Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://forms.office.com/e/tBp2XcGpEy

Overview

General Information

Sample URL:https://forms.office.com/e/tBp2XcGpEy
Analysis ID:1465354

Detection

HTMLPhisher
Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected phishing page
Phishing site detected (based on favicon image match)
Yara detected HtmlPhish54
Phishing site detected (based on image similarity)
Detected hidden input values containing email addresses (often used in phishing pages)
HTML body contains low number of good links
HTML body contains password input but no form action
HTML title does not match URL
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 7096 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://forms.office.com/e/tBp2XcGpEy MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6212 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1972,i,6951622617809385496,11899697623652637181,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
SourceRuleDescriptionAuthorStrings
2.5.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
    3.6.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
      2.5.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
        3.6.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
          3.7.pages.csvJoeSecurity_HtmlPhish_54Yara detected HtmlPhish_54Joe Security
            Click to see the 6 entries
            No Sigma rule has matched
            No Snort rule has matched

            Click to jump to signature section

            Show All Signature Results

            Phishing

            barindex
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.comLLM: Score: 9 brands: Microsoft Reasons: The URL 'https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com' is highly suspicious. It does not match the legitimate domain for Microsoft login, which is 'login.microsoftonline.com'. The presence of a prominent login form is a common tactic used in phishing attacks to capture user credentials. Additionally, the use of a subdomain with random characters is a known social engineering technique to mislead users. There is no CAPTCHA present, which is often used by legitimate sites to prevent automated attacks. The combination of these factors strongly indicates that this is a phishing site. DOM: 3.7.pages.csv
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.comLLM: Score: 9 brands: Microsoft Reasons: The URL 'https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com' is highly suspicious. It does not match the legitimate domain for Microsoft, which is 'microsoft.com'. The presence of a prominent login form asking for a password is a common phishing tactic. Additionally, the URL structure and the use of a subdomain with random characters are typical of phishing attempts. The site also uses social engineering techniques by mimicking the legitimate Microsoft login page to deceive users into entering their credentials. There is no CAPTCHA present, which is often used in legitimate sites to prevent automated attacks. The 'Forgot password?' link could potentially lead to further phishing attempts. DOM: 4.9.pages.csv
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.comLLM: Score: 9 brands: Microsoft Reasons: The URL 'https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com' is highly suspicious. It does not match the legitimate domain 'microsoft.com' associated with the brand Microsoft. The domain name is convoluted and uses a subdomain structure often seen in phishing attacks. The webpage prominently displays a login form asking for a password, which is a common tactic used in phishing to steal credentials. Additionally, the presence of a 'Forgot password?' link is another common element used to make phishing sites appear legitimate. There is no CAPTCHA present, which is often used on legitimate login pages to prevent automated attacks. Overall, the combination of these factors strongly suggests that this is a phishing site. DOM: 4.8.pages.csv
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0&sso_reload=trueMatcher: Template: microsoft matched with high similarity
            Source: Yara matchFile source: 2.5.pages.csv, type: HTML
            Source: Yara matchFile source: 3.6.pages.csv, type: HTML
            Source: Yara matchFile source: 2.5.pages.csv, type: HTML
            Source: Yara matchFile source: 3.6.pages.csv, type: HTML
            Source: Yara matchFile source: 3.7.pages.csv, type: HTML
            Source: Yara matchFile source: 2.5.pages.csv, type: HTML
            Source: Yara matchFile source: 3.6.pages.csv, type: HTML
            Source: Yara matchFile source: 3.7.pages.csv, type: HTML
            Source: Yara matchFile source: 2.5.pages.csv, type: HTML
