Edit tour

Windows Analysis Report
http://url729.onlineformretrieval.com/ls/click?upn=wL8YJfzkJKts4QrXWi3lzzmAorYSM7zaJSGHrUq3iKDVRRfbuLTFsDXWTOku9mV4gqNhQm1I0EdRwEj8hCA1ZxDPnFOud4NkvlrIFZyedf0-3DwncP_tRzgCILXoBvefhOmUpZm7rwZ8gZFDwSV-2BqfVWQ4drExh0dglMcRPocBjSy03TKbS7zQ2RFPSwssj-2F0zW7JeZ1vBcZSUsoMpxEko34O-2Fcc1iYqasFbyW4RijL6Zk1owLf

Overview

General Information

Sample URL:http://url729.onlineformretrieval.com/ls/click?upn=wL8YJfzkJKts4QrXWi3lzzmAorYSM7zaJSGHrUq3iKDVRRfbuLTFsDXWTOku9mV4gqNhQm1I0EdRwEj8hCA1ZxDPnFOud4NkvlrIFZyedf0-3DwncP_tRzgCILXoBvefhOmUpZm7rwZ8gZFDwSV-2
Analysis ID:1389404

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Creates files inside the system directory
HTML page contains hidden URLs or javascript code
Stores files to the Windows start menu directory

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 1792 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://url729.onlineformretrieval.com/ls/click?upn=wL8YJfzkJKts4QrXWi3lzzmAorYSM7zaJSGHrUq3iKDVRRfbuLTFsDXWTOku9mV4gqNhQm1I0EdRwEj8hCA1ZxDPnFOud4NkvlrIFZyedf0-3DwncP_tRzgCILXoBvefhOmUpZm7rwZ8gZFDwSV-2BqfVWQ4drExh0dglMcRPocBjSy03TKbS7zQ2RFPSwssj-2F0zW7JeZ1vBcZSUsoMpxEko34O-2Fcc1iYqasFbyW4RijL6Zk1owLfNPSZiQz3jJSeEBefge9ZgjHU4tv36-2BqSlRidOCvKV-2B8F0rWZHQ6kSGH3-2FrVYIkH3MgQ8zlO6yo3HPNoj0gGpzMvn5nwHS7TPphka93yAPY94dO311nvJN2wXw9jrOluOGXrFmPXFhYdQLBUDSPW35C9kFrcAytD5VNtpW8xKO-2B5I9zOVDXuI4Xaf-2BpnbLnXmPfE4EIqA2ChTgWgwEvwARdMK3KHUM8X35T6BfYEWQgPrTqn73cmtO6WozXNMtRiI-2F6Bivnd1Z38qzRUS3HYUF1V-2BxnsNsYOtiBwO9jcKwtJ5mZOq6DI9LZVW6P6MAYyu MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5740 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2152 --field-trial-handle=1960,i,1374078380068316531,7128409897629197432,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://9769445.fls.doubleclick.net/activityi;dc_pre=CJucouqvnIQDFYmqOgUdn7gKiA;src=9769445;type=retar0;cat=sitew0;u1=https%3A%2F%2Fyearli.com%2Flegal%2Fterms-of-use;ord=8417969111632.071?HTTP Parser: Base64 decoded: floodlight_config_id: 9769445advertiser_domain: "https://yearli.com"xfa_attribution_interaction_type: CONVERSIONdebug_key: 15256569309970491528ctc_conversion_bucket: 6archetype_id: 1archetype_id: 3archetype_id: 4archetype_id: 5archetype_id: 6arc...
