........?2........6...... .2......
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):280
              Entropy (8bit):4.188920072053371
              Encrypted:false
              SSDEEP:
              MD5:20AF3275F86826B6FA0CACBD71576305
              SHA1:387EE1A8EB0C3D33BAC224759B7633AA0194EF6C
              SHA-256:AA54939C4A9E7A9008AF6016E9DC4D1A3DFAE6E48D3C521F538D2CE52341AA36
              SHA-512:AAEF3318C21A2E5D983660098C82B585BD893C80F35BDB273FA345F11BB3B841DC24325A972923523E2DC688BDF0240D03DDF97A071DE7ED6F2B42BD2DF7E982
              Malicious:false
              Reputation:low
              Preview:sdPC......................z....K..s...x."vfSn8LvoRR6x9HfN//24V2w+A0djSL3uj44qFpD7tBM="..................................................................................47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=....................7dc5f755-0f90-4102-bc8e-37d02917bdc7............
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):701715
              Entropy (8bit):4.562252591250131
              Encrypted:false
              SSDEEP:
              MD5:08D8FAC834C186FDCA8688E12C4BF2AA
              SHA1:9A9EBF2FAFB2E0B73001B0D2879CFA9FCE624C82
              SHA-256:5B4A0F6D4EBB2303EF99165E920B7AC52722A16E98D10ACAD67DF76B773B33E7
              SHA-512:FDD540A37A55E7B8CB8DEDCC22A652E74DEC13EF25BD710EBF462EF91C640BC869C4F73BE652AAD6890079334D62F7AF679DFBBEC115603DE763D36C76BF0CD6
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):701715
              Entropy (8bit):4.562247289228356
              Encrypted:false
              SSDEEP:
              MD5:65AE60386ABD02CC7A7BCC037F066AA5
              SHA1:FB6C0351612BB80DE7B7DCA40D163E8B263D9068
              SHA-256:455549C74AE0CF92E3CFB1D8E293E650A0C27CC50E5D574B30186109378E497C
              SHA-512:75F97DE97C6D6F36D4E726B84AA7B33501A07E6611CDE2AC24983AC17A2490DE68BCD7A39B18AD215FEBCBEEB7773F4C9807AA24BCDACC830A28281953A013FA
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):703099
              Entropy (8bit):4.56541801610757
              Encrypted:false
              SSDEEP:
              MD5:56CC00F346F16D552105265F0130BADA
              SHA1:D66D055FD01CF89781E57A29877741E74FBC6440
              SHA-256:9DFFF003BFDBCEC00AD4F27C890470F62A518CE598C1AA66D519E426D64B6A4E
              SHA-512:6833E56CD24A976BB0A6C90FDE5CDEB1A336C25E5B9DDE91D81DA90A7A10D6449B3DEBA54E9F0817D90B8F57187AD2DCC11EF8437D1BD407C4535B3CDBAA8A18
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text, with very long lines (1597), with CRLF line terminators
              Category:dropped
              Size (bytes):115717
              Entropy (8bit):5.183660917461099
              Encrypted:false
              SSDEEP:
              MD5:3D8183370B5E2A9D11D43EBEF474B305
              SHA1:155AB0A46E019E834FA556F3D818399BFF02162B
              SHA-256:6A30BADAD93601FC8987B8239D8907BCBE65E8F1993E4D045D91A77338A2A5B4
              SHA-512:B7AD04F10CD5DE147BDBBE2D642B18E9ECB2D39851BE1286FDC65FF83985EA30278C95263C98999B6D94683AE1DB86436877C30A40992ACA1743097A2526FE81
              Malicious:false
              Reputation:low
              Preview:{.. "current_locale": "en-GB",.. "hub_apps": [ {.. "auto_show": {.. "enabled": true,.. "fre_notification": {.. "enabled": true,.. "header": "Was opening this pane helpful to you?",.. "show_count": 2,.. "text": "Was opening this pane helpful to you?".. },.. "settings_description": "We'll automatically open Bing Chat in the sidebar to show you relevant web experiences alongside your web content",.. "settings_title": "Automatically open Bing Chat in the sidebar",.. "triggering_configs|flight:msHubAppsMsnArticleAutoShowTriggering": [ {.. "show_count_basis": "signal",.. "signal_name": "IsMsnArticleAutoOpenFromP1P2",.. "signal_threshold": 0.5.. } ],.. "triggering_configs|flight:msUndersidePersistentChat": [ {.. "signal_name": "IsUndersidePersistentChatLink",.. "signal_threshold": 0.5.. } ],.. "triggering_co
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):40356
              Entropy (8bit):5.561733377650997
              Encrypted:false
              SSDEEP:
              MD5:6AC5A9D740724DD21AB2777934F10B38
              SHA1:7C0B39CF47DE3F725A89027F307401EBE7BC3AC5
              SHA-256:A96CC21F9894A17159A856DCF50A8E8A47B5F1CD555CE1AC0365F9A2E0D2850E
              SHA-512:57D7666E84A65AFA5504DFF4095C2767BE4B7B758CE288F207FCD7FF2E632DA9A2FE22D4CBC144A35242052C4EB22113D02F8A1ABF0500EB7CB0219EA4CD5A4A
              Malicious:false
              Reputation:low
              Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13351022489477537","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13351022489477537","location":5,"ma
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):701550
              Entropy (8bit):4.562054216132389
              Encrypted:false
              SSDEEP:
              MD5:329CBBE97A0A4BF94143245C7BFF7E2F
              SHA1:1AC9D4130BA23CC1C90762AA1247747648DE96EE
              SHA-256:C7549494ED24FFFEEA8B81503DA209C14C2AED68559E3514E23FCF50003A081C
              SHA-512:C01BD90B524AF46D74B17AE321757E2E531CEBFCA3C2F67A875115BE944B4CC9016C884A2F8E454A9D9810159C6762CA917DBC7D1C63FA42E609E0D9A2764134
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):16
              Entropy (8bit):3.2743974703476995
              Encrypted:false
              SSDEEP:
              MD5:46295CAC801E5D4857D09837238A6394
              SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
              SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
              SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
              Malicious:false
              Reputation:low
              Preview:MANIFEST-000001.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):33
              Entropy (8bit):3.5394429593752084
              Encrypted:false
              SSDEEP:
              MD5:F27314DD366903BBC6141EAE524B0FDE
              SHA1:4714D4A11C53CF4258C3A0246B98E5F5A01FBC12
              SHA-256:68C7AD234755B9EDB06832A084D092660970C89A7305E0C47D327B6AC50DD898
              SHA-512:07A0D529D9458DE5E46385F2A9D77E0987567BA908B53DDB1F83D40D99A72E6B2E3586B9F79C2264A83422C4E7FC6559CAC029A6F969F793F7407212BB3ECD51
              Malicious:false
              Reputation:low
              Preview:...m.................DB_VERSION.1
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):16
              Entropy (8bit):3.2743974703476995
              Encrypted:false
              SSDEEP:
              MD5:46295CAC801E5D4857D09837238A6394
              SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
              SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
              SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
              Malicious:false
              Reputation:low
              Preview:MANIFEST-000001.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):305
              Entropy (8bit):5.230306711792698
              Encrypted:false
              SSDEEP:
              MD5:2EBCBADB4EC4CC6F50F22124DC9B4E88
              SHA1:52A0A2C39FA9736D59462D533BBC7EF7E0401CFB
              SHA-256:531B62C73FACDD71A1E3B876C1AA376FF7AAFD763A6777F6DA5EDDA987D2B50A
              SHA-512:DB34EA70B3CF11E619D717544019B6AF0B1C3652646C11997A3D796D6181C99CDDD281D0D230D0B8C5D242E82D4B7F16715BC119886A4B25773CEB8B1385002F
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:43.918 10e0 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AdPlatform/auto_show_data.db since it was missing..2024/01/29-18:21:43.927 10e0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AdPlatform/auto_show_data.db/MANIFEST-000001.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:OpenPGP Secret Key
              Category:dropped
              Size (bytes):41
              Entropy (8bit):4.704993772857998
              Encrypted:false
              SSDEEP:
              MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
              SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
              SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
              SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
              Malicious:false
              Reputation:low
              Preview:.|.."....leveldb.BytewiseComparator......
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:modified
              Size (bytes):2164091
              Entropy (8bit):5.223265292355146
              Encrypted:false
              SSDEEP:
              MD5:0FEAC7F22B5B795031204BCFAA628A86
              SHA1:36598CF25325293DB86BDF73789F2DB9AC33938D
              SHA-256:C028B9C07CAA09F38594A1DEB1099CF8F75D09FAC2AB99D78AA77D3B0FB91275
              SHA-512:77FAFD8BDFD4DB4592DD7CDB160CB80F4EC564ED07397A7D1E62A84D16B2634BE0FAC8CEB134F40A8F8020FE15711D58DDB45C208AEF629CBC87E94EDB4794BF
              Malicious:false
              Reputation:low
              Preview:...m.................DB_VERSION.1...8.................QUERY_TIMESTAMP:arbitration_priority_list4.*.*.13341056840624329.$QUERY:arbitration_priority_list4.*.*..[{"name":"arbitration_priority_list","url":"https://edgeassetservice.azureedge.net/assets/arbitration_priority_list/4.0.5/asset?sv=2017-07-29&sr=c&sig=NtPyTqjbjPElpw2mWa%2FwOk1no4JFJEK8%2BwO4xQdDJO4%3D&st=2021-01-01T00%3A00%3A00Z&se=2023-12-30T00%3A00%3A00Z&sp=r&assetgroup=ArbitrationService","version":{"major":4,"minor":0,"patch":5},"hash":"N0MkrPHaUyfTgQSPaiVpHemLMcVgqoPh/xUYLZyXayg=","size":11749}]...................'ASSET_VERSION:arbitration_priority_list.4.0.5..ASSET:arbitration_priority_list.[{. "configVersion": 32,. "PrivilegedExperiences": [. "ShorelinePrivilegedExperienceID",. "SHOPPING_AUTO_SHOW_COUPONS_CHECKOUT",. "SHOPPING_AUTO_SHOW_LOWER_PRICE_FOUND",. "SHOPPING_AUTO_SHOW_BING_SEARCH",. "SHOPPING_AUTO_SHOW_REBATES",. "SHOPPING_AUTO_SHOW_REBATES_CONFIRMATION",. "SHOPPING_AUTO_SHOW_REBATES_DEACTI
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):332
              Entropy (8bit):5.161095576206774
              Encrypted:false
              SSDEEP:
              MD5:0775C3E132786064B307BFF03FC6B12D
              SHA1:CAD59A6C87098D70F0AC1A8DE97A9F330B8714D1
              SHA-256:933667C738585376AD447D9840B6A0226B7443491F922773D87E1ED4BBCF0234
              SHA-512:8F7AAAA5228808B9CC3A033CCD7F76BCF862E1FCDC9D9C84DDAD79E7BD27718366FEE008486BF9F10639FB6D93E31B1C1A20AD28ABCE6DD4BFB365F4B06A518E
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:34.669 1c70 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/MANIFEST-000001.2024/01/29-18:21:34.671 1c70 Recovering log #3.2024/01/29-18:21:34.728 1c70 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/000003.log .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):4364
              Entropy (8bit):4.238135272432774
              Encrypted:false
              SSDEEP:
              MD5:E08D62D3DC69660DDC31B9444DA6787A
              SHA1:D7537ED5DBE967ABCABA6880DEF2335662F6F708
              SHA-256:F1F8720E6DDF0880B6C25FE7C4FC79B6552F234F47C8DC3004868A1CED331C23
              SHA-512:DC2424DFA2F6A868E25A569A06BE07036B31E536AF042B848D0E5E176770629645A4730B8065249A385EB3BCA3E94EEB7387477AB9CB585915B7629675D419C4
              Malicious:false
              Reputation:low
              Preview:{.. "checksum": "45c5e75d52aad358849be76b67352156",.. "roots": {.. "bookmark_bar": {.. "children": [ {.. "date_added": "13341058798227977",.. "date_last_used": "0",.. "guid": "0cf761a5-eee5-4b4b-b2a0-f6a690c3218f",.. "id": "7",.. "name": "Amazon",.. "show_icon": false,.. "source": "import_fre",.. "type": "url",.. "url": "http://www.amazon.com/".. }, {.. "date_added": "13341058798227977",.. "date_last_used": "0",.. "guid": "af554a4d-85e9-43d4-8452-bbdb5ba50ffd",.. "id": "8",.. "name": "Facebook",.. "show_icon": false,.. "source": "import_fre",.. "type": "url",.. "url": "http://www.facebook.com/".. }, {.. "date_added": "13341058798227977",.. "date_last_used": "0",.. "guid": "857ef466-f810-478d-b451-1871aea5363c",.. "i
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 1
              Category:dropped
              Size (bytes):28672
              Entropy (8bit):0.4770146931461761
              Encrypted:false
              SSDEEP:
              MD5:0FE75307642F5212D08A47F262919B99
              SHA1:E2904CD11E297F02720C2807308A90714FD650CE
              SHA-256:25AD46DACCF47C992F3D0753EA3BC82DF6D8CD17C45678679F075F76EBBA71EB
              SHA-512:9FF99CCEE6D5B38F69A97DEBE2874D59E5B6E22A272A0B6FA3AC5421C44472567F1CDADAF28620F69826A30337A19983687707A7E1378743FD7234E3F2981F42
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ ..........................................................................j..........g.....8...n................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 5, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 5
              Category:dropped
              Size (bytes):10240
              Entropy (8bit):0.8708334089814068
              Encrypted:false
              SSDEEP:
              MD5:92F9F7F28AB4823C874D79EDF2F582DE
              SHA1:2D4F1B04C314C79D76B7FF3F50056ECA517C338B
              SHA-256:6318FCD9A092D1F5B30EBD9FB6AEC30B1AEBD241DC15FE1EEED3B501571DA3C7
              SHA-512:86FEF0E05F871A166C3FAB123B0A4B95870DCCECBE20B767AF4BDFD99653184BBBFE4CE1EDF17208B7700C969B65B8166EE264287B613641E7FDD55A6C09E6D4
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ ..........................................................................j...v... .. .....M....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:FoxPro FPT, blocks size 512, next free block index 3284796609, field type 0
              Category:dropped
              Size (bytes):8192
              Entropy (8bit):0.01057775872642915
              Encrypted:false
              SSDEEP:
              MD5:CF89D16BB9107C631DAABF0C0EE58EFB
              SHA1:3AE5D3A7CF1F94A56E42F9A58D90A0B9616AE74B
              SHA-256:D6A5FE39CD672781B256E0E3102F7022635F1D4BB7CFCC90A80FFFE4D0F3877E
              SHA-512:8CB5B059C8105EB91E74A7D5952437AAA1ADA89763C5843E7B0F1B93D9EBE15ED40F287C652229291FAC02D712CF7FF5ECECEF276BA0D7DDC35558A3EC3F77B0
              Malicious:false
              Reputation:low
              Preview:............$...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
              Category:dropped
              Size (bytes):262512
              Entropy (8bit):9.553120663130604E-4
              Encrypted:false
              SSDEEP:
              MD5:7DCE3C9C364EF9E51F5D2314A12A52E1
              SHA1:A8B9840165A1856822167F2A3E817D30FE41D7A5
              SHA-256:E91273396A5C2AB31AA84C6D9E661E8AC2F47D41289E2418FE394C71A30E9732
              SHA-512:5DFCA6FBE85A2FC3E81675CAB2AC9933007F0749ACA7DD36763F927B90E1B8858BA5ED836C929FF4534C9884CAAB15E1DC501392F26F306522FA04D8A78B6B0D
              Malicious:false
              Reputation:low
              Preview:.........................................2...n/.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):773562
              Entropy (8bit):5.9914175354748105
              Encrypted:false
              SSDEEP:
              MD5:47300E1FDF11C4465DD6C4F76317E4DE
              SHA1:42BAF82B425ED341AC37F73CB6894594BFD05EF2
              SHA-256:3F2CEDA9DB352A5A60361036684AEFC31992714948283E7410209D494246FC62
              SHA-512:A63AFF6E4AF19336D6F15C32A90C39D2B963AEE937EC63304931BF058965354252DDC4F01D24994CA6549309E1C66B77742A12BB5A053F55482A844159352C8A
              Malicious:false
              Reputation:low
              Preview:...m.................DB_VERSION.1k`.j.................BLOOM_FILTER:./{"numberOfHashFunctions":8,"shiftBase":9,"bloomFilterArraySize":4589816,"primeBases":[5381,5381,5381,5381],"supportedDomains":"fML64y9OsfFMKLn70O+DpYRl7fu9+Ov/dvsUPvwdoIwJU4ATaWXlD+Q4svB/WRDXYk11R1gTJkHV/6CQwDYikQuUMS4SIQiDeGiD5nBzfB+FYBdTlOyBb6YgQEz7YDUIia8H+4CopTFPs24CwbByhR5iHrKZRBQh//70oyuBCy+KY3g3ai2cSKMCwDaNRSGkAzgES3/7TxOVupjXzr6sV2QpPDDv4RBLJBwjtRNZqZnuj9ZLEUMsIkDikoTOV5j9XP89f0rwWaQrQEeCTLrvv+U9XcpRtNrPMDHN8MIYDmVYUHb0zfmCJeMPdQ4hgGO+1Mjv//p6eXLJsRIROYLNQmCNShrliwkzjUOGF4k0DFVNlZZDEYpck1503zKuEK50lzz/FSqcj9juDeh6VFDx89On8q21/ju4518CSQtsoRCRg1ImlfjBzDAoS4L76qOjf8Xt6rySx3q2xJu6CSNVliliMmSZJRc4RMv/p0U20mAowk4hJOoUGeFvuSUakTWDn6CCkafGeF4Fy8Tx96QDjZAiQYbc9N79/v4VvbSt2E3M1rQ3MqFCp2ogWDCUBhSG7N5+2/epO4VVut/WeiM2DhXmxFoOqySAuAKYpchLxpLVwCEhFvmpMP0+g1usIVQKjidSkwUABFBIo47SfJFFqQEgUpq+oWRYlWWbUfsNSfG+/utFID3rCJT4KhEVCaCb0BHCC1VobwtcEDToqWWgDZDGBHws2jDa/xd0iAjQKsHgLwBhKcfU4BBrDk0bxIG2ZJgY5HUHmvf5L991OStX4ctQzd5/dtO+YEU
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):142
              Entropy (8bit):5.033019384243301
              Encrypted:false
              SSDEEP:
              MD5:148A1AEA26B3C5FF2E1CB631C194B2A7
              SHA1:1F4FD8293C4569423CD1C54C3E63037B9FE2F208
              SHA-256:2A1797D05C210ED11D359E33A3E5F757ECF4B0E45D54846F487FEE2BE12B1BC7
              SHA-512:E9309359E78D00AFEC98AB24BCD62485FCC07E04ABDF681DB8476AC87F1564B2E66E11F582C8B09A03E3775217CE05961B84D6E83D1CD23DF3AAD933A0B3AB40
              Malicious:false
              Reputation:low
              Preview:.s..9................BLOOM_FILTER_EXPIRY_TIME:.1706635391.699578.,I.G................BLOOM_FILTER_LAST_MODIFIED:.Mon, 29 Jan 2024 07:22:08 GMT
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):773509
              Entropy (8bit):5.9903938217564106
              Encrypted:false
              SSDEEP:
              MD5:50EBF7112E66F6423ACAB5EC903D65ED
              SHA1:7E9475904BEE3CD68BE913C30E3F48503ACCE254
              SHA-256:636579ACFD48B4FF4BAE9D98A171CF6434B3CBEBADED27E01AE113CC6FDDD6A6
              SHA-512:5FD0EC56D353A0213EA1EA1AEE905D0A4D70F8408DD5E4DAE3E24FA0FD2D3BAD2FC7BFCF33986FAD1212816A5F3643664072250C91D1BA17642713D48FB9A540
              Malicious:false
              Reputation:low
              Preview:.../BLOOM_FILTER:........{"numberOfHashFunctions":8,"shiftBase":9,"bloomFilterArraySize":4589816,"primeBases":[5381,5381,5381,5381],"supportedDomains":"fML64y9OsfFMKLn70O+DpYRl7fu9+Ov/dvsUPvwdoIwJU4ATaWXlD+Q4svB/WRDXYk11R1gTJkHV/6CQwDYikQuUMS4SIQiDeGiD5nBzfB+FYBdTlOyBb6YgQEz7YDUIia8H+4CopTFPs24CwbByhR5iHrKZRBQh//70oyuBCy+KY3g3ai2cSKMCwDaNRSGkAzgES3/7TxOVupjXzr6sV2QpPDDv4RBLJBwjtRNZqZnuj9ZLEUMsIkDikoTOV5j9XP89f0rwWaQrQEeCTLrvv+U9XcpRtNrPMDHN8MIYDmVYUHb0zfmCJeMPdQ4hgGO+1Mjv//p6eXLJsRIROYLNQmCNShrliwkzjUOGF4k0DFVNlZZDEYpck1503zKuEK50lzz/FSqcj9juDeh6VFDx89On8q21/ju4518CSQtsoRCRg1ImlfjBzDAoS4L76qOjf8Xt6rySx3q2xJu6CSNVliliMmSZJRc4RMv/p0U20mAowk4hJOoUGeFvuSUakTWDn6CCkafGeF4Fy8Tx96QDjZAiQYbc9N79/v4VvbSt2E3M1rQ3MqFCp2ogWDCUBhSG7N5+2/epO4VVut/WeiM2DhXmxFoOqySAuAKYpchLxpLVwCEhFvmpMP0+g1usIVQKjidSkwUABFBIo47SfJFFqQEgUpq+oWRYlWWbUfsNSfG+/utFID3rCJT4KhEVCaCb0BHCC1VobwtcEDToqWWgDZDGBHws2jDa/xd0iAjQKsHgLwBhKcfU4BBrDk0bxIG2ZJgY5HUHmvf5L991OStX4ctQzd5/dtO+YEU1TK9YIoD8KCKhEeg6x+65S7/MHrbIL7P6D0GI2iwIEoF
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):508
              Entropy (8bit):5.25132640023439
              Encrypted:false
              SSDEEP:
              MD5:24ED21E7DE3CD5C924C3F3EA728A370C
              SHA1:9BEF06548DCA4495E222A627620A548729837535
              SHA-256:E833C25D77A0D00E985D8B6E0A43C2D52364D970D9658DF78180B51E7514A34B
              SHA-512:EE400002A4ECF45580590B8DD17BC0D94797217C5F62FAC988DBF4FF99F58E354F4EDA2664C6977CB937645DA27AFFBE7FD41E1E630E52D44FE372281641E82E
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:29.603 14cc Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/MANIFEST-000001.2024/01/29-18:21:29.604 14cc Recovering log #3.2024/01/29-18:21:29.611 14cc Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/000003.log .2024/01/29-18:23:11.731 1894 Level-0 table #5: started.2024/01/29-18:23:11.777 1894 Level-0 table #5: 773509 bytes OK.2024/01/29-18:23:11.779 1894 Delete type=0 #3.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:OpenPGP Secret Key
              Category:dropped
              Size (bytes):103
              Entropy (8bit):5.241151534110313
              Encrypted:false
              SSDEEP:
              MD5:ECEAE6476CF0313360B837F88FD18765
              SHA1:D6C82FC147DDB396D6EF36E4FE5070D44869D146
              SHA-256:528569A9766831F623847E3329C6AF92AABD2AF72E57CA4D833A086918439851
              SHA-512:D40C489AFA33E7918E97CE7593670FFF3831EBCD3DFF4CF8A7F2622CC7B127565F4D61F1DE0C472BD9CDC5E0A155029F761A90ED2AAB45A09CA196183BDC0B9B
              Malicious:false
              Reputation:low
              Preview:.|.."....leveldb.BytewiseComparator......"..a7.............../.BLOOM_FILTER:.........DB_VERSION........
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 6, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 6
              Category:dropped
              Size (bytes):20480
              Entropy (8bit):0.6128459234443624
              Encrypted:false
              SSDEEP:
              MD5:0066876B7182C48887743E9296B7DE99
              SHA1:B895C949B3843F7EED72078A7C53EBAB069814DB
              SHA-256:B576345F7A9BE9B5980D3021722718635F65D599B817A920BA3202898776EA16
              SHA-512:D606F4E79B7CB738E28484DCA5DB5F268DFA0A2336EDB08D70D974171FA2AB88AAE06DA2C77D91A9BA5391DBA5F9DEACD8F032FD491533A3D855EED17A3D804D
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ ..........................................................................j...%.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):392647
              Entropy (8bit):5.4094573311666885
              Encrypted:false
              SSDEEP:
              MD5:7E6116195ECC3050C8D330CE861EF23E
              SHA1:6D8668FCBAA3405B8295CD18F827A5C1D4F911CF
              SHA-256:028827A52DEC1E875BCE4CCC16C45EA640F0B79CBCD3AF369FB15E908E9B9EF3
              SHA-512:B628E3AA80E7206C1189C287FB858BF6FE6F6AD7B8C50C5941D26EA1ABBCDF8F213155795650F0B067DFB44E7A1AE33CB487F746D6461A9581482C1BF2BD9BC8
              Malicious:false
              Reputation:low
              Preview:...m.................DB_VERSION.11...................&QUERY_TIMESTAMP:domains_config_gz2.*.*.13351022505607077..QUERY:domains_config_gz2.*.*..[{"name":"domains_config_gz","url":"https://edgeassetservice.azureedge.net/assets/domains_config_gz/2.8.75/asset?sv=2017-07-29&sr=c&sig=ODCnll3A%2Fpr7IBDaNsDR2zA%2FOssZl6xdmLkM6vzzbZ0%3D&st=2021-01-01T00%3A00%3A00Z&se=2024-03-31T00%3A00%3A00Z&sp=r&assetgroup=EntityExtractionDomainsConfig","version":{"major":2,"minor":8,"patch":75},"hash":"EwG2gkfquexLj6u3yjHyiL4YQwdU318k1Hub+1rSDMI=","size":391864}].....}...............ASSET_VERSION:domains_config_gz.2.8.75..ASSET:domains_config_gz...{"config": {"token_limit": 1600, "page_cutoff": 4320, "default_locale_map": {"bg": "bg-bg", "bs": "bs-ba", "el": "el-gr", "en": "en-us", "es": "es-mx", "et": "et-ee", "cs": "cs-cz", "da": "da-dk", "de": "de-de", "fa": "fa-ir", "fi": "fi-fi", "fr": "fr-fr", "he": "he-il", "hr": "hr-hr", "hu": "hu-hu", "id": "id-id", "is": "is-is", "it": "it-it", "ja": "ja-jp", "ko": "
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):307
              Entropy (8bit):5.15379426692592
              Encrypted:false
              SSDEEP:
              MD5:D12B8CAC72B7254B44913650E5F03E51
              SHA1:B6CFAC11C5FB162274E0CA99CDFAFFF94B7BF6D6
              SHA-256:0688E414291F7A75B4C43F117495D1D943BFA322B68A9D70CFF0DA08AFD1B9BF
              SHA-512:FCBA64DD49FB72271474221D334AAC7FDBACE6C02FC7BFCBAEA675ECF46D2823DC137D6F782C681E3AAAF4B145E8D44D4A4A817289BA33174C06E7DA36A8B414
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:44.225 1600 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EntityExtractionAssetStore.db since it was missing..2024/01/29-18:21:45.082 1600 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EntityExtractionAssetStore.db/MANIFEST-000001.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:modified
              Size (bytes):374811
              Entropy (8bit):5.396166842073875
              Encrypted:false
              SSDEEP:
              MD5:024D5E8FCD39BAB485E6BE197ADA7A8C
              SHA1:97A93E649801B0BD4E6E44FC20BD9B84544B9ED7
              SHA-256:935D0BE695229EA3BB69153F16DABFE6EB5CC91B8512C01A06BF0685709DACB0
              SHA-512:FA4DFEB870A0B0E7202F042CD06E7FF79AC40B3E7BEAE37E6304DC49CDDF240EBBB20516ABE5B9F19EECE00B1456731E0516184EA4B13894F689658EBA39EF7D
              Malicious:false
              Reputation:low
              Preview:{"aee_config":{"ar":{"price_regex":{"ae":"(((ae|aed|\\x{062F}\\x{0660}\\x{0625}\\x{0660}|\\x{062F}\\.\\x{0625}|dhs|dh)\\s*\\d{1,3})|(\\d{1,3}\\s*(ae|aed|\\x{062F}\\x{0660}\\x{0625}\\x{0660}|\\x{062F}\\.\\x{0625}|dhs|dh)))","dz":"(((dzd|da|\\x{062F}\\x{062C})\\s*\\d{1,3})|(\\d{1,3}\\s*(dzd|da|\\x{062F}\\x{062C})))","eg":"(((e\\x{00a3}|egp)\\s*\\d{1,3})|(\\d{1,3}\\s*(e\\x{00a3}|egp)))","ma":"(((mad|dhs|dh)\\s*\\d{1,3})|(\\d{1,3}\\s*(mad|dhs|dh)))","sa":"((\\d{1,3}\\s*(sar\\s*\\x{fdfc}|sar|sr|\\x{fdfc}|\\.\\x{0631}\\.\\x{0633}))|((sar\\s*\\x{fdfc}|sar|sr|\\x{fdfc}|\\.\\x{0631}\\.\\x{0633})\\s*\\d{1,3}))"},"product_terms":"((\\x{0623}\\x{0636}\\x{0641}\\s*\\x{0625}\\x{0644}\\x{0649}\\s*\\x{0627}\\x{0644}\\x{0639}\\x{0631}\\x{0628}\\x{0629})|(\\x{0623}\\x{0636}\\x{0641}\\s*\\x{0625}\\x{0644}\\x{0649}\\s*\\x{0627}\\x{0644}\\x{062D}\\x{0642}\\x{064A}\\x{0628}\\x{0629})|(\\x{0627}\\x{0634}\\x{062A}\\x{0631}\\x{064A}\\s*\\x{0627}\\x{0644}\\x{0622}\\x{0646})|(\\x{062E}\\x{064A}\\x{0627}\\x{0631}
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):418
              Entropy (8bit):1.8784775129881184
              Encrypted:false
              SSDEEP:
              MD5:BF097D724FDF1FCA9CF3532E86B54696
              SHA1:4039A5DD607F9FB14018185F707944FE7BA25EF7
              SHA-256:1B8B50A996172C16E93AC48BCB94A3592BEED51D3EF03F87585A1A5E6EC37F6B
              SHA-512:31857C157E5B02BCA225B189843CE912A792A7098CEA580B387977B29E90A33C476DF99AD9F45AD5EB8DA1EFFD8AC3A78870988F60A32D05FA2DA8F47794FACE
              Malicious:false
              Reputation:low
              Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5...............
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):320
              Entropy (8bit):5.169475212464368
              Encrypted:false
              SSDEEP:
              MD5:28624941DD889593E240D198DCCE9CB7
              SHA1:A90E3474BF7E32AD0BF578C7BCE32FB63B85C21B
              SHA-256:F54C07B705E5F7669D26CC2DC1766214EDF0E9C21595BE473170BAF15D02CA68
              SHA-512:20EA6BC219312997C4F43BCDE88EC4EAC8D3DA4287992F724CCBA26BC3687EFB9DADB582E14C71B8FB629BB2DF983E8064DEBB08B3536E9DDC4E91A59078BC9E
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:29.603 1824 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/MANIFEST-000001.2024/01/29-18:21:29.611 1824 Recovering log #3.2024/01/29-18:21:29.615 1824 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/000003.log .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):324
              Entropy (8bit):5.173285664715831
              Encrypted:false
              SSDEEP:
              MD5:E29C15CB871A89A0D2E0C7C444FFC2CE
              SHA1:004D5373FA8174AAFC3F52DEA2A92108BB3DD060
              SHA-256:1CEA1B74B34E7198803DC65326E28D38ED90D68F9ED0AB329A7FB7C333EC6354
              SHA-512:63EF808336F1185E24493FB3A0BF56A4167B97F65DBA045334AF738BADA8B5A2548D8ECA3BF65E1ECBBBA3BF055723F2FA4F0CB44DCEE9196D48B2E428148EA3
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:29.632 13a8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/MANIFEST-000001.2024/01/29-18:21:29.633 13a8 Recovering log #3.2024/01/29-18:21:29.633 13a8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/000003.log .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):1254
              Entropy (8bit):1.8784775129881184
              Encrypted:false
              SSDEEP:
              MD5:826B4C0003ABB7604485322423C5212A
              SHA1:6B8EF07391CD0301C58BB06E8DEDCA502D59BCB4
              SHA-256:C56783C3A6F28D9F7043D2FB31B8A956369F25E6CE6441EB7C03480334341A63
              SHA-512:0474165157921EA84062102743EE5A6AFE500F1F87DE2E87DBFE36C32CFE2636A0AE43D8946342740A843D5C2502EA4932623C609B930FE8511FE7356D4BAA9C
              Malicious:false
              Reputation:low
              Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5........