            Source: Yara matchFile source: 3.6.pages.csv, type: HTML
            Source: Yara matchFile source: 3.7.pages.csv, type: HTML
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0&sso_reload=trueMatcher: Found strong image similarity, brand: MICROSOFT
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2flandingv2&response_type=code+id_token&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&x-client-SKU=ID_NET8_0&x-client-Ver=7.3.1.0&uaid=976181e54da940e29d919d30b3841ead&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAAApTwJmzXqdR4BN2miheQMYnqHLls0CaoB_DpHqTN_HArxmPF1V1KvJ63jDI7-4VQ9Lk8TDOD7W_RcY0hixyy57QQY7mQj-UaGrO607yvAiXRJaYknfqDOVJAG1dLwSK554Z54xsBKJ-ualLWloKQ265Asu1UDzwhQ9k9MoUgVZ46BYQ0SgsTj7yv3Y5IX_zvVy32yGKsihu0WmVH2CdP-LSE4_Ky2IMoynSGdnKI1odCAA&jshs=0&username=bum%40bum.com&login_hint=bum%40bum.comHTTP Parser: bum@bum.com
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0HTTP Parser: Number of links: 0
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0&sso_reload=trueHTTP Parser: Number of links: 0
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2flandingv2&response_type=code+id_token&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&x-client-SKU=ID_NET8_0&x-client-Ver=7.3.1.0&uaid=976181e54da940e29d919d30b3841ead&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAAApTwJmzXqdR4BN2miheQMYnqHLls0CaoB_DpHqTN_HArxmPF1V1KvJ63jDI7-4VQ9Lk8TDOD7W_RcY0hixyy57QQY7mQj-UaGrO607yvAiXRJaYknfqDO...HTTP Parser: Number of links: 0
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/ppsecure/post.srf?username=bum%40bum.com&client_id=4765445b-32c6-49b0-83e6-1d93765276ca&contextid=2E846C5FA95026DB&opid=9D0903C250E0D8EE&bk=1719840359&uaid=976181e54da940e29d919d30b3841ead&pid=15216HTTP Parser: Number of links: 0
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2flandingv2&response_type=code+id_token&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&x-client-SKU=ID_NET8_0&x-client-Ver=7.3.1.0&uaid=976181e54da940e29d919d30b3841ead&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAAApTwJmzXqdR4BN2miheQMYnqHLls0CaoB_DpHqTN_HArxmPF1V1KvJ63jDI7-4VQ9Lk8TDOD7W_RcY0hixyy57QQY7mQj-UaGrO607yvAiXRJaYknfqDO...HTTP Parser: <input type="password" .../> found but no <form action="...
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0HTTP Parser: Title: Redirecting does not match URL
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0&sso_reload=trueHTTP Parser: Title: Sign in to your account does not match URL
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2flandingv2&response_type=code+id_token&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&x-client-SKU=ID_NET8_0&x-client-Ver=7.3.1.0&uaid=976181e54da940e29d919d30b3841ead&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAAApTwJmzXqdR4BN2miheQMYnqHLls0CaoB_DpHqTN_HArxmPF1V1KvJ63jDI7-4VQ9Lk8TDOD7W_RcY0hixyy57QQY7mQj-UaGrO607yvAiXRJaYknfqDO...HTTP Parser: Title: Sign in to your Microsoft account does not match URL
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/ppsecure/post.srf?username=bum%40bum.com&client_id=4765445b-32c6-49b0-83e6-1d93765276ca&contextid=2E846C5FA95026DB&opid=9D0903C250E0D8EE&bk=1719840359&uaid=976181e54da940e29d919d30b3841ead&pid=15216HTTP Parser: Title: Sign in to your Microsoft account does not match URL
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0&sso_reload=trueHTTP Parser: <input type="password" .../> found
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2flandingv2&response_type=code+id_token&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&x-client-SKU=ID_NET8_0&x-client-Ver=7.3.1.0&uaid=976181e54da940e29d919d30b3841ead&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAAApTwJmzXqdR4BN2miheQMYnqHLls0CaoB_DpHqTN_HArxmPF1V1KvJ63jDI7-4VQ9Lk8TDOD7W_RcY0hixyy57QQY7mQj-UaGrO607yvAiXRJaYknfqDO...HTTP Parser: <input type="password" .../> found
            Source: https://assets-eur.mkt.dynamics.com/21f9f50d-1320-ef11-8406-000d3adc9e50/digitalassets/standaloneforms/b957aef6-0232-ef11-8409-6045bddd5e05?=outlook.office.com/mail/inbox/id/xMwAQAP%2FO5QhSWQBJt%2Bdd51R9eCU%3D?actSwt=trueHTTP Parser: No favicon
            Source: https://assets-eur.mkt.dynamics.com/21f9f50d-1320-ef11-8406-000d3adc9e50/digitalassets/standaloneforms/b957aef6-0232-ef11-8409-6045bddd5e05?=outlook.office.com/mail/inbox/id/xMwAQAP%2FO5QhSWQBJt%2Bdd51R9eCU%3D?actSwt=trueHTTP Parser: No favicon
            Source: https://assets-eur.mkt.dynamics.com/21f9f50d-1320-ef11-8406-000d3adc9e50/digitalassets/standaloneforms/b957aef6-0232-ef11-8409-6045bddd5e05?=outlook.office.com/mail/inbox/id/xMwAQAP%2FO5QhSWQBJt%2Bdd51R9eCU%3D?actSwt=trueHTTP Parser: No favicon
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0HTTP Parser: No favicon