Source: https://9769445.fls.doubleclick.net/activityi;dc_pre=CJucouqvnIQDFYmqOgUdn7gKiA;src=9769445;type=retar0;cat=sitew0;u1=https%3A%2F%2Fyearli.com%2Flegal%2Fterms-of-use;ord=8417969111632.071?HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 23.220.189.216:443 -> 192.168.2.16:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.220.189.216:443 -> 192.168.2.16:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:49749 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:49769 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.21.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 23.220.189.216
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: global trafficHTTP traffic detected: GET /ls/click?upn=wL8YJfzkJKts4QrXWi3lzzmAorYSM7zaJSGHrUq3iKDVRRfbuLTFsDXWTOku9mV4gqNhQm1I0EdRwEj8hCA1ZxDPnFOud4NkvlrIFZyedf0-3DwncP_tRzgCILXoBvefhOmUpZm7rwZ8gZFDwSV-2BqfVWQ4drExh0dglMcRPocBjSy03TKbS7zQ2RFPSwssj-2F0zW7JeZ1vBcZSUsoMpxEko34O-2Fcc1iYqasFbyW4RijL6Zk1owLfNPSZiQz3jJSeEBefge9ZgjHU4tv36-2BqSlRidOCvKV-2B8F0rWZHQ6kSGH3-2FrVYIkH3MgQ8zlO6yo3HPNoj0gGpzMvn5nwHS7TPphka93yAPY94dO311nvJN2wXw9jrOluOGXrFmPXFhYdQLBUDSPW35C9kFrcAytD5VNtpW8xKO-2B5I9zOVDXuI4Xaf-2BpnbLnXmPfE4EIqA2ChTgWgwEvwARdMK3KHUM8X35T6BfYEWQgPrTqn73cmtO6WozXNMtRiI-2F6Bivnd1Z38qzRUS3HYUF1V-2BxnsNsYOtiBwO9jcKwtJ5mZOq6DI9LZVW6P6MAYyu HTTP/1.1Host: url729.onlineformretrieval.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.greatland.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: s_vi=[CS]v1|32E28EBFC5EC1EEA-40000E41E25E7C67[CE]
Source: unknownDNS traffic detected: queries for: url729.onlineformretrieval.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
Source: unknownNetwork traffic detected: HTTP traffic on port 49949 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49859
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
Source: unknownNetwork traffic detected: HTTP traffic on port 49950 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49915 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49909 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49933 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49951
Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49950
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49938 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49949
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49948
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49947
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49946
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49945
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49945 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 49951 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49916 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49939 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 49885 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49899
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49897
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49896
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49895
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49897 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49885
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49940 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49875
Source: unknownNetwork traffic detected: HTTP traffic on port 49923 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49934 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49869
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49868
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49867
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49935 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49866 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49946 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49947 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 49856 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49895 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49941 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49867 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
Source: unknownNetwork traffic detected: HTTP traffic on port 49842 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49941
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49940
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49939
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49938
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49937
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49936
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49935
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49934
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49933
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49936 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49923
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49914 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49937 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49916
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49915
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49914
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49948 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49899 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49909
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49900
Source: unknownHTTPS traffic detected: 23.220.189.216:443 -> 192.168.2.16:49741 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.220.189.216:443 -> 192.168.2.16:49744 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:49749 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:49769 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\chrome_BITS_1792_1986024275
Source: classification engineClassification label: clean1.win@19/6@94/245
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://url729.onlineformretrieval.com/ls/click?upn=wL8YJfzkJKts4QrXWi3lzzmAorYSM7zaJSGHrUq3iKDVRRfbuLTFsDXWTOku9mV4gqNhQm1I0EdRwEj8hCA1ZxDPnFOud4NkvlrIFZyedf0-3DwncP_tRzgCILXoBvefhOmUpZm7rwZ8gZFDwSV-2BqfVWQ4drExh0dglMcRPocBjSy03TKbS7zQ2RFPSwssj-2F0zW7JeZ1vBcZSUsoMpxEko34O-2Fcc1iYqasFbyW4RijL6Zk1owLfNPSZiQz3jJSeEBefge9ZgjHU4tv36-2BqSlRidOCvKV-2B8F0rWZHQ6kSGH3-2FrVYIkH3MgQ8zlO6yo3HPNoj0gGpzMvn5nwHS7TPphka93yAPY94dO311nvJN2wXw9jrOluOGXrFmPXFhYdQLBUDSPW35C9kFrcAytD5VNtpW8xKO-2B5I9zOVDXuI4Xaf-2BpnbLnXmPfE4EIqA2ChTgWgwEvwARdMK3KHUM8X35T6BfYEWQgPrTqn73cmtO6WozXNMtRiI-2F6Bivnd1Z38qzRUS3HYUF1V-2BxnsNsYOtiBwO9jcKwtJ5mZOq6DI9LZVW6P6MAYyu
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2152 --field-trial-handle=1960,i,1374078380068316531,7128409897629197432,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2152 --field-trial-handle=1960,i,1374078380068316531,7128409897629197432,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
11