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):320
              Entropy (8bit):5.160056787851367
              Encrypted:false
              SSDEEP:
              MD5:971591885BF2163E9602B20D891A430C
              SHA1:449FD6D09654A3550218F1BF1DD5E222A5E1D10B
              SHA-256:8FF68A1F2D453B01725FD0CF0ED9E09A899453F37D05FE03B4FE9080BE92440F
              SHA-512:200409644C6B7B20D92506C588C0FB0F2D511FC450DD99D86E8BA1D1AA58B50BDF738E1E28C6CD82EF79D5D9764006C33B2AC23A4EAF26E8AAFBBC3A6663540E
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:30.105 1894 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/MANIFEST-000001.2024/01/29-18:21:30.106 1894 Recovering log #3.2024/01/29-18:21:30.106 1894 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/000003.log .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):429
              Entropy (8bit):5.809210454117189
              Encrypted:false
              SSDEEP:
              MD5:5D1D9020CCEFD76CA661902E0C229087
              SHA1:DCF2AA4A1C626EC7FFD9ABD284D29B269D78FCB6
              SHA-256:B829B0DF7E3F2391BFBA70090EB4CE2BA6A978CCD665EEBF1073849BDD4B8FB9
              SHA-512:5F6E72720E64A7AC19F191F0179992745D5136D41DCDC13C5C3C2E35A71EB227570BD47C7B376658EF670B75929ABEEBD8EF470D1E24B595A11D320EC1479E3C
              Malicious:false
              Reputation:low
              Preview:{"file_hashes":[{"block_hashes":["OdZL4YFLwCTKbdslekC6/+U9KTtDUk+T+nnpVOeRzUc=","6RbL+qKART8FehO4s7U0u67iEI8/jaN+8Kg3kII+uy4=","CuN6+RcZAysZCfrzCZ8KdWDkQqyaIstSrcmsZ/c2MVs="],"block_size":4096,"path":"content.js"},{"block_hashes":["OdZL4YFLwCTKbdslekC6/+U9KTtDUk+T+nnpVOeRzUc=","UL53sQ5hOhAmII/Yx6muXikzahxM+k5gEmVOh7xJ3Rw=","u6MdmVNzBUfDzMwv2LEJ6pXR8k0nnvpYRwOL8aApwP8="],"block_size":4096,"path":"content_new.js"}],"version":2}
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 20, cookie 0x8, schema 4, UTF-8, version-valid-for 3
              Category:dropped
              Size (bytes):40960
              Entropy (8bit):5.047829265367233
              Encrypted:false
              SSDEEP:
              MD5:EFCDBBAF8AF5AEC9D78FBEEF11445273
              SHA1:4825705D0C0F2305B05CBF258FE446273B452BAA
              SHA-256:8BE70EC212026DD38673FE9F6AA122CB01B7B5F8711543F9A5D79F9FA5CDF57F
              SHA-512:38E8E1C7E134DB0C6E04EEC84B97364A732FDA4878501D526A9F84CC9CD5297A05591A8E8FEA50DDF58F4C78F6AAD6132EE4DD508B1DC8C2B12B545692E900E2
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ ..........................................................................j..........g....._.c...~.2.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................s...;+...indexfavicon_bitmaps_icon_idfavico
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):270336
              Entropy (8bit):8.280239615765425E-4
              Encrypted:false
              SSDEEP:
              MD5:D0D388F3865D0523E451D6BA0BE34CC4
              SHA1:8571C6A52AACC2747C048E3419E5657B74612995
              SHA-256:902F30C1FB0597D0734BC34B979EC5D131F8F39A4B71B338083821216EC8D61B
              SHA-512:376011D00DE659EB6082A74E862CFAC97A9BB508E0B740761505142E2D24EC1C30AA61EFBC1C0DD08FF0F34734444DE7F77DD90A6CA42B48A4C7FAD5F0BDDD17
              Malicious:false
              Reputation:low
              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):8192
              Entropy (8bit):0.011852361981932763
              Encrypted:false
              SSDEEP:
              MD5:0962291D6D367570BEE5454721C17E11
              SHA1:59D10A893EF321A706A9255176761366115BEDCB
              SHA-256:EC1702806F4CC7C42A82FC2B38E89835FDE7C64BB32060E0823C9077CA92EFB7
              SHA-512:F555E961B69E09628EAF9C61F465871E6984CD4D31014F954BB747351DAD9CEA6D17C1DB4BCA2C1EB7F187CB5F3C0518748C339C8B43BBD1DBD94AEAA16F58ED
              Malicious:false
              Reputation:low
              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):8192
              Entropy (8bit):0.012340643231932763
              Encrypted:false
              SSDEEP:
              MD5:41876349CB12D6DB992F1309F22DF3F0
              SHA1:5CF26B3420FC0302CD0A71E8D029739B8765BE27
              SHA-256:E09F42C398D688DCE168570291F1F92D079987DEDA3099A34ADB9E8C0522B30C
              SHA-512:E9A4FC1F7CB6AE2901F8E02354A92C4AAA7A53C640DCF692DB42A27A5ACC2A3BFB25A0DE0EB08AB53983132016E7D43132EA4292E439BB636AAFD53FB6EF907E
              Malicious:false
              Reputation:low
              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
              Category:dropped
              Size (bytes):262512
              Entropy (8bit):9.553120663130604E-4
              Encrypted:false
              SSDEEP:
              MD5:7C61F6E00AE9A2E8977EC250BDDE5F76
              SHA1:1C0ECD4C1579B471E44877FFADB94264A1B5402C
              SHA-256:E87F5114ABF3D1A2121341505C5FB9C4091F25E28C66C74A008B2E9F48B8D03E
              SHA-512:68DD5B668AB3746137C7D5E535B598DD4822DE6FC7C6D62652C531FD1010FC7A79931FDF28157BAAABC94E1E14AEAA771BEE126757B1586E1080313D43AD6FA7
              Malicious:false
              Reputation:low
              Preview:.........................................o...n/.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 2, database pages 38, cookie 0x1f, schema 4, UTF-8, version-valid-for 2
              Category:dropped
              Size (bytes):155648
              Entropy (8bit):0.5695210061218663
              Encrypted:false
              SSDEEP:
              MD5:1C674085128155AECB46F4BC79A4B3DC
              SHA1:33FEE22466E604DFEDC172917187EC8F4BE7A100
              SHA-256:A5B6DF7135FCBC3F1B93A62FD80ECEDEC575AD0A96718B4602EB75063F8C0EE7
              SHA-512:C04D98B2A492251821A8A52505BB96805940C1BF12442EB1E609D1DFFDFFEF5B10F9B5CD37C84BD792E4B31CB5F07490BBC133A3937DE3D97FE405F907304380
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ .......&..................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text, with very long lines (1597), with CRLF line terminators
              Category:dropped
              Size (bytes):115717
              Entropy (8bit):5.183660917461099
              Encrypted:false
              SSDEEP:
              MD5:3D8183370B5E2A9D11D43EBEF474B305
              SHA1:155AB0A46E019E834FA556F3D818399BFF02162B
              SHA-256:6A30BADAD93601FC8987B8239D8907BCBE65E8F1993E4D045D91A77338A2A5B4
              SHA-512:B7AD04F10CD5DE147BDBBE2D642B18E9ECB2D39851BE1286FDC65FF83985EA30278C95263C98999B6D94683AE1DB86436877C30A40992ACA1743097A2526FE81
              Malicious:false
              Reputation:low
              Preview:{.. "current_locale": "en-GB",.. "hub_apps": [ {.. "auto_show": {.. "enabled": true,.. "fre_notification": {.. "enabled": true,.. "header": "Was opening this pane helpful to you?",.. "show_count": 2,.. "text": "Was opening this pane helpful to you?".. },.. "settings_description": "We'll automatically open Bing Chat in the sidebar to show you relevant web experiences alongside your web content",.. "settings_title": "Automatically open Bing Chat in the sidebar",.. "triggering_configs|flight:msHubAppsMsnArticleAutoShowTriggering": [ {.. "show_count_basis": "signal",.. "signal_name": "IsMsnArticleAutoOpenFromP1P2",.. "signal_threshold": 0.5.. } ],.. "triggering_configs|flight:msUndersidePersistentChat": [ {.. "signal_name": "IsUndersidePersistentChatLink",.. "signal_threshold": 0.5.. } ],.. "triggering_co
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 6, database pages 11, cookie 0x3, schema 4, UTF-8, version-valid-for 6
              Category:dropped
              Size (bytes):45056
              Entropy (8bit):3.571310377031016
              Encrypted:false
              SSDEEP:
              MD5:C5322B0EDD493EDFB9A4EDB968F2D2A6
              SHA1:0A005039337AC02A1DFFF7C4C75FBAFC8A5F997C
              SHA-256:A7CFEB38EB6995DC6319124EA68CB508E27BEA5B6825BE5F915BEC362A662120
              SHA-512:06E783035BF235B9C1D539FC813046490E5B66491818329150F7BE6663F96DA0DC892EC6E63D28AF75BDDCEEF3DE306818657DF8D629224BDEDD8BA3977CF59B
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ ..........................................................................j..........g...:.8....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):404
              Entropy (8bit):5.221862307761534
              Encrypted:false
              SSDEEP:
              MD5:76A8694EE7BF6914762A0A6595AFD870
              SHA1:825D4181F1468DA4D1E10CC4E50EDB2AAA46D6B3
              SHA-256:EDACAE36CAFAED8242746B53B688CDD574853C3784EEBF033B21493C7DAFC087
              SHA-512:82848372FE30C0E393D701F18CC4C14697EF992CBC470B0FAC2116EDA4328A0BCE0511F527232140B1170BAD767A19CE43D3D0BE7C44939E8AE7F4E7385178BB
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:31.310 13a8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/MANIFEST-000001.2024/01/29-18:21:31.311 13a8 Recovering log #3.2024/01/29-18:21:31.311 13a8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/000003.log .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):559
              Entropy (8bit):5.4055913623119
              Encrypted:false
              SSDEEP:
              MD5:2076F30B69EC9D635855F69632A55F68
              SHA1:AD4B6B162E81DB5981B7A1F5C6171A3AC6B1F237
              SHA-256:FA779BBD26A7908346F00B9C1BA3F1CE64418E1FF4A44BE202124A4CEBABBCA6
              SHA-512:1FC54BB2C5852C83F59938714FCD7540FF4BFCB0E6F38416E270DC5DF45D92D7B7C37BAFCD0133308D3D243797625F5A1E3F3CEAE78FA82ABF514DF559CFF3A3
              Malicious:false
              Reputation:low
              Preview:.-.(................VERSION.1./META:https://microsoftedgewelcome.microsoft.com..............4_https://microsoftedgewelcome.microsoft.com.._uetsid!.1602ed60becb11ee8b2d5f1c82808971.8_https://microsoftedgewelcome.microsoft.com.._uetsid_exp..Tue, 30 Jan 2024 17:23:15 GMT.4_https://microsoftedgewelcome.microsoft.com.._uetvid!.160320f0becb11eeb6400d3836a25a87.8_https://microsoftedgewelcome.microsoft.com.._uetvid_exp..Sat, 22 Feb 2025 17:23:15 GMT.o_https://microsoftedgewelcome.microsoft.com..Mon Jan 29 2024 18:23:15 GMT+0100 (Central European Standard Time)
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):332
              Entropy (8bit):5.124383493674824
              Encrypted:false
              SSDEEP:
              MD5:B94B6BC72B4C2AA82A180743E87ACD8F
              SHA1:D63772F4BCF17A06B82BB4299A82E17F819CF374
              SHA-256:1622487CEDA0E1FE98428040505EEFE8425256458904DE5B1B218A4690C909FF
              SHA-512:C489A217F2D55B8987622E7117750CCBD98D937D8C006440BCC7BA8EAFB8846F2A50569287FA659F883A0C571F7EDC4568EFF70C3AD1A44289EA19D32E574056
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:30.088 16c0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/MANIFEST-000001.2024/01/29-18:21:30.091 16c0 Recovering log #3.2024/01/29-18:21:30.096 16c0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/000003.log .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):40
              Entropy (8bit):4.1275671571169275
              Encrypted:false
              SSDEEP:
              MD5:20D4B8FA017A12A108C87F540836E250
              SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
              SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
              SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
              Malicious:false
              Reputation:low
              Preview:{"SDCH":{"dictionaries":{},"version":2}}
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1501
              Entropy (8bit):5.312406317193556
              Encrypted:false
              SSDEEP:
              MD5:24CF5AEE937F40B30914219C7ED49DC4
              SHA1:1DB113D35450C88D5340DBB0121E8B1CC5A9A56E
              SHA-256:AF5A2E7B1C940B855238168C03E8ADF2F821683BAD6AF0BA7C5AFAFBDE8E29C1
              SHA-512:36969076B9500BD92C6F1394DDA134F82ADD864F10B9048EC97E89ECB6434D9A716892208175F83B3B08962977DB792B869B67507049E1345696FF098213101A
              Malicious:false
              Reputation:low
              Preview:{"net":{"http_server_properties":{"servers":[{"anonymization":["FAAAAA4AAABodHRwOi8vbXNuLmNvbQAA",false],"server":"https://assets.msn.com","supports_spdy":true},{"anonymization":["FAAAAA8AAABodHRwczovL21zbi5jb20A",false],"server":"https://assets.msn.com","supports_spdy":true},{"anonymization":["IAAAABoAAABodHRwczovL3d3dy5nb29nbGVhcGlzLmNvbQAA",false],"server":"https://www.googleapis.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13353614491482676","port":443,"protocol_str":"quic"}],"anonymization":["GAAAABIAAABodHRwczovL2dvb2dsZS5jb20AAA==",false],"server":"https://clients2.google.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13353614492175106","port":443,"protocol_str":"quic"}],"anonymization":["JAAAAB0AAABodHRwczovL2dvb2dsZXVzZXJjb250ZW50LmNvbQAAAA==",false],"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"anonymization":["HAAAABUAAABodHRwczovL2F6dXJlZWRnZS5uZXQAAAA=",f
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 7, database pages 9, cookie 0x4, schema 4, UTF-8, version-valid-for 7
              Category:dropped
              Size (bytes):36864
              Entropy (8bit):1.1142174677292562
              Encrypted:false
              SSDEEP:
              MD5:B56D90CD71BFD20640DC1A1D8BA7D0C7
              SHA1:9B4B02628383E3D2FB235134E8A7132145DC543D
              SHA-256:E085B16DF969395354A4CB22F1674F3DC05CD89F489560CCD09349B0C4BAE905
              SHA-512:04216ACB758EDDBA1823F3EEDEC922A73FD679CD19D0597FC673B69D649F6375C42E448334A83E1A93341B0C356650AF6540D8EA4CA1D614F6BBFA0F1C53DD12
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ ..........................................................................j..........g...D.........7............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):40
              Entropy (8bit):4.1275671571169275
              Encrypted:false
              SSDEEP:
              MD5:20D4B8FA017A12A108C87F540836E250
              SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
              SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
              SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
              Malicious:false
              Reputation:low
              Preview:{"SDCH":{"dictionaries":{},"version":2}}
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 2, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 2
              Category:dropped
              Size (bytes):20480
              Entropy (8bit):0.4716248163409303
              Encrypted:false
              SSDEEP:
              MD5:72E9D82D6C1742197EEA43EC203C6825
              SHA1:275AE552E437747FD707962111675AA2C8DEEB0F
              SHA-256:0DB0BA239E0421208146C4FBB809F2DBD960019FE4F4EC4CBC894C29627DD759
              SHA-512:C62C7C0C9BBE1CFAE2FEF39FBDF70BB5316713D87453096676BD854A19FDD8BC62F1608F8BE3602AD8770B94C13FFE5A9516F05A95548615CB78ED9CEADC7EA9
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ ..........................................................................j.......q..g...q.0....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 3
              Category:dropped
              Size (bytes):20480
              Entropy (8bit):0.6840578855946601
              Encrypted:false
              SSDEEP:
              MD5:07BF84BA873E7D2B7E6699FB7CFC8579
              SHA1:4E8F7B0C1A53361F6DDE90B055F5C3122359E9A3
              SHA-256:4239F1109FE4E20A2D0CDF031BD52F2E530CB035E97C550CAAB1B5EB175A3B4F
              SHA-512:1ABCF8BF5B039DB92E0446EEA83521D4E806298BB50C6DC1098096C21E605A5CD3805F432B23A2DE8A6D1B46ED6227A6310CFFF6FBBB31B530CC4BACE3E8D7E2
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):7506
              Entropy (8bit):5.083990252620817
              Encrypted:false
              SSDEEP:
              MD5:A81F5E4C51DAB10B5B5461FC1F167EF9
              SHA1:3FB50B1E9B47C95ED54966B3F81C306A1F31E9E8
              SHA-256:EEA5884C83379E18FC031313928C6ED23B3B71D7B6FFACA9D41870C250DD64D0
              SHA-512:07879396D834A8F19D68CC0DE205939B6554389216A4C030080935E3C90769B6DC9A5F20F84DA3184143EB7E73DF1B1C2E498C6CD1556BFE9AD24BADB7655446
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false},"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"domain_diversity":{"last_reporting_timestamp":"13351022489942229"},"dual_engine":{"consumer_mode":{"ie_user":false},"consumer_site_list_with_ie_entries":false,"consumer_sitelist_location":"","consumer_sitelist_version":"","external_consumer_shared_cookie_data":{},"shared_cookie_data":{},"sitelist_data_2":{},"sitelist_has_consumer_data":false,"sitelist_has_enterprise_data":false,"sitelist_location":"","sitelist_source":0,"sitelist_version":""},"edge":{
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):7506
              Entropy (8bit):5.083990252620817
              Encrypted:false
              SSDEEP:
              MD5:A81F5E4C51DAB10B5B5461FC1F167EF9
              SHA1:3FB50B1E9B47C95ED54966B3F81C306A1F31E9E8
              SHA-256:EEA5884C83379E18FC031313928C6ED23B3B71D7B6FFACA9D41870C250DD64D0
              SHA-512:07879396D834A8F19D68CC0DE205939B6554389216A4C030080935E3C90769B6DC9A5F20F84DA3184143EB7E73DF1B1C2E498C6CD1556BFE9AD24BADB7655446
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false},"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"domain_diversity":{"last_reporting_timestamp":"13351022489942229"},"dual_engine":{"consumer_mode":{"ie_user":false},"consumer_site_list_with_ie_entries":false,"consumer_sitelist_location":"","consumer_sitelist_version":"","external_consumer_shared_cookie_data":{},"shared_cookie_data":{},"sitelist_data_2":{},"sitelist_has_consumer_data":false,"sitelist_has_enterprise_data":false,"sitelist_location":"","sitelist_source":0,"sitelist_version":""},"edge":{
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):7506
              Entropy (8bit):5.083990252620817
              Encrypted:false
              SSDEEP:
              MD5:A81F5E4C51DAB10B5B5461FC1F167EF9
              SHA1:3FB50B1E9B47C95ED54966B3F81C306A1F31E9E8
              SHA-256:EEA5884C83379E18FC031313928C6ED23B3B71D7B6FFACA9D41870C250DD64D0
              SHA-512:07879396D834A8F19D68CC0DE205939B6554389216A4C030080935E3C90769B6DC9A5F20F84DA3184143EB7E73DF1B1C2E498C6CD1556BFE9AD24BADB7655446
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false},"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"domain_diversity":{"last_reporting_timestamp":"13351022489942229"},"dual_engine":{"consumer_mode":{"ie_user":false},"consumer_site_list_with_ie_entries":false,"consumer_sitelist_location":"","consumer_sitelist_version":"","external_consumer_shared_cookie_data":{},"shared_cookie_data":{},"sitelist_data_2":{},"sitelist_has_consumer_data":false,"sitelist_has_enterprise_data":false,"sitelist_location":"","sitelist_source":0,"sitelist_version":""},"edge":{
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):7506
              Entropy (8bit):5.083990252620817
              Encrypted:false
              SSDEEP:
              MD5:A81F5E4C51DAB10B5B5461FC1F167EF9
              SHA1:3FB50B1E9B47C95ED54966B3F81C306A1F31E9E8
              SHA-256:EEA5884C83379E18FC031313928C6ED23B3B71D7B6FFACA9D41870C250DD64D0
              SHA-512:07879396D834A8F19D68CC0DE205939B6554389216A4C030080935E3C90769B6DC9A5F20F84DA3184143EB7E73DF1B1C2E498C6CD1556BFE9AD24BADB7655446
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false},"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"domain_diversity":{"last_reporting_timestamp":"13351022489942229"},"dual_engine":{"consumer_mode":{"ie_user":false},"consumer_site_list_with_ie_entries":false,"consumer_sitelist_location":"","consumer_sitelist_version":"","external_consumer_shared_cookie_data":{},"shared_cookie_data":{},"sitelist_data_2":{},"sitelist_has_consumer_data":false,"sitelist_has_enterprise_data":false,"sitelist_location":"","sitelist_source":0,"sitelist_version":""},"edge":{
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):7506
              Entropy (8bit):5.083990252620817
              Encrypted:false
              SSDEEP:
              MD5:A81F5E4C51DAB10B5B5461FC1F167EF9
              SHA1:3FB50B1E9B47C95ED54966B3F81C306A1F31E9E8
              SHA-256:EEA5884C83379E18FC031313928C6ED23B3B71D7B6FFACA9D41870C250DD64D0
              SHA-512:07879396D834A8F19D68CC0DE205939B6554389216A4C030080935E3C90769B6DC9A5F20F84DA3184143EB7E73DF1B1C2E498C6CD1556BFE9AD24BADB7655446
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false},"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"domain_diversity":{"last_reporting_timestamp":"13351022489942229"},"dual_engine":{"consumer_mode":{"ie_user":false},"consumer_site_list_with_ie_entries":false,"consumer_sitelist_location":"","consumer_sitelist_version":"","external_consumer_shared_cookie_data":{},"shared_cookie_data":{},"sitelist_data_2":{},"sitelist_has_consumer_data":false,"sitelist_has_enterprise_data":false,"sitelist_location":"","sitelist_source":0,"sitelist_version":""},"edge":{
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):7506
              Entropy (8bit):5.083990252620817
              Encrypted:false
              SSDEEP:
              MD5:A81F5E4C51DAB10B5B5461FC1F167EF9
              SHA1:3FB50B1E9B47C95ED54966B3F81C306A1F31E9E8
              SHA-256:EEA5884C83379E18FC031313928C6ED23B3B71D7B6FFACA9D41870C250DD64D0
              SHA-512:07879396D834A8F19D68CC0DE205939B6554389216A4C030080935E3C90769B6DC9A5F20F84DA3184143EB7E73DF1B1C2E498C6CD1556BFE9AD24BADB7655446
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false},"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"domain_diversity":{"last_reporting_timestamp":"13351022489942229"},"dual_engine":{"consumer_mode":{"ie_user":false},"consumer_site_list_with_ie_entries":false,"consumer_sitelist_location":"","consumer_sitelist_version":"","external_consumer_shared_cookie_data":{},"shared_cookie_data":{},"sitelist_data_2":{},"sitelist_has_consumer_data":false,"sitelist_has_enterprise_data":false,"sitelist_location":"","sitelist_source":0,"sitelist_version":""},"edge":{
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):7506
              Entropy (8bit):5.083990252620817
              Encrypted:false
              SSDEEP:
              MD5:A81F5E4C51DAB10B5B5461FC1F167EF9
              SHA1:3FB50B1E9B47C95ED54966B3F81C306A1F31E9E8
              SHA-256:EEA5884C83379E18FC031313928C6ED23B3B71D7B6FFACA9D41870C250DD64D0
              SHA-512:07879396D834A8F19D68CC0DE205939B6554389216A4C030080935E3C90769B6DC9A5F20F84DA3184143EB7E73DF1B1C2E498C6CD1556BFE9AD24BADB7655446
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false},"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"domain_diversity":{"last_reporting_timestamp":"13351022489942229"},"dual_engine":{"consumer_mode":{"ie_user":false},"consumer_site_list_with_ie_entries":false,"consumer_sitelist_location":"","consumer_sitelist_version":"","external_consumer_shared_cookie_data":{},"shared_cookie_data":{},"sitelist_data_2":{},"sitelist_has_consumer_data":false,"sitelist_has_enterprise_data":false,"sitelist_location":"","sitelist_source":0,"sitelist_version":""},"edge":{
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):7506
              Entropy (8bit):5.083990252620817
              Encrypted:false
              SSDEEP:
              MD5:A81F5E4C51DAB10B5B5461FC1F167EF9
              SHA1:3FB50B1E9B47C95ED54966B3F81C306A1F31E9E8
              SHA-256:EEA5884C83379E18FC031313928C6ED23B3B71D7B6FFACA9D41870C250DD64D0
              SHA-512:07879396D834A8F19D68CC0DE205939B6554389216A4C030080935E3C90769B6DC9A5F20F84DA3184143EB7E73DF1B1C2E498C6CD1556BFE9AD24BADB7655446
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false},"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"domain_diversity":{"last_reporting_timestamp":"13351022489942229"},"dual_engine":{"consumer_mode":{"ie_user":false},"consumer_site_list_with_ie_entries":false,"consumer_sitelist_location":"","consumer_sitelist_version":"","external_consumer_shared_cookie_data":{},"shared_cookie_data":{},"sitelist_data_2":{},"sitelist_has_consumer_data":false,"sitelist_has_enterprise_data":false,"sitelist_location":"","sitelist_source":0,"sitelist_version":""},"edge":{
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):7506
              Entropy (8bit):5.083990252620817
              Encrypted:false
              SSDEEP:
              MD5:A81F5E4C51DAB10B5B5461FC1F167EF9
              SHA1:3FB50B1E9B47C95ED54966B3F81C306A1F31E9E8
              SHA-256:EEA5884C83379E18FC031313928C6ED23B3B71D7B6FFACA9D41870C250DD64D0
              SHA-512:07879396D834A8F19D68CC0DE205939B6554389216A4C030080935E3C90769B6DC9A5F20F84DA3184143EB7E73DF1B1C2E498C6CD1556BFE9AD24BADB7655446
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false},"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"domain_diversity":{"last_reporting_timestamp":"13351022489942229"},"dual_engine":{"consumer_mode":{"ie_user":false},"consumer_site_list_with_ie_entries":false,"consumer_sitelist_location":"","consumer_sitelist_version":"","external_consumer_shared_cookie_data":{},"shared_cookie_data":{},"sitelist_data_2":{},"sitelist_has_consumer_data":false,"sitelist_has_enterprise_data":false,"sitelist_location":"","sitelist_source":0,"sitelist_version":""},"edge":{
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:modified
              Size (bytes):537
              Entropy (8bit):5.887471758257939
              Encrypted:false
              SSDEEP:
              MD5:5A9C8C142B7272258F0B5EE476F7CEEA
              SHA1:94FEEF9759213E443CEC5C6839548B5672E2D91E
              SHA-256:661BDF68A0EE692326D7899D0591507B07E60C623B5C1D84C826A49BEB442981
              SHA-512:7520A885DD131B9C645B7A3CBD8E46C4545D141DD56F9037D18BE2790389CAF6F17E979F633B916FFF68B50E947DEC8D556B08D9F6195A45A54A1C24EE894768
              Malicious:false
              Reputation:low
              Preview:...m.................DB_VERSION.1C..................(QUERY_TIMESTAMP:product_category_en1.*.*.13351022597599264..QUERY:product_category_en1.*.*..[{"name":"product_category_en","url":"https://edgeassetservice.azureedge.net/assets/product_category_en/1.0.0/asset?sv=2017-07-29&sr=c&sig=ODCnll3A%2Fpr7IBDaNsDR2zA%2FOssZl6xdmLkM6vzzbZ0%3D&st=2021-01-01T00%3A00%3A00Z&se=2024-03-31T00%3A00%3A00Z&sp=r&assetgroup=ProductCategories","version":{"major":1,"minor":0,"patch":0},"hash":"r2jWYy3aqoi3+S+aPyOSfXOCPeLSy5AmAjNHvYRv9Hg=","size":82989}]
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):305
              Entropy (8bit):5.183398480430143
              Encrypted:false
              SSDEEP:
              MD5:41BC22D28C9EF6EB66BE84F55CA92256
              SHA1:3F02ADC554D57097D880D03797EA4BA27D74AAF7
              SHA-256:FA696321B5B77AC5712003480CC1FA88287225916A56E3CF4A80A42CA2DF9B61
              SHA-512:1EDD5C65BD29CF4B7991FB3E3AD9FE5097DD813FA5D8BFF7993956D8AC37DE0D744DC3C7BD99311DDE766E0F1CC5779A07889A5574FF3FA8243E44B099C5870C
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:23:17.083 17d0 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\PriceComparisonAssetStore.db since it was missing..2024/01/29-18:23:17.105 17d0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\PriceComparisonAssetStore.db/MANIFEST-000001.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):28252
              Entropy (8bit):5.55896286464827
              Encrypted:false
              SSDEEP:
              MD5:9FB93E71AD30EDD07A774DBF20EEFBAC
              SHA1:CB22AB7E2228057758A2F2F6CAD2D30B57D96E81
              SHA-256:C742B061C2311A28C6AAB13A95692CBD5CEA8D5F0A13C928C405C9C2D3795C9B
              SHA-512:A6E282A66FCCCA76335174A8A605A7102C8A2923D3AD8A49CB725734BB2DB5E37AA67C3DD550AEEE2C1409EC0F4910C57444F7A28CBE4EA11DE81B2B86CB345B
              Malicious:false
              Reputation:low
              Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13351022489477537","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13351022489477537","location":5,"ma
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):28252
              Entropy (8bit):5.55896286464827
              Encrypted:false
              SSDEEP:
              MD5:9FB93E71AD30EDD07A774DBF20EEFBAC
              SHA1:CB22AB7E2228057758A2F2F6CAD2D30B57D96E81
              SHA-256:C742B061C2311A28C6AAB13A95692CBD5CEA8D5F0A13C928C405C9C2D3795C9B
              SHA-512:A6E282A66FCCCA76335174A8A605A7102C8A2923D3AD8A49CB725734BB2DB5E37AA67C3DD550AEEE2C1409EC0F4910C57444F7A28CBE4EA11DE81B2B86CB345B
              Malicious:false
              Reputation:low
              Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13351022489477537","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13351022489477537","location":5,"ma
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):733
              Entropy (8bit):4.965954715379713
              Encrypted:false
              SSDEEP:
              MD5:E198903EBE46859A33CB12F4D0BCC5F6
              SHA1:3F943997E21DB8DDA32546D00FD38D6B08DF91D0
              SHA-256:FE1EA043C756D8A3182FB927F60FC30B65BF21D9ADB93E22BFE5F72935C331D5
              SHA-512:B8CB68F2396D030F91866BFA356214E25AF50391FAA7B85A82966488DD2850BD313BD8CE951307A4570CA35EEFB6F3CF490FE945999D18CAA0EB6969B4C5FDD7
              Malicious:false
              Reputation:low
              Preview:*...#................version.1..namespace-..&f.................&f.................&f.................&f.................&f.................&f.................&f.................&f.................&f.................&f...............`...y................next-map-id.1.Znamespace-160a06cc_0709_4b81_8350_9ebe3c2e7a0b-https://microsoftedgewelcome.microsoft.com/.0V.e..................j.y................next-map-id.2.Znamespace-554e4356_8706_4f47_a888_4a66e660f20c-https://microsoftedgewelcome.microsoft.com/.1`.w.r................map-1-_cltk.1.2.n.p.w.5.q..Hmap-1-Mon Jan 29 2024 18:23:15 GMT+0100 (Central European Standard Time).]..b................next-map-id.3.Cnamespace-56e32952_e66e_4bfb_8ad0_51f30e5eec3c-https://ntp.msn.com/.2
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):320
              Entropy (8bit):5.138548156214091
              Encrypted:false
              SSDEEP:
              MD5:15527B04B31EBCA90A800FD10B59EE62
              SHA1:900F3070DDE4F3CB26D21E601B4729E688DECD64
              SHA-256:1A8E3D212B357A2CFDACBBF97494F3077919A95846C17F0F8A522A2CCD67FCDE
              SHA-512:ABA3BE2928963EE183A8BB11494673E8ECCDA7CF707C03BE695C010DB91DB7DAC2BEC25D06CDE90ACE12A5BFFF4348E84AC10D416A7C984CA1460F03927E4330
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:41.690 16c0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/MANIFEST-000001.2024/01/29-18:21:41.692 16c0 Recovering log #3.2024/01/29-18:21:41.705 16c0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/000003.log .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):14755
              Entropy (8bit):3.7872028406674074
              Encrypted:false
              SSDEEP:
              MD5:632A5745DA226F0DF3BE96A8AAB6A2D6
              SHA1:54CBD7523B229C12133F453093E22F7201310AD3
              SHA-256:3234EB9BDD22C7E526E932165171A90040478D5C9C7469B44002E78EBC3A4D13
              SHA-512:E95E04947DD54ED50565C08AA4AD54EC4015BE2CFEE81240FEC3A360B8335B774F1ADC0E29931038063B7F0636B7308853026F690EC4256A63DC4C490A06C879
              Malicious:false
              Reputation:low
              Preview:SNSS................................"........................................................!.............................................1..,.......$...160a06cc_0709_4b81_8350_9ebe3c2e7a0b......................c.5..................................................................5..0.......&...{1E0EB698-B9B7-4961-B591-EC148C400099}..........................................................................Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47...........................Microsoft Edge......117.....Not;A=Brand.....8.......Chromium....117.........Microsoft Edge......117.0.2045.47.......Not;A=Brand.....8.0.0.0.....Chromium....117.0.5938.132......117.0.2045.47.......Windows.....10.0.0......x86.............64............................................Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47.........................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 1
              Category:dropped
              Size (bytes):20480
              Entropy (8bit):0.44194574462308833
              Encrypted:false
              SSDEEP:
              MD5:B35F740AA7FFEA282E525838EABFE0A6
              SHA1:A67822C17670CCE0BA72D3E9C8DA0CE755A3421A
              SHA-256:5D599596D116802BAD422497CF68BE59EEB7A9135E3ED1C6BEACC48F73827161
              SHA-512:05C0D33516B2C1AB6928FB34957AD3E03CB0A8B7EEC0FD627DD263589655A16DEA79100B6CC29095C3660C95FD2AFB2E4DD023F0597BD586DD664769CABB67F8
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ ..........................................................................j..........g....."....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):348
              Entropy (8bit):5.145715576964823
              Encrypted:false
              SSDEEP:
              MD5:B1BAC903EDE00DCA3EFDBE6545909BDD
              SHA1:9625461AB02CBB936F12C809143EAA1F4FD5FBAD
              SHA-256:0CDFCA9F664BC66572FB0928056D43A82E837F2D8E3DDB4F024DC2A37F13FC60
              SHA-512:D3B939E35939B1513700A67FFD12F9932B457F41C6F9D0805604AB2F0C8839CABA55677E2F30226CD8269E038F212592F91F3960AA95A4853D53CF3BCE663C65
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:29.545 19e4 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/MANIFEST-000001.2024/01/29-18:21:29.556 19e4 Recovering log #3.2024/01/29-18:21:29.556 19e4 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/000003.log .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:XML 1.0 document, ASCII text
              Category:dropped
              Size (bytes):705404
              Entropy (8bit):4.69800839097965
              Encrypted:false
              SSDEEP:
              MD5:ECF772746DECBE102BD2F0FC75732FF4
              SHA1:9C1F83C067DA762BAD2B4C69EF458801B1F746AB
              SHA-256:351FE304DE3204BDC58413C14E1252541E60D88CAE5FCD88BCEBA5D93074264D
              SHA-512:42DEC8082A017FBE29B570FA6F51634A79BD66E34D0F8D87AA594D2ED5B155AD4D78DA8F6A778815D9CD16DB0CA7CC47B9BE685834D6E8EE9D186F81C2F065B1
              Malicious:false
              Reputation:low
              Preview:<?xml version="1.0"?>.<site-list version="97">. <site url="0rga.org">. <open-in allow-redirect="true">MSEdge</open-in>. </site>. <site url="100partnerprogramme.de">. <open-in allow-redirect="true">MSEdge</open-in>. </site>. <site url="10bet.co.uk">. <open-in allow-redirect="true">MSEdge</open-in>. </site>. <site url="12circuit.state.fl.us">. <open-in allow-redirect="true">MSEdge</open-in>. </site>. <site url="12stream.de">. <open-in allow-redirect="true">MSEdge</open-in>. </site>. <site url="12thman.com">. <open-in allow-redirect="true">MSEdge</open-in>. </site>. <site url="17thswscoutsleeds.org.uk">. <open-in allow-redirect="true">MSEdge</open-in>. </site>. <site url="1822direkt-banking.de">. <open-in allow-redirect="true">MSEdge</open-in>. </site>. <site url="1987ser.co.jp">. <open-in allow-redirect="true">MSEdge</open-in>. </site>. <site url="1newhorizon.in">. <open-in allow-redirect="true">MSEdge</open-in>. </site>. <site url="1q.com">. <open-in allow-redirect="true">MSE
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):270336
              Entropy (8bit):0.0012471779557650352
              Encrypted:false
              SSDEEP:
              MD5:F50F89A0A91564D0B8A211F8921AA7DE
              SHA1:112403A17DD69D5B9018B8CEDE023CB3B54EAB7D
              SHA-256:B1E963D702392FB7224786E7D56D43973E9B9EFD1B89C17814D7C558FFC0CDEC
              SHA-512:BF8CDA48CF1EC4E73F0DD1D4FA5562AF1836120214EDB74957430CD3E4A2783E801FA3F4ED2AFB375257CAEED4ABE958265237D6E0AACF35A9EDE7A2E8898D58
              Malicious:false
              Reputation:low
              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):430
              Entropy (8bit):5.186437461347892
              Encrypted:false
              SSDEEP:
              MD5:D8DA9393B45DC1FCEAE1D95477A0302F
              SHA1:748A2373E1C23A9493BAC97E363D3C792ACDA39B
              SHA-256:D602D77E457815F0EDA6DAC696C52EC074DDC68892509A19042580DFB7A3B642
              SHA-512:B03519D812703D439AE2795BFCCED616E0587D77072DBCE3AD63B9DEFACE793337BE17039EFBD0E617E70CDE655D4CED0A95D08AFFD640E8E770954F0FEA191D
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:30.116 1130 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/MANIFEST-000001.2024/01/29-18:21:30.121 1130 Recovering log #3.2024/01/29-18:21:30.126 1130 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/000003.log .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2
              Entropy (8bit):1.0
              Encrypted:false
              SSDEEP:
              MD5:D751713988987E9331980363E24189CE
              SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
              SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
              SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
              Malicious:false
              Reputation:low
              Preview:[]
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2
              Entropy (8bit):1.0
              Encrypted:false
              SSDEEP:
              MD5:D751713988987E9331980363E24189CE
              SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
              SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
              SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
              Malicious:false
              Reputation:low
              Preview:[]
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 4, database pages 9, cookie 0x7, schema 4, UTF-8, version-valid-for 4
              Category:dropped
              Size (bytes):36864
              Entropy (8bit):0.3886039372934488
              Encrypted:false
              SSDEEP:
              MD5:DEA619BA33775B1BAEEC7B32110CB3BD
              SHA1:949B8246021D004B2E772742D34B2FC8863E1AAA
              SHA-256:3669D76771207A121594B439280A67E3A6B1CBAE8CE67A42C8312D33BA18854B
              SHA-512:7B9741E0339B30D73FACD4670A9898147BE62B8F063A59736AFDDC83D3F03B61349828F2AE88F682D42C177AE37E18349FD41654AEBA50DDF10CD6DC70FA5879
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ ..........................................................................j..........g...}.....$.X..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):80
              Entropy (8bit):3.4921535629071894
              Encrypted:false
              SSDEEP:
              MD5:69449520FD9C139C534E2970342C6BD8
              SHA1:230FE369A09DEF748F8CC23AD70FD19ED8D1B885
              SHA-256:3F2E9648DFDB2DDB8E9D607E8802FEF05AFA447E17733DD3FD6D933E7CA49277
              SHA-512:EA34C39AEA13B281A6067DE20AD0CDA84135E70C97DB3CDD59E25E6536B19F7781E5FC0CA4A11C3618D43FC3BD3FBC120DD5C1C47821A248B8AD351F9F4E6367
              Malicious:false
              Reputation:low
              Preview:*...#................version.1..namespace-..&f.................&f...............