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0HTTP Parser: No <meta name="author".. found
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0&sso_reload=trueHTTP Parser: No <meta name="author".. found
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0&sso_reload=trueHTTP Parser: No <meta name="author".. found
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2flandingv2&response_type=code+id_token&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&x-client-SKU=ID_NET8_0&x-client-Ver=7.3.1.0&uaid=976181e54da940e29d919d30b3841ead&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAAApTwJmzXqdR4BN2miheQMYnqHLls0CaoB_DpHqTN_HArxmPF1V1KvJ63jDI7-4VQ9Lk8TDOD7W_RcY0hixyy57QQY7mQj-UaGrO607yvAiXRJaYknfqDOHTTP Parser: No <meta name="author".. found
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2flandingv2&response_type=code+id_token&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&x-client-SKU=ID_NET8_0&x-client-Ver=7.3.1.0&uaid=976181e54da940e29d919d30b3841ead&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAAApTwJmzXqdR4BN2miheQMYnqHLls0CaoB_DpHqTN_HArxmPF1V1KvJ63jDI7-4VQ9Lk8TDOD7W_RcY0hixyy57QQY7mQj-UaGrO607yvAiXRJaYknfqDOHTTP Parser: No <meta name="author".. found
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/ppsecure/post.srf?username=bum%40bum.com&client_id=4765445b-32c6-49b0-83e6-1d93765276ca&contextid=2E846C5FA95026DB&opid=9D0903C250E0D8EE&bk=1719840359&uaid=976181e54da940e29d919d30b3841ead&pid=15216HTTP Parser: No <meta name="author".. found
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/ppsecure/post.srf?username=bum%40bum.com&client_id=4765445b-32c6-49b0-83e6-1d93765276ca&contextid=2E846C5FA95026DB&opid=9D0903C250E0D8EE&bk=1719840359&uaid=976181e54da940e29d919d30b3841ead&pid=15216HTTP Parser: No <meta name="author".. found
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0HTTP Parser: No <meta name="copyright".. found
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0&sso_reload=trueHTTP Parser: No <meta name="copyright".. found
            Source: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0&sso_reload=trueHTTP Parser: No <meta name="copyright".. found
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2flandingv2&response_type=code+id_token&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&x-client-SKU=ID_NET8_0&x-client-Ver=7.3.1.0&uaid=976181e54da940e29d919d30b3841ead&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAAApTwJmzXqdR4BN2miheQMYnqHLls0CaoB_DpHqTN_HArxmPF1V1KvJ63jDI7-4VQ9Lk8TDOD7W_RcY0hixyy57QQY7mQj-UaGrO607yvAiXRJaYknfqDO...HTTP Parser: No <meta name="copyright".. found
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2flandingv2&response_type=code+id_token&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&x-client-SKU=ID_NET8_0&x-client-Ver=7.3.1.0&uaid=976181e54da940e29d919d30b3841ead&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAAApTwJmzXqdR4BN2miheQMYnqHLls0CaoB_DpHqTN_HArxmPF1V1KvJ63jDI7-4VQ9Lk8TDOD7W_RcY0hixyy57QQY7mQj-UaGrO607yvAiXRJaYknfqDO...HTTP Parser: No <meta name="copyright".. found
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/ppsecure/post.srf?username=bum%40bum.com&client_id=4765445b-32c6-49b0-83e6-1d93765276ca&contextid=2E846C5FA95026DB&opid=9D0903C250E0D8EE&bk=1719840359&uaid=976181e54da940e29d919d30b3841ead&pid=15216HTTP Parser: No <meta name="copyright".. found
            Source: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/ppsecure/post.srf?username=bum%40bum.com&client_id=4765445b-32c6-49b0-83e6-1d93765276ca&contextid=2E846C5FA95026DB&opid=9D0903C250E0D8EE&bk=1719840359&uaid=976181e54da940e29d919d30b3841ead&pid=15216HTTP Parser: No <meta name="copyright".. found
            Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49744 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49747 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49758 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49809 version: TLS 1.2
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
            Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
            Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
            Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
            Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
            Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
            Source: global trafficDNS traffic detected: DNS query: forms.office.com
            Source: global trafficDNS traffic detected: DNS query: cdn.forms.office.net
            Source: global trafficDNS traffic detected: DNS query: lists.office.com
            Source: global trafficDNS traffic detected: DNS query: www.google.com