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://url729.onlineformretrieval.com/ls/click?upn=wL8YJfzkJKts4QrXWi3lzzmAorYSM7zaJSGHrUq3iKDVRRfbuLTFsDXWTOku9mV4gqNhQm1I0EdRwEj8hCA1ZxDPnFOud4NkvlrIFZyedf0-3DwncP_tRzgCILXoBvefhOmUpZm7rwZ8gZFDwSV-2BqfVWQ4drExh0dglMcRPocBjSy03TKbS7zQ2RFPSwssj-2F0zW7JeZ1vBcZSUsoMpxEko34O-2Fcc1iYqasFbyW4RijL6Zk1owLfNPSZiQz3jJSeEBefge9ZgjHU4tv36-2BqSlRidOCvKV-2B8F0rWZHQ6kSGH3-2FrVYIkH3MgQ8zlO6yo3HPNoj0gGpzMvn5nwHS7TPphka93yAPY94dO311nvJN2wXw9jrOluOGXrFmPXFhYdQLBUDSPW35C9kFrcAytD5VNtpW8xKO-2B5I9zOVDXuI4Xaf-2BpnbLnXmPfE4EIqA2ChTgWgwEvwARdMK3KHUM8X35T6BfYEWQgPrTqn73cmtO6WozXNMtRiI-2F6Bivnd1Z38qzRUS3HYUF1V-2BxnsNsYOtiBwO9jcKwtJ5mZOq6DI9LZVW6P6MAYyu0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
about:blank0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
jsdelivr.map.fastly.net
151.101.1.229
truefalse
    unknown
    dart.l.doubleclick.net
    64.233.177.148
    truefalse
      high
      retrieval.greatland.com
      13.82.175.96
      truefalse
        high
        sendgrid.net
        167.89.118.52
        truefalse
          high
          greatland.com.102.122.2o7.net
          63.140.39.117
          truefalse
            high
            adservice.google.com
            64.233.177.156
            truefalse
              high
              stats.g.doubleclick.net
              74.125.138.155
              truefalse
                high
                collect.tealiumiq.com
                3.234.157.123
                truefalse
                  high
                  getambassador.map.fastly.net
                  151.101.2.133
                  truefalse
                    unknown
                    bes.gcp.data.bigcommerce.com
                    34.111.131.117
                    truefalse
                      high
                      www.google.com
                      108.177.122.99
                      truefalse
                        high
                        yearli-cdn.nyc3.cdn.digitaloceanspaces.com
                        104.18.13.192
                        truefalse
                          high
                          accounts.google.com
                          74.125.136.84
                          truefalse
                            high
                            ad.doubleclick.net
                            74.125.136.148
                            truefalse
                              high
                              greatland.com
                              63.141.128.23
                              truefalse
                                high
                                tracking.hawksearch.com
                                12.133.121.70
                                truefalse
                                  high
                                  microapp-cdn.gcp.bigcommerce.net
                                  34.117.232.248
                                  truefalse
                                    unknown
                                    manage.hawksearch.com
                                    12.133.122.170
                                    truefalse
                                      high
                                      analytics-alv.google.com
                                      216.239.38.181
                                      truefalse
                                        high
                                        part-0013.t-0009.t-msedge.net
                                        13.107.246.41
                                        truefalse
                                          unknown
                                          googleads.g.doubleclick.net
                                          74.125.138.155
                                          truefalse
                                            high
                                            yearli.com
                                            206.189.253.98
                                            truefalse
                                              unknown
                                              td.doubleclick.net
                                              142.250.105.155
                                              truefalse
                                                high
                                                clients.l.google.com
                                                172.253.124.102
                                                truefalse
                                                  high
                                                  d31y97ze264gaa.cloudfront.net
                                                  54.239.153.156
                                                  truefalse
                                                    high
                                                    dzfq4ouujrxm8.cloudfront.net
                                                    3.162.112.76
                                                    truefalse
                                                      high
                                                      cdn.jsdelivr.net
                                                      unknown
                                                      unknownfalse
                                                        high
                                                        cdn11.bigcommerce.com
                                                        unknown
                                                        unknownfalse
                                                          high
                                                          clients2.google.com
                                                          unknown
                                                          unknownfalse
                                                            high
                                                            clients1.google.com
                                                            unknown
                                                            unknownfalse
                                                              high
                                                              cdn.getambassador.com
                                                              unknown
                                                              unknownfalse
                                                                high
                                                                www.clarity.ms
                                                                unknown
                                                                unknownfalse
                                                                  unknown
                                                                  microapps.bigcommerce.com
                                                                  unknown
                                                                  unknownfalse
                                                                    high