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):418
              Entropy (8bit):5.208562225375149
              Encrypted:false
              SSDEEP:
              MD5:38C866154F3956A620221EB611554407
              SHA1:80A3C6AEF66BB8343EBA06E92038ECDC2B37DAE8
              SHA-256:701EF33AD9D615D69C371AB93E524CC237CB0654E99900B7A04B8C1779D80208
              SHA-512:4C5D0A0B7D689CBCF000223A0185828CB41F5DEE5128D316E8F5D4A4CBF0D18DF9EF3C3EB2EE947CD27FAD17D16615764A32F14510E8E7E85EB6C542C0D2FBFB
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:46.018 16c0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/MANIFEST-000001.2024/01/29-18:21:46.020 16c0 Recovering log #3.2024/01/29-18:21:46.026 16c0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/000003.log .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):324
              Entropy (8bit):5.176082237021198
              Encrypted:false
              SSDEEP:
              MD5:E467090C59C2B11BC4D2252436470AAB
              SHA1:F817F41A8FD2A04089FADDD6A66B57AF8A0DBD2E
              SHA-256:AA5D367E95A8476E43BA98BB0F3CB094A06CC6FE517C6E893A834BD47D74FEF8
              SHA-512:1D1E97C2ABAC6E47EB93223C2BA172EB036F5F525982A1C4543387B26BE9190B102CB5538A24546EF08663EB4D08E145593CDC2553A3680C961FBFDC96FCCF94
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:29.498 14d0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/MANIFEST-000001.2024/01/29-18:21:29.498 14d0 Recovering log #3.2024/01/29-18:21:29.500 14d0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/000003.log .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):131072
              Entropy (8bit):0.0033464165558137224
              Encrypted:false
              SSDEEP:
              MD5:D6B043D069208A275ECDD95195388CE5
              SHA1:A508ACAA57007E3CFE4E99665C4815CC41BEF246
              SHA-256:AD43B72EB7EDCDDE291BF58261344946435B573DFDDCE8FD35B17873985FEB4C
              SHA-512:41821A31ADDB785768E6D6E0F28E889F196E19C16E463B0BDF2FCBB6EED6BF7D2A9B0979A289CBE55661D2061F8888ACD0A1EC009746BBBE334E438719115BC9
              Malicious:false
              Reputation:low
              Preview:VLnk.....?.......v|..lON................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 9, database pages 91, cookie 0x36, schema 4, UTF-8, version-valid-for 9
              Category:dropped
              Size (bytes):196608
              Entropy (8bit):1.2653335697041757
              Encrypted:false
              SSDEEP:
              MD5:C729A8CF3ED9C22E76E9B6EC85151297
              SHA1:39DAFA94151400F2D4D568AA92B40830825DB278
              SHA-256:432A66C2F4D8CD42A773CA1AEDC4095D5483EE5780B31FC551453D65EEE16BE9
              SHA-512:7A39293728ACF343CD4512284E66DDAA2D53862677034F0ECB1AF00C660EC81ADD09028785CAF2E480CC22742A426864E80D5F16D6D49D725B46C247050358BC
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ .......[...........6......................................................j............W........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 10, cookie 0x7, schema 4, UTF-8, version-valid-for 1
              Category:modified
              Size (bytes):40960
              Entropy (8bit):0.41235120905181716
              Encrypted:false
              SSDEEP:
              MD5:981F351994975A68A0DD3ECE5E889FD0
              SHA1:080D3386290A14A68FCE07709A572AF98097C52D
              SHA-256:3F0C0B2460E0AA2A94E0BF79C8944F2F4835D2701249B34A13FD200F7E5316D7
              SHA-512:C5930797C46EEC25D356BAEB6CFE37E9F462DEE2AE8866343B2C382DBAD45C1544EF720D520C4407F56874596B31EFD6822B58A9D3DAE6F85E47FF802DBAA20B
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ ..........................................................................j.......w..g...........M...w..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):702592
              Entropy (8bit):4.564242183574512
              Encrypted:false
              SSDEEP:
              MD5:EBCCA3622901532F565141EFC199A751
              SHA1:5F68CFBC933AB03E8EE00AB2D0B824D9B3A15B5E
              SHA-256:A580E812940B22113F6DDA87205FB1AC8D8C87522BFEB4C500075E9D9486964E
              SHA-512:FFCAFD546BFC7F166EF2E663C6B9E4C5B3373394BCD37BA580A4945EA1A3FE049AC1766192721887719FD9D87292620F5C8B2771D9AA8FD8386B83914EDEACA6
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text, with very long lines (3951), with CRLF line terminators
              Category:dropped
              Size (bytes):11755
              Entropy (8bit):5.190465908239046
              Encrypted:false
              SSDEEP:
              MD5:07301A857C41B5854E6F84CA00B81EA0
              SHA1:7441FC1018508FF4F3DBAA139A21634C08ED979C
              SHA-256:2343C541E095E1D5F202E8D2A0807113E69E1969AF8E15E3644C51DB0BF33FBF
              SHA-512:00ADE38E9D2F07C64648202F1D5F18A2DFB2781C0517EAEBCD567D8A77DBB7CB40A58B7C7D4EC03336A63A20D2E11DD64448F020C6FF72F06CA870AA2B4765E0
              Malicious:false
              Reputation:low
              Preview:{.. "DefaultCohort": {.. "21f3388b-c2a5-4791-8f6e-a4cad6d17f4f.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.BingHomePage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Covid.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Finance.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Jobs.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.KnowledgeCard.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Local.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.NTP3PCLICK.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.NotifySearchPage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Recipe.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.SearchPage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Sports.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Travel.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Weather.Bubble": 1,.. "2cb2db96-3bd0-403e-abe2-9269b3761041.Bubble": 1,.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):7506
              Entropy (8bit):5.083990252620817
              Encrypted:false
              SSDEEP:
              MD5:A81F5E4C51DAB10B5B5461FC1F167EF9
              SHA1:3FB50B1E9B47C95ED54966B3F81C306A1F31E9E8
              SHA-256:EEA5884C83379E18FC031313928C6ED23B3B71D7B6FFACA9D41870C250DD64D0
              SHA-512:07879396D834A8F19D68CC0DE205939B6554389216A4C030080935E3C90769B6DC9A5F20F84DA3184143EB7E73DF1B1C2E498C6CD1556BFE9AD24BADB7655446
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false},"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"domain_diversity":{"last_reporting_timestamp":"13351022489942229"},"dual_engine":{"consumer_mode":{"ie_user":false},"consumer_site_list_with_ie_entries":false,"consumer_sitelist_location":"","consumer_sitelist_version":"","external_consumer_shared_cookie_data":{},"shared_cookie_data":{},"sitelist_data_2":{},"sitelist_has_consumer_data":false,"sitelist_has_enterprise_data":false,"sitelist_location":"","sitelist_source":0,"sitelist_version":""},"edge":{
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):28252
              Entropy (8bit):5.55896286464827
              Encrypted:false
              SSDEEP:
              MD5:9FB93E71AD30EDD07A774DBF20EEFBAC
              SHA1:CB22AB7E2228057758A2F2F6CAD2D30B57D96E81
              SHA-256:C742B061C2311A28C6AAB13A95692CBD5CEA8D5F0A13C928C405C9C2D3795C9B
              SHA-512:A6E282A66FCCCA76335174A8A605A7102C8A2923D3AD8A49CB725734BB2DB5E37AA67C3DD550AEEE2C1409EC0F4910C57444F7A28CBE4EA11DE81B2B86CB345B
              Malicious:false
              Reputation:low
              Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13351022489477537","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13351022489477537","location":5,"ma
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):700957
              Entropy (8bit):4.558323623269897
              Encrypted:false
              SSDEEP:
              MD5:8D12BD8D5A58B71CCA1738EA5CE374A0
              SHA1:0DA3C51B0FFA9DF4C041470F8A0B54371126F925
              SHA-256:DFEF698A22EADDB1652667E8655C3F3476599151F3351594DE2D710F17698403
              SHA-512:1346FE1E295AA23D4DAF28880D774BE4B01FA917F9C04ED87F4A120C6D840FE451CB578D94968D0AEC7FB35346900E4A515E7DDEEDB959E84380E9657C53C462
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 7, cookie 0x4, schema 4, UTF-8, version-valid-for 1
              Category:dropped
              Size (bytes):28672
              Entropy (8bit):0.3410017321959524
              Encrypted:false
              SSDEEP:
              MD5:98643AF1CA5C0FE03CE8C687189CE56B
              SHA1:ECADBA79A364D72354C658FD6EA3D5CF938F686B
              SHA-256:4DC3BF7A36AB5DA80C0995FAF61ED0F96C4DE572F2D6FF9F120F9BC44B69E444
              SHA-512:68B69FCE8EF5AB1DDA2994BA4DB111136BD441BC3EFC0251F57DC20A3095B8420669E646E2347EAB7BAF30CACA4BCF74BD88E049378D8DE57DE72E4B8A5FF74B
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ ..........................................................................j..........g.....P....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):4364
              Entropy (8bit):4.238135272432774
              Encrypted:false
              SSDEEP:
              MD5:E08D62D3DC69660DDC31B9444DA6787A
              SHA1:D7537ED5DBE967ABCABA6880DEF2335662F6F708
              SHA-256:F1F8720E6DDF0880B6C25FE7C4FC79B6552F234F47C8DC3004868A1CED331C23
              SHA-512:DC2424DFA2F6A868E25A569A06BE07036B31E536AF042B848D0E5E176770629645A4730B8065249A385EB3BCA3E94EEB7387477AB9CB585915B7629675D419C4
              Malicious:false
              Reputation:low
              Preview:{.. "checksum": "45c5e75d52aad358849be76b67352156",.. "roots": {.. "bookmark_bar": {.. "children": [ {.. "date_added": "13341058798227977",.. "date_last_used": "0",.. "guid": "0cf761a5-eee5-4b4b-b2a0-f6a690c3218f",.. "id": "7",.. "name": "Amazon",.. "show_icon": false,.. "source": "import_fre",.. "type": "url",.. "url": "http://www.amazon.com/".. }, {.. "date_added": "13341058798227977",.. "date_last_used": "0",.. "guid": "af554a4d-85e9-43d4-8452-bbdb5ba50ffd",.. "id": "8",.. "name": "Facebook",.. "show_icon": false,.. "source": "import_fre",.. "type": "url",.. "url": "http://www.facebook.com/".. }, {.. "date_added": "13341058798227977",.. "date_last_used": "0",.. "guid": "857ef466-f810-478d-b451-1871aea5363c",.. "i
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):701740
              Entropy (8bit):4.56226577042009
              Encrypted:false
              SSDEEP:
              MD5:03317F3A1C9E80BF99F3918989CF7463
              SHA1:3D5F8FCF378CD7EEEECD0A44A6B1AA234FC2F968
              SHA-256:5134D363A15D368A3F2C2552A927289217AE505190C06B8877B096BA0B38BD99
              SHA-512:875ED886B3F17E6817D7DF0912DD6DBE94C81704C71D1C6560689727EC81170511DBF7DF616468FAA5059E90974920DC8F4B8D10B6A9D70EC57C0B0A991EFBAA
              Malicious:false
              Reputation:low
              Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13351022489939005","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):32768
              Entropy (8bit):0.27642199331413314
              Encrypted:false
              SSDEEP:
              MD5:18BB06F91AB049D816CA1753AE089DAA
              SHA1:3214D64B9228A87CDD71F28716EBC2F58A0F6C66
              SHA-256:9E3908EEC562A3E5CA660A47BB4D918FC881EBF9D40F569D05DA6CD08FD9245E
              SHA-512:14E96CC997A2651D3F9ADA7A6524AC0AFB80B12B4F8615A43658711C1D7EDC2067BEB379D4EC95B0FCD09D3A2EF259A9EE521672F576F5E9520EF1B3092700B4
              Malicious:false
              Reputation:low
              Preview:..-.....C..................k@..p^..>l_..Q=..0.j...-.....C..................k@..p^..>l_..Q=..0.j.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite Write-Ahead Log, version 3007000
              Category:dropped
              Size (bytes):1174232
              Entropy (8bit):2.5207997778458364
              Encrypted:false
              SSDEEP:
              MD5:A0BE3987DE41523F2304B9C76D5F9863
              SHA1:857C103CFE957AD7DC03F258425D8D2A9BBAB101
              SHA-256:63E4648BEA289A1C9CCB61ADBF230DBEBF0670BE7745D490B950A9F7DC288E4B
              SHA-512:0EF6170EB06B89D607AC160BCCB2AC4C24A1A0809E794881E6A142834A013E29A70B279B6C9A1174C761924317D9D2F78A0F711EF8B39C5AB9D4E28881125838
              Malicious:false
              Reputation:low
              Preview:7....-..........^..>l_.....q..$.........^..>l_..X....9I4SQLite format 3......@ ..........................................................................j.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):675
              Entropy (8bit):3.660150736762058
              Encrypted:false
              SSDEEP:
              MD5:B62742F22FF46AE007D6CC27E13107CE
              SHA1:F25C0B86BC1BC9E94B22F4C741746EBC55BE9983
              SHA-256:EC37F809BA9FBAFD6663A4B26C78EDB8232BE62B0331959992BED8AA2DDA2566
              SHA-512:F01CC3B42DFB2A5FD72A2AD0353DB852C1BBEE76FBFCCC6B7894C16C19971A5D0DFEF1D7D796945785C0D97ECCDA400710765510BFFFCB808E6362D4856D4859
              Malicious:false
              Reputation:low
              Preview:A..r.................20_1_1...1.,U.................20_1_1...1?.Q;0................39_config..........6.....n ...1u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=................v..;...............#38_h.......6.Z..W.F......o.......o...........V.e.................%i0................39_config..........6.....n ....12B.l...............2B.l...............2B.l...............2B.l...............2B.l...............
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):317
              Entropy (8bit):5.237412659700385
              Encrypted:false
              SSDEEP:
              MD5:026BE9E2D82F3FD87D5245FB3D87A592
              SHA1:BBA9E8E6957DB968D6D8FE6203E69632F300D62F
              SHA-256:107628DAF00E87DBE9DFC4F1BE411DE6B9D516C36714D1ED631A2FB2D4EEC811
              SHA-512:0C50D3B34F6017C85A7363C180504C96DEE378C8EC30A29CE3AFBE5346DECF39F830856CFB1ADD9B27A65923F40B1D0014252CE0023A4E2798C9DC3EEBE1A073
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:29.972 bb4 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/MANIFEST-000001.2024/01/29-18:21:29.973 bb4 Recovering log #3.2024/01/29-18:21:29.973 bb4 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/000003.log .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):782
              Entropy (8bit):4.049291162962452
              Encrypted:false
              SSDEEP:
              MD5:FDF465758A7489458B387EB41C7D42B0
              SHA1:9509283CF1BD7397790091C5A7580CBA353A1143
              SHA-256:C5A7592A847D101DCB71AEE0A234835548121C647E6D99EF794337823A347703
              SHA-512:9E40B768990B3FAC6960274C5C78F9B86585100DBFE92BC885FC5384937F2922C3ED435B44C42DEAC138E8FB22CD1EED865DBB984CFFDAE8ED0BE96EDADA1698
              Malicious:false
              Reputation:low
              Preview:.h.6.................__global... .t...................__global... .9..b.................33_..........................33_........v.................21_.....vuNX.................21_.....<...................20_.....X...................20_.....W.J+.................19_......qY.................18_.....'}2..................37_.......c..................38_......i...................39_.....Owa..................20_.....4.9..................20_.....B.I..................19_..........................18_.....2.1..................37_..........................38_......=.%.................39_.....p.j..................9_.....JJ...................9_.....|.&R.................__global... ./....................__global... ..T...................__global... ...G..................__global... .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):335
              Entropy (8bit):5.235516573622505
              Encrypted:false
              SSDEEP:
              MD5:D0062EFF2A851C2B6A78BC7811E7C266
              SHA1:E290F67A6EF5F4754D6C8DCC8DD760E4DB682757
              SHA-256:203EB5A2FC4E472122C845399CBE0969443B72401922943124AE7E36CD6B3AD5
              SHA-512:EAB03364D3973EACFEE89CE6BB5A0EFB45B45695C762EBDA1592CEED4B050B733DF8A33E0BC83FE88E1C39249A27CBF035CDF9D186CBBEEBBBA053C4305E5AF9
              Malicious:false
              Reputation:low
              Preview:2024/01/29-18:21:29.956 bb4 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/MANIFEST-000001.2024/01/29-18:21:29.958 bb4 Recovering log #3.2024/01/29-18:21:29.958 bb4 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/000003.log .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):120
              Entropy (8bit):3.32524464792714
              Encrypted:false
              SSDEEP:
              MD5:A397E5983D4A1619E36143B4D804B870
              SHA1:AA135A8CC2469CFD1EF2D7955F027D95BE5DFBD4
              SHA-256:9C70F766D3B84FC2BB298EFA37CC9191F28BEC336329CC11468CFADBC3B137F4
              SHA-512:4159EA654152D2810C95648694DD71957C84EA825FCCA87B36F7E3282A72B30EF741805C610C5FA847CA186E34BDE9C289AAA7B6931C5B257F1D11255CD2A816
              Malicious:false
              Reputation:low
              Preview:C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t.\.E.d.g.e.\.A.p.p.l.i.c.a.t.i.o.n.\.m.s.e.d.g.e...e.x.e.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text, with no line terminators
              Category:modified
              Size (bytes):13
              Entropy (8bit):2.7192945256669794
              Encrypted:false
              SSDEEP:
              MD5:BF16C04B916ACE92DB941EBB1AF3CB18
              SHA1:FA8DAEAE881F91F61EE0EE21BE5156255429AA8A
              SHA-256:7FC23C9028A316EC0AC25B09B5B0D61A1D21E58DFCF84C2A5F5B529129729098
              SHA-512:F0B7DF5517596B38D57C57B5777E008D6229AB5B1841BBE74602C77EEA2252BF644B8650C7642BD466213F62E15CC7AB5A95B28E26D3907260ED1B96A74B65FB
              Malicious:false
              Reputation:low
              Preview:117.0.2045.47
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):58458
              Entropy (8bit):6.10344102847642
              Encrypted:false
              SSDEEP:
              MD5:3F47A8EC3A6E3241F633F4F8B4D1E1BA
              SHA1:555A963F91D2D1BEE9F8E1DC60BFC74AB39974D9
              SHA-256:445699D3D8EFB04F5F6BE942A4B3AE8F8CCD0FD01DAE043BF667AC7B9D64AD1D
              SHA-512:401C18B4AD1A9AB151FEA09ACBE25B1346BF8D51F48D385799E38A94D7F040C5B751A0B13A50AF90D90ACAE417E9CFABE0E7F5E0A97708088A4E7A41DE652CBB
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):58458
              Entropy (8bit):6.10344102847642
              Encrypted:false
              SSDEEP:
              MD5:3F47A8EC3A6E3241F633F4F8B4D1E1BA
              SHA1:555A963F91D2D1BEE9F8E1DC60BFC74AB39974D9
              SHA-256:445699D3D8EFB04F5F6BE942A4B3AE8F8CCD0FD01DAE043BF667AC7B9D64AD1D
              SHA-512:401C18B4AD1A9AB151FEA09ACBE25B1346BF8D51F48D385799E38A94D7F040C5B751A0B13A50AF90D90ACAE417E9CFABE0E7F5E0A97708088A4E7A41DE652CBB
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):58458
              Entropy (8bit):6.10344102847642
              Encrypted:false
              SSDEEP:
              MD5:3F47A8EC3A6E3241F633F4F8B4D1E1BA
              SHA1:555A963F91D2D1BEE9F8E1DC60BFC74AB39974D9
              SHA-256:445699D3D8EFB04F5F6BE942A4B3AE8F8CCD0FD01DAE043BF667AC7B9D64AD1D
              SHA-512:401C18B4AD1A9AB151FEA09ACBE25B1346BF8D51F48D385799E38A94D7F040C5B751A0B13A50AF90D90ACAE417E9CFABE0E7F5E0A97708088A4E7A41DE652CBB
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):58458
              Entropy (8bit):6.10344102847642
              Encrypted:false
              SSDEEP:
              MD5:3F47A8EC3A6E3241F633F4F8B4D1E1BA
              SHA1:555A963F91D2D1BEE9F8E1DC60BFC74AB39974D9
              SHA-256:445699D3D8EFB04F5F6BE942A4B3AE8F8CCD0FD01DAE043BF667AC7B9D64AD1D
              SHA-512:401C18B4AD1A9AB151FEA09ACBE25B1346BF8D51F48D385799E38A94D7F040C5B751A0B13A50AF90D90ACAE417E9CFABE0E7F5E0A97708088A4E7A41DE652CBB
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):58458
              Entropy (8bit):6.10344102847642
              Encrypted:false
              SSDEEP:
              MD5:3F47A8EC3A6E3241F633F4F8B4D1E1BA
              SHA1:555A963F91D2D1BEE9F8E1DC60BFC74AB39974D9
              SHA-256:445699D3D8EFB04F5F6BE942A4B3AE8F8CCD0FD01DAE043BF667AC7B9D64AD1D
              SHA-512:401C18B4AD1A9AB151FEA09ACBE25B1346BF8D51F48D385799E38A94D7F040C5B751A0B13A50AF90D90ACAE417E9CFABE0E7F5E0A97708088A4E7A41DE652CBB
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):58458
              Entropy (8bit):6.10344102847642
              Encrypted:false
              SSDEEP:
              MD5:3F47A8EC3A6E3241F633F4F8B4D1E1BA
              SHA1:555A963F91D2D1BEE9F8E1DC60BFC74AB39974D9
              SHA-256:445699D3D8EFB04F5F6BE942A4B3AE8F8CCD0FD01DAE043BF667AC7B9D64AD1D
              SHA-512:401C18B4AD1A9AB151FEA09ACBE25B1346BF8D51F48D385799E38A94D7F040C5B751A0B13A50AF90D90ACAE417E9CFABE0E7F5E0A97708088A4E7A41DE652CBB
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):58458
              Entropy (8bit):6.10344102847642
              Encrypted:false
              SSDEEP:
              MD5:3F47A8EC3A6E3241F633F4F8B4D1E1BA
              SHA1:555A963F91D2D1BEE9F8E1DC60BFC74AB39974D9
              SHA-256:445699D3D8EFB04F5F6BE942A4B3AE8F8CCD0FD01DAE043BF667AC7B9D64AD1D
              SHA-512:401C18B4AD1A9AB151FEA09ACBE25B1346BF8D51F48D385799E38A94D7F040C5B751A0B13A50AF90D90ACAE417E9CFABE0E7F5E0A97708088A4E7A41DE652CBB
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):58458
              Entropy (8bit):6.10344102847642
              Encrypted:false
              SSDEEP:
              MD5:3F47A8EC3A6E3241F633F4F8B4D1E1BA
              SHA1:555A963F91D2D1BEE9F8E1DC60BFC74AB39974D9
              SHA-256:445699D3D8EFB04F5F6BE942A4B3AE8F8CCD0FD01DAE043BF667AC7B9D64AD1D
              SHA-512:401C18B4AD1A9AB151FEA09ACBE25B1346BF8D51F48D385799E38A94D7F040C5B751A0B13A50AF90D90ACAE417E9CFABE0E7F5E0A97708088A4E7A41DE652CBB
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 6, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 6
              Category:dropped
              Size (bytes):20480
              Entropy (8bit):0.6111597644407213
              Encrypted:false
              SSDEEP:
              MD5:1B30AF3C48C2AABF031B1C94AED4240C
              SHA1:7A045239947E06996A05E91640A22C3CABFB3EFB
              SHA-256:3ED5CEE21B6C34189F3A5316718FD5407A8B626BD6FD8CD5CA4288B733B209E9
              SHA-512:C125F94C34724006009BD84E0B6D79666913F0372469D8C0AA741575C8A2133350171CB24F63D489BFA799DBF1B76A1CFC3DDC6498EEDBFE2AC48C01C740ECA6
              Malicious:false
              Reputation:low
              Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text, with no line terminators
              Category:dropped
              Size (bytes):47
              Entropy (8bit):4.3818353308528755
              Encrypted:false
              SSDEEP:
              MD5:48324111147DECC23AC222A361873FC5
              SHA1:0DF8B2267ABBDBD11C422D23338262E3131A4223
              SHA-256:D8D672F953E823063955BD9981532FC3453800C2E74C0CC3653D091088ABD3B3
              SHA-512:E3B5DB7BA5E4E3DE3741F53D91B6B61D6EB9ECC8F4C07B6AE1C2293517F331B716114BAB41D7935888A266F7EBDA6FABA90023EFFEC850A929986053853F1E02
              Malicious:false
              Reputation:low
              Preview:customSettings_F95BA787499AB4FA9EFFF472CE383A14
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):35
              Entropy (8bit):4.014438730983427
              Encrypted:false
              SSDEEP:
              MD5:BB57A76019EADEDC27F04EB2FB1F1841
              SHA1:8B41A1B995D45B7A74A365B6B1F1F21F72F86760
              SHA-256:2BAE8302F9BD2D87AE26ACF692663DF1639B8E2068157451DA4773BD8BD30A2B
              SHA-512:A455D7F8E0BE9A27CFB7BE8FE0B0E722B35B4C8F206CAD99064473F15700023D5995CC2C4FAFDB8FBB50F0BAB3EC8B241E9A512C0766AAAE1A86C3472C589FFD
              Malicious:false
              Reputation:low
              Preview:{"forceServiceDetermination":false}
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text, with no line terminators
              Category:dropped
              Size (bytes):81
              Entropy (8bit):4.3439888556902035
              Encrypted:false
              SSDEEP:
              MD5:177F4D75F4FEE84EF08C507C3476C0D2
              SHA1:08E17AEB4D4066AC034207420F1F73DD8BE3FAA0
              SHA-256:21EE7A30C2409E0041CDA6C04EEE72688EB92FE995DC94487FF93AD32BD8F849
              SHA-512:94FC142B3CC4844BF2C0A72BCE57363C554356C799F6E581AA3012E48375F02ABD820076A8C2902A3C6BE6AC4D8FA8D4F010D4FF261327E878AF5E5EE31038FB
              Malicious:false
              Reputation:low
              Preview:edgeSettings_2.0-48b11410dc937a1723bf4c5ad33ecdb286d8ec69544241bc373f753e64b396c1
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):130439
              Entropy (8bit):3.80180718117079
              Encrypted:false
              SSDEEP:
              MD5:EB75CEFFE37E6DF9C171EE8380439EDA
              SHA1:F00119BA869133D64E4F7F0181161BD47968FA23
              SHA-256:48B11410DC937A1723BF4C5AD33ECDB286D8EC69544241BC373F753E64B396C1
              SHA-512:044C5113D877CE2E3B42CF07670620937ED7BE2D8B3BF2BAB085C43EF4F64598A7AC56328DDBBE7F0F3CFB9EA49D38CA332BB4ECBFEDBE24AE53B14334A30C8E
              Malicious:false
              Reputation:low