                                                                    smetrics.greatland.com
                                                                    unknown
                                                                    unknownfalse
                                                                      high
                                                                      url729.onlineformretrieval.com
                                                                      unknown
                                                                      unknownfalse
                                                                        unknown
                                                                        9769445.fls.doubleclick.net
                                                                        unknown
                                                                        unknownfalse
                                                                          high
                                                                          dc.services.visualstudio.com
                                                                          unknown
                                                                          unknownfalse
                                                                            high
                                                                            analytics.google.com
                                                                            unknown
                                                                            unknownfalse
                                                                              high
                                                                              tags.tiqcdn.com
                                                                              unknown
                                                                              unknownfalse
                                                                                high
                                                                                www.greatland.com
                                                                                unknown
                                                                                unknownfalse
                                                                                  high
                                                                                  lptag.liveperson.net
                                                                                  unknown
                                                                                  unknownfalse
                                                                                    high
                                                                                    NameMaliciousAntivirus DetectionReputation
                                                                                    https://retrieval.greatland.com/Content/GetContent?contentName=About_Usfalse
                                                                                      high
                                                                                      https://9769445.fls.doubleclick.net/activityi;dc_pre=CJucouqvnIQDFYmqOgUdn7gKiA;src=9769445;type=retar0;cat=sitew0;u1=https%3A%2F%2Fyearli.com%2Flegal%2Fterms-of-use;ord=8417969111632.071?false
                                                                                        high
                                                                                        http://url729.onlineformretrieval.com/ls/click?upn=wL8YJfzkJKts4QrXWi3lzzmAorYSM7zaJSGHrUq3iKDVRRfbuLTFsDXWTOku9mV4gqNhQm1I0EdRwEj8hCA1ZxDPnFOud4NkvlrIFZyedf0-3DwncP_tRzgCILXoBvefhOmUpZm7rwZ8gZFDwSV-2BqfVWQ4drExh0dglMcRPocBjSy03TKbS7zQ2RFPSwssj-2F0zW7JeZ1vBcZSUsoMpxEko34O-2Fcc1iYqasFbyW4RijL6Zk1owLfNPSZiQz3jJSeEBefge9ZgjHU4tv36-2BqSlRidOCvKV-2B8F0rWZHQ6kSGH3-2FrVYIkH3MgQ8zlO6yo3HPNoj0gGpzMvn5nwHS7TPphka93yAPY94dO311nvJN2wXw9jrOluOGXrFmPXFhYdQLBUDSPW35C9kFrcAytD5VNtpW8xKO-2B5I9zOVDXuI4Xaf-2BpnbLnXmPfE4EIqA2ChTgWgwEvwARdMK3KHUM8X35T6BfYEWQgPrTqn73cmtO6WozXNMtRiI-2F6Bivnd1Z38qzRUS3HYUF1V-2BxnsNsYOtiBwO9jcKwtJ5mZOq6DI9LZVW6P6MAYyufalse
                                                                                          unknown
                                                                                          http://www.greatland.com/false
                                                                                            high
                                                                                            about:blankfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            low
                                                                                            https://yearli.com/legal/terms-of-usefalse
                                                                                              unknown
                                                                                              https://retrieval.greatland.com/a59f3db6-5f21-41f2-b8cc-bd3c4ce91668false
                                                                                                high
                                                                                                • No. of IPs < 25%
                                                                                                • 25% < No. of IPs < 50%
                                                                                                • 50% < No. of IPs < 75%
                                                                                                • 75% < No. of IPs
                                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                                167.89.118.52
                                                                                                sendgrid.netUnited States
                                                                                                11377SENDGRIDUSfalse
                                                                                                172.217.215.102
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                74.125.138.138
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                74.125.136.84
                                                                                                accounts.google.comUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                204.79.197.200
                                                                                                unknownUnited States
                                                                                                8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                74.125.136.148