              Preview:{.. "geoidMaps": {.. "au": "https://australia.smartscreen.microsoft.com/",.. "ch": "https://switzerland.smartscreen.microsoft.com/",.. "eu": "https://europe.smartscreen.microsoft.com/",.. "ffl4": "https://unitedstates1.ss.wd.microsoft.us/",.. "ffl4mod": "https://unitedstates4.ss.wd.microsoft.us/",.. "ffl5": "https://unitedstates2.ss.wd.microsoft.us/",.. "in": "https://india.smartscreen.microsoft.com/",.. "test": "https://eu-9.smartscreen.microsoft.com/",.. "uk": "https://unitedkingdom.smartscreen.microsoft.com/",.. "us": "https://unitedstates.smartscreen.microsoft.com/",.. "gw_au": "https://australia.smartscreen.microsoft.com/",.. "gw_ch": "https://switzerland.smartscreen.microsoft.com/",.. "gw_eu": "https://europe.smartscreen.microsoft.com/",.. "gw_ffl4": "https://unitedstates1.ss.wd.microsoft.us/",.. "gw_ffl4mod": "https://unitedstates4.ss.wd.microsoft.us/",.. "gw_ffl5": "https://unitedstates2.ss.wd.microsoft.us/",.. "gw_in": "https
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text, with no line terminators
              Category:dropped
              Size (bytes):40
              Entropy (8bit):4.346439344671015
              Encrypted:false
              SSDEEP:
              MD5:6A3A60A3F78299444AACAA89710A64B6
              SHA1:2A052BF5CF54F980475085EEF459D94C3CE5EF55
              SHA-256:61597278D681774EFD8EB92F5836EB6362975A74CEF807CE548E50A7EC38E11F
              SHA-512:C5D0419869A43D712B29A5A11DC590690B5876D1D95C1F1380C2F773CA0CB07B173474EE16FE66A6AF633B04CC84E58924A62F00DCC171B2656D554864BF57A4
              Malicious:false
              Reputation:low
              Preview:synchronousLookupUris_638343870221005468
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):57
              Entropy (8bit):4.556488479039065
              Encrypted:false
              SSDEEP:
              MD5:3A05EAEA94307F8C57BAC69C3DF64E59
              SHA1:9B852B902B72B9D5F7B9158E306E1A2C5F6112C8
              SHA-256:A8EF112DF7DAD4B09AAA48C3E53272A2EEC139E86590FD80E2B7CBD23D14C09E
              SHA-512:6080AEF2339031FAFDCFB00D3179285E09B707A846FD2EA03921467DF5930B3F9C629D37400D625A8571B900BC46021047770BAC238F6BAC544B48FB3D522FB0
              Malicious:false
              Reputation:low
              Preview:9.......murmur3.............,M.h...Z...8.\..<&Li.H..[.?m
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text, with no line terminators
              Category:dropped
              Size (bytes):29
              Entropy (8bit):4.030394788231021
              Encrypted:false
              SSDEEP:
              MD5:52E2839549E67CE774547C9F07740500
              SHA1:B172E16D7756483DF0CA0A8D4F7640DD5D557201
              SHA-256:F81B7B9CE24F5A2B94182E817037B5F1089DC764BC7E55A9B0A6227A7E121F32
              SHA-512:D80E7351E4D83463255C002D3FDCE7E5274177C24C4C728D7B7932D0BE3EBCFEB68E1E65697ED5E162E1B423BB8CDFA0864981C4B466D6AD8B5E724D84B4203B
              Malicious:false
              Reputation:low
              Preview:topTraffic_638004170464094982
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):575056
              Entropy (8bit):7.999649474060713
              Encrypted:true
              SSDEEP:
              MD5:BE5D1A12C1644421F877787F8E76642D
              SHA1:06C46A95B4BD5E145E015FA7E358A2D1AC52C809
              SHA-256:C1CE928FBEF4EF5A4207ABAFD9AB6382CC29D11DDECC215314B0522749EF6A5A
              SHA-512:FD5B100E2F192164B77F4140ADF6DE0322F34D7B6F0CF14AED91BACAB18BB8F195F161F7CF8FB10651122A598CE474AC4DC39EDF47B6A85C90C854C2A3170960
              Malicious:false
              Reputation:low
              Preview:...._+jE.`..}....S..1....G}s..E....y".Wh.^.W.H...-...#.A...KR...9b........>k......bU.IVo...D......Y..[l.yx.......'c=..I0.....E.d...-...1 ....m../C...OQ.........qW..<:N.....38.u..X-..s....<..U.,Mi..._.......`.Y/.........^..,.E..........j@..G8..N.... ..Ea...4.+.79k.!T.-5W..!..@+..!.P..LDG.....V."....L.... .(#..$..&......C.....%A.T}....K_.S..'Q.".d....s....(j.D!......Ov..)*d0)."(..%..-..G..L.}....i.....m9;.....t.w..0....f?..-..M.c.3.....N7K.T..D>.3.x...z..u$5!..4..T.....U.O^L{.5..=E..'..;.}(|.6.:..f!.>...?M.8......P.D.J.I4.<...*.y.E....>....i%.6..Y.@..n.....M..r..C.f.;..<..0.H...F....h.......HB1]1....u..:...H..k....B.Q..J...@}j~.#...'Y.J~....I...ub.&..L[z..1.W/.Ck....M.......[.......N.F..z*.{nZ~d.V.4.u.K.V.......X.<p..cz..>*....X...W..da3(..g..Z$.L4.j=~.p.l.\.[e.&&.Y ...U)..._.^r0.,.{_......`S..[....(.\..p.bt.g..%.$+....f.....d....Im..f...W ......G..i_8a..ae..7....pS.....z-H..A.s.4.3..O.r.....u.S......a.}..v.-/..... ...a.x#./:...sS&U.().xL...pg
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:raw G3 (Group 3) FAX, byte-padded
              Category:dropped
              Size (bytes):460992
              Entropy (8bit):7.999625908035124
              Encrypted:true
              SSDEEP:
              MD5:E9C502DB957CDB977E7F5745B34C32E6
              SHA1:DBD72B0D3F46FA35A9FE2527C25271AEC08E3933
              SHA-256:5A6B49358772DB0B5C682575F02E8630083568542B984D6D00727740506569D4
              SHA-512:B846E682427CF144A440619258F5AA5C94CAEE7612127A60E4BD3C712F8FF614DA232D9A488E27FC2B0D53FD6ACF05409958AEA3B21EA2C1127821BD8E87A5CA
              Malicious:false
              Reputation:low
              Preview:...2lI.5.<C.;.{....._+jE.`..}....-...#.A...KR...l.M0,s...).9..........x.......F.b......jU....y.h'....L<...*..Z..*%.*..._...g.4yu...........'c=..I0..........qW..<:N....<..U.,Mi..._......'(..U.9.!........u....7...4. ..Ea...4.+.79k.!T.-5W..!..@+..$..t|1.E..7F...+..xf....z&_Q...-.B...)8R.c....0.......B.M.Z...0....&v..<..H...3.....N7K.T..D>.8......P.D.J.I4.B.H.VHy...@.Wc.Cl..6aD..j.....E..*4..mI..X]2.GH.G.L...E.F.=.J...@}j~.#...'Y.L[z..1.W/.Ck....L..X........J.NYd........>...N.F..z*.{nZ~d.N..../..6.\L...Q...+.w..p...>.S.iG...0]..8....S..)`B#.v..^.*.T.?...Z.rz.D'.!.T.w....S..8....V.4.u.K.V.......W.6s...Y.).[.c.X.S..........5.X7F...tQ....z.L.X..(3#j...8...i.[..j$.Q....0...]"W.c.H..n..2Te.ak...c..-F(..W2.b....3.]......c.d|.../....._...f.....d....Im..g.b..R.q.<x*x...i2..r.I()Iat..b.j.r@K.+5..C.....nJ.>*P,.V@.....s.4.3..O.r.....smd7...L.....].u&1../t.*.......uXb...=@.....wv......]....#.{$.w......i.....|.....?....E7...}$+..t).E.U..Q..~.`.)..Y@.6.h.......%(
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text, with no line terminators
              Category:dropped
              Size (bytes):9
              Entropy (8bit):3.169925001442312
              Encrypted:false
              SSDEEP:
              MD5:B6F7A6B03164D4BF8E3531A5CF721D30
              SHA1:A2134120D4712C7C629CDCEEF9DE6D6E48CA13FA
              SHA-256:3D6F3F8F1456D7CE78DD9DFA8187318B38E731A658E513F561EE178766E74D39
              SHA-512:4B473F45A5D45D420483EA1D9E93047794884F26781BBFE5370A554D260E80AD462E7EEB74D16025774935C3A80CBB2FD1293941EE3D7B64045B791B365F2B63
              Malicious:false
              Reputation:low
              Preview:uriCache_
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):180
              Entropy (8bit):4.982445779335154
              Encrypted:false
              SSDEEP:
              MD5:0DBEF560BF8F66E1A9F4ED2294CAD8B7
              SHA1:56136766C3930DAA040A8571C5579FD49135401D
              SHA-256:B7AF8B15088EDC2C7593B91343ECE76DCD723A8A6EB5709777ED438AFFB90AF3
              SHA-512:A97DC8A71563CB4E706AEBD69F3D82BF9D9A55563863FF6FBFF3AD83A2AAC288C7CE7094174D627C57D87B9F53B697EAB4E290F3DA09797B8FB066ED5CCCCCD2
              Malicious:false
              Reputation:low
              Preview:{"version":1,"cache_data":[{"file_hash":"d029e048c7fd482d","server_context":"1;c5faad59-a2e3-31f2-b86e-aaf958e12824;phsh:005;7e-05","result":0,"expiration_time":1706649806467517}]}
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):86
              Entropy (8bit):4.3751917412896075
              Encrypted:false
              SSDEEP:
              MD5:16B7586B9EBA5296EA04B791FC3D675E
              SHA1:8890767DD7EB4D1BEAB829324BA8B9599051F0B0
              SHA-256:474D668707F1CB929FEF1E3798B71B632E50675BD1A9DCEAAB90C9587F72F680
              SHA-512:58668D0C28B63548A1F13D2C2DFA19BCC14C0B7406833AD8E72DFC07F46D8DF6DED46265D74A042D07FBC88F78A59CB32389EF384EC78A55976DFC2737868771
              Malicious:false
              Reputation:low
              Preview:{"user_experience_metrics.stability.exited_cleanly":false,"variations_crash_streak":2}
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):64601
              Entropy (8bit):6.104716923366231
              Encrypted:false
              SSDEEP:
              MD5:4267DEA4FF6141C11EC6D1B5D2207CBC
              SHA1:198B460C94BA1B0B566706F0504F9762E5028F8F
              SHA-256:7AF249FE251D01A7EB85F53F5E96916183A487047E83AC28927E0C8351866A74
              SHA-512:2DB7E1E331DB7D24A30CBC6A25D244A9FBBC8286D933D614B40344C0D8A982D3A57D9E2BA22A941AEB0416B59D469484A59BD42D9AE6A231CB01CBA94FBEA83A
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"1B94E5024015A307769363A60E0D5B42FA1F9C3BB6A108D492D64D1251C4F3D1\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"desktop_session_duration_tracker":{"last_session_end_timestamp":"0"},"domain_actions_config":"H4sIAAAAAAAAAL1dW5PctrH+K6p9SlIerHZ1s5wnH1mOXSeyXY5Srjqp1BYIYkgsQYDCZWY4Kf/30w3O3jQEZpryOQ9xVhw2bmx0f93obvzngm+uboStpbhZSx6ikzeilaK7sRvpnKrlxTf/ueDDoJXgQVnjL7751+GBrG8GC8/Hi28ufh7CzzFcfHVR254rA0+MDGutdkzY/uL3rygkPsRaWT9R/vuri0Sh5NSz4b18TBzGAf/97ebqHU7i+2kO73AKh3ewCZiLh8FffHP1+1cXou6pszN6fL8brJe/aD7+Knk9Ph6318o0hYneU/8GPW6UkY+Jg40sbJZQ9nwHf0sGs1hAzSuxeMgbhhRyKb3mb5gKSyh3a2VUGJd2vOVBtDB6YUt8WWxCNTAACW042wBTLW2m0lGK6DbYkm/5lgm+pJlW4hbbwC82OGuWjkY4mJMD/hctN0bqpe2YwEOLLLn0+9jt4KSXJvhBx8WLu2l3C7dUG3Vc2iu8zj5FJ
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:modified
              Size (bytes):64531
              Entropy (8bit):6.104830948158959
              Encrypted:false
              SSDEEP:
              MD5:5D28F0611D5EA885AF416F9CB8555DBE
              SHA1:DF6E6336960799EBDB1FD0A57907624B9E56DB9C
              SHA-256:1BBD50E2DA1A20D8EFF85920487BECDA9DEBB84C3B4E5B9DB413CBB2BF61D068
              SHA-512:B2DE072739D920FB3545868982D32EC89D2EA3276AD7078A85FA8E4775D11FC63149F98F0B5595E19C61A9F4E7BFFFD0F64CBE95E5D85B36AB543F2E41850C03
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"1B94E5024015A307769363A60E0D5B42FA1F9C3BB6A108D492D64D1251C4F3D1\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"desktop_session_duration_tracker":{"last_session_end_timestamp":"1706548905"},"domain_actions_config":"H4sIAAAAAAAAAL1dW5PctrH+K6p9SlIerHZ1s5wnH1mOXSeyXY5Srjqp1BYIYkgsQYDCZWY4Kf/30w3O3jQEZpryOQ9xVhw2bmx0f93obvzngm+uboStpbhZSx6ikzeilaK7sRvpnKrlxTf/ueDDoJXgQVnjL7751+GBrG8GC8/Hi28ufh7CzzFcfHVR254rA0+MDGutdkzY/uL3rygkPsRaWT9R/vuri0Sh5NSz4b18TBzGAf/97ebqHU7i+2kO73AKh3ewCZiLh8FffHP1+1cXou6pszN6fL8brJe/aD7+Knk9Ph6318o0hYneU/8GPW6UkY+Jg40sbJZQ9nwHf0sGs1hAzSuxeMgbhhRyKb3mb5gKSyh3a2VUGJd2vOVBtDB6YUt8WWxCNTAACW042wBTLW2m0lGK6DbYkm/5lgm+pJlW4hbbwC82OGuWjkY4mJMD/hctN0bqpe2YwEOLLLn0+9jt4KSXJvhBx8WLu2l3C7dUG3Vc
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):64435
              Entropy (8bit):6.104792893085664
              Encrypted:false
              SSDEEP:
              MD5:DF90309044227C71FF0EB101FC3C7A7B
              SHA1:34D7B4CACCC1B8E1ECD05482935D2CE0A30677DC
              SHA-256:EA55D8FDC87D7C30D570BBC56BD88CD5D70319563417390FDD8AD803769515F7
              SHA-512:B6BE797213D1CF144D8E42976F484D75509233D2E68803D5CCE6E4884614877EBBF8B4A8A50CCD5FB1D4EA6DDB17F5787191041B327798BCF13FD8E589D76056
              Malicious:false
              Reputation:low
              Preview:{"abusive_adblocker_etag":"\"1B94E5024015A307769363A60E0D5B42FA1F9C3BB6A108D492D64D1251C4F3D1\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"desktop_session_duration_tracker":{"last_session_end_timestamp":"1706548905"},"domain_actions_config":"H4sIAAAAAAAAAL1dW5PctrH+K6p9SlIerHZ1s5wnH1mOXSeyXY5Srjqp1BYIYkgsQYDCZWY4Kf/30w3O3jQEZpryOQ9xVhw2bmx0f93obvzngm+uboStpbhZSx6ikzeilaK7sRvpnKrlxTf/ueDDoJXgQVnjL7751+GBrG8GC8/Hi28ufh7CzzFcfHVR254rA0+MDGutdkzY/uL3rygkPsRaWT9R/vuri0Sh5NSz4b18TBzGAf/97ebqHU7i+2kO73AKh3ewCZiLh8FffHP1+1cXou6pszN6fL8brJe/aD7+Knk9Ph6318o0hYneU/8GPW6UkY+Jg40sbJZQ9nwHf0sGs1hAzSuxeMgbhhRyKb3mb5gKSyh3a2VUGJd2vOVBtDB6YUt8WWxCNTAACW042wBTLW2m0lGK6DbYkm/5lgm+pJlW4hbbwC82OGuWjkY4mJMD/hctN0bqpe2YwEOLLLn0+9jt4KSXJvhBx8WLu2l3C7dUG3Vc
              Process:C:\Program Files\Internet Explorer\iexplore.exe
              File Type:Composite Document File V2 Document, Cannot read section info
              Category:dropped
              Size (bytes):4608
              Entropy (8bit):2.0370914145997947
              Encrypted:false
              SSDEEP:
              MD5:6CA07EB68E1F396E4BA6E58ACDB28D71
              SHA1:7A33A38BC6EA1883670C836A863CA80C9E1C03FB
              SHA-256:225CF8E595892AD5865C9430D3A9B85C8180DA70DA5BBE23B8D3B62B26E6417B
              SHA-512:F3DF8EFACD503FAAE9F91CDE731AD726FFA08C880CF5846ADC09E6D7A42352CD1901138932279D579A947B3EB69079D1BCF06A934908C3B5F06257E3D15DCF3D
              Malicious:false
              Reputation:low
              Preview:......................>.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y.........................................................................................`.N..R................K.j.j.a.q.f.a.j.N.2.c.0.u.z.g.v.1.l.4.q.y.5.n.f.W.e...........8...............................................................F.r.a.m.e.L.i.s.t.......................................................................................................0.......O._.T.S.u.o.H.8.1.M.q.+.7.h.G.M.L.O.z.0.u.#.8.l.i.g.=.=.........:.......................................
              Process:C:\Program Files\Internet Explorer\iexplore.exe
              File Type:Composite Document File V2 Document, Cannot read section info
              Category:dropped
              Size (bytes):4608
              Entropy (8bit):1.8924355718489212
              Encrypted:false
              SSDEEP:
              MD5:3ABF5049B58695F61113E5DAD0211F8B
              SHA1:071F0C34408BD5B55AB3C42D0AD01C17A85F22CE
              SHA-256:BA5BCDD5072C9F77970D99F45ABF2F267F40C5BA4E1E9E3DE6F5CB94C3994E75
              SHA-512:A06E3C5A54CCA050D52BDCCC830652BD65F8440B35B74E5B9332CF50813940000531D9B8B93209482DD05459CC09230A383AE5B7C6C4B7D68C6D1CCC7F486C92
              Malicious:false
              Reputation:low
              Preview:......................>.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y......................................................................................... ....R................K.j.j.a.q.f.a.j.N.2.c.0.u.z.g.v.1.l.4.q.y.5.n.f.W.e...........8.......................................................@.......T.r.a.v.e.l.L.o.g.......................................................................................................................................................................................................................
              Process:C:\Program Files\Internet Explorer\iexplore.exe
              File Type:Composite Document File V2 Document, Cannot read section info
              Category:dropped
              Size (bytes):3584
              Entropy (8bit):1.5646520463610019
              Encrypted:false
              SSDEEP:
              MD5:D8B7DC1CD92B80ECB81FC8B53BD69206
              SHA1:27577E4C36E6256480F86D39364E572DCB0673F8
              SHA-256:603275693D088D20F036F0415F38CE9BB1A78037F48712C5476362F64119D981
              SHA-512:3347BBB902A6BAECBBAAFB5E2815748DA4C42C329317BDA519E397FC4035E4C45F56943F2D6723EA4A67830E01829D8D7341A234E4AB4F3EEBE851582EF1B7DA
              Malicious:false
              Reputation:low
              Preview:......................>.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y..........................................................................................x...R................K.j.j.a.q.f.a.j.N.2.c.0.u.z.g.v.1.l.4.q.y.5.n.f.W.e...........8.......................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):2278
              Entropy (8bit):3.839882838019488
              Encrypted:false
              SSDEEP:
              MD5:840E9EF14F273C11BB094B8FF0BEDDBD
              SHA1:5C5A00037892C72415289725393B9557B13974EF
              SHA-256:074178575068708CF42B75594269583308B7441F035044828BDE56CACFB1B783
              SHA-512:FFB24E73A0047DB4722689CB0555C7C6340C4D2478C97E2726C8F1F0F9D82101D5807B488A30C043841AD627D689949DB52B05CF4B5F7C34F5A81CBBFB689EBF
              Malicious:false
              Reputation:low
              Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".W.i.p.w.W.M.+.N.H.l.b.C.D.m.s.Z.p.8.S.O.s.j.h.t.F.B.s.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".g.A.d.p.+.9.9.S.2.g.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.v.H.7.E.X.S.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:data
              Category:dropped
              Size (bytes):4622
              Entropy (8bit):4.004828240268555
              Encrypted:false
              SSDEEP:
              MD5:069C807F21520EFAB9FC623F0A7CC050
              SHA1:85A8E678F64670A2B254031E5D96E15487DEFF95
              SHA-256:942F95D6F25F76E1C7695BF81D513FB8CFD57AC32041599BC124B8441D85B0B4
              SHA-512:CCBB8A3ADE90F833ECA491FB888DC1E52D338E2B70A54E636D2E055D89C760562D4C63099BEFA76E76E9773EA388B2E42AEAADB180F81B8815F3A3A1B516579D
              Malicious:false
              Reputation:low
              Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".z.3.U.T.q.T.b.3.7./.u.z.h.i.f.l.b.4.0.f.z.h.D.r.E.s.w.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".i.C.r.H.4.d.d.S.2.g.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.w.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.v.H.7.E.X.S.
              Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):17524
              Entropy (8bit):4.340063035506032
              Encrypted:false
              SSDEEP:
              MD5:03710426AB25AD1280E197F61249F9DE
              SHA1:F5E7A6FD42503AE4758BC36C8DD78D98EFB35047
              SHA-256:21E63F7C77896ED2B5F115957F2448E0A9E2DD738D7D487E471217421F6A93E1
              SHA-512:213CB55B8573335D1384AE704FF4267F224376056F71548660F9B2FDAA1203D8ABDDB787900AAF5D1E0AC6E5BE261F713BDBEFB67643D08E8D3672512A1AF588
              Malicious:false
              Reputation:low
              Preview:(function()..{.. var XHTML = "http://www.w3.org/1999/xhtml";.. .. // Time slicing constants.. var LIMIT = 10; // Maximum number of nodes to process before checking time.. var DURATION = 200; // Maximum amount of time (ms) to process before unblocking UI.. var DELAY = 15; // Amount of time (ms) to unblock UI.... // Tree building state.. var iterator;.. var nextNode;.. var root;.. var rootFirstChild;.. var time;.. .. // Template References.. var attrTemplate, attrName, attrValue;.. var elmStartTemplate, elmStartName;.. var elmEndTemplate, elmEndName;.. var cdataTemplate, cdataValue;.. var commentTemplate, commentValue;.. var style; .. .. // Only invoke this script if it was injected by our parser. Test for a condition that is.. // impossible for a markup to create - two direct children of the document... var secondRootElement = document.documentElement.nextElementSibling;.. if (secondRootElement == null
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 135363
              Category:dropped
              Size (bytes):76326
              Entropy (8bit):7.9961120748813075
              Encrypted:true
              SSDEEP:
              MD5:01E352D35675990A139199DD86B38AAC
              SHA1:E16163C81E5F36B3B819AA0A63BFA63D88548A91
              SHA-256:148CDE42D38C62C1A1E8B8D3D4BD8830F0F8C2DC684E3C59B0A510E31011CA4A
              SHA-512:75A58FFAD6E3E0546268CC863AE382B5429795D8BCED64BAE2D06BCEEB6C2E37BD656A3E335EB61B521888B76913F2D0281F8C9C081FF8637307AE5934D98C8B
              Malicious:false
              Reputation:low
              Preview:...........m{..(.}...7.\...N.D*.w..m..q....%XfL.*I.ql..;/.....s...E...0....`..A..[o^.^Y...F_.'.*.."L...^.......Y..W..l...E0..YY...:.&.u?....J..U<.q."...p.ib:.g.*.^.q.mr.....^&.{.E.....,EAp.q.......=.=.....z^.,d.^..J.R..zI4..2b?.-D5/.^...+.G..Y..?5..k........i.,.T#........_DV....P..d2......b\..L....o....Z.}../....CU.$.-..D9`..~......=....._.2O..?....b.{...7IY.L..q....K....T..5m.d.s.4.^... ..~<..7~6OS..b...^>.......s..n....k."..G.....L...z.U...... ... .ZY...,...kU1..N...(..V.r\$..s...X.It...x.mr..W....g........9DQR....*d......;L.S.....G... .._D.{.=.zI.g.Y~...`T..p.yO..4......8$..v.J..I.%..._.d.[..du5._._...?\..8.c.....U...fy.t....q.t....T@.......:zu..\,.!.I..AN_.....FeX..h.c.i.W.......(.....Y..F...R%.\..@.. 2(e,&.76..F+...l.t.$..`...........Wi.{.U.&(.b}...}.i..,...k....!..%...&.c..D-."..SQ.......q9....)j....7.".N....AX...).d./giR....uk.....s.....^...........:...~......(hP..K.@.&..?.E0:+D|9...U.q.cu..)t{.e...X...{.....z......LL&I6.=.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 208336
              Category:dropped
              Size (bytes):261072
              Entropy (8bit):7.982092603864871
              Encrypted:false
              SSDEEP:
              MD5:657714D7C0607407E976DA323FC0E8A3
              SHA1:218DE448C90990A26FC41F0206AD452A577DBE55
              SHA-256:B1C7045B24653AC8E4C10B01BA43D5C5A4FA390CB37E7B2F9A6EA3A4FF495760
              SHA-512:28904D9E9764289A14DA9790B42D3A1E4CE424DD9BC76DD3EBA764135E2B6841384A7124CC54727FD875F1FF30E9BB87BD4F972E7182BCD0752223AA4FBDC8B8
              Malicious:false
              Reputation:low
              Preview:...........i{..(........V."..4.+..X.,)..dB3..........5".o....4.R.Ir..<.El..T....[..j.....C.&...(..R?.k...@T.y.........z...~8.....~0...$......s...dbw..f...x.d..:.a........!.e....y.f.`....j?..Z....".....B...-....].7..v.q...Z..4.B.Y..~..p....t.c..P......c.......<.Dn.n.r.&<...f...D.%.......p...>.<..`..b.x8...v.c.q4.%F.T..wL.....Q.d.GA.%.8I..wT_...p2..R(.:?..yt.c......u...tR...z..Cnom..[w.Y..Ev.>...h.o...Z..1U.QO..?...&.[N}:..m.h..M....(..P..|...c.!..H.......Q%,...D~hC[.e-.>..`...-..g..I;E.Ia...!.D...8.b......n-....U.Z....-.%...(N..^.....p0.4.Y..,.n...k>.az:z....7.C..v.i..lE..@.....q}..:v.........q..@..!|Po....."....y.^;.h...Dl...r.a..M..'ry....Y......`.6.}9..|tV..0..>.....:..`X;:.9.8/...6...'W'..A0.qX..a0....!F6......$.....B1...UK&.,..ny-....[........&`A. ...#Z.......\..N.^wlO.6.9...X.^}..)...Y.k6-...Q=..]:q ....;..y...>....=....)....N.i.Ih>..Q....h..kF..`H_.Z..[...........)..8...B..a.....M..d.\]]\.5>..4ca.......?..X,.c&Jp....Bj/...m..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:PNG image data, 342 x 126, 8-bit colormap, non-interlaced
              Category:dropped
              Size (bytes):17801
              Entropy (8bit):7.964191646854066
              Encrypted:false
              SSDEEP:
              MD5:482B0C33083455554CFA37F10AF0B033
              SHA1:E7C383EF495151FB2E8B3BB27194C566FD55EADC
              SHA-256:665C5C1869B7B6C9C69D71CB701BFE61971922E1767223562F23130F458E00B8
              SHA-512:C7EB77939C12BCBADE6F2BED8379DCE192BA9A7A73EAF3D164FB740EAE1145A50EFDE4A2EF422533E5340A110AE7C7EEC5A5A9BA0EA50988941FBAA1AA5BE10E
              Malicious:false
              Reputation:low
              Preview:.PNG........IHDR...V...~.....H..^....PLTE....ZB.|S.........E.TE.E.TF........(L{.......E.+Fm.......................WL..................UI....Jh......\O...~.L<.OE.........[.k..o.\..f.V....eY.{...u.j......~.......\.bR^......{.`.T.b..r._T.ob.L;.V..w.y..N..z.}j..r._........WK.......{n.n..F...n.sb.lY.h..........b...........{...o.d.a.N3.....n....l....O..U..j..y....S.w.....y.?&..m..R..........s.n..{..^..V...y.-....D..........D...:f..S....Y..b..[{."h..S.....g.T..dx..x.;^.qR....Fs.!L.r...'....oo..0......i.0K......fF...o..0%.}..D....Wi..D.2,.CZ.s?p.2.Ud.c....4..@.b-.:~..#. .......K..y.dy..<:.%9...:Y.J'.$Eo.....>]..}Y.>.6<X>6.bW.d4.......cxTA......dI.OA..S-K.....tRNS... .vvv....p..l.....IDATx...;..0..a...[w..=;.`!>..X..FW...?..)tY..2......*d.*..&N.K.N.v....T..n.]U$.V+L.X.Fq..kV..fq'.X!...!}~..|...P0.........Y+feVf=....0...n.R."E(..H
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1366x720, components 3
              Category:dropped
              Size (bytes):278989
              Entropy (8bit):7.902681019173286
              Encrypted:false
              SSDEEP:
              MD5:206D7FDD205702CD52FEF631A2C9987E
              SHA1:680B3C5B21E45B4DF7A62888ED4A4E086ACC7B2B
              SHA-256:54D5D2EF589DA2F84427F31C5103127211E65886FA5B45FB308378F9EE7E1D5A
              SHA-512:F2CD6376AF37EB1815D73DB23AEE34D91D1B754E43A156468EAE8B625952DDFFE1A52068BFF5B821C9B51E79CBF52159BD7917C61E7F577B9650078AC808AEC7
              Malicious:false
              Reputation:low
              Preview:......Exif..II*.................Ducky.......2......Adobe.d...........................................................#"""#''''''''''..................................................!! !!''''''''''........V.."....................................................................................!1..AQ..aq."2....R..T....Br.#S.U..b..3Cs...t6.c.$D.5uV...4d.E&....%F......................!1..AQaq....."2......BRbr3CS....#..4.............?......1f.n..T......TP....E...........P.....@.........E..@......E.P........@........E.....P.P..A@@.E..@.P.P..AP.P..AP..@....T..AP.E..P.Z .. ....."... .....7.H...w.....t.....T....M.."... P..n.n..t5..*B.P..*(.................*.....................( ..................*.. .".... .".......(.. .".....*.. ....o......E.6... ..*..."........."J......Ah......@.@@....:@{6..wCp..3...((.(......................*...@..(...."....................*......*.. ........T.......@.@@........AP.P..@.E@....E@.d.E@.@@..@.P.T..@..@..P.D...@M........EO..."...=.wCp.....R......P.@......
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:Google Chrome extension, version 3
              Category:dropped
              Size (bytes):91671
              Entropy (8bit):7.8774767243532695
              Encrypted:false
              SSDEEP:
              MD5:2BBD469CC894351258066DB2023D206B
              SHA1:3EF9EA3B62E43301B6287361B16AC01F5780AD35
              SHA-256:70CE55C69127635BCB579E1878C4C74F7707BD708CD57273E8B4891459A6A0EF
              SHA-512:421F3D78F5C132243B78C73FE7660BB3E045E83E30C0B3A2D6597E0C9E3C19DD4681491981E3C3A649C1E4E2A91BD982529234DA8DA1BFFB46651B74321E34D4
              Malicious:false
              Reputation:low
              Preview:Cr24....e"........0.."0...*.H.............0.........^...1"...w.g..t..2J.G1.)X4..=&.?[j,Lz..j.u.e[I.q*Ba/X...P.h..L.....2%3_o.......H.)'.=.e...?.......j..3UH.|.X.M..u..s[.*..?$....F%....I....)..,-./.e5).f..O.q.^........9..(.._.ph2..^.YBPXf_8....h[.v...S.*1`.#..5.SF.:f-.#.65.i..b.]9...y2.'....k[........V....h.[..9..?..R...a.y..x....P..o...Tc.<^.N..S.....c$j.jZ...t.A.3...H..._....Q.Sx.{7...<......wO.......%>..ZGs...*...K...&..ua#.>......E.a..2u;...|.^yU........o......!.;7..E;.3.~..B...*...W.a!....O.q.z...yd...)3.6...f..?.B..G.......]'-.....[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...F0D. ..O7..~.y.G..!s(........Faul.... .G..GZ.. <tS..28/22dlO.V...&...".>...........|]s.<{._.........l...X".}.:.{...A`....y.{..y..v.=....d..|-].k-.........4.O.......4myn.ij>...?.......?..87......Sy.R..k.U.kI.Z..........|,.....[........(C=..[..t4..c....>....=..^.._.._P.......z.}).;.9>}./m,..Z..u...`.g6...P.....k
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1420
              Entropy (8bit):5.401331260170966
              Encrypted:false
              SSDEEP:
              MD5:46D6DB5285031221D29FCBEC035AB5E3
              SHA1:CDF48CF9AC2228A153E566ED940192BA1F68A5F2
              SHA-256:98952CEB31AB517B27936F965C3FC9FDA91DE0C80ADA598B354A850BFD98F306
              SHA-512:87A58571EFE408C33F3EED807BEECF555FD27651BE4031BB3BD19A3A56E201A5DD90469A8F84B2043770E24F9DBC40D6C76777D6D48A97675BF2C522131B048E
              Malicious:false
              Reputation:low
              Preview:{"logTime": "1006/090722", "correlationVector":"rmkayOhJfEabcRCB2/Bp31","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1006/090722", "correlationVector":"jqHPV/yTVN5KYgOfDN/5Rr","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1006/090722", "correlationVector":"25C1A0EE3BD244A1BB83CF2641B12F1A","action":"FETCH_UX_CONFIG", "result":""}.{"logTime": "1006/093120", "correlationVector":"a/GaihlkzouX6tpAQ3civy","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1006/093121", "correlationVector":"2831F27CA5B645488E2DF2452C16A59E","action":"FETCH_UX_CONFIG", "result":""}.{"logTime": "1006/093243", "correlationVector":"7DhT8FK3VbHYWFgub0ZtsN","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1006/093243", "correlationVector":"83EFC8979E1A419495133BAFAFA5A23F","action":"FETCH_UX_CONFIG", "result":""}.{"logTime": "1006/093745", "correlationVector":"Bxyvid0fodNJ7Wehc/BC7P","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1006/093746", "correlationVector":"B1516CBB
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:Google Chrome extension, version 3
              Category:dropped
              Size (bytes):11185
              Entropy (8bit):7.951995436832936
              Encrypted:false
              SSDEEP:
              MD5:78E47DDA17341BED7BE45DCCFD89AC87
              SHA1:1AFDE30E46997452D11E4A2ADBBF35CCE7A1404F
              SHA-256:67D161098BE68CD24FEBC0C7B48F515F199DDA72F20AE3BBB97FCF2542BB0550
              SHA-512:9574A66D3756540479DC955C4057144283E09CAE11CE11EBCE801053BB48E536E67DC823B91895A9E3EE8D3CB27C065D5E9030C39A26CBF3F201348385B418A5
              Malicious:false
              Reputation:low
              Preview:Cr24..............0.."0...*.H.............0.........N.......E#......9e.u.q...VYY..@.+.C..k.O..bK.`..6.G..%.....3Z...e _.6....F..1p..K.Z......./ .3...OT..`..0...Y...FT..43.th.y...}....p.L...2S.&i.`..o...f.oH.....N..:..ijT.3.F{.0.,.f?'f.CQt;b_"Pc.. ..~S.I.c.8Z.;.....{G.a......k...>.`.o..%.$>;.....g.............jg?.R..@.:..........&..{...x@.Py..;kT....%F".S..w...N....9...A..@X.t!i.@..1;......1E..X.....[.~$....J......;=T.;)k..Y...$......S......M.P..P..>..=..u.....2p...w.9..1qw.a\A..Vj .C.....A..Cf1.r6.A...L. _m...[..l.Wr_../.. .B..9!.!+..ZG.K.......0.."0...*.H.............0.........^SUd%Q.L].......Cl2o...\[.....'*...;R=....N.C5....d. .....J.C>u.kr..Y..syJC.XS.q..E.n?....(G.5..)2.G..!.M.SS.{..U....!.EE..M[.#qs.A.1...g)nQ.c..G....Bd..7... .O.BI..KXQ..4.d.K.0......g.....-p....Z.E{...M&.~n.TE7..{0....5.#.C+3.y)pd9.e.........@..3.9..B.....I....2nX........2.?.~..S....]G.N.....Lr.O.Ve....9..D1.G..W)...P.?=.#..7.R.lz..a.wX.e..h.h.~....v..RP.@X....d.G
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
              Category:dropped
              Size (bytes):4982
              Entropy (8bit):7.929761711048726
              Encrypted:false
              SSDEEP:
              MD5:913064ADAAA4C4FA2A9D011B66B33183
              SHA1:99EA751AC2597A080706C690612AEEEE43161FC1
              SHA-256:AFB4CE8882EF7AE80976EBA7D87F6E07FCDDC8E9E84747E8D747D1E996DEA8EB
              SHA-512:162BF69B1AD5122C6154C111816E4B87A8222E6994A72743ED5382D571D293E1467A2ED2FC6CC27789B644943CF617A56DA530B6A6142680C5B2497579A632B5
              Malicious:false
              Reputation:low
              Preview:.PNG........IHDR..............>a....=IDATx..]}...U..;...O.Q..QH.I(....v..E....GUb*..R[.4@%..hK..B..(.B..". ....&)U#.%...jZ...JC.8.....{.cfvgf.3;.....}ow.....{...P.B...*T.P.B...*Tx...=.Q..wv.w.....|.e.1.$.P.?..l_\.n.}...~.g.....Q...A.f....m.....{,...C2 %..X.......FE.1.N..f...Q..D.K87.....:g..Q.{............3@$.8.....{.....q....G.. .....5..y......)XK..F...D.......... ."8...J#.eM.i....H.E.....a.RIP.`......)..T.....! .[p`X.`..L.a....e. .T..2.....H..p$..02...j....\..........s{...Ymm~.a........f.$./.[.{..C.2:.0..6..]....`....NW.....0..o.T..$;k.2......_...k..{,.+........{..6...L..... .dw...l$..}...K...EV....0......P...e....k....+Go....qw.9.1...X2\..qfw0v.....N...{...l.."....f.A..I..+#.v....'..~E.N-k.........{...l.$..ga..1...$......x$X=}.N..S..B$p..`..`.ZG:c..RA.(.0......Gg.A.I..>...3u.u........_..KO.m.........C...,..c.......0...@_..m...-..7.......4LZ......j@.......\..'....u. QJ.:G..I`.w'B0..w.H..'b.0- ......|..}./.....e..,.K.1........W.u.v. ...\.o
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):908
              Entropy (8bit):4.512512697156616
              Encrypted:false
              SSDEEP:
              MD5:12403EBCCE3AE8287A9E823C0256D205
              SHA1:C82D43C501FAE24BFE05DB8B8F95ED1C9AC54037
              SHA-256:B40BDE5B612CFFF936370B32FB0C58CC205FC89937729504C6C0B527B60E2CBA
              SHA-512:153401ECDB13086D2F65F9B9F20ACB3CEFE5E2AEFF1C31BA021BE35BF08AB0634812C33D1D34DA270E5693A8048FC5E2085E30974F6A703F75EA1622A0CA0FFD
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "SKEP NUWE".. },.. "explanationofflinedisabled": {.. "message": "Jy is vanlyn. As jy Google Dokumente sonder 'n internetverbinding wil gebruik, moet jy die volgende keer as jy aan die internet gekoppel is na instellings op die Google Dokumente-tuisblad gaan en vanlynsinkronisering aanskakel.".. },.. "explanationofflineenabled": {.. "message": "Jy is vanlyn, maar jy kan nog steeds beskikbare l.ers redigeer of nuwes skep.".. },.. "extdesc": {.. "message": "Skep, wysig en bekyk jou dokumente, sigblaaie en aanbiedings . alles sonder toegang tot die internet.".. },.. "extname": {.. "message": "Google Vanlyn Dokumente".. },.. "learnmore": {.. "message": "Kom meer te wete".. },.. "popuphelptext": {.. "message": "Skryf, redigeer en werk saam, waar jy ook al is, met of sonder 'n internetverbinding.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1285
              Entropy (8bit):4.702209356847184
              Encrypted:false
              SSDEEP:
              MD5:9721EBCE89EC51EB2BAEB4159E2E4D8C
              SHA1:58979859B28513608626B563138097DC19236F1F
              SHA-256:3D0361A85ADFCD35D0DE74135723A75B646965E775188F7DCDD35E3E42DB788E
              SHA-512:FA3689E8663565D3C1C923C81A620B006EA69C99FB1EB15D07F8F45192ED9175A6A92315FA424159C1163382A3707B25B5FC23E590300C62CBE2DACE79D84871
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "... ...".. },.. "explanationofflinedisabled": {.. "message": "..... .. .... Google ..... ........ ..... ..... .Google .... ... .. .. .. ..... .... ....... .. ....... ... .. .. ..... .. ..... ....".. },.. "explanationofflineenabled": {.. "message": "..... .. .... ... .. .... .... ..... .... ... ..... .... .....".. },.. "extdesc": {.. "message": "...... ..... .... ... .. ..... ...... ..... .... .. ..... . .... .. ...... .....".. },.. "extname": {.. "message": "..... .. Goog
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1244
              Entropy (8bit):4.5533961615623735
              Encrypted:false
              SSDEEP:
              MD5:3EC93EA8F8422FDA079F8E5B3F386A73
              SHA1:24640131CCFB21D9BC3373C0661DA02D50350C15
              SHA-256:ABD0919121956AB535E6A235DE67764F46CFC944071FCF2302148F5FB0E8C65A
              SHA-512:F40E879F85BC9B8120A9B7357ED44C22C075BF065F45BEA42BD5316AF929CBD035D5D6C35734E454AEF5B79D378E51A77A71FA23F9EBD0B3754159718FCEB95C
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "..... ....".. },.. "explanationofflinedisabled": {.. "message": "... ... ...... ........ ....... Google ... ..... .......... ..... ... ......... .. ...... ........ ........ Google ..... ........ ... ..... .. ..... ....... .... .... .... ..........".. },.. "explanationofflineenabled": {.. "message": "... ... ...... .... .. .... ....... ..... ....... ....... .. ..... ..... ......".. },.. "extdesc": {.. "message": "..... ......... ...... ........ ....... ......... ........ ....... .. ... ... ..... .........".. },.. "extname": {.. "message": "....... Google ... ......".. },.. "learnmore": {.. "messa
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):977
              Entropy (8bit):4.867640976960053
              Encrypted:false
              SSDEEP:
              MD5:9A798FD298008074E59ECC253E2F2933
              SHA1:1E93DA985E880F3D3350FC94F5CCC498EFC8C813
              SHA-256:628145F4281FA825D75F1E332998904466ABD050E8B0DC8BB9B6A20488D78A66
              SHA-512:9094480379F5AB711B3C32C55FD162290CB0031644EA09A145E2EF315DA12F2E55369D824AF218C3A7C37DD9A276AEEC127D8B3627D3AB45A14B0191ED2BBE70
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "YEN.S.N. YARADIN".. },.. "explanationofflinedisabled": {.. "message": "Oflayns.n.z. Google S.n.di internet ba.lant.s. olmadan istifad. etm.k ist.yirsinizs., Google S.n.din .sas s.hif.sind. ayarlara gedin v. n.vb.ti d.f. internet. qo.ulanda oflayn sinxronizasiyan. aktiv edin.".. },.. "explanationofflineenabled": {.. "message": "Oflayns.n.z, amma m.vcud fayllar. redakt. ed. v. yenil.rini yarada bil.rsiniz.".. },.. "extdesc": {.. "message": "S.n.d, c.dv.l v. t.qdimatlar.n ham.s.n. internet olmadan redakt. edin, yarad.n v. bax.n.".. },.. "extname": {.. "message": "Google S.n.d Oflayn".. },.. "learnmore": {.. "message": ".trafl. M.lumat".. },.. "popuphelptext": {.. "message": "Harda olma..n.zdan v. internet. qo.ulu olub-olmad...n.zdan as.l. olmayaraq, yaz.n, redakt. edin v. .m.kda.l.q edin.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):3107
              Entropy (8bit):3.535189746470889
              Encrypted:false
              SSDEEP:
              MD5:68884DFDA320B85F9FC5244C2DD00568
              SHA1:FD9C01E03320560CBBB91DC3D1917C96D792A549
              SHA-256:DDF16859A15F3EB3334D6241975CA3988AC3EAFC3D96452AC3A4AFD3644C8550
              SHA-512:7FF0FBD555B1F9A9A4E36B745CBFCAD47B33024664F0D99E8C080BE541420D1955D35D04B5E973C07725573E592CD0DD84FDBB867C63482BAFF6929ADA27CCDE
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"\u0421\u0422\u0412\u0410\u0420\u042b\u0426\u042c \u041d\u041e\u0412\u042b"},"explanationofflinedisabled":{"message":"\u0412\u044b \u045e \u043f\u0430\u0437\u0430\u0441\u0435\u0442\u043a\u0430\u0432\u044b\u043c \u0440\u044d\u0436\u044b\u043c\u0435. \u041a\u0430\u0431 \u043a\u0430\u0440\u044b\u0441\u0442\u0430\u0446\u0446\u0430 \u0414\u0430\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u043c\u0456 Google \u0431\u0435\u0437 \u043f\u0430\u0434\u043a\u043b\u044e\u0447\u044d\u043d\u043d\u044f \u0434\u0430 \u0456\u043d\u0442\u044d\u0440\u043d\u044d\u0442\u0443, \u043f\u0435\u0440\u0430\u0439\u0434\u0437\u0456\u0446\u0435 \u0434\u0430 \u043d\u0430\u043b\u0430\u0434 \u043d\u0430 \u0433\u0430\u043b\u043e\u045e\u043d\u0430\u0439 \u0441\u0442\u0430\u0440\u043e\u043d\u0446\u044b \u0414\u0430\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u045e Google \u0456 \u045e\u043a\u043b\u044e\u0447\u044b\u0446\u0435 \u0441\u0456\u043d\u0445\u0440\u0430\u043d\u0456\u0437\u0430\u0446\u044b\u044e
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1389
              Entropy (8bit):4.561317517930672
              Encrypted:false
              SSDEEP:
              MD5:2E6423F38E148AC5A5A041B1D5989CC0
              SHA1:88966FFE39510C06CD9F710DFAC8545672FFDCEB
              SHA-256:AC4A8B5B7C0B0DD1C07910F30DCFBDF1BCB701CFCFD182B6153FD3911D566C0E
              SHA-512:891FCDC6F07337970518322C69C6026896DD3588F41F1E6C8A1D91204412CAE01808F87F9F2DEA1754458D70F51C3CEF5F12A9E3FC011165A42B0844C75EC683
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": ".........".. },.. "explanationofflinedisabled": {.. "message": "...... .... .. .. .......... Google ......... ... ........ ......, ........ ........... . ......... ........ .. Google ......... . ........ ...... .............. ......... ..., ...... ..... ...... . .........".. },.. "explanationofflineenabled": {.. "message": "...... ..., .. ... ...... .. ........... ......... ....... ... .. ......... .....".. },.. "extdesc": {.. "message": "............, .......... . ............ ...... ........., .......... ....... . ........... . ...... .... ... ...... .. .........".. },..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1763
              Entropy (8bit):4.25392954144533
              Encrypted:false
              SSDEEP:
              MD5:651375C6AF22E2BCD228347A45E3C2C9
              SHA1:109AC3A912326171D77869854D7300385F6E628C
              SHA-256:1DBF38E425C5C7FC39E8077A837DF0443692463BA1FBE94E288AB5A93242C46E
              SHA-512:958AA7CF645FAB991F2ECA0937BA734861B373FB1C8BCC001599BE57C65E0917F7833A971D93A7A6423C5F54A4839D3A4D5F100C26EFA0D2A068516953989F9D
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": ".... .... ....".. },.. "explanationofflinedisabled": {.. "message": ".... ....... ....... .... ......... ..... ..... Google ........ ....... ...., Google .......... ........ ....... ... ... .... ... .... ... ........... .... ....... .... ... ...... ..... .... .....".. },.. "explanationofflineenabled": {.. "message": ".... ....... ......, ...... .... .... ...... .......... ........ .... .. .... .... .... .... .......".. },.. "extdesc":
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):930
              Entropy (8bit):4.569672473374877
              Encrypted:false
              SSDEEP:
              MD5:D177261FFE5F8AB4B3796D26835F8331
              SHA1:4BE708E2FFE0F018AC183003B74353AD646C1657
              SHA-256:D6E65238187A430FF29D4C10CF1C46B3F0FA4B91A5900A17C5DFD16E67FFC9BD
              SHA-512:E7D730304AED78C0F4A78DADBF835A22B3D8114FB41D67B2B26F4FE938B572763D3E127B7C1C81EBE7D538DA976A7A1E7ADC40F918F88AFADEA2201AE8AB47D0
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "CREA'N UN DE NOU".. },.. "explanationofflinedisabled": {.. "message": "No tens connexi.. Per utilitzar Documents de Google sense connexi. a Internet, ves a la configuraci. de la p.gina d'inici d'aquest servei i activa l'opci. per sincronitzar-se sense connexi. la propera vegada que estiguis connectat a la xarxa.".. },.. "explanationofflineenabled": {.. "message": "Tot i que no tens connexi., pots editar o crear fitxers.".. },.. "extdesc": {.. "message": "Edita, crea i consulta documents, fulls de c.lcul i presentacions, tot sense acc.s a Internet.".. },.. "extname": {.. "message": "Documents de Google sense connexi.".. },.. "learnmore": {.. "message": "M.s informaci.".. },.. "popuphelptext": {.. "message": "Escriu text, edita fitxers i col.labora-hi siguis on siguis, amb o sense connexi. a Internet.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):913
              Entropy (8bit):4.947221919047
              Encrypted:false
              SSDEEP:
              MD5:CCB00C63E4814F7C46B06E4A142F2DE9
              SHA1:860936B2A500CE09498B07A457E0CCA6B69C5C23
              SHA-256:21AE66CE537095408D21670585AD12599B0F575FF2CB3EE34E3A48F8CC71CFAB
              SHA-512:35839DAC6C985A6CA11C1BFF5B8B5E59DB501FCB91298E2C41CB0816B6101BF322445B249EAEA0CEF38F76D73A4E198F2B6E25EEA8D8A94EA6007D386D4F1055
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "VYTVO.IT".. },.. "explanationofflinedisabled": {.. "message": "Jste offline. Pokud chcete Dokumenty Google pou..vat bez p.ipojen. k.internetu, a. budete p...t. online, p.ejd.te do nastaven. na domovsk. str.nce Dokument. Google a.zapn.te offline synchronizaci.".. },.. "explanationofflineenabled": {.. "message": "Jste offline, ale st.le m..ete upravovat dostupn. soubory nebo vytv..et nov..".. },.. "extdesc": {.. "message": "Upravujte, vytv..ejte a.zobrazujte sv. dokumenty, tabulky a.prezentace . v.e bez p..stupu k.internetu.".. },.. "extname": {.. "message": "Dokumenty Google offline".. },.. "learnmore": {.. "message": "Dal.. informace".. },.. "popuphelptext": {.. "message": "Pi.te, upravujte a.spolupracujte kdekoli, s.p.ipojen.m k.internetu i.bez n.j.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):806
              Entropy (8bit):4.815663786215102
              Encrypted:false
              SSDEEP:
              MD5:A86407C6F20818972B80B9384ACFBBED
              SHA1:D1531CD0701371E95D2A6BB5EDCB79B949D65E7C
              SHA-256:A482663292A913B02A9CDE4635C7C92270BF3C8726FD274475DC2C490019A7C9
              SHA-512:D9FBF675514A890E9656F83572208830C6D977E34D5744C298A012515BC7EB5A17726ADD0D9078501393BABD65387C4F4D3AC0CC0F7C60C72E09F336DCA88DE7
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"CREU NEWYDD"},"explanationofflinedisabled":{"message":"Rydych chi all-lein. I ddefnyddio Dogfennau Google heb gysylltiad \u00e2'r rhyngrwyd, ewch i'r gosodiadau ar dudalen hafan Dogfennau Google a throi 'offine sync' ymlaen y tro nesaf y byddwch wedi'ch cysylltu \u00e2'r rhyngrwyd."},"explanationofflineenabled":{"message":"Rydych chi all-lein, ond gallwch barhau i olygu'r ffeiliau sydd ar gael neu greu rhai newydd."},"extdesc":{"message":"Gallwch olygu, creu a gweld eich dogfennau, taenlenni a chyflwyniadau \u2013 i gyd heb fynediad i'r rhyngrwyd."},"extname":{"message":"Dogfennau Google All-lein"},"learnmore":{"message":"DYSGU MWY"},"popuphelptext":{"message":"Ysgrifennwch, golygwch a chydweithiwch lle bynnag yr ydych, gyda chysylltiad \u00e2'r rhyngrwyd neu hebddo."}}.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):883
              Entropy (8bit):4.5096240460083905
              Encrypted:false
              SSDEEP:
              MD5:B922F7FD0E8CCAC31B411FC26542C5BA
              SHA1:2D25E153983E311E44A3A348B7D97AF9AAD21A30
              SHA-256:48847D57C75AF51A44CBF8F7EF1A4496C2007E58ED56D340724FDA1604FF9195
              SHA-512:AD0954DEEB17AF04858DD5EC3D3B3DA12DFF7A666AF4061DEB6FD492992D95DB3BAF751AB6A59BEC7AB22117103A93496E07632C2FC724623BB3ACF2CA6093F3
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "OPRET NYT".. },.. "explanationofflinedisabled": {.. "message": "Du er offline. Hvis du vil bruge Google Docs uden en internetforbindelse, kan du g. til indstillinger p. startsiden for Google Docs og aktivere offlinesynkronisering, n.ste gang du har internetforbindelse.".. },.. "explanationofflineenabled": {.. "message": "Du er offline, men du kan stadig redigere tilg.ngelige filer eller oprette nye.".. },.. "extdesc": {.. "message": "Rediger, opret og se dine dokumenter, regneark og pr.sentationer helt uden internetadgang.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "F. flere oplysninger".. },.. "popuphelptext": {.. "message": "Skriv, rediger og samarbejd, uanset hvor du er, og uanset om du har internetforbindelse.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1031
              Entropy (8bit):4.621865814402898
              Encrypted:false
              SSDEEP:
              MD5:D116453277CC860D196887CEC6432FFE
              SHA1:0AE00288FDE696795CC62FD36EABC507AB6F4EA4
              SHA-256:36AC525FA6E28F18572D71D75293970E0E1EAD68F358C20DA4FDC643EEA2C1C5
              SHA-512:C788C3202A27EC220E3232AE25E3C855F3FDB8F124848F46A3D89510C564641A2DFEA86D5014CEA20D3D2D3C1405C96DBEB7CCAD910D65C55A32FDCA8A33FDD4
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "NEU ERSTELLEN".. },.. "explanationofflinedisabled": {.. "message": "Sie sind offline. Um Google Docs ohne Internetverbindung zu verwenden, gehen Sie auf der Google Docs-Startseite auf \"Einstellungen\" und schalten die Offlinesynchronisierung ein, wenn Sie das n.chste Mal mit dem Internet verbunden sind.".. },.. "explanationofflineenabled": {.. "message": "Sie sind offline, aber k.nnen weiterhin verf.gbare Dateien bearbeiten oder neue Dateien erstellen.".. },.. "extdesc": {.. "message": "Mit der Erweiterung k.nnen Sie Dokumente, Tabellen und Pr.sentationen bearbeiten, erstellen und aufrufen.. ganz ohne Internetverbindung.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Weitere Informationen".. },.. "popuphelptext": {.. "message": "Mit oder ohne Internetverbindung: Sie k.nnen von .berall Dokumente erstellen, .ndern und zusammen mit anderen
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1613
              Entropy (8bit):4.618182455684241
              Encrypted:false
              SSDEEP:
              MD5:9ABA4337C670C6349BA38FDDC27C2106
              SHA1:1FC33BE9AB4AD99216629BC89FBB30E7AA42B812
              SHA-256:37CA6AB271D6E7C9B00B846FDB969811C9CE7864A85B5714027050795EA24F00
              SHA-512:8564F93AD8485C06034A89421CE74A4E719BBAC865E33A7ED0B87BAA80B7F7E54B240266F2EDB595DF4E6816144428DB8BE18A4252CBDCC1E37B9ECC9F9D7897
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": ".......... ....".. },.. "explanationofflinedisabled": {.. "message": "..... ..... ......... ... .. ............... .. ....... Google ..... ....... ... ........., ......... .... ......... .... ...... ...... ... ........ Google ... ............. ... ........... ..... ........ ... ....... .... ... .. ..... ............ ... ..........".. },.. "explanationofflineenabled": {.. "message": "..... ..... ........ .... ........ .. .............. .. ......... ...... . .. ............. ... .......".. },.. "extdesc": {.. "message": ".............., ............ ... ..... .. ......., .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):851
              Entropy (8bit):4.4858053753176526
              Encrypted:false
              SSDEEP:
              MD5:07FFBE5F24CA348723FF8C6C488ABFB8
              SHA1:6DC2851E39B2EE38F88CF5C35A90171DBEA5B690
              SHA-256:6895648577286002F1DC9C3366F558484EB7020D52BBF64A296406E61D09599C
              SHA-512:7ED2C8DB851A84F614D5DAF1D5FE633BD70301FD7FF8A6723430F05F642CEB3B1AD0A40DE65B224661C782FFCEC69D996EBE3E5BB6B2F478181E9A07D8CD41F6
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn More".. },.. "popuphelptext": {.. "message": "Write, edit, and collaborate wherever you are, with or without an internet connection.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):848
              Entropy (8bit):4.494568170878587
              Encrypted:false
              SSDEEP:
              MD5:3734D498FB377CF5E4E2508B8131C0FA
              SHA1:AA23E39BFE526B5E3379DE04E00EACBA89C55ADE
              SHA-256:AB5CDA04013DCE0195E80AF714FBF3A67675283768FFD062CF3CF16EDB49F5D4
              SHA-512:56D9C792954214B0DE56558983F7EB7805AC330AF00E944E734340BE41C68E5DD03EDDB17A63BC2AB99BDD9BE1F2E2DA5BE8BA7C43D938A67151082A9041C7BA
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an Internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the Internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create and view your documents, spreadsheets and presentations . all without Internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn more".. },.. "popuphelptext": {.. "message": "Write, edit and collaborate wherever you are, with or without an Internet connection.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1425
              Entropy (8bit):4.461560329690825
              Encrypted:false
              SSDEEP:
              MD5:578215FBB8C12CB7E6CD73FBD16EC994
              SHA1:9471D71FA6D82CE1863B74E24237AD4FD9477187
              SHA-256:102B586B197EA7D6EDFEB874B97F95B05D229EA6A92780EA8544C4FF1E6BC5B1
              SHA-512:E698B1A6A6ED6963182F7D25AC12C6DE06C45D14499DDC91E81BDB35474E7EC9071CFEBD869B7D129CB2CD127BC1442C75E408E21EB8E5E6906A607A3982B212
              Malicious:false
              Reputation:low
              Preview:{.. "createNew": {.. "description": "Text shown in the extension pop up for creating a new document",.. "message": "CREATE NEW".. },.. "explanationOfflineDisabled": {.. "description": "Text shown in the extension popup when the user is offline and offline is disabled.",.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationOfflineEnabled": {.. "description": "Text shown in the extension popup when the user is offline and offline is enabled.",.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extDesc": {.. "description": "Extension description",.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extName": {.. "description": "Extension name",..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):961
              Entropy (8bit):4.537633413451255
              Encrypted:false
              SSDEEP:
              MD5:F61916A206AC0E971CDCB63B29E580E3
              SHA1:994B8C985DC1E161655D6E553146FB84D0030619
              SHA-256:2008F4FAAB71AB8C76A5D8811AD40102C380B6B929CE0BCE9C378A7CADFC05EB
              SHA-512:D9C63B2F99015355ACA04D74A27FD6B81170750C4B4BE7293390DC81EF4CD920EE9184B05C61DC8979B6C2783528949A4AE7180DBF460A2620DBB0D3FD7A05CF
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "CREAR".. },.. "explanationofflinedisabled": {.. "message": "No tienes conexi.n. Para usar Documentos de Google sin conexi.n a Internet, ve a Configuraci.n en la p.gina principal de Documentos de Google y activa la sincronizaci.n sin conexi.n la pr.xima vez que te conectes a Internet.".. },.. "explanationofflineenabled": {.. "message": "No tienes conexi.n. Aun as., puedes crear archivos o editar los que est.n disponibles.".. },.. "extdesc": {.. "message": "Edita, crea y consulta tus documentos, hojas de c.lculo y presentaciones; todo ello, sin acceso a Internet.".. },.. "extname": {.. "message": "Documentos de Google sin conexi.n".. },.. "learnmore": {.. "message": "M.s informaci.n".. },.. "popuphelptext": {.. "message": "Escribe o edita contenido y colabora con otras personas desde cualquier lugar, con o sin conexi.n a Internet.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):959
              Entropy (8bit):4.570019855018913
              Encrypted:false
              SSDEEP:
              MD5:535331F8FB98894877811B14994FEA9D
              SHA1:42475E6AFB6A8AE41E2FC2B9949189EF9BBE09FB
              SHA-256:90A560FF82605DB7EDA26C90331650FF9E42C0B596CEDB79B23598DEC1B4988F
              SHA-512:2CE9C69E901AB5F766E6CFC1E592E1AF5A07AA78D154CCBB7898519A12E6B42A21C5052A86783ABE3E7A05043D4BD41B28960FEDDB30169FF7F7FE7208C8CFE9
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "CREAR NUEVO".. },.. "explanationofflinedisabled": {.. "message": "No tienes conexi.n. Para usar Documentos de Google sin conexi.n a Internet, ve a la configuraci.n de la p.gina principal de Documentos de Google y activa la sincronizaci.n sin conexi.n la pr.xima vez que est.s conectado a Internet.".. },.. "explanationofflineenabled": {.. "message": "No tienes conexi.n, pero a.n puedes modificar los archivos disponibles o crear otros nuevos.".. },.. "extdesc": {.. "message": "Edita, crea y consulta tus documentos, hojas de c.lculo y presentaciones aunque no tengas acceso a Internet".. },.. "extname": {.. "message": "Documentos de Google sin conexi.n".. },.. "learnmore": {.. "message": "M.s informaci.n".. },.. "popuphelptext": {.. "message": "Escribe, modifica y colabora dondequiera que est.s, con conexi.n a Internet o sin ella.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):968
              Entropy (8bit):4.633956349931516
              Encrypted:false
              SSDEEP:
              MD5:64204786E7A7C1ED9C241F1C59B81007
              SHA1:586528E87CD670249A44FB9C54B1796E40CDB794
              SHA-256:CC31B877238DA6C1D51D9A6155FDE565727A1956572F466C387B7E41C4923A29
              SHA-512:44FCF93F3FB10A3DB68D74F9453995995AB2D16863EC89779DB451A4D90F19743B8F51095EEC3ECEF5BD0C5C60D1BF3DFB0D64DF288DCCFBE70C129AE350B2C6
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "LOO UUS".. },.. "explanationofflinedisabled": {.. "message": "Teil ei ole v.rgu.hendust. Teenuse Google.i dokumendid kasutamiseks ilma Interneti-.henduseta avage j.rgmine kord, kui olete Internetiga .hendatud, teenuse Google.i dokumendid avalehel seaded ja l.litage sisse v.rgu.henduseta s.nkroonimine.".. },.. "explanationofflineenabled": {.. "message": "Teil ei ole v.rgu.hendust, kuid saate endiselt saadaolevaid faile muuta v.i uusi luua.".. },.. "extdesc": {.. "message": "Saate luua, muuta ja vaadata oma dokumente, arvustustabeleid ning esitlusi ilma Interneti-.henduseta.".. },.. "extname": {.. "message": "V.rgu.henduseta Google.i dokumendid".. },.. "learnmore": {.. "message": "Lisateave".. },.. "popuphelptext": {.. "message": "Kirjutage, muutke ja tehke koost..d .ksk.ik kus olenemata sellest, kas teil on Interneti-.hendus.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):838
              Entropy (8bit):4.4975520913636595
              Encrypted:false
              SSDEEP:
              MD5:29A1DA4ACB4C9D04F080BB101E204E93
              SHA1:2D0E4587DDD4BAC1C90E79A88AF3BD2C140B53B1
              SHA-256:A41670D52423BA69C7A65E7E153E7B9994E8DD0370C584BDA0714BD61C49C578
              SHA-512:B7B7A5A0AA8F6724B0FA15D65F25286D9C66873F03080CBABA037BDEEA6AADC678AC4F083BC52C2DB01BEB1B41A755ED67BBDDB9C0FE4E35A004537A3F7FC458
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"SORTU"},"explanationofflinedisabled":{"message":"Ez zaude konektatuta Internetera. Google Dokumentuak konexiorik gabe erabiltzeko, joan Google Dokumentuak zerbitzuaren orri nagusiko ezarpenetara eta aktibatu konexiorik gabeko sinkronizazioa Internetera konektatzen zaren hurrengoan."},"explanationofflineenabled":{"message":"Ez zaude konektatuta Internetera, baina erabilgarri dauden fitxategiak edita ditzakezu, baita beste batzuk sortu ere."},"extdesc":{"message":"Editatu, sortu eta ikusi dokumentuak, kalkulu-orriak eta aurkezpenak Interneteko konexiorik gabe."},"extname":{"message":"Google Dokumentuak konexiorik gabe"},"learnmore":{"message":"Lortu informazio gehiago"},"popuphelptext":{"message":"Edonon zaudela ere, ez duzu zertan konektatuta egon idatzi, editatu eta lankidetzan jardun ahal izateko."}}.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1305
              Entropy (8bit):4.673517697192589
              Encrypted:false
              SSDEEP:
              MD5:097F3BA8DE41A0AAF436C783DCFE7EF3
              SHA1:986B8CABD794E08C7AD41F0F35C93E4824AC84DF
              SHA-256:7C4C09D19AC4DA30CC0F7F521825F44C4DFBC19482A127FBFB2B74B3468F48F1
              SHA-512:8114EA7422E3B20AE3F08A3A64A6FFE1517A7579A3243919B8F789EB52C68D6F5A591F7B4D16CEE4BD337FF4DAF4057D81695732E5F7D9E761D04F859359FADB
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "..... ... ....".. },.. "explanationofflinedisabled": {.. "message": "...... ...... .... ....... .. ....... Google .... ..... ........ .... ... .. .. ....... ... ..... .. ....... .. .... .... ....... Google ..... . .......... ...... .. .... .....".. },.. "explanationofflineenabled": {.. "message": "...... ..... ... ...... ......... ......... .. .. .. ..... ..... ...... .... .. ........ ..... ..... .....".. },.. "extdesc": {.. "message": "...... ............ . ........ .. ....... ..... . ...... .... . ... ... ..... .... ...... .. ........".. },.. "extname": {.. "message": "....... Google .