                                                                                                ad.doubleclick.netUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                52.188.247.151
                                                                                                unknownUnited States
                                                                                                8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                142.250.105.155
                                                                                                td.doubleclick.netUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                216.239.38.181
                                                                                                analytics-alv.google.comUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                72.21.81.200
                                                                                                unknownUnited States
                                                                                                15133EDGECASTUSfalse
                                                                                                3.162.112.76
                                                                                                dzfq4ouujrxm8.cloudfront.netUnited States
                                                                                                16509AMAZON-02USfalse
                                                                                                172.253.124.102
                                                                                                clients.l.google.comUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                13.82.175.96
                                                                                                retrieval.greatland.comUnited States
                                                                                                8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                64.233.177.156
                                                                                                adservice.google.comUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                142.251.15.95
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                104.18.12.192
                                                                                                unknownUnited States
                                                                                                13335CLOUDFLARENETUSfalse
                                                                                                74.125.138.155
                                                                                                stats.g.doubleclick.netUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                151.101.1.229
                                                                                                jsdelivr.map.fastly.netUnited States
                                                                                                54113FASTLYUSfalse
                                                                                                74.125.136.97
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                74.125.136.94
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                63.140.38.138
                                                                                                unknownUnited States
                                                                                                4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                                                                                                1.1.1.1
                                                                                                unknownAustralia
                                                                                                13335CLOUDFLARENETUSfalse
                                                                                                142.250.105.94
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                142.250.105.95
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                142.250.105.99
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                104.18.13.192
                                                                                                yearli-cdn.nyc3.cdn.digitaloceanspaces.comUnited States
                                                                                                13335CLOUDFLARENETUSfalse
                                                                                                63.140.39.117
                                                                                                greatland.com.102.122.2o7.netUnited States
                                                                                                4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                                                                                                63.141.128.23
                                                                                                greatland.comUnited States
                                                                                                36351SOFTLAYERUSfalse
                                                                                                142.250.105.148
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                64.233.177.148
                                                                                                dart.l.doubleclick.netUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                52.179.73.39
                                                                                                unknownUnited States
                                                                                                8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                239.255.255.250
                                                                                                unknownReserved
                                                                                                unknownunknownfalse
                                                                                                151.101.2.133
                                                                                                getambassador.map.fastly.netUnited States
                                                                                                54113FASTLYUSfalse
                                                                                                52.179.73.37
                                                                                                unknownUnited States