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):911
              Entropy (8bit):4.6294343834070935
              Encrypted:false
              SSDEEP:
              MD5:B38CBD6C2C5BFAA6EE252D573A0B12A1
              SHA1:2E490D5A4942D2455C3E751F96BD9960F93C4B60
              SHA-256:2D752A5DBE80E34EA9A18C958B4C754F3BC10D63279484E4DF5880B8FD1894D2
              SHA-512:6E65207F4D8212736059CC802C6A7104E71A9CC0935E07BD13D17EC46EA26D10BC87AD923CD84D78781E4F93231A11CB9ED8D3558877B6B0D52C07CB005F1C0C
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "LUO UUSI".. },.. "explanationofflinedisabled": {.. "message": "Olet offline-tilassa. Jos haluat k.ytt.. Google Docsia ilman internetyhteytt., siirry Google Docsin etusivulle ja ota asetuksissa k.ytt..n offline-synkronointi, kun seuraavan kerran olet yhteydess. internetiin.".. },.. "explanationofflineenabled": {.. "message": "Olet offline-tilassa. Voit kuitenkin muokata k.ytett.viss. olevia tiedostoja tai luoda uusia.".. },.. "extdesc": {.. "message": "Muokkaa, luo ja katso dokumentteja, laskentataulukoita ja esityksi. ilman internetyhteytt..".. },.. "extname": {.. "message": "Google Docsin offline-tila".. },.. "learnmore": {.. "message": "Lis.tietoja".. },.. "popuphelptext": {.. "message": "Kirjoita, muokkaa ja tee yhteisty.t. paikasta riippumatta, my.s ilman internetyhteytt..".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):939
              Entropy (8bit):4.451724169062555
              Encrypted:false
              SSDEEP:
              MD5:FCEA43D62605860FFF41BE26BAD80169
              SHA1:F25C2CE893D65666CC46EA267E3D1AA080A25F5B
              SHA-256:F51EEB7AAF5F2103C1043D520E5A4DE0FA75E4DC375E23A2C2C4AFD4D9293A72
              SHA-512:F66F113A26E5BCF54B9AAFA69DAE3C02C9C59BD5B9A05F829C92AF208C06DC8CCC7A1875CBB7B7CE425899E4BA27BFE8CE2CDAF43A00A1B9F95149E855989EE0
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "GUMAWA NG BAGO".. },.. "explanationofflinedisabled": {.. "message": "Naka-offline ka. Upang magamit ang Google Docs nang walang koneksyon sa internet, pumunta sa mga setting sa homepage ng Google Docs at i-on ang offline na pag-sync sa susunod na nakakonekta ka sa internet.".. },.. "explanationofflineenabled": {.. "message": "Naka-offline ka, ngunit maaari mo pa ring i-edit ang mga available na file o gumawa ng mga bago.".. },.. "extdesc": {.. "message": "I-edit, gawin, at tingnan ang iyong mga dokumento, spreadsheet, at presentation . lahat ng ito nang walang access sa internet.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Matuto Pa".. },.. "popuphelptext": {.. "message": "Magsulat, mag-edit at makipag-collaborate nasaan ka man, nang mayroon o walang koneksyon sa internet.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):977
              Entropy (8bit):4.622066056638277
              Encrypted:false
              SSDEEP:
              MD5:A58C0EEBD5DC6BB5D91DAF923BD3A2AA
              SHA1:F169870EEED333363950D0BCD5A46D712231E2AE
              SHA-256:0518287950A8B010FFC8D52554EB82E5D93B6C3571823B7CECA898906C11ABCC
              SHA-512:B04AFD61DE490BC838354E8DC6C22BE5C7AC6E55386FFF78489031ACBE2DBF1EAA2652366F7A1E62CE87CFCCB75576DA3B2645FEA1645B0ECEB38B1FA3A409E8
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "CR.ER".. },.. "explanationofflinedisabled": {.. "message": "Vous .tes hors connexion. Pour pouvoir utiliser Google.Docs sans connexion Internet, acc.dez aux param.tres de la page d'accueil de Google.Docs et activez la synchronisation hors connexion lors de votre prochaine connexion . Internet.".. },.. "explanationofflineenabled": {.. "message": "Vous .tes hors connexion, mais vous pouvez quand m.me modifier les fichiers disponibles ou cr.er des fichiers.".. },.. "extdesc": {.. "message": "Modifiez, cr.ez et consultez des documents, feuilles de calcul et pr.sentations, sans acc.s . Internet.".. },.. "extname": {.. "message": "Google.Docs hors connexion".. },.. "learnmore": {.. "message": "En savoir plus".. },.. "popuphelptext": {.. "message": "R.digez des documents, modifiez-les et collaborez o. que vous soyez, avec ou sans connexion Internet.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):972
              Entropy (8bit):4.621319511196614
              Encrypted:false
              SSDEEP:
              MD5:6CAC04BDCC09034981B4AB567B00C296
              SHA1:84F4D0E89E30ED7B7ACD7644E4867FFDB346D2A5
              SHA-256:4CAA46656ECC46A420AA98D3307731E84F5AC1A89111D2E808A228C436D83834
              SHA-512:160590B6EC3DCF48F3EA7A5BAA11A8F6FA4131059469623E00AD273606B468B3A6E56D199E97DAA0ECB6C526260EBAE008570223F2822811F441D1C900DC33D6
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "CR.ER".. },.. "explanationofflinedisabled": {.. "message": "Vous .tes hors connexion. Pour utiliser Google.Documents sans connexion Internet, acc.dez aux param.tres sur la page d'accueil Google.Documents et activez la synchronisation hors ligne la prochaine fois que vous .tes connect. . Internet.".. },.. "explanationofflineenabled": {.. "message": "Vous .tes hors connexion, mais vous pouvez toujours modifier les fichiers disponibles ou en cr.er.".. },.. "extdesc": {.. "message": "Modifiez, cr.ez et consultez vos documents, vos feuilles de calcul et vos pr.sentations, le tout sans acc.s . Internet.".. },.. "extname": {.. "message": "Google.Documents hors connexion".. },.. "learnmore": {.. "message": "En savoir plus".. },.. "popuphelptext": {.. "message": ".crivez, modifiez et collaborez o. que vous soyez, avec ou sans connexion Internet.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):990
              Entropy (8bit):4.497202347098541
              Encrypted:false
              SSDEEP:
              MD5:6BAAFEE2F718BEFBC7CD58A04CCC6C92
              SHA1:CE0BDDDA2FA1F0AD222B604C13FF116CBB6D02CF
              SHA-256:0CF098DFE5BBB46FC0132B3CF0C54B06B4D2C8390D847EE2A65D20F9B7480F4C
              SHA-512:3DA23E74CD6CF9C0E2A0C4DBA60301281D362FB0A2A908F39A55ABDCA4CC69AD55638C63CC3BEFD44DC032F9CBB9E2FDC1B4C4ABE292917DF8272BA25B82AF20
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "CREAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Est.s sen conexi.n. Para utilizar Documentos de Google sen conexi.n a Internet, accede .s opci.ns de configuraci.n na p.xina de inicio de Documentos de Google e activa a sincronizaci.n sen conexi.n a pr.xima vez que esteas conectado a Internet.".. },.. "explanationofflineenabled": {.. "message": "Est.s sen conexi.n. A.nda podes editar os ficheiros dispo.ibles ou crear outros novos.".. },.. "extdesc": {.. "message": "Modifica, crea e consulta os teus documentos, follas de c.lculo e presentaci.ns sen necesidade de acceder a Internet.".. },.. "extname": {.. "message": "Documentos de Google sen conexi.n".. },.. "learnmore": {.. "message": "M.is informaci.n".. },.. "popuphelptext": {.. "message": "Escribe, edita e colabora esteas onde esteas, tanto se tes conexi.n a Internet como se non a tes.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1658
              Entropy (8bit):4.294833932445159
              Encrypted:false
              SSDEEP:
              MD5:BC7E1D09028B085B74CB4E04D8A90814
              SHA1:E28B2919F000B41B41209E56B7BF3A4448456CFE
              SHA-256:FE8218DF25DB54E633927C4A1640B1A41B8E6CB3360FA386B5382F833B0B237C
              SHA-512:040A8267D67DB05BBAA52F1FAC3460F58D35C5B73AA76BBF17FA78ACC6D3BFB796A870DD44638F9AC3967E35217578A20D6F0B975CEEEEDBADFC9F65BE7E72C9
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": ".... .....".. },.. "explanationofflinedisabled": {.. "message": "... ...... ... ........ ....... ... Google .......... ..... .... ...., ... .... .... ...... ........ .... ...... ... ...... Google ........ ...... .. ........ .. ... ... ...... ....... .... ....".. },.. "explanationofflineenabled": {.. "message": "... ...... .., ..... ... ... .. ...... ..... ....... ... ... .. .... ... ..... ... ...".. },.. "extdesc": {.. "message": "..... ........., ..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1672
              Entropy (8bit):4.314484457325167
              Encrypted:false
              SSDEEP:
              MD5:98A7FC3E2E05AFFFC1CFE4A029F47476
              SHA1:A17E077D6E6BA1D8A90C1F3FAF25D37B0FF5A6AD
              SHA-256:D2D1AFA224CDA388FF1DC8FAC24CDA228D7CE09DE5D375947D7207FA4A6C4F8D
              SHA-512:457E295C760ABFD29FC6BBBB7FC7D4959287BCA7FB0E3E99EB834087D17EED331DEF18138838D35C48C6DDC8A0134AFFFF1A5A24033F9B5607B355D3D48FDF88
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "... .....".. },.. "explanationofflinedisabled": {.. "message": ".. ...... .... ....... ....... .. .... Google ........ .. ..... .... .. ..., .... ... ....... .. ...... .... .. Google ........ .. ........ .. ...... ... .... .. ...... ....... .... .....".. },.. "explanationofflineenabled": {.. "message": ".. ...... ..., ..... .. .. .. ...... ...... ..... .. .... ... .. .. ...... ... .... ....".. },.. "extdesc": {.. "message": ".... .... ....... ...... ..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):935
              Entropy (8bit):4.6369398601609735
              Encrypted:false
              SSDEEP:
              MD5:25CDFF9D60C5FC4740A48EF9804BF5C7
              SHA1:4FADECC52FB43AEC084DF9FF86D2D465FBEBCDC0
              SHA-256:73E6E246CEEAB9875625CD4889FBF931F93B7B9DEAA11288AE1A0F8A6E311E76
              SHA-512:EF00B08496427FEB5A6B9FB3FE2E5404525BE7C329D9DD2A417480637FD91885837D134A26980DCF9F61E463E6CB68F09A24402805807E656AF16B116A75E02C
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "IZRADI NOVI".. },.. "explanationofflinedisabled": {.. "message": "Vi ste izvan mre.e. Da biste koristili Google dokumente bez internetske veze, idite na postavke na po.etnoj stranici Google dokumenata i uklju.ite izvanmre.nu sinkronizaciju sljede.i put kada se pove.ete s internetom.".. },.. "explanationofflineenabled": {.. "message": "Vi ste izvan mre.e, no i dalje mo.ete ure.ivati dostupne datoteke i izra.ivati nove.".. },.. "extdesc": {.. "message": "Uredite, izradite i pregledajte dokumente, prora.unske tablice i prezentacije . sve bez pristupa internetu.".. },.. "extname": {.. "message": "Google dokumenti izvanmre.no".. },.. "learnmore": {.. "message": "Saznajte vi.e".. },.. "popuphelptext": {.. "message": "Pi.ite, ure.ujte i sura.ujte gdje god se nalazili, povezani s internetom ili izvanmre.no.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1065
              Entropy (8bit):4.816501737523951
              Encrypted:false
              SSDEEP:
              MD5:8930A51E3ACE3DD897C9E61A2AEA1D02
              SHA1:4108506500C68C054BA03310C49FA5B8EE246EA4
              SHA-256:958C0F664FCA20855FA84293566B2DDB7F297185619143457D6479E6AC81D240
              SHA-512:126B80CD3428C0BC459EEAAFCBE4B9FDE2541A57F19F3EC7346BAF449F36DC073A9CF015594A57203255941551B25F6FAA6D2C73C57C44725F563883FF902606
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": ".J L.TREHOZ.SA".. },.. "explanationofflinedisabled": {.. "message": "Jelenleg offline .llapotban van. Ha a Google Dokumentumokat internetkapcsolat n.lk.l szeretn. haszn.lni, a legk.zelebbi internethaszn.lata sor.n nyissa meg a Google Dokumentumok kezd.oldal.n tal.lhat. be.ll.t.sokat, .s tiltsa le az offline szinkroniz.l.s be.ll.t.st.".. },.. "explanationofflineenabled": {.. "message": "Offline .llapotban van, de az el.rhet. f.jlokat .gy is szerkesztheti, valamint l.trehozhat .jakat.".. },.. "extdesc": {.. "message": "Szerkesszen, hozzon l.tre .s tekintsen meg dokumentumokat, t.bl.zatokat .s prezent.ci.kat . ak.r internetkapcsolat n.lk.l is.".. },.. "extname": {.. "message": "Google Dokumentumok Offline".. },.. "learnmore": {.. "message": "Tov.bbi inform.ci.".. },.. "popuphelptext": {.. "message": ".rjon, szerkesszen .s dolgozzon egy.tt m.sokkal
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2771
              Entropy (8bit):3.7629875118570055
              Encrypted:false
              SSDEEP:
              MD5:55DE859AD778E0AA9D950EF505B29DA9
              SHA1:4479BE637A50C9EE8A2F7690AD362A6A8FFC59B2
              SHA-256:0B16E3F8BD904A767284345AE86A0A9927C47AFE89E05EA2B13AD80009BDF9E4
              SHA-512:EDAB2FCC14CABB6D116E9C2907B42CFBC34F1D9035F43E454F1F4D1F3774C100CBADF6B4C81B025810ED90FA91C22F1AEFE83056E4543D92527E4FE81C7889A8
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"\u054d\u054f\u0535\u0542\u053e\u0535\u053c \u0546\u0548\u0550"},"explanationofflinedisabled":{"message":"Google \u0553\u0561\u057d\u057f\u0561\u0569\u0572\u0569\u0565\u0580\u0568 \u0576\u0561\u0587 \u0561\u0576\u0581\u0561\u0576\u0581 \u057c\u0565\u056a\u056b\u0574\u0578\u0582\u0574 \u0585\u0563\u057f\u0561\u0563\u0578\u0580\u056e\u0565\u056c\u0578\u0582 \u0570\u0561\u0574\u0561\u0580 \u0574\u056b\u0561\u0581\u0565\u0584 \u0570\u0561\u0574\u0561\u0581\u0561\u0576\u0581\u056b\u0576, \u0562\u0561\u0581\u0565\u0584 \u056e\u0561\u057c\u0561\u0575\u0578\u0582\u0569\u0575\u0561\u0576 \u0563\u056c\u056d\u0561\u057e\u0578\u0580 \u0567\u057b\u0568, \u0561\u0576\u0581\u0565\u0584 \u056f\u0561\u0580\u0563\u0561\u057e\u0578\u0580\u0578\u0582\u0574\u0576\u0565\u0580 \u0587 \u0574\u056b\u0561\u0581\u0580\u0565\u0584 \u0561\u0576\u0581\u0561\u0576\u0581 \u0570\u0561\u0574\u0561\u056a\u0561\u0574\u0561\u0581\u0578\u0582\u0574\u0568:"},"explanationofflineenabled":{"message":"\u
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):858
              Entropy (8bit):4.474411340525479
              Encrypted:false
              SSDEEP:
              MD5:34D6EE258AF9429465AE6A078C2FB1F5
              SHA1:612CAE151984449A4346A66C0A0DF4235D64D932
              SHA-256:E3C86DDD2EFEBE88EED8484765A9868202546149753E03A61EB7C28FD62CFCA1
              SHA-512:20427807B64A0F79A6349F8A923152D9647DA95C05DE19AD3A4BF7DB817E25227F3B99307C8745DD323A6591B515221BD2F1E92B6F1A1783BDFA7142E84601B1
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "BUAT BARU".. },.. "explanationofflinedisabled": {.. "message": "Anda sedang offline. Untuk menggunakan Google Dokumen tanpa koneksi internet, buka setelan di beranda Google Dokumen dan aktifkan sinkronisasi offline saat terhubung ke internet.".. },.. "explanationofflineenabled": {.. "message": "Anda sedang offline, namun Anda masih dapat mengedit file yang tersedia atau membuat file baru.".. },.. "extdesc": {.. "message": "Edit, buat, dan lihat dokumen, spreadsheet, dan presentasi . tanpa perlu akses internet.".. },.. "extname": {.. "message": "Google Dokumen Offline".. },.. "learnmore": {.. "message": "Pelajari Lebih Lanjut".. },.. "popuphelptext": {.. "message": "Tulis, edit, dan gabungkan di mana saja, dengan atau tanpa koneksi internet.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):954
              Entropy (8bit):4.631887382471946
              Encrypted:false
              SSDEEP:
              MD5:1F565FB1C549B18AF8BBFED8DECD5D94
              SHA1:B57F4BDAE06FF3DFC1EB3E56B6F2F204D6F63638
              SHA-256:E16325D1A641EF7421F2BAFCD6433D53543C89D498DD96419B03CBA60B9C7D60
              SHA-512:A60B8E042A9BCDCC136B87948E9924A0B24D67C6CA9803904B876F162A0AD82B9619F1316BE9FF107DD143B44F7E6F5DF604ABFE00818DEB40A7D62917CDA69F
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"B\u00daA TIL N\u00ddTT"},"explanationofflinedisabled":{"message":"\u00de\u00fa ert \u00e1n nettengingar. Til a\u00f0 nota Google skj\u00f6l \u00e1n nettengingar skaltu opna stillingarnar \u00e1 heimas\u00ed\u00f0u Google skjala og virkja samstillingu \u00e1n nettengingar n\u00e6st \u00feegar \u00fe\u00fa tengist netinu."},"explanationofflineenabled":{"message":"Engin nettenging. \u00de\u00fa getur samt sem \u00e1\u00f0ur breytt tilt\u00e6kum skr\u00e1m e\u00f0a b\u00fai\u00f0 til n\u00fdjar."},"extdesc":{"message":"Breyttu, b\u00fa\u00f0u til og sko\u00f0a\u00f0u skj\u00f6lin \u00fe\u00edn, t\u00f6flureikna og kynningar \u2014 allt \u00e1n nettengingar."},"extname":{"message":"Google skj\u00f6l \u00e1n nettengingar"},"learnmore":{"message":"Frekari uppl\u00fdsingar"},"popuphelptext":{"message":"Skrifa\u00f0u, breyttu og starfa\u00f0u me\u00f0 \u00f6\u00f0rum hvort sem nettenging er til sta\u00f0ar e\u00f0a ekki."}}.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):899
              Entropy (8bit):4.474743599345443
              Encrypted:false
              SSDEEP:
              MD5:0D82B734EF045D5FE7AA680B6A12E711
              SHA1:BD04F181E4EE09F02CD53161DCABCEF902423092
              SHA-256:F41862665B13C0B4C4F562EF1743684CCE29D4BCF7FE3EA494208DF253E33885
              SHA-512:01F305A280112482884485085494E871C66D40C0B03DE710B4E5F49C6A478D541C2C1FDA2CEAF4307900485946DEE9D905851E98A2EB237642C80D464D1B3ADA
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "CREA NUOVO".. },.. "explanationofflinedisabled": {.. "message": "Sei offline. Per utilizzare Documenti Google senza una connessione Internet, apri le impostazioni nella home page di Documenti Google e attiva la sincronizzazione offline la prossima volta che ti colleghi a Internet.".. },.. "explanationofflineenabled": {.. "message": "Sei offline, ma puoi comunque modificare i file disponibili o crearne di nuovi.".. },.. "extdesc": {.. "message": "Modifica, crea e visualizza documenti, fogli di lavoro e presentazioni, senza accesso a Internet.".. },.. "extname": {.. "message": "Documenti Google offline".. },.. "learnmore": {.. "message": "Ulteriori informazioni".. },.. "popuphelptext": {.. "message": "Scrivi, modifica e collabora ovunque ti trovi, con o senza una connessione Internet.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2230
              Entropy (8bit):3.8239097369647634
              Encrypted:false
              SSDEEP:
              MD5:26B1533C0852EE4661EC1A27BD87D6BF
              SHA1:18234E3ABAF702DF9330552780C2F33B83A1188A
              SHA-256:BBB81C32F482BA3216C9B1189C70CEF39CA8C2181AF3538FFA07B4C6AD52F06A
              SHA-512:450BFAF0E8159A4FAE309737EA69CA8DD91CAAFD27EF662087C4E7716B2DCAD3172555898E75814D6F11487F4F254DE8625EF0CFEA8DF0133FC49E18EC7FD5D2
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"\u05d9\u05e6\u05d9\u05e8\u05ea \u05d7\u05d3\u05e9"},"explanationofflinedisabled":{"message":"\u05d0\u05d9\u05df \u05dc\u05da \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8. \u05db\u05d3\u05d9 \u05dc\u05d4\u05e9\u05ea\u05de\u05e9 \u05d1-Google Docs \u05dc\u05dc\u05d0 \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8, \u05d1\u05d4\u05ea\u05d7\u05d1\u05e8\u05d5\u05ea \u05d4\u05d1\u05d0\u05d4 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8, \u05d9\u05e9 \u05dc\u05e2\u05d1\u05d5\u05e8 \u05dc\u05e7\u05d8\u05e2 \u05d4\u05d4\u05d2\u05d3\u05e8\u05d5\u05ea \u05d1\u05d3\u05e3 \u05d4\u05d1\u05d9\u05ea \u05e9\u05dc Google Docs \u05d5\u05dc\u05d4\u05e4\u05e2\u05d9\u05dc \u05e1\u05e0\u05db\u05e8\u05d5\u05df \u05d1\u05de\u05e6\u05d1 \u05d0\u05d5\u05e4\u05dc\u05d9\u05d9\u05df."},"explanationofflineenabled":{"message":"\u05d0\u05d9\u05df \u05dc\u05da \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1160
              Entropy (8bit):5.292894989863142
              Encrypted:false
              SSDEEP:
              MD5:15EC1963FC113D4AD6E7E59AE5DE7C0A
              SHA1:4017FC6D8B302335469091B91D063B07C9E12109
              SHA-256:34AC08F3C4F2D42962A3395508818B48CA323D22F498738CC9F09E78CB197D73
              SHA-512:427251F471FA3B759CA1555E9600C10F755BC023701D058FF661BEC605B6AB94CFB3456C1FEA68D12B4D815FFBAFABCEB6C12311DD1199FC783ED6863AF97C0F
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "....".. },.. "explanationofflinedisabled": {.. "message": "....................... Google ............................... Google .............. [..] .......[.......] ...........".. },.. "explanationofflineenabled": {.. "message": ".............................................".. },.. "extdesc": {.. "message": ".........................................................".. },.. "extname": {.. "message": "Google ..... ......".. },.. "learnmore": {.. "message": "..".. },.. "popuphelp
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):3264
              Entropy (8bit):3.586016059431306
              Encrypted:false
              SSDEEP:
              MD5:83F81D30913DC4344573D7A58BD20D85
              SHA1:5AD0E91EA18045232A8F9DF1627007FE506A70E0
              SHA-256:30898BBF51BDD58DB397FF780F061E33431A38EF5CFC288B5177ECF76B399F26
              SHA-512:85F97F12AD4482B5D9A6166BB2AE3C4458A582CF575190C71C1D8E0FB87C58482F8C0EFEAD56E3A70EDD42BED945816DB5E07732AD27B8FFC93F4093710DD58F
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"\u10d0\u10ee\u10da\u10d8\u10e1 \u10e8\u10d4\u10e5\u10db\u10dc\u10d0"},"explanationofflinedisabled":{"message":"\u10d7\u10e5\u10d5\u10d4\u10dc \u10ee\u10d0\u10d6\u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10ee\u10d0\u10e0\u10d7. Google Docs-\u10d8\u10e1 \u10d8\u10dc\u10e2\u10d4\u10e0\u10dc\u10d4\u10e2\u10d7\u10d0\u10dc \u10d9\u10d0\u10d5\u10e8\u10d8\u10e0\u10d8\u10e1 \u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10d2\u10d0\u10db\u10dd\u10e1\u10d0\u10e7\u10d4\u10dc\u10d4\u10d1\u10da\u10d0\u10d3 \u10d2\u10d0\u10d3\u10d0\u10d3\u10d8\u10d7 \u10de\u10d0\u10e0\u10d0\u10db\u10d4\u10e2\u10e0\u10d4\u10d1\u10d6\u10d4 Google Docs-\u10d8\u10e1 \u10db\u10d7\u10d0\u10d5\u10d0\u10e0 \u10d2\u10d5\u10d4\u10e0\u10d3\u10d6\u10d4 \u10d3\u10d0 \u10e9\u10d0\u10e0\u10d7\u10d4\u10d7 \u10ee\u10d0\u10d6\u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10e1\u10d8\u10dc\u10e5\u10e0\u10dd\u10dc\u10d8\u10d6\u10d0\u10ea\u10d8\u10d0, \u10e0\u10dd\u10d3\u10d4\u10e1\u10d0\u10ea \u10e8\u10d4\u10db\u10d3\u10d2\u10dd\u10
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):3235
              Entropy (8bit):3.6081439490236464
              Encrypted:false
              SSDEEP:
              MD5:2D94A58795F7B1E6E43C9656A147AD3C
              SHA1:E377DB505C6924B6BFC9D73DC7C02610062F674E
              SHA-256:548DC6C96E31A16CE355DC55C64833B08EF3FBA8BF33149031B4A685959E3AF4
              SHA-512:F51CC857E4CF2D4545C76A2DCE7D837381CE59016E250319BF8D39718BE79F9F6EE74EA5A56DE0E8759E4E586D93430D51651FC902376D8A5698628E54A0F2D8
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"\u0416\u0410\u04a2\u0410\u0421\u042b\u041d \u0416\u0410\u0421\u0410\u0423"},"explanationofflinedisabled":{"message":"\u0421\u0456\u0437 \u043e\u0444\u043b\u0430\u0439\u043d \u0440\u0435\u0436\u0438\u043c\u0456\u043d\u0434\u0435\u0441\u0456\u0437. Google Docs \u049b\u043e\u043b\u0434\u0430\u043d\u0431\u0430\u0441\u044b\u043d \u0436\u0435\u043b\u0456 \u0431\u0430\u0439\u043b\u0430\u043d\u044b\u0441\u044b\u043d\u0441\u044b\u0437 \u049b\u043e\u043b\u0434\u0430\u043d\u0443 \u04af\u0448\u0456\u043d, \u043a\u0435\u043b\u0435\u0441\u0456 \u0436\u043e\u043b\u044b \u0436\u0435\u043b\u0456\u0433\u0435 \u049b\u043e\u0441\u044b\u043b\u0493\u0430\u043d\u0434\u0430, Google Docs \u043d\u0435\u0433\u0456\u0437\u0433\u0456 \u0431\u0435\u0442\u0456\u043d\u0435\u043d \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u043b\u0435\u0440 \u0431\u04e9\u043b\u0456\u043c\u0456\u043d \u043a\u0456\u0440\u0456\u043f, \u043e\u0444\u043b\u0430\u0439\u043d \u0440\u0435\u0436\u0438\u043c\u0456\u
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):3122
              Entropy (8bit):3.891443295908904
              Encrypted:false
              SSDEEP:
              MD5:B3699C20A94776A5C2F90AEF6EB0DAD9
              SHA1:1F9B968B0679A20FA097624C9ABFA2B96C8C0BEA
              SHA-256:A6118F0A0DE329E07C01F53CD6FB4FED43E54C5F53DB4CD1C7F5B2B4D9FB10E6
              SHA-512:1E8D15B8BFF1D289434A244172F9ED42B4BB6BCB6372C1F300B01ACEA5A88167E97FEDABA0A7AE3BEB5E24763D1B09046AE8E30745B80E2E2FE785C94DF362F6
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"\u1794\u1784\u17d2\u1780\u17be\u178f\u200b\u1790\u17d2\u1798\u17b8"},"explanationofflinedisabled":{"message":"\u17a2\u17d2\u1793\u1780\u200b\u1782\u17d2\u1798\u17b6\u1793\u200b\u17a2\u17ca\u17b8\u1793\u1792\u17ba\u178e\u17b7\u178f\u17d4 \u178a\u17be\u1798\u17d2\u1794\u17b8\u200b\u1794\u17d2\u179a\u17be Google \u17af\u1780\u179f\u17b6\u179a\u200b\u1794\u17b6\u1793\u200b\u200b\u178a\u17c4\u1799\u200b\u200b\u1798\u17b7\u1793\u1798\u17b6\u1793\u200b\u200b\u200b\u17a2\u17ca\u17b8\u1793\u1792\u17ba\u178e\u17b7\u178f \u179f\u17bc\u1798\u200b\u200b\u1791\u17c5\u200b\u1780\u17b6\u1793\u17cb\u200b\u1780\u17b6\u179a\u200b\u1780\u17c6\u178e\u178f\u17cb\u200b\u1793\u17c5\u200b\u179b\u17be\u200b\u1782\u17c1\u17a0\u1791\u17c6\u1796\u17d0\u179a Google \u17af\u1780\u179f\u17b6\u179a \u1793\u17b7\u1784\u200b\u1794\u17be\u1780\u200b\u1780\u17b6\u179a\u1792\u17d2\u179c\u17be\u200b\u179f\u1798\u1780\u17b6\u179b\u1780\u1798\u17d2\u1798\u200b\u200b\u200b\u1782\u17d2\u1798\u17b6\u1793
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1880
              Entropy (8bit):4.295185867329351
              Encrypted:false
              SSDEEP:
              MD5:8E16966E815C3C274EEB8492B1EA6648
              SHA1:7482ED9F1C9FD9F6F9BA91AB15921B19F64C9687
              SHA-256:418FF53FCA505D54268413C796E4DF80E947A09F399AB222A90B81E93113D5B5
              SHA-512:85B28202E874B1CF45B37BA05B87B3D8D6FE38E89C6011C4240CF6B563EA6DA60181D712CCE20D07C364F4A266A4EC90C4934CC8B7BB2013CB3B22D755796E38
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "........ .....".. },.. "explanationofflinedisabled": {.. "message": ".... ..................... ......... ............. Google ...... ....., Google ...... ............ ............... .... ..... ...... .... .... ............ ............. ........ ..... ... .....".. },.. "explanationofflineenabled": {.. "message": ".... ...................., .... .... .... ......... ........... ............ .... ........ .........."..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1042
              Entropy (8bit):5.3945675025513955
              Encrypted:false
              SSDEEP:
              MD5:F3E59EEEB007144EA26306C20E04C292
              SHA1:83E7BDFA1F18F4C7534208493C3FF6B1F2F57D90
              SHA-256:C52D9B955D229373725A6E713334BBB31EA72EFA9B5CF4FBD76A566417B12CAC
              SHA-512:7808CB5FF041B002CBD78171EC5A0B4DBA3E017E21F7E8039084C2790F395B839BEE04AD6C942EED47CCB53E90F6DE818A725D1450BF81BA2990154AFD3763AF
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": ".. ...".. },.. "explanationofflinedisabled": {.. "message": ".... ...... ... .. .. Google Docs. ..... Google Docs .... .... .... .... .... ..... . .... .... ..... ......".. },.. "explanationofflineenabled": {.. "message": ".... ...... ... .. ... ... ..... ... ... .. . .....".. },.. "extdesc": {.. "message": ".... .... ... .., ...... . ....... .., .., ......".. },.. "extname": {.. "message": "Google Docs ....".. },.. "learnmore": {.. "message": "... ....".. },.. "popuphelptext": {.. "message": "... .. ... .... ..... .... .... .....
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2535
              Entropy (8bit):3.8479764584971368
              Encrypted:false
              SSDEEP:
              MD5:E20D6C27840B406555E2F5091B118FC5
              SHA1:0DCECC1A58CEB4936E255A64A2830956BFA6EC14
              SHA-256:89082FB05229826BC222F5D22C158235F025F0E6DF67FF135A18BD899E13BB8F
              SHA-512:AD53FC0B153005F47F9F4344DF6C4804049FAC94932D895FD02EEBE75222CFE77EEDD9CD3FDC4C88376D18C5972055B00190507AA896488499D64E884F84F093
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"\u0eaa\u0ec9\u0eb2\u0e87\u0ec3\u0edd\u0ec8"},"explanationofflinedisabled":{"message":"\u0e97\u0ec8\u0eb2\u0e99\u0ead\u0ead\u0e9a\u0ea5\u0eb2\u0e8d\u0ea2\u0eb9\u0ec8. \u0ec0\u0e9e\u0eb7\u0ec8\u0ead\u0ec3\u0e8a\u0ec9 Google Docs \u0ec2\u0e94\u0e8d\u0e9a\u0ecd\u0ec8\u0ec0\u0e8a\u0eb7\u0ec8\u0ead\u0ea1\u0e95\u0ecd\u0ec8\u0ead\u0eb4\u0e99\u0ec0\u0e95\u0eb5\u0ec0\u0e99\u0eb1\u0e94, \u0ec3\u0eab\u0ec9\u0ec4\u0e9b\u0e97\u0eb5\u0ec8\u0e81\u0eb2\u0e99\u0e95\u0eb1\u0ec9\u0e87\u0e84\u0ec8\u0eb2\u0ec3\u0e99\u0edc\u0ec9\u0eb2 Google Docs \u0ec1\u0ea5\u0ec9\u0ea7\u0ec0\u0e9b\u0eb5\u0e94\u0ec3\u0e8a\u0ec9\u0e81\u0eb2\u0e99\u0e8a\u0eb4\u0ec9\u0e87\u0ec1\u0e9a\u0e9a\u0ead\u0ead\u0e9a\u0ea5\u0eb2\u0e8d\u0ec3\u0e99\u0ec0\u0e97\u0eb7\u0ec8\u0ead\u0e95\u0ecd\u0ec8\u0ec4\u0e9b\u0e97\u0eb5\u0ec8\u0e97\u0ec8\u0eb2\u0e99\u0ec0\u0e8a\u0eb7\u0ec8\u0ead\u0ea1\u0e95\u0ecd\u0ec8\u0ead\u0eb4\u0e99\u0ec0\u0e95\u0eb5\u0ec0\u0e99\u0eb1\u0e94."},"explanationofflineenabled":{"message":"\u0e97\u0ec
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1028
              Entropy (8bit):4.797571191712988
              Encrypted:false
              SSDEEP:
              MD5:970544AB4622701FFDF66DC556847652
              SHA1:14BEE2B77EE74C5E38EBD1DB09E8D8104CF75317
              SHA-256:5DFCBD4DFEAEC3ABE973A78277D3BD02CD77AE635D5C8CD1F816446C61808F59
              SHA-512:CC12D00C10B970189E90D47390EEB142359A8D6F3A9174C2EF3AE0118F09C88AB9B689D9773028834839A7DFAF3AAC6747BC1DCB23794A9F067281E20B8DC6EA
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "SUKURTI NAUJ.".. },.. "explanationofflinedisabled": {.. "message": "Esate neprisijung.. Jei norite naudoti .Google. dokumentus be interneto ry.io, pagrindiniame .Google. dokument. puslapyje eikite . nustatym. skilt. ir .junkite sinchronizavim. neprisijungus, kai kit. kart. b.site prisijung. prie interneto.".. },.. "explanationofflineenabled": {.. "message": "Esate neprisijung., bet vis tiek galite redaguoti pasiekiamus failus arba sukurti nauj..".. },.. "extdesc": {.. "message": "Redaguokite, kurkite ir per.i.r.kite savo dokumentus, skai.iuokles ir pristatymus . visk. darykite be prieigos prie interneto.".. },.. "extname": {.. "message": ".Google. dokumentai neprisijungus".. },.. "learnmore": {.. "message": "Su.inoti daugiau".. },.. "popuphelptext": {.. "message": "Ra.ykite, redaguokite ir bendradarbiaukite bet kurioje vietoje naudodami interneto ry.. arba
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):994
              Entropy (8bit):4.700308832360794
              Encrypted:false
              SSDEEP:
              MD5:A568A58817375590007D1B8ABCAEBF82
              SHA1:B0F51FE6927BB4975FC6EDA7D8A631BF0C1AB597
              SHA-256:0621DE9161748F45D53052ED8A430962139D7F19074C7FFE7223ECB06B0B87DB
              SHA-512:FCFBADEC9F73975301AB404DB6B09D31457FAC7CCAD2FA5BE348E1CAD6800F87CB5B56DE50880C55BBADB3C40423351A6B5C2D03F6A327D898E35F517B1C628C
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "IZVEIDOT JAUNU".. },.. "explanationofflinedisabled": {.. "message": "J.s esat bezsaist.. Lai lietotu pakalpojumu Google dokumenti bez interneta savienojuma, n.kamaj. reiz., kad ir izveidots savienojums ar internetu, atveriet Google dokumentu s.kumlapas iestat.jumu izv.lni un iesl.dziet sinhroniz.ciju bezsaist..".. },.. "explanationofflineenabled": {.. "message": "J.s esat bezsaist., ta.u varat redi..t pieejamos failus un izveidot jaunus.".. },.. "extdesc": {.. "message": "Redi..jiet, veidojiet un skatiet savus dokumentus, izkl.jlapas un prezent.cijas, neizmantojot savienojumu ar internetu.".. },.. "extname": {.. "message": "Google dokumenti bezsaist.".. },.. "learnmore": {.. "message": "Uzziniet vair.k".. },.. "popuphelptext": {.. "message": "Rakstiet, redi..jiet un sadarbojieties ar interneta savienojumu vai bez t. neatkar.gi no t., kur atrodaties.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2091
              Entropy (8bit):4.358252286391144
              Encrypted:false
              SSDEEP:
              MD5:4717EFE4651F94EFF6ACB6653E868D1A
              SHA1:B8A7703152767FBE1819808876D09D9CC1C44450
              SHA-256:22CA9415E294D9C3EC3384B9D08CDAF5164AF73B4E4C251559E09E529C843EA6
              SHA-512:487EAB4938F6BC47B1D77DD47A5E2A389B94E01D29849E38E96C95CABC7BD98679451F0E22D3FEA25C045558CD69FDDB6C4FEF7C581141F1C53C4AA17578D7F7
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "....... ............".. },.. "explanationofflinedisabled": {.. "message": "...... ........... ........... ............. ..... Google ....... ..........., Google ....... .......... ............. .... ...... ...... ... ............... .................... '.......... ................' .........".. },.. "explanationofflineenabled": {.. "message": "................., .......... ......... ....... ...... ..............
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2778
              Entropy (8bit):3.595196082412897
              Encrypted:false
              SSDEEP:
              MD5:83E7A14B7FC60D4C66BF313C8A2BEF0B
              SHA1:1CCF1D79CDED5D65439266DB58480089CC110B18
              SHA-256:613D8751F6CC9D3FA319F4B7EA8B2BD3BED37FD077482CA825929DD7C12A69A8
              SHA-512:3742E24FFC4B5283E6EE496813C1BDC6835630D006E8647D427C3DE8B8E7BF814201ADF9A27BFAB3ABD130B6FEC64EBB102AC0EB8DEDFE7B63D82D3E1233305D
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"\u0428\u0418\u041d\u0418\u0419\u0413 \u04ae\u04ae\u0421\u0413\u042d\u0425"},"explanationofflinedisabled":{"message":"\u0422\u0430 \u043e\u0444\u043b\u0430\u0439\u043d \u0431\u0430\u0439\u043d\u0430. Google \u0414\u043e\u043a\u044b\u0433 \u0438\u043d\u0442\u0435\u0440\u043d\u044d\u0442\u0433\u04af\u0439\u0433\u044d\u044d\u0440 \u0430\u0448\u0438\u0433\u043b\u0430\u0445\u044b\u043d \u0442\u0443\u043b\u0434 \u0434\u0430\u0440\u0430\u0430\u0433\u0438\u0439\u043d \u0443\u0434\u0430\u0430 \u0438\u043d\u0442\u0435\u0440\u043d\u044d\u0442\u044d\u0434 \u0445\u043e\u043b\u0431\u043e\u0433\u0434\u043e\u0445\u0434\u043e\u043e Google \u0414\u043e\u043a\u044b\u043d \u043d\u04af\u04af\u0440 \u0445\u0443\u0443\u0434\u0430\u0441\u043d\u0430\u0430\u0441 \u0442\u043e\u0445\u0438\u0440\u0433\u043e\u043e \u0434\u043e\u0442\u043e\u0440\u0445 \u043e\u0444\u043b\u0430\u0439\u043d \u0441\u0438\u043d\u043a\u0438\u0439\u0433 \u0438\u0434\u044d\u0432\u0445\u0436\u04af\u04af\u043b\u043d\u0
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1719
              Entropy (8bit):4.287702203591075
              Encrypted:false
              SSDEEP:
              MD5:3B98C4ED8874A160C3789FEAD5553CFA
              SHA1:5550D0EC548335293D962AAA96B6443DD8ABB9F6
              SHA-256:ADEB082A9C754DFD5A9D47340A3DDCC19BF9C7EFA6E629A2F1796305F1C9A66F
              SHA-512:5139B6C6DF9459C7B5CDC08A98348891499408CD75B46519BA3AC29E99AAAFCC5911A1DEE6C3A57E3413DBD0FAE72D7CBC676027248DCE6364377982B5CE4151
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": ".... .... ...".. },.. "explanationofflinedisabled": {.. "message": "...... ...... ..... ......... ....... ....... ..... Google ....... ............, Google ....... .............. .......... .. ... ..... .... ...... ......... ...... ...... ...... .... .... ....".. },.. "explanationofflineenabled": {.. "message": "...... ...... ...., ..... ...... ...... ...... .... ....... ... ..... .... .... ... .....".. },.. "extdesc": {.. "message": "..... ..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):936
              Entropy (8bit):4.457879437756106
              Encrypted:false
              SSDEEP:
              MD5:7D273824B1E22426C033FF5D8D7162B7
              SHA1:EADBE9DBE5519BD60458B3551BDFC36A10049DD1
              SHA-256:2824CF97513DC3ECC261F378BFD595AE95A5997E9D1C63F5731A58B1F8CD54F9
              SHA-512:E5B611BBFAB24C9924D1D5E1774925433C65C322769E1F3B116254B1E9C69B6DF1BE7828141EEBBF7524DD179875D40C1D8F29C4FB86D663B8A365C6C60421A7
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "BUAT BAHARU".. },.. "explanationofflinedisabled": {.. "message": "Anda berada di luar talian. Untuk menggunakan Google Docs tanpa sambungan Internet, pergi ke tetapan di halaman utama Google Docs dan hidupkan penyegerakan luar talian apabila anda disambungkan ke Internet selepas ini.".. },.. "explanationofflineenabled": {.. "message": "Anda berada di luar talian, tetapi anda masih boleh mengedit fail yang tersedia atau buat fail baharu.".. },.. "extdesc": {.. "message": "Edit, buat dan lihat dokumen, hamparan dan pembentangan anda . kesemuanya tanpa akses Internet.".. },.. "extname": {.. "message": "Google Docs Luar Talian".. },.. "learnmore": {.. "message": "Ketahui Lebih Lanjut".. },.. "popuphelptext": {.. "message": "Tulis, edit dan bekerjasama di mana-mana sahaja anda berada, dengan atau tanpa sambungan Internet.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):3830
              Entropy (8bit):3.5483353063347587
              Encrypted:false
              SSDEEP:
              MD5:342335A22F1886B8BC92008597326B24
              SHA1:2CB04F892E430DCD7705C02BF0A8619354515513
              SHA-256:243BEFBD6B67A21433DCC97DC1A728896D3A070DC20055EB04D644E1BB955FE7
              SHA-512:CD344D060E30242E5A4705547E807CE3CE2231EE983BB9A8AD22B3E7598A7EC87399094B04A80245AD51D039370F09D74FE54C0B0738583884A73F0C7E888AD8
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"\u1021\u101e\u1005\u103a \u1015\u103c\u102f\u101c\u102f\u1015\u103a\u101b\u1014\u103a"},"explanationofflinedisabled":{"message":"\u101e\u1004\u103a \u1021\u1031\u102c\u1037\u1016\u103a\u101c\u102d\u102f\u1004\u103a\u1038\u1016\u103c\u1005\u103a\u1014\u1031\u1015\u102b\u101e\u100a\u103a\u104b \u1021\u1004\u103a\u1010\u102c\u1014\u1000\u103a\u1001\u103b\u102d\u1010\u103a\u1006\u1000\u103a\u1019\u103e\u102f \u1019\u101b\u103e\u102d\u1018\u1032 Google Docs \u1000\u102d\u102f \u1021\u101e\u102f\u1036\u1038\u1015\u103c\u102f\u101b\u1014\u103a \u1014\u1031\u102c\u1000\u103a\u1010\u1005\u103a\u1000\u103c\u102d\u1019\u103a \u101e\u1004\u103a\u1021\u1004\u103a\u1010\u102c\u1014\u1000\u103a\u1001\u103b\u102d\u1010\u103a\u1006\u1000\u103a\u101e\u100a\u1037\u103a\u1021\u1001\u102b Google Docs \u1015\u1004\u103a\u1019\u1005\u102c\u1019\u103b\u1000\u103a\u1014\u103e\u102c\u101b\u103e\u102d \u1006\u1000\u103a\u1010\u1004\u103a\u1019\u103b\u102c\u1038\u101e\u102d\u102f\u1037\u1
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1898
              Entropy (8bit):4.187050294267571
              Encrypted:false
              SSDEEP:
              MD5:B1083DA5EC718D1F2F093BD3D1FB4F37
              SHA1:74B6F050D918448396642765DEF1AD5390AB5282
              SHA-256:E6ED0A023EF31705CCCBAF1E07F2B4B2279059296B5CA973D2070417BA16F790
              SHA-512:7102B90ABBE2C811E8EE2F1886A73B1298D4F3D5D05F0FFDB57CF78B9A49A25023A290B255BAA4895BB150B388BAFD9F8432650B8C70A1A9A75083FFFCD74F1A
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": ".... ....... .........".. },.. "explanationofflinedisabled": {.. "message": "..... ...... .......... .... ........ .... .... Google ........ ...... .... ..... ..... ... .......... ....... .... Google ........ .......... ..... .......... .. ...... ..... .... ..... ......... .. ..........".. },.. "explanationofflineenabled": {.. "message": "..... ...... ........., .. ..... ... ... ...... ....... ....... .. .... ....... ....
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):914
              Entropy (8bit):4.513485418448461
              Encrypted:false
              SSDEEP:
              MD5:32DF72F14BE59A9BC9777113A8B21DE6
              SHA1:2A8D9B9A998453144307DD0B700A76E783062AD0
              SHA-256:F3FE1FFCB182183B76E1B46C4463168C746A38E461FD25CA91FF2A40846F1D61
              SHA-512:E0966F5CCA5A8A6D91C58D716E662E892D1C3441DAA5D632E5E843839BB989F620D8AC33ED3EDBAFE18D7306B40CD0C4639E5A4E04DA2C598331DACEC2112AAD
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "NIEUW MAKEN".. },.. "explanationofflinedisabled": {.. "message": "Je bent offline. Wil je Google Documenten zonder internetverbinding gebruiken, ga dan de volgende keer dat je verbinding met internet hebt naar 'Instellingen' op de homepage van Google Documenten en zet 'Offline synchronisatie' aan.".. },.. "explanationofflineenabled": {.. "message": "Je bent offline, maar je kunt nog wel beschikbare bestanden bewerken of nieuwe bestanden maken.".. },.. "extdesc": {.. "message": "Bewerk, maak en bekijk je documenten, spreadsheets en presentaties. Allemaal zonder internettoegang.".. },.. "extname": {.. "message": "Offline Documenten".. },.. "learnmore": {.. "message": "Meer informatie".. },.. "popuphelptext": {.. "message": "Overal schrijven, bewerken en samenwerken, met of zonder internetverbinding.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):878
              Entropy (8bit):4.4541485835627475
              Encrypted:false
              SSDEEP:
              MD5:A1744B0F53CCF889955B95108367F9C8
              SHA1:6A5A6771DFF13DCB4FD425ED839BA100B7123DE0
              SHA-256:21CEFF02B45A4BFD60D144879DFA9F427949A027DD49A3EB0E9E345BD0B7C9A8
              SHA-512:F55E43F14514EECB89F6727A0D3C234149609020A516B193542B5964D2536D192F40CC12D377E70C683C269A1BDCDE1C6A0E634AA84A164775CFFE776536A961
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "OPPRETT NYTT".. },.. "explanationofflinedisabled": {.. "message": "Du er uten nett. For . bruke Google Dokumenter uten internettilkobling, g. til innstillingene p. Google Dokumenter-nettsiden og sl. p. synkronisering uten nett neste gang du er koblet til Internett.".. },.. "explanationofflineenabled": {.. "message": "Du er uten nett, men du kan likevel endre tilgjengelige filer eller opprette nye.".. },.. "extdesc": {.. "message": "Rediger, opprett og se dokumentene, regnearkene og presentasjonene dine . uten nettilgang.".. },.. "extname": {.. "message": "Google Dokumenter uten nett".. },.. "learnmore": {.. "message": "Finn ut mer".. },.. "popuphelptext": {.. "message": "Skriv, rediger eller samarbeid uansett hvor du er, med eller uten internettilkobling.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2766
              Entropy (8bit):3.839730779948262
              Encrypted:false
              SSDEEP:
              MD5:97F769F51B83D35C260D1F8CFD7990AF
              SHA1:0D59A76564B0AEE31D0A074305905472F740CECA
              SHA-256:BBD37D41B7DE6F93948FA2437A7699D4C30A3C39E736179702F212CB36A3133C
              SHA-512:D91F5E2D22FC2D7F73C1F1C4AF79DB98FCFD1C7804069AE9B2348CBC729A6D2DFF7FB6F44D152B0BDABA6E0D05DFF54987E8472C081C4D39315CEC2CBC593816
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"\u0a28\u0a35\u0a3e\u0a02 \u0a2c\u0a23\u0a3e\u0a13"},"explanationofflinedisabled":{"message":"\u0a24\u0a41\u0a38\u0a40\u0a02 \u0a06\u0a2b\u0a3c\u0a32\u0a3e\u0a08\u0a28 \u0a39\u0a4b\u0964 \u0a07\u0a70\u0a1f\u0a30\u0a28\u0a48\u0a71\u0a1f \u0a15\u0a28\u0a48\u0a15\u0a36\u0a28 \u0a26\u0a47 \u0a2c\u0a3f\u0a28\u0a3e\u0a02 Google Docs \u0a28\u0a42\u0a70 \u0a35\u0a30\u0a24\u0a23 \u0a32\u0a08, \u0a05\u0a17\u0a32\u0a40 \u0a35\u0a3e\u0a30 \u0a1c\u0a26\u0a4b\u0a02 \u0a24\u0a41\u0a38\u0a40\u0a02 \u0a07\u0a70\u0a1f\u0a30\u0a28\u0a48\u0a71\u0a1f \u0a26\u0a47 \u0a28\u0a3e\u0a32 \u0a15\u0a28\u0a48\u0a15\u0a1f \u0a39\u0a4b\u0a35\u0a4b \u0a24\u0a3e\u0a02 Google Docs \u0a2e\u0a41\u0a71\u0a16 \u0a2a\u0a70\u0a28\u0a47 '\u0a24\u0a47 \u0a38\u0a48\u0a1f\u0a3f\u0a70\u0a17\u0a3e\u0a02 \u0a35\u0a3f\u0a71\u0a1a \u0a1c\u0a3e\u0a13 \u0a05\u0a24\u0a47 \u0a06\u0a2b\u0a3c\u0a32\u0a3e\u0a08\u0a28 \u0a38\u0a3f\u0a70\u0a15 \u0a28\u0a42\u0a70 \u0a1a\u0a3e\u0a32\u0a42 \u0a15\u0a30\u0a4b\u0964"},"expla
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):978
              Entropy (8bit):4.879137540019932
              Encrypted:false
              SSDEEP:
              MD5:B8D55E4E3B9619784AECA61BA15C9C0F
              SHA1:B4A9C9885FBEB78635957296FDDD12579FEFA033
              SHA-256:E00FF20437599A5C184CA0C79546CB6500171A95E5F24B9B5535E89A89D3EC3D
              SHA-512:266589116EEE223056391C65808255EDAE10EB6DC5C26655D96F8178A41E283B06360AB8E08AC3857D172023C4F616EF073D0BEA770A3B3DD3EE74F5FFB2296B
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "UTW.RZ NOWY".. },.. "explanationofflinedisabled": {.. "message": "Jeste. offline. Aby korzysta. z Dokument.w Google bez po..czenia internetowego, otw.rz ustawienia na stronie g..wnej Dokument.w Google i w..cz synchronizacj. offline nast.pnym razem, gdy b.dziesz mie. dost.p do internetu.".. },.. "explanationofflineenabled": {.. "message": "Jeste. offline, ale nadal mo.esz edytowa. dost.pne pliki i tworzy. nowe.".. },.. "extdesc": {.. "message": "Edytuj, tw.rz i wy.wietlaj swoje dokumenty, arkusze kalkulacyjne oraz prezentacje bez konieczno.ci ..czenia si. z internetem.".. },.. "extname": {.. "message": "Dokumenty Google offline".. },.. "learnmore": {.. "message": "Wi.cej informacji".. },.. "popuphelptext": {.. "message": "Pisz, edytuj i wsp..pracuj, gdziekolwiek jeste. . niezale.nie od tego, czy masz po..czenie z internetem.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):907
              Entropy (8bit):4.599411354657937
              Encrypted:false
              SSDEEP:
              MD5:608551F7026E6BA8C0CF85D9AC11F8E3
              SHA1:87B017B2D4DA17E322AF6384F82B57B807628617
              SHA-256:A73EEA087164620FA2260D3910D3FBE302ED85F454EDB1493A4F287D42FC882F
              SHA-512:82F52F8591DB3C0469CC16D7CBFDBF9116F6D5B5D2AD02A3D8FA39CE1378C64C0EA80AB8509519027F71A89EB8BBF38A8702D9AD26C8E6E0F499BF7DA18BF747
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "CRIAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Voc. est. off-line. Para usar o Documentos Google sem conex.o com a Internet, na pr.xima vez que se conectar, acesse as configura..es na p.gina inicial do Documentos Google e ative a sincroniza..o off-line.".. },.. "explanationofflineenabled": {.. "message": "Voc. est. off-line, mas mesmo assim pode editar os arquivos dispon.veis ou criar novos arquivos.".. },.. "extdesc": {.. "message": "Edite, crie e veja seus documentos, planilhas e apresenta..es sem precisar de acesso . Internet.".. },.. "extname": {.. "message": "Documentos Google off-line".. },.. "learnmore": {.. "message": "Saiba mais".. },.. "popuphelptext": {.. "message": "Escreva, edite e colabore onde voc. estiver, com ou sem conex.o com a Internet.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):914
              Entropy (8bit):4.604761241355716
              Encrypted:false
              SSDEEP:
              MD5:0963F2F3641A62A78B02825F6FA3941C
              SHA1:7E6972BEAB3D18E49857079A24FB9336BC4D2D48
              SHA-256:E93B8E7FB86D2F7DFAE57416BB1FB6EE0EEA25629B972A5922940F0023C85F90
              SHA-512:22DD42D967124DA5A2209DD05FB6AD3F5D0D2687EA956A22BA1E31C56EC09DEB53F0711CD5B24D672405358502E9D1C502659BB36CED66CAF83923B021CA0286
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "CRIAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Est. offline. Para utilizar o Google Docs sem uma liga..o . Internet, aceda .s defini..es na p.gina inicial do Google Docs e ative a sincroniza..o offline da pr.xima vez que estiver ligado . Internet.".. },.. "explanationofflineenabled": {.. "message": "Est. offline, mas continua a poder editar os ficheiros dispon.veis ou criar novos ficheiros.".. },.. "extdesc": {.. "message": "Edite, crie e veja os documentos, as folhas de c.lculo e as apresenta..es, tudo sem precisar de aceder . Internet.".. },.. "extname": {.. "message": "Google Docs offline".. },.. "learnmore": {.. "message": "Saber mais".. },.. "popuphelptext": {.. "message": "Escreva edite e colabore onde quer que esteja, com ou sem uma liga..o . Internet.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):937
              Entropy (8bit):4.686555713975264
              Encrypted:false
              SSDEEP:
              MD5:BED8332AB788098D276B448EC2B33351
              SHA1:6084124A2B32F386967DA980CBE79DD86742859E
              SHA-256:085787999D78FADFF9600C9DC5E3FF4FB4EB9BE06D6BB19DF2EEF8C284BE7B20
              SHA-512:22596584D10707CC1C8179ED3ABE46EF2C314CF9C3D0685921475944B8855AAB660590F8FA1CFDCE7976B4BB3BD9ABBBF053F61F1249A325FD0094E1C95692ED
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "CREEAZ. UN DOCUMENT".. },.. "explanationofflinedisabled": {.. "message": "E.ti offline. Pentru a utiliza Documente Google f.r. conexiune la internet, intr. .n set.rile din pagina principal. Documente Google .i activeaz. sincronizarea offline data viitoare c.nd e.ti conectat(.) la internet.".. },.. "explanationofflineenabled": {.. "message": "E.ti offline, dar po.i .nc. s. editezi fi.ierele disponibile sau s. creezi altele.".. },.. "extdesc": {.. "message": "Editeaz., creeaz. .i acceseaz. documente, foi de calcul .i prezent.ri - totul f.r. acces la internet.".. },.. "extname": {.. "message": "Documente Google Offline".. },.. "learnmore": {.. "message": "Afl. mai multe".. },.. "popuphelptext": {.. "message": "Scrie, editeaz. .i colaboreaz. oriunde ai fi, cu sau f.r. conexiune la internet.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1337
              Entropy (8bit):4.69531415794894
              Encrypted:false
              SSDEEP:
              MD5:51D34FE303D0C90EE409A2397FCA437D
              SHA1:B4B9A7B19C62D0AA95D1F10640A5FBA628CCCA12
              SHA-256:BE733625ACD03158103D62BC0EEF272CA3F265AC30C87A6A03467481A177DAE3
              SHA-512:E8670DED44DC6EE30E5F41C8B2040CF8A463CD9A60FC31FA70EB1D4C9AC1A3558369792B5B86FA761A21F5266D5A35E5C2C39297F367DAA84159585C19EC492A
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": ".......".. },.. "explanationofflinedisabled": {.. "message": "..... ............ Google ......... ... ........., ............ . .... . ......... ............. . ......-...... . .......... .. ......... .........".. },.. "explanationofflineenabled": {.. "message": "... ........... . .......... .. ...... ......... ..... ..... . ............. .., . ....... ........ ......-.......".. },.. "extdesc": {.. "message": ".........., .............. . ............ ........., ....... . ........... ... ....... . ..........".. },.. "extname": {.. "message": "Google.......... ......".. },.. "learnmore": {.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2846
              Entropy (8bit):3.7416822879702547
              Encrypted:false
              SSDEEP:
              MD5:B8A4FD612534A171A9A03C1984BB4BDD
              SHA1:F513F7300827FE352E8ECB5BD4BB1729F3A0E22A
              SHA-256:54241EBE651A8344235CC47AFD274C080ABAEBC8C3A25AFB95D8373B6A5670A2
              SHA-512:C03E35BFDE546AEB3245024EF721E7E606327581EFE9EAF8C5B11989D9033BDB58437041A5CB6D567BAA05466B6AAF054C47F976FD940EEEDF69FDF80D79095B
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"\u0db1\u0dc0 \u0dbd\u0dda\u0d9b\u0db1\u0dba\u0d9a\u0dca \u0dc3\u0dcf\u0daf\u0db1\u0dca\u0db1"},"explanationofflinedisabled":{"message":"\u0d94\u0db6 \u0db1\u0ddc\u0db6\u0dd0\u0db3\u0dd2\u0dba. \u0d85\u0db1\u0dca\u0dad\u0dbb\u0dca\u0da2\u0dcf\u0dbd \u0dc3\u0db8\u0dca\u0db6\u0db1\u0dca\u0db0\u0dad\u0dcf\u0dc0\u0d9a\u0dca \u0db1\u0ddc\u0db8\u0dd0\u0dad\u0dd2\u0dc0 Google Docs \u0db7\u0dcf\u0dc0\u0dd2\u0dad \u0d9a\u0dd2\u0dbb\u0dd3\u0db8\u0da7, Google Docs \u0db8\u0dd4\u0dbd\u0dca \u0db4\u0dd2\u0da7\u0dd4\u0dc0 \u0db8\u0dad \u0dc3\u0dd0\u0d9a\u0dc3\u0dd3\u0db8\u0dca \u0dc0\u0dd9\u0dad \u0d9c\u0ddc\u0dc3\u0dca \u0d94\u0db6 \u0d8a\u0dc5\u0d9f \u0d85\u0dc0\u0dc3\u0dca\u0dae\u0dcf\u0dc0\u0dda \u0d85\u0db1\u0dca\u0dad\u0dbb\u0dca\u0da2\u0dcf\u0dbd\u0dba\u0da7 \u0dc3\u0db6\u0dd0\u0db3\u0dd2 \u0dc0\u0dd2\u0da7 \u0db1\u0ddc\u0db6\u0dd0\u0db3\u0dd2 \u0dc3\u0db8\u0db8\u0dd4\u0dc4\u0dd4\u0dbb\u0dca\u0dad \u0d9a\u0dd2\u0dbb\u0dd3\u0db8 \u0d9a\u0dca\u200d\u0dbb\u0dd2\u0dba\u0dc
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):934
              Entropy (8bit):4.882122893545996
              Encrypted:false
              SSDEEP:
              MD5:8E55817BF7A87052F11FE554A61C52D5
              SHA1:9ABDC0725FE27967F6F6BE0DF5D6C46E2957F455
              SHA-256:903060EC9E76040B46DEB47BBB041D0B28A6816CB9B892D7342FC7DC6782F87C
              SHA-512:EFF9EC7E72B272DDE5F29123653BC056A4BC2C3C662AE3C448F8CB6A4D1865A0679B7E74C1B3189F3E262109ED6BC8F8D2BDE14AEFC8E87E0F785AE4837D01C7
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "VYTVORI. NOV.".. },.. "explanationofflinedisabled": {.. "message": "Ste offline. Ak chcete pou.i. Dokumenty Google bez pripojenia na internet, po najbli..om pripojen. na internet prejdite do nastaven. na domovskej str.nke Dokumentov Google a.zapnite offline synchroniz.ciu.".. },.. "explanationofflineenabled": {.. "message": "Ste offline, no st.le m..ete upravova. dostupn. s.bory a.vytv.ra. nov..".. },.. "extdesc": {.. "message": ".prava, tvorba a.zobrazenie dokumentov, tabuliek a.prezent.ci.. To v.etko bez pr.stupu na internet.".. },.. "extname": {.. "message": "Dokumenty Google v re.ime offline".. },.. "learnmore": {.. "message": ".al.ie inform.cie".. },.. "popuphelptext": {.. "message": "P..te, upravujte a.spolupracuje, kdeko.vek ste, a.to s.pripojen.m na internet aj bez neho.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):963
              Entropy (8bit):4.6041913416245
              Encrypted:false
              SSDEEP:
              MD5:BFAEFEFF32813DF91C56B71B79EC2AF4
              SHA1:F8EDA2B632610972B581724D6B2F9782AC37377B
              SHA-256:AAB9CF9098294A46DC0F2FA468AFFF7CA7C323A1A0EFA70C9DB1E3A4DA05D1D4
              SHA-512:971F2BBF5E9C84DE3D31E5F2A4D1A00D891A2504F8AF6D3F75FC19056BFD059A270C4C9836AF35258ABA586A1888133FB22B484F260C1CBC2D1D17BC3B4451AA
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "USTVARI NOVO".. },.. "explanationofflinedisabled": {.. "message": "Nimate vzpostavljene povezave. .e .elite uporabljati Google Dokumente brez internetne povezave, odprite nastavitve na doma.i strani Google Dokumentov in vklopite sinhronizacijo brez povezave, ko naslednji. vzpostavite internetno povezavo.".. },.. "explanationofflineenabled": {.. "message": "Nimate vzpostavljene povezave, vendar lahko .e vedno urejate razpolo.ljive datoteke ali ustvarjate nove.".. },.. "extdesc": {.. "message": "Urejajte, ustvarjajte in si ogledujte dokumente, preglednice in predstavitve . vse to brez internetnega dostopa.".. },.. "extname": {.. "message": "Google Dokumenti brez povezave".. },.. "learnmore": {.. "message": "Ve. o tem".. },.. "popuphelptext": {.. "message": "Pi.ite, urejajte in sodelujte, kjer koli ste, z internetno povezavo ali brez nje.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1320
              Entropy (8bit):4.569671329405572
              Encrypted:false
              SSDEEP:
              MD5:7F5F8933D2D078618496C67526A2B066
              SHA1:B7050E3EFA4D39548577CF47CB119FA0E246B7A4
              SHA-256:4E8B69E864F57CDDD4DC4E4FAF2C28D496874D06016BC22E8D39E0CB69552769
              SHA-512:0FBAB56629368EEF87DEEF2977CA51831BEB7DEAE98E02504E564218425C751853C4FDEAA40F51ECFE75C633128B56AE105A6EB308FD5B4A2E983013197F5DBA
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "....... ....".. },.. "explanationofflinedisabled": {.. "message": "...... .... .. ..... ......... Google ......... ... ........ ...., ..... . .......... .. ........ ........ Google .......... . ........ ...... .............. ... ....... ... ...... ........ .. ...........".. },.. "explanationofflineenabled": {.. "message": "...... ..., ... . .... ...... .. ....... ...... . ........ ........ ... .. ....... .....".. },.. "extdesc": {.. "message": "....... . ........... ........., ...... . ............ . ....... ...... . ... . ... .. ... ........ .........".. },.. "extname": {.. "message
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):884
              Entropy (8bit):4.627108704340797
              Encrypted:false
              SSDEEP:
              MD5:90D8FB448CE9C0B9BA3D07FB8DE6D7EE
              SHA1:D8688CAC0245FD7B886D0DEB51394F5DF8AE7E84
              SHA-256:64B1E422B346AB77C5D1C77142685B3FF7661D498767D104B0C24CB36D0EB859
              SHA-512:6D58F49EE3EF0D3186EA036B868B2203FE936CE30DC8E246C32E90B58D9B18C624825419346B62AF8F7D61767DBE9721957280AA3C524D3A5DFB1A3A76C00742
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "SKAPA NYTT".. },.. "explanationofflinedisabled": {.. "message": "Du .r offline. Om du vill anv.nda Google Dokument utan internetuppkoppling, .ppna inst.llningarna p. Google Dokuments startsida och aktivera offlinesynkronisering n.sta g.ng du .r ansluten till internet.".. },.. "explanationofflineenabled": {.. "message": "Du .r offline, men det g.r fortfarande att redigera tillg.ngliga filer eller skapa nya.".. },.. "extdesc": {.. "message": "Redigera, skapa och visa dina dokument, kalkylark och presentationer . helt utan internet.tkomst.".. },.. "extname": {.. "message": "Google Dokument Offline".. },.. "learnmore": {.. "message": "L.s mer".. },.. "popuphelptext": {.. "message": "Skriv, redigera och samarbeta .verallt, med eller utan internetanslutning.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):980
              Entropy (8bit):4.50673686618174
              Encrypted:false
              SSDEEP:
              MD5:D0579209686889E079D87C23817EDDD5
              SHA1:C4F99E66A5891973315D7F2BC9C1DAA524CB30DC
              SHA-256:0D20680B74AF10EF8C754FCDE259124A438DCE3848305B0CAF994D98E787D263
              SHA-512:D59911F91ED6C8FF78FD158389B4D326DAF4C031B940C399569FE210F6985E23897E7F404B7014FC7B0ACEC086C01CC5F76354F7E5D3A1E0DEDEF788C23C2978
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "FUNGUA MPYA".. },.. "explanationofflinedisabled": {.. "message": "Haupo mtandaoni. Ili uweze kutumia Hati za Google bila muunganisho wa intaneti, wakati utakuwa umeunganishwa kwenye intaneti, nenda kwenye sehemu ya mipangilio kwenye ukurasa wa kwanza wa Hati za Google kisha uwashe kipengele cha usawazishaji nje ya mtandao.".. },.. "explanationofflineenabled": {.. "message": "Haupo mtandaoni, lakini bado unaweza kubadilisha faili zilizopo au uunde mpya.".. },.. "extdesc": {.. "message": "Badilisha, unda na uangalie hati, malahajedwali na mawasilisho yako . yote bila kutumia muunganisho wa intaneti.".. },.. "extname": {.. "message": "Hati za Google Nje ya Mtandao".. },.. "learnmore": {.. "message": "Pata Maelezo Zaidi".. },.. "popuphelptext": {.. "message": "Andika hati, zibadilishe na ushirikiane na wengine popote ulipo, iwe una muunganisho wa intaneti au huna.".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1941
              Entropy (8bit):4.132139619026436
              Encrypted:false
              SSDEEP:
              MD5:DCC0D1725AEAEAAF1690EF8053529601
              SHA1:BB9D31859469760AC93E84B70B57909DCC02EA65
              SHA-256:6282BF9DF12AD453858B0B531C8999D5FD6251EB855234546A1B30858462231A
              SHA-512:6243982D764026D342B3C47C706D822BB2B0CAFFA51F0591D8C878F981EEF2A7FC68B76D012630B1C1EB394AF90EB782E2B49329EB6538DD5608A7F0791FDCF5
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "..... ....... .........".. },.. "explanationofflinedisabled": {.. "message": ".......... ........... .... ....... ..... Google ......... .........., ...... .... ........... ......... ...., Google ... ................... ................ ......, ........ ......... ..........".. },.. "explanationofflineenabled": {.. "message": ".......... ..........., .......... .......... .......... ......... ........... ...... .....