                                                                                                8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                52.179.73.36
                                                                                                unknownUnited States
                                                                                                8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                64.233.176.102
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                142.250.9.103
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                108.177.122.94
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                108.177.122.95
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                64.233.185.149
                                                                                                unknownUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                192.200.160.253
                                                                                                unknownUnited States
                                                                                                36351SOFTLAYERUSfalse
                                                                                                206.189.253.98
                                                                                                yearli.comUnited States
                                                                                                14061DIGITALOCEAN-ASNUSfalse
                                                                                                34.117.232.248
                                                                                                microapp-cdn.gcp.bigcommerce.netUnited States
                                                                                                139070GOOGLE-AS-APGoogleAsiaPacificPteLtdSGfalse
                                                                                                108.177.122.99
                                                                                                www.google.comUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                IP
                                                                                                192.168.2.16
                                                                                                Joe Sandbox version:40.0.0 Tourmaline
                                                                                                Analysis ID:1389404
                                                                                                Start date and time:2024-02-08 19:27:14 +01:00
                                                                                                Joe Sandbox product:CloudBasic
                                                                                                Overall analysis duration:
                                                                                                Hypervisor based Inspection enabled:false
                                                                                                Report type:full
                                                                                                Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                                                Sample URL:http://url729.onlineformretrieval.com/ls/click?upn=wL8YJfzkJKts4QrXWi3lzzmAorYSM7zaJSGHrUq3iKDVRRfbuLTFsDXWTOku9mV4gqNhQm1I0EdRwEj8hCA1ZxDPnFOud4NkvlrIFZyedf0-3DwncP_tRzgCILXoBvefhOmUpZm7rwZ8gZFDwSV-2BqfVWQ4drExh0dglMcRPocBjSy03TKbS7zQ2RFPSwssj-2F0zW7JeZ1vBcZSUsoMpxEko34O-2Fcc1iYqasFbyW4RijL6Zk1owLfNPSZiQz3jJSeEBefge9ZgjHU4tv36-2BqSlRidOCvKV-2B8F0rWZHQ6kSGH3-2FrVYIkH3MgQ8zlO6yo3HPNoj0gGpzMvn5nwHS7TPphka93yAPY94dO311nvJN2wXw9jrOluOGXrFmPXFhYdQLBUDSPW35C9kFrcAytD5VNtpW8xKO-2B5I9zOVDXuI4Xaf-2BpnbLnXmPfE4EIqA2ChTgWgwEvwARdMK3KHUM8X35T6BfYEWQgPrTqn73cmtO6WozXNMtRiI-2F6Bivnd1Z38qzRUS3HYUF1V-2BxnsNsYOtiBwO9jcKwtJ5mZOq6DI9LZVW6P6MAYyu
                                                                                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                Number of analysed new started processes analysed:14
                                                                                                Number of new started drivers analysed:0
                                                                                                Number of existing processes analysed:0
                                                                                                Number of existing drivers analysed:0
                                                                                                Number of injected processes analysed:0
                                                                                                Technologies:
                                                                                                • EGA enabled
                                                                                                Analysis Mode:stream
                                                                                                Analysis stop reason:Timeout
                                                                                                Detection:CLEAN
                                                                                                Classification:clean1.win@19/6@94/245
                                                                                                • Exclude process from analysis (whitelisted): svchost.exe
                                                                                                • Excluded IPs from analysis (whitelisted): 142.250.105.94, 34.104.35.123, 72.21.81.200, 108.177.122.95, 142.250.9.95, 64.233.185.95, 64.233.176.95, 64.233.177.95, 172.217.215.95, 74.125.136.95, 142.251.15.95, 173.194.219.95, 142.250.105.95, 172.253.124.95, 74.125.138.95, 52.179.73.39, 52.179.73.37
                                                                                                • Excluded domains from analysis (whitelisted): gig-ai-g-prod-eastus-11-app-v4-tag.eastus.cloudapp.azure.com, fs.microsoft.com, edgedl.me.gvt1.com, content-autofill.googleapis.com, dc.trafficmanager.net, clientservices.googleapis.com, dc.applicationinsights.microsoft.com, gig-ai-g-prod-eastus-7-app-v4-tag.eastus.cloudapp.azure.com, ai-global-ingestion-prod-eastus.trafficmanager.net, az416426.vo.msecnd.net, cs9.wpc.v0cdn.net
                                                                                                • Not all processes where analyzed, report is missing behavior information
                                                                                                • Report size getting too big, too many NtOpenFile calls found.