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1969
              Entropy (8bit):4.327258153043599
              Encrypted:false
              SSDEEP:
              MD5:385E65EF723F1C4018EEE6E4E56BC03F
              SHA1:0CEA195638A403FD99BAEF88A360BD746C21DF42
              SHA-256:026C164BAE27DBB36A564888A796AA3F188AAD9E0C37176D48910395CF772CEA
              SHA-512:E55167CB5638E04DF3543D57C8027B86B9483BFCAFA8E7C148EDED66454AEBF554B4C1CF3C33E93EC63D73E43800D6A6E7B9B1A1B0798B6BDB2F699D3989B052
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "..... ...... ........ ......".. },.. "explanationofflinedisabled": {.. "message": ".... ........... ........ ......... ........ ....... Google Docs... .............., .... ............ ....... ..... ...... .... Google Docs .... ...... ............. ......, ........ ........ ... .......".. },.. "explanationofflineenabled": {.. "message": ".... ........... ......., .... .... ........ .......... .... ....... ..... ....... .... ..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1674
              Entropy (8bit):4.343724179386811
              Encrypted:false
              SSDEEP:
              MD5:64077E3D186E585A8BEA86FF415AA19D
              SHA1:73A861AC810DABB4CE63AD052E6E1834F8CA0E65
              SHA-256:D147631B2334A25B8AA4519E4A30FB3A1A85B6A0396BC688C68DC124EC387D58
              SHA-512:56DD389EB9DD335A6214E206B3BF5D63562584394D1DE1928B67D369E548477004146E6CB2AD19D291CB06564676E2B2AC078162356F6BC9278B04D29825EF0C
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": ".........".. },.. "explanationofflinedisabled": {.. "message": ".............. ............. Google .................................... ............................... Google ...... .................................................................".. },.. "explanationofflineenabled": {.. "message": "................................................................".. },.. "extdesc": {.. "message": "..... ..... ........
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1063
              Entropy (8bit):4.853399816115876
              Encrypted:false
              SSDEEP:
              MD5:76B59AAACC7B469792694CF3855D3F4C
              SHA1:7C04A2C1C808FA57057A4CCEEE66855251A3C231
              SHA-256:B9066A162BEE00FD50DC48C71B32B69DFFA362A01F84B45698B017A624F46824
              SHA-512:2E507CA6874DE8028DC769F3D9DFD9E5494C268432BA41B51568D56F7426F8A5F2E5B111DDD04259EB8D9A036BB4E3333863A8FC65AAB793BCEF39EDFE41403B
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "YEN. OLU.TUR".. },.. "explanationofflinedisabled": {.. "message": ".nternet'e ba.l. de.ilsiniz. Google Dok.manlar'. .nternet ba.lant.s. olmadan kullanmak i.in, .nternet'e ba.lanabildi.inizde Google Dok.manlar ana sayfas.nda Ayarlar'a gidin ve .evrimd... senkronizasyonu etkinle.tirin.".. },.. "explanationofflineenabled": {.. "message": ".nternet'e ba.l. de.ilsiniz. Ancak, yine de mevcut dosyalar. d.zenleyebilir veya yeni dosyalar olu.turabilirsiniz.".. },.. "extdesc": {.. "message": "Dok.man, e-tablo ve sunu olu.turun, bunlar. d.zenleyin ve g.r.nt.leyin. T.m bu i.lemleri internet eri.imi olmadan yapabilirsiniz.".. },.. "extname": {.. "message": "Google Dok.manlar .evrimd...".. },.. "learnmore": {.. "message": "Daha Fazla Bilgi".. },.. "popuphelptext": {.. "message": ".nternet ba.lant.n.z olsun veya olmas.n, nerede olursan.z olun yaz.n, d.zenl
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1333
              Entropy (8bit):4.686760246306605
              Encrypted:false
              SSDEEP:
              MD5:970963C25C2CEF16BB6F60952E103105
              SHA1:BBDDACFEEE60E22FB1C130E1EE8EFDA75EA600AA
              SHA-256:9FA26FF09F6ACDE2457ED366C0C4124B6CAC1435D0C4FD8A870A0C090417DA19
              SHA-512:1BED9FE4D4ADEED3D0BC8258D9F2FD72C6A177C713C3B03FC6F5452B6D6C2CB2236C54EA972ECE7DBFD756733805EB2352CAE44BAB93AA8EA73BB80460349504
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "........".. },.. "explanationofflinedisabled": {.. "message": ".. . ...... ....... ... ............. Google ........... ... ......... . .........., ......... . ............ .. ........ ........ Google .......... . ......... ......-............., .... ...... . .......".. },.. "explanationofflineenabled": {.. "message": ".. . ...... ......, ..... ... .... ...... .......... ........ ..... ... .......... .....".. },.. "extdesc": {.. "message": "........., ......... . ............ ........., .......... ....... .. ........... ... ....... .. ..........".. },.. "extname": {.. "message": "Goo
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1263
              Entropy (8bit):4.861856182762435
              Encrypted:false
              SSDEEP:
              MD5:8B4DF6A9281333341C939C244DDB7648
              SHA1:382C80CAD29BCF8AAF52D9A24CA5A6ECF1941C6B
              SHA-256:5DA836224D0F3A96F1C5EB5063061AAD837CA9FC6FED15D19C66DA25CF56F8AC
              SHA-512:FA1C015D4EA349F73468C78FDB798D462EEF0F73C1A762298798E19F825E968383B0A133E0A2CE3B3DF95F24C71992235BFC872C69DC98166B44D3183BF8A9E5
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "... ......".. },.. "explanationofflinedisabled": {.. "message": ".. .. .... .... Google Docs .. .... ....... ..... ....... .... ..... .... ... .. .. ....... .. ..... ... .. Google Docs ... ... .. ....... .. ..... ... .. .... ...... ..... .. .. .....".. },.. "explanationofflineenabled": {.. "message": ".. .. .... ... .... .. ... ... ...... ..... ... ..... .. .... ... .. ... ..... ... .... ....".. },.. "extdesc": {.. "message": ".......... .......... ... ....... . .... ... ....... .. ..... .. .... ...... ..... .... ... ..... .......".. },.. "extname": {.. "message": "Google Docs .. ....".. },.. "learnmore": {..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1074
              Entropy (8bit):5.062722522759407
              Encrypted:false
              SSDEEP:
              MD5:773A3B9E708D052D6CBAA6D55C8A5438
              SHA1:5617235844595D5C73961A2C0A4AC66D8EA5F90F
              SHA-256:597C5F32BC999746BC5C2ED1E5115C523B7EB1D33F81B042203E1C1DF4BBCAFE
              SHA-512:E5F906729E38B23F64D7F146FA48F3ABF6BAED9AAFC0E5F6FA59F369DC47829DBB4BFA94448580BD61A34E844241F590B8D7AEC7091861105D8EBB2590A3BEE9
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "T.O M.I".. },.. "explanationofflinedisabled": {.. "message": "B.n .ang ngo.i tuy.n. .. s. d.ng Google T.i li.u m. kh.ng c.n k.t n.i Internet, .i ..n c.i ..t tr.n trang ch. c.a Google T.i li.u v. b.t ..ng b. h.a ngo.i tuy.n v.o l.n ti.p theo b.n ...c k.t n.i v.i m.ng Internet.".. },.. "explanationofflineenabled": {.. "message": "B.n .ang ngo.i tuy.n, tuy nhi.n b.n v.n c. th. ch.nh s.a c.c t.p c. s.n ho.c t.o c.c t.p m.i.".. },.. "extdesc": {.. "message": "Ch.nh s.a, t.o v. xem t.i li.u, b.ng t.nh v. b.n tr.nh b.y . t.t c. m. kh.ng c.n truy c.p Internet.".. },.. "extname": {.. "message": "Google T.i li.u ngo.i tuy.n".. },.. "learnmore": {.. "message": "Ti.m hi..u th.m".. },.. "popuphelptext": {.. "message": "Vi.t, ch.nh s.a v. c.ng t.c
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):879
              Entropy (8bit):5.7905809868505544
              Encrypted:false
              SSDEEP:
              MD5:3E76788E17E62FB49FB5ED5F4E7A3DCE
              SHA1:6904FFA0D13D45496F126E58C886C35366EFCC11
              SHA-256:E72D0BB08CC3005556E95A498BD737E7783BB0E56DCC202E7D27A536616F5EE0
              SHA-512:F431E570AB5973C54275C9EEF05E49E6FE2D6C17000F98D672DD31F9A1FAD98E0D50B5B0B9CF85D5BBD3B655B93FD69768C194C8C1688CB962AA75FF1AF9BDB6
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": "..".. },.. "explanationofflinedisabled": {.. "message": "....................... Google ................ Google ....................".. },.. "explanationofflineenabled": {.. "message": ".............................".. },.. "extdesc": {.. "message": "...................... - ........".. },.. "extname": {.. "message": "Google .......".. },.. "learnmore": {.. "message": "....".. },.. "popuphelptext": {.. "message": "...............................".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1205
              Entropy (8bit):4.50367724745418
              Encrypted:false
              SSDEEP:
              MD5:524E1B2A370D0E71342D05DDE3D3E774
              SHA1:60D1F59714F9E8F90EF34138D33FBFF6DD39E85A
              SHA-256:30F44CFAD052D73D86D12FA20CFC111563A3B2E4523B43F7D66D934BA8DACE91
              SHA-512:D2225CF2FA94B01A7B0F70A933E1FDCF69CDF92F76C424CE4F9FCC86510C481C9A87A7B71F907C836CBB1CA41A8BEBBD08F68DBC90710984CA738D293F905272
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"\u5efa\u7acb\u65b0\u9805\u76ee"},"explanationofflinedisabled":{"message":"\u60a8\u8655\u65bc\u96e2\u7dda\u72c0\u614b\u3002\u5982\u8981\u5728\u6c92\u6709\u4e92\u806f\u7db2\u9023\u7dda\u7684\u60c5\u6cc1\u4e0b\u4f7f\u7528\u300cGoogle \u6587\u4ef6\u300d\uff0c\u8acb\u524d\u5f80\u300cGoogle \u6587\u4ef6\u300d\u9996\u9801\u7684\u8a2d\u5b9a\uff0c\u4e26\u5728\u4e0b\u6b21\u9023\u63a5\u4e92\u806f\u7db2\u6642\u958b\u555f\u96e2\u7dda\u540c\u6b65\u529f\u80fd\u3002"},"explanationofflineenabled":{"message":"\u60a8\u8655\u65bc\u96e2\u7dda\u72c0\u614b\uff0c\u4f46\u60a8\u4ecd\u53ef\u4ee5\u7de8\u8f2f\u53ef\u7528\u6a94\u6848\u6216\u5efa\u7acb\u65b0\u6a94\u6848\u3002"},"extdesc":{"message":"\u7de8\u8f2f\u3001\u5efa\u7acb\u53ca\u67e5\u770b\u60a8\u7684\u6587\u4ef6\u3001\u8a66\u7b97\u8868\u548c\u7c21\u5831\uff0c\u5b8c\u5168\u4e0d\u9700\u4f7f\u7528\u4e92\u806f\u7db2\u3002"},"extname":{"message":"\u300cGoogle \u6587\u4ef6\u300d\u96e2\u7dda\u7248"},"learnmore":{"message":"\u77ad\u89e3\u8a
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):843
              Entropy (8bit):5.76581227215314
              Encrypted:false
              SSDEEP:
              MD5:0E60627ACFD18F44D4DF469D8DCE6D30
              SHA1:2BFCB0C3CA6B50D69AD5745FA692BAF0708DB4B5
              SHA-256:F94C6DDEDF067642A1AF18D629778EC65E02B6097A8532B7E794502747AEB008
              SHA-512:6FF517EED4381A61075AC7C8E80C73FAFAE7C0583BA4FA7F4951DD7DBE183C253702DEE44B3276EFC566F295DAC1592271BE5E0AC0C7D2C9F6062054418C7C27
              Malicious:false
              Reputation:low
              Preview:{.. "createnew": {.. "message": ".....".. },.. "explanationofflinedisabled": {.. "message": ".................. Google ................ Google .................".. },.. "explanationofflineenabled": {.. "message": ".........................".. },.. "extdesc": {.. "message": ".............................".. },.. "extname": {.. "message": "Google .....".. },.. "learnmore": {.. "message": "....".. },.. "popuphelptext": {.. "message": "................................".. }..}..
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):912
              Entropy (8bit):4.65963951143349
              Encrypted:false
              SSDEEP:
              MD5:71F916A64F98B6D1B5D1F62D297FDEC1
              SHA1:9386E8F723C3F42DA5B3F7E0B9970D2664EA0BAA
              SHA-256:EC78DDD4CCF32B5D76EC701A20167C3FBD146D79A505E4FB0421FC1E5CF4AA63
              SHA-512:30FA4E02120AF1BE6E7CC7DBB15FAE5D50825BD6B3CF28EF21D2F2E217B14AF5B76CFCC165685C3EDC1D09536BFCB10CA07E1E2CC0DA891CEC05E19394AD7144
              Malicious:false
              Reputation:low
              Preview:{"createnew":{"message":"DALA ENTSHA"},"explanationofflinedisabled":{"message":"Awuxhunyiwe ku-inthanethi. Ukuze usebenzise i-Google Amadokhumenti ngaphandle koxhumano lwe-inthanethi, iya kokuthi izilungiselelo ekhasini lasekhaya le-Google Amadokhumenti bese uvula ukuvumelanisa okungaxhunyiwe ku-inthanethi ngesikhathi esilandelayo lapho uxhunywe ku-inthanethi."},"explanationofflineenabled":{"message":"Awuxhunyiwe ku-inthanethi, kodwa usangakwazi ukuhlela amafayela atholakalayo noma udale amasha."},"extdesc":{"message":"Hlela, dala, futhi ubuke amadokhumenti akho, amaspredishithi, namaphrezentheshini \u2014 konke ngaphandle kokufinyelela kwe-inthanethi."},"extname":{"message":"I-Google Amadokhumenti engaxhumekile ku-intanethi"},"learnmore":{"message":"Funda kabanzi"},"popuphelptext":{"message":"Bhala, hlela, futhi hlanganyela noma yikuphi lapho okhona, unalo noma ungenalo uxhumano lwe-inthanethi."}}.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):18518
              Entropy (8bit):5.7097772112154646
              Encrypted:false
              SSDEEP:
              MD5:2DC758B77A5496DAB488A0ABD71D4893
              SHA1:C0F2B401A8E68FB6F2C8D6CC8AF2167188C92D92
              SHA-256:D05B97CFF25B0DC4DE9DDABE8A08671BDDC64F0ADFE549BFE53B0C9801C8FBDB
              SHA-512:1BB43A1B470ECA32BF0266E5535B1791F473E2715E16D6D6139F5C359B8BD6E5981FE7DF6CBFA51EAE68C6B5F95A139F59C0ECCB986AEA37F634D722B4CF8546
              Malicious:false
              Reputation:low
              Preview:[{"description":"treehash per file","signed_content":{"payload":"eyJjb250ZW50X2hhc2hlcyI6W3siYmxvY2tfc2l6ZSI6NDA5NiwiZGlnZXN0Ijoic2hhMjU2IiwiZmlsZXMiOlt7InBhdGgiOiIxMjgucG5nIiwicm9vdF9oYXNoIjoiZ2NWZy0xWWgySktRNVFtUmtjZGNmamU1dzVIc1JNN1ZCTmJyaHJ4eGZ5ZyJ9LHsiY2Fub25pY2FsX2pzb25fcm9vdF9oYXNoIjoiOE1xa2JXMkFQWkVpbzlQTHlYNVItT3o1bGs5a29sbnlWTWtvYlVabk15YyIsInBhdGgiOiJfbG9jYWxlcy9hZi9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoicWhJZ1d4Q0hVTS1mb0plRVlhYllpQjVPZ05vZ3FFYllKTnBBYWRuSkdFYyJ9LHsiY2Fub25pY2FsX2pzb25fcm9vdF9oYXNoIjoiV0E0cW96b3R5ZzJrcUpKU0FEYWNVMGNDbEdJYjlmMmp1ejhYalh0YUhybyIsInBhdGgiOiJfbG9jYWxlcy9hbS9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoiWk9BYndwSzZMcUZwbFhiOHhFVTJjRWRTRHVpVjRwRE03aURDVEpNMjJPOCJ9LHsiY2Fub25pY2FsX2pzb25fcm9vdF9oYXNoIjoiQlk4QVRlUUktWHNqLWFSbVZfTi03dHVzUlJyQUNkU25yU3NhT2d3R3pTWSIsInBhdGgiOiJfbG9jYWxlcy9hci9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoiUjJVaEZjdTVFcEJfUUZtU19QeGstWWRrSVZqd3l6WEoxdURVZEMyRE9BSSJ9LHsiY2Fub25pY2FsX2pzb25fcm9vdF9oYXNoIjoiX0pLU3pRcGk4TVczZE5WZldwN281STVjX09
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):854
              Entropy (8bit):4.284628987131403
              Encrypted:false
              SSDEEP:
              MD5:4EC1DF2DA46182103D2FFC3B92D20CA5
              SHA1:FB9D1BA3710CF31A87165317C6EDC110E98994CE
              SHA-256:6C69CE0FE6FAB14F1990A320D704FEE362C175C00EB6C9224AA6F41108918CA6
              SHA-512:939D81E6A82B10FF73A35C931052D8D53D42D915E526665079EEB4820DF4D70F1C6AEBAB70B59519A0014A48514833FEFD687D5A3ED1B06482223A168292105D
              Malicious:false
              Reputation:low
              Preview:{. "type": "object",. "properties": {. "allowedDocsOfflineDomains": {. "type": "array",. "items": {. "type": "string". },. "title": "Allow users to enable Docs offline for the specified managed domains.",. "description": "Users on managed devices will be able to enable docs offline if they are part of the specified managed domains.". },. "autoEnabledDocsOfflineDomains": {. "type": "array",. "items": {. "type": "string". },. "title": "Auto enable Docs offline for the specified managed domains in certain eligible situations.",. "description": "Users on managed devices, in certain eligible situations, will be able to automatically access and edit recent files offline for the managed domains set in this property. They can still disable it from Drive settings.". }. }.}.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text, with very long lines (3422)
              Category:dropped
              Size (bytes):82340
              Entropy (8bit):5.380000995741104
              Encrypted:false
              SSDEEP:
              MD5:4902A531B4D907B2B81AF35251CADF2C
              SHA1:7875EE813923CB16B0F0C4DE3C49C08C85CE52A1
              SHA-256:C3CE23C47225A594425A1290E49CED80FF9F3360D787767B6C45C80314FCF666
              SHA-512:A7B8E713F33B1155D8D45B8B635B318262EA21F3D0856FA0409ED6636F84CB9E38B78FB0E0296C3A253953FBFBF11FD68AF6C5EDB00A17A90A9129161CCDC7EE
              Malicious:true
              Reputation:low
              Preview:'use strict';function m(){return function(){}}var p;function aa(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}}var ba="function"==typeof Object.defineProperties?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.function ca(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");}var q=ca(this);function t(a,b){if(b)a:{var c=q;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&null!=b&&ba(c,a,{configurable:!0,writable:!0,value:b})}}.t("Symbol",function(a){function b(f){if(this instanceof b)throw new TypeError("Symbol is not a constructor");return new c(d+(f||"")+"_"+e++,f)}function c(f,g){this.g=f;ba(this,"description",{configurable:!
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2397
              Entropy (8bit):5.423648641408232
              Encrypted:false
              SSDEEP:
              MD5:807FB975635CF94C90974AF09BAFE5DD
              SHA1:91CF6811EB772D863F003BA0239CCB3025EEDF76
              SHA-256:B05DD3371A32526FDDEE35B45762E86E58DD8FEE0E533B736D6F967EF85101B1
              SHA-512:F6D9AEEFC4E80BC7F091083C6162C8EB07DE5422991A4F006F6D81125320762A69075D9DBA11204BD7EB3AE3A49EC9A8A80194DFE50C092809D743ECEA9A0DC7
              Malicious:false
              Reputation:low
              Preview:{.. "author": {.. "email": "docs-hosted-app-own@google.com".. },.. "background": {.. "persistent": false,.. "scripts": [ "eventpage_bin_prod.js" ].. },.. "content_capabilities": {.. "matches": [ "https://docs.google.com/*", "https://drive.google.com/*", "https://drive-autopush.corp.google.com/*", "https://drive-daily-0.corp.google.com/*", "https://drive-daily-1.corp.google.com/*", "https://drive-daily-2.corp.google.com/*", "https://drive-daily-3.corp.google.com/*", "https://drive-daily-4.corp.google.com/*", "https://drive-daily-5.corp.google.com/*", "https://drive-daily-6.corp.google.com/*", "https://drive-preprod.corp.google.com/*", "https://drive-staging.corp.google.com/*" ],.. "permissions": [ "clipboardRead", "clipboardWrite", "unlimitedStorage" ].. },.. "content_security_policy": "script-src 'self'; object-src 'self'",.. "default_locale": "en_US",.. "description": "__MSG_extDesc__",.. "externally_connectable": {.. "matches": [ "htt
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):291
              Entropy (8bit):4.644891151983713
              Encrypted:false
              SSDEEP:
              MD5:EE9839F99DED6F38DC561DB846B51E80
              SHA1:DD2128A473C2FF47471400C81EFF416285DE606E
              SHA-256:06E08E421EB7F0FE7959D68E27D40A9146A54503090D95CFAC6F2FFD72A78769
              SHA-512:C8D77607F00CB8012CD056CE61CB77918EC43621270511303E09577F89CC57D4954E22E2C8C3FB1029AAE29F8142DAAE2E938CD5590AD0E5DE6DB1208AFEF874
              Malicious:true
              Reputation:low
              Preview:(function(){window._docs_chrome_extension_exists=!0;window._docs_chrome_extension_features_version=2;window._docs_chrome_extension_permissions="alarms clipboardRead clipboardWrite storage unlimitedStorage offscreen".split(" ");window._docs_chrome_extension_manifest_version=2;}).call(this);.
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1753
              Entropy (8bit):5.8889033066924155
              Encrypted:false
              SSDEEP:
              MD5:738E757B92939B24CDBBD0EFC2601315
              SHA1:77058CBAFA625AAFBEA867052136C11AD3332143
              SHA-256:D23B2BA94BA22BBB681E6362AE5870ACD8A3280FA9E7241B86A9E12982968947
              SHA-512:DCA3E12DD5A9F1802DB6D11B009FCE2B787E79B9F730094367C9F26D1D87AF1EA072FF5B10888648FB1231DD83475CF45594BB0C9915B655EE363A3127A5FFC2
              Malicious:false
              Reputation:low
              Preview:[.. {.. "description": "treehash per file",.. "signed_content": {.. "payload": "eyJpdGVtX2lkIjoiam1qZmxnanBjcGVwZWFmbW1nZHBma29na2doY3BpaGEiLCJpdGVtX3ZlcnNpb24iOiIxLjIuMSIsInByb3RvY29sX3ZlcnNpb24iOjEsImNvbnRlbnRfaGFzaGVzIjpbeyJmb3JtYXQiOiJ0cmVlaGFzaCIsImRpZ2VzdCI6InNoYTI1NiIsImJsb2NrX3NpemUiOjQwOTYsImhhc2hfYmxvY2tfc2l6ZSI6NDA5NiwiZmlsZXMiOlt7InBhdGgiOiJjb250ZW50LmpzIiwicm9vdF9oYXNoIjoiQS13R1JtV0VpM1lybmxQNktneUdrVWJ5Q0FoTG9JZnRRZGtHUnBEcnp1QSJ9LHsicGF0aCI6ImNvbnRlbnRfbmV3LmpzIiwicm9vdF9oYXNoIjoiVU00WVRBMHc5NFlqSHVzVVJaVTFlU2FBSjFXVENKcHhHQUtXMGxhcDIzUSJ9LHsicGF0aCI6Im1hbmlmZXN0Lmpzb24iLCJyb290X2hhc2giOiJKNXYwVTkwRmN0ejBveWJMZmZuNm5TbHFLU0h2bHF2YkdWYW9FeWFOZU1zIn1dfV19",.. "signatures": [.. {.. "header": {.. "kid": "publisher".. },.. "protected": "eyJhbGciOiJSUzI1NiJ9",.. "signature": "UglEEilkOml5P1W0X6wc-_dB87PQB73uMir11923av57zPKujb4IUe_lbGpn7cRZsy6x-8i9eEKxAW7L2TSmYqrcp4XtiON6ppcf27FWACXOUJDax9wlMr-EOtyZhykCnB9vR
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:Unicode text, UTF-8 text, with very long lines (8031), with no line terminators
              Category:dropped
              Size (bytes):9815
              Entropy (8bit):6.1716321262973315
              Encrypted:false
              SSDEEP:
              MD5:3D20584F7F6C8EAC79E17CCA4207FB79
              SHA1:3C16DCC27AE52431C8CDD92FBAAB0341524D3092
              SHA-256:0D40A5153CB66B5BDE64906CA3AE750494098F68AD0B4D091256939EEA243643
              SHA-512:315D1B4CC2E70C72D7EB7D51E0F304F6E64AC13AE301FD2E46D585243A6C936B2AD35A0964745D291AE9B317C316A29760B9B9782C88CC6A68599DB531F87D59
              Malicious:true
              Reputation:low
              Preview:(()=>{"use strict";var e={1:(e,o)=>{Object.defineProperty(o,"__esModule",{value:!0}),o.newCwsPromotionalButtonCta=o.chromeToEdgeCwsButtonCtaMapping=void 0,o.chromeToEdgeCwsButtonCtaMapping={"...... ... Chrome":"...... ....","........ .. Chrome":".....",........:"..........",".......... .. Chrome":"..........","Chrome . .....":"...","Chrome .... ....":"....","Afegeix a Chrome":"Obt.n","Suprimeix de Chrome":"Suprimeix","P.idat do Chromu":"Z.skat","Odstranit z Chromu":"Odebrat","F.j til Chrome":"F.","Fjern fra Chrome":"Fjerne",Hinzuf.gen:"Abrufen","Aus Chrome entfernen":"Entfernen","Add to Chrome":"Get","Remove from Chrome":"Remove","A.adir a Chrome":"Obtener",Desinstalar:"Quitar","Agregar a Chrome":"Obtener","Eliminar de Chrome":"Quitar","Lisa Chrome'i":"Hangi","Chrome'ist eemaldamine":"Eemalda",.......H:"........","......... ... .. Chr
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:Unicode text, UTF-8 text, with very long lines (8604), with no line terminators
              Category:dropped
              Size (bytes):10388
              Entropy (8bit):6.174387413738973
              Encrypted:false
              SSDEEP:
              MD5:3DE1E7D989C232FC1B58F4E32DE15D64
              SHA1:42B152EA7E7F31A964914F344543B8BF14B5F558
              SHA-256:D4AA4602A1590A4B8A1BCE8B8D670264C9FB532ADC97A72BC10C43343650385A
              SHA-512:177E5BDF3A1149B0229B6297BAF7B122602F7BD753F96AA41CCF2D15B2BCF6AF368A39BB20336CCCE121645EC097F6BEDB94666C74ACB6174EB728FBFC43BC2A
              Malicious:true
              Reputation:low
              Preview:(()=>{"use strict";var e={1:(e,o)=>{Object.defineProperty(o,"__esModule",{value:!0}),o.newCwsPromotionalButtonCta=o.chromeToEdgeCwsButtonCtaMapping=void 0,o.chromeToEdgeCwsButtonCtaMapping={"...... ... Chrome":"...... ....","........ .. Chrome":".....",........:"..........",".......... .. Chrome":"..........","Chrome . .....":"...","Chrome .... ....":"....","Afegeix a Chrome":"Obt.n","Suprimeix de Chrome":"Suprimeix","P.idat do Chromu":"Z.skat","Odstranit z Chromu":"Odebrat","F.j til Chrome":"F.","Fjern fra Chrome":"Fjerne",Hinzuf.gen:"Abrufen","Aus Chrome entfernen":"Entfernen","Add to Chrome":"Get","Remove from Chrome":"Remove","A.adir a Chrome":"Obtener",Desinstalar:"Quitar","Agregar a Chrome":"Obtener","Eliminar de Chrome":"Quitar","Lisa Chrome'i":"Hangi","Chrome'ist eemaldamine":"Eemalda",.......H:"........","......... ... .. Chr
              Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):962
              Entropy (8bit):5.698567446030411
              Encrypted:false
              SSDEEP:
              MD5:E805E9E69FD6ECDCA65136957B1FB3BE
              SHA1:2356F60884130C86A45D4B232A26062C7830E622
              SHA-256:5694C91F7D165C6F25DAF0825C18B373B0A81EA122C89DA60438CD487455FD6A
              SHA-512:049662EF470D2B9E030A06006894041AE6F787449E4AB1FBF4959ADCB88C6BB87A957490212697815BB3627763C01B7B243CF4E3C4620173A95795884D998A75
              Malicious:false
              Reputation:low
              Preview:{.. "content_scripts": [ {.. "js": [ "content.js" ],.. "matches": [ "https://chrome.google.com/webstore/*" ].. }, {.. "js": [ "content_new.js" ],.. "matches": [ "https://chromewebstore.google.com/*" ].. } ],.. "description": "Edge relevant text changes on select websites to improve user experience and precisely surfaces the action they want to take.",.. "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu06p2Mjoy6yJDUUjCe8Hnqvtmjll73XqcbylxFZZWe+MCEAEK+1D0Nxrp0+IuWJL02CU3jbuR5KrJYoezA36M1oSGY5lIF/9NhXWEx5GrosxcBjxqEsdWv/eDoOOEbIvIO0ziMv7T1SUnmAA07wwq8DXWYuwlkZU/PA0Mxx0aNZ5+QyMfYqRmMpwxkwPG8gyU7kmacxgCY1v7PmmZo1vSIEOBYrxl064w5Q6s/dpalSJM9qeRnvRMLsszGY/J2bjQ1F0O2JfIlBjCOUg/89+U8ZJ1mObOFrKO4um8QnenXtH0WGmsvb5qBNrvbWNPuFgr2+w5JYlpSQ+O8zUCb8QZwIDAQAB",.. "manifest_version": 3,.. "name": "Edge relevant text changes",.. "update_url": "https://edge.microsoft.com/extensionwebstorebase/v1/crx",.. "version": "1.2.1"..}..
              Process:C:\Program Files\Internet Explorer\iexplore.exe
              File Type:data
              Category:dropped
              Size (bytes):16384
              Entropy (8bit):0.08196855197999947
              Encrypted:false
              SSDEEP:
              MD5:C0E467CD3F60AA82430F533C33152A00
              SHA1:DD464D94EB593BB6ED95E2E19492526140CE73FF
              SHA-256:F0852E301B20164CECCFDBCDCB57B03792485F7895D752005A4CD2389A759443
              SHA-512:7EB44B21FB377DD24BF02D46B90CE2597861B74C0BE9443A6467C9BB2EF75B64081A432F348C613A75B0D741A7520542657201C3D5A606668BCE94796D05C6DE
              Malicious:false
              Reputation:low
              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files\Internet Explorer\iexplore.exe
              File Type:data
              Category:dropped
              Size (bytes):16384
              Entropy (8bit):0.10850469149549735
              Encrypted:false
              SSDEEP:
              MD5:F4FA5D3FBC6CAF7912B7B0898136C5FA
              SHA1:D7A737B98B5449233A536FA8681350BF456EEA0D
              SHA-256:CEE7EA5D50CF9C02106571E0075A4C8FB442CB4A2A98BC6A3DE006FF3045B4C8
              SHA-512:80EF3E1EE30297B42BF9798908D2E4E21C5DA3855D4C628136E39971D6601C1244D0194CD2B0FD34FDB0A84B96A3919A3F69C9169EB397C8F621E2193C324F26
              Malicious:false
              Reputation:low
              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Program Files\Internet Explorer\iexplore.exe
              File Type:data
              Category:dropped
              Size (bytes):16384
              Entropy (8bit):0.0932618906695476
              Encrypted:false
              SSDEEP:
              MD5:AE0DBE20986530C71249277057EFA9F3
              SHA1:B82B4EF47F496AFEBAE0893989B7208B06554EE2
              SHA-256:3941E7D54EB0B6B371AD86B6DB3F45D268B918906CBF43E734772B6BA54473B0
              SHA-512:5FD6F4D3954F89FE8638EEB278BAD2EA7AD86175FD252E8CE14BF89819CEA3BB5EBFF878632EC5EE70AB772CF1DBBE1C882E5B576D0E70FB7EA5269FE73ED70C
              Malicious:false
              Reputation:low
              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              File type:ASCII text, with CRLF line terminators
              Entropy (8bit):4.50672103993778
              TrID:
                File name:officeclicktorun.exe_Rules.xml
                File size:361'201 bytes
                MD5:815172747c64e2f781505da8d849c0f6
                SHA1:3d0ab653a45e7869a8f82bd711501616c3f7f367
                SHA256:6898e40a8ef1d64e6314c438882814785719886b99d2560e6a59168c1b65ed8b
                SHA512:c53eb93d383516e166f337b8d502ec375272dee978c4ca4bca86a1ac6f0635fcb939c5670a65debc9def8fc8823b4894d12213a7b481626a9ca8d4d9ca267dc5
                SSDEEP:768:X0u8UMAXYNycOKT3DgJgW9lzOFCTeD99XuJb7rX9dh/7KmYJ:XECYxOmWreD9Vm90
                TLSH:B274D384D0D364136B79A505B3A18EDEEFB1C193A9C47850705D37BB9F328890E4BA7B
                File Content Preview:<Rules><R Id="120402" V="21" DC="SM" EN="Office.System.SystemHealthUngracefulAppExitDesktop" ATT="cd836626611c4caaa8fc5b2e728ee81d-3b6d6c45-6377-4bf5-9792-dbf8e1881088-7521" SP="CriticalCensus" DL="A" DCa="PSP" xmlns="">.. <RIS>.. <RI N="Crash" />..
                Icon Hash:72e2a2a292a2a2b2