                                                                                                • VT rate limit hit for: http://url729.onlineformretrieval.com/ls/click?upn=wL8YJfzkJKts4QrXWi3lzzmAorYSM7zaJSGHrUq3iKDVRRfbuLTFsDXWTOku9mV4gqNhQm1I0EdRwEj8hCA1ZxDPnFOud4NkvlrIFZyedf0-3DwncP_tRzgCILXoBvefhOmUpZm7rwZ8gZFDwSV-2BqfVWQ4drExh0dglMcRPocBjSy03TKbS7zQ2RFPSwssj-2F0zW7JeZ1vBcZSUsoMpxEko34O-2Fcc1iYqasFbyW4RijL6Zk1owLfNPSZiQz3jJSeEBefge9ZgjHU4tv36-2BqSlRidOCvKV-2B8F0rWZHQ6kSGH3-2FrVYIkH3MgQ8zlO6yo3HPNoj0gGpzMvn5nwHS7TPphka93yAPY94dO311nvJN2wXw9jrOluOGXrFmPXFhYdQLBUDSPW35C9kFrcAytD5VNtpW8xKO-2B5I9zOVDXuI4Xaf-2BpnbLnXmPfE4EIqA2ChTgWgwEvwARdMK3KHUM8X35T6BfYEWQgPrTqn73cmtO6WozXNMtRiI-2F6Bivnd1Z38qzRUS3HYUF1V-2BxnsNsYOtiBwO9jcKwtJ5mZOq6DI9LZVW6P6MAYyu
                                                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Feb 8 17:27:44 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                Category:dropped
                                                                                                Size (bytes):2673
                                                                                                Entropy (8bit):3.985041326409957
                                                                                                Encrypted:false
                                                                                                SSDEEP:
                                                                                                MD5:7A2BA0C3695D146F35B6CA5B142665C3
                                                                                                SHA1:6FA0A045BB832DFF8439F876D749120A29FF3C44
                                                                                                SHA-256:9854CA05F019B37FBCFA37E837305E3A2252F60D931869AEEC49DCF1B9AFB678
                                                                                                SHA-512:4C31EE1F942A7A2BB7FCDA6D5A81F0829CBF80103BEEDF4880C53224821FBBEB5E6BC1F8ED90EB893346EDA9A30D4371FD7932A049B05963EE571B98218CE85A
                                                                                                Malicious:false
                                                                                                Reputation:unknown
                                                                                                Preview:L..................F.@.. ...$+.,....c.:..Z..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IHXn.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHXu.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHXu.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHXu............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHXw............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........6........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Feb 8 17:27:44 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                Category:dropped
                                                                                                Size (bytes):2675
                                                                                                Entropy (8bit):3.9987267541424965
                                                                                                Encrypted:false
                                                                                                SSDEEP:
                                                                                                MD5:FE54A8E5EF527D2BC378A95616F66E6E
                                                                                                SHA1:25B74192B1964BCC24245EEFD78BF9BC11BF158A
                                                                                                SHA-256:8CBA828E77C34468E4A96AD9D35F3ECEF2C9A43BDEEF1C2524C2F61E90C69020
                                                                                                SHA-512:EB101E7F456AE2B1AA789E1C9209371E3CE10FAF6D67D72D14D20A7B99435D3F4FCF9A397BB07E525B225DA6F92CC0F50EFFE79ECBCE5E0EAE6E9AD30B3F9834
                                                                                                Malicious:false
                                                                                                Reputation:unknown
                                                                                                Preview:L..................F.@.. ...$+.,......-..Z..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IHXn.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHXu.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHXu.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHXu............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHXw............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........6........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                Category:dropped
                                                                                                Size (bytes):2689
                                                                                                Entropy (8bit):4.009217232691271
                                                                                                Encrypted:false
                                                                                                SSDEEP:
                                                                                                MD5:839BD64EA4BE934D73B0B29A29F6281D
                                                                                                SHA1:21D573F635EA4F450AE1A98EC6B547B6E941AE07
                                                                                                SHA-256:5886A2470667E94F6040576D5AA666B29C30827B9E112E5F42B277833387BF39
                                                                                                SHA-512:477A411F7796CBA61BF7029D6FAFC0B32BFDE8E0AA02452DDF75D6EB2578AF2AFAA748186A8E433C35618A2B8A874599E7577B7F9BDF8665194EAB69E1D3C122
                                                                                                Malicious:false
                                                                                                Reputation:unknown
                                                                                                Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IHXn.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHXu.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHXu.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHXu............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........6........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Feb 8 17:27:44 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                Category:dropped
                                                                                                Size (bytes):2677
                                                                                                Entropy (8bit):4.00261660906715
                                                                                                Encrypted:false
                                                                                                SSDEEP:
                                                                                                MD5:0C5885CC0B19D22DD5C267D9DA6359C3
                                                                                                SHA1:08DDD9E34A5943E3BBF4437F83D9D2F155DF33AD
                                                                                                SHA-256:E5D193DAA435C8841EA3C6265989C850F39EACBF055CC6A080462B24041E33F3
                                                                                                SHA-512:57AC20A8C529959447B58C7C3202197A4BD878914BC06B2D66D7CA2A768CAC42CBA9A9948664C28D3BF9A758E82F66162DDFA2823E4851A66A6FA83DA58AAA1F
                                                                                                Malicious:false
                                                                                                Reputation:unknown
                                                                                                Preview:L..................F.@.. ...$+.,......'..Z..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IHXn.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHXu.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHXu.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHXu............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHXw............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........6........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Feb 8 17:27:44 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                Category:dropped
                                                                                                Size (bytes):2677
                                                                                                Entropy (8bit):3.9893629374147808
                                                                                                Encrypted:false
                                                                                                SSDEEP:
                                                                                                MD5:502DB1E925AE6B446446BE2E145BA37A
                                                                                                SHA1:EE4995BD45D8D4AA41F7E2AFC290AAE1FB80C700
                                                                                                SHA-256:FB760F712AEBF058DDE87E4B9EA41668019BC6FB4A67B847E0384FEA6D483F2F
                                                                                                SHA-512:88C240F1B285DD11E396B030F51F140B9B4ACD9811733E535F39378BBB824B5F906057586C28C3DC235B60ADC510438F15277FC4F78CDF345E65917088DEFB5E
                                                                                                Malicious:false
                                                                                                Reputation:unknown
                                                                                                Preview:L..................F.@.. ...$+.,......3..Z..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IHXn.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHXu.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHXu.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHXu............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHXw............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........6........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Feb 8 17:27:44 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                Category:dropped
                                                                                                Size (bytes):2679
                                                                                                Entropy (8bit):3.997117723793692
                                                                                                Encrypted:false
                                                                                                SSDEEP:
                                                                                                MD5:C9FA51D7AE78913FF9AA93B37FC4472E
                                                                                                SHA1:26045523400E3C266289387CF2CCED2416E5B590
                                                                                                SHA-256:5BE848F32A6E23014324BCB127A639B1809B71B1059E37F7FCC3D612BC7C95E1
                                                                                                SHA-512:A10D71B3D8B0FA2A1910FE17C4024C6229C339FC002537A58F6861EE6E0F1B20190176899076F77CF0F75BB4ACFB766F1EE29D42CCAD9D9BD82F367EBDDCD06E
                                                                                                Malicious:false
                                                                                                Reputation:unknown
                                                                                                Preview:L..................F.@.. ...$+.,.....`...Z..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IHXn.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHXu.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHXu.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHXu............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHXw............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........6........C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                No static file info