            Source: global trafficDNS traffic detected: DNS query: c.office.com
            Source: global trafficDNS traffic detected: DNS query: assets-eur.mkt.dynamics.com
            Source: global trafficDNS traffic detected: DNS query: public-eur.mkt.dynamics.com
            Source: global trafficDNS traffic detected: DNS query: login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com
            Source: global trafficDNS traffic detected: DNS query: www.mmhnzmefkqeqeuthdhbhgeez.from-wa.com
            Source: global trafficDNS traffic detected: DNS query: aadcdn.msftauth.net
            Source: global trafficDNS traffic detected: DNS query: ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com
            Source: global trafficDNS traffic detected: DNS query: identity.nel.measure.office.net
            Source: global trafficDNS traffic detected: DNS query: logincdn.msftauth.net
            Source: global trafficDNS traffic detected: DNS query: acctcdn.msftauth.net
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
            Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
            Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
            Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
            Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
            Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
            Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
            Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
            Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
            Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
            Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
            Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
            Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
            Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
            Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
            Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
            Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
            Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
            Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
            Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
            Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
            Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
            Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
            Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
            Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
            Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
            Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49744 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49747 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49758 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49809 version: TLS 1.2
            Source: classification engineClassification label: mal68.phis.win@16/57@48/268
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
            Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://forms.office.com/e/tBp2XcGpEy
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1972,i,6951622617809385496,11899697623652637181,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1972,i,6951622617809385496,11899697623652637181,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: Window RecorderWindow detected: More than 3 window changes detected
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
            Registry Run Keys / Startup Folder
            1
            Process Injection
            1
            Masquerading
            OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
            Registry Run Keys / Startup Folder
            1
            Process Injection
            LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
            Non-Application Layer Protocol
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
            Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            https://forms.office.com/e/tBp2XcGpEy0%Avira URL Cloudsafe
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            s-part-0014.t-0009.t-msedge.net
            13.107.246.42
            truefalse
              unknown
              prdia888neu0aks.mkt.dynamics.com
              52.146.128.240
              truefalse
                unknown
                s-part-0044.t-0009.fb-t-msedge.net
                13.107.253.72
                truefalse
                  unknown
                  mmhnzmefkqeqeuthdhbhgeez.from-wa.com
                  85.10.151.176
                  truetrue
                    unknown
                    sni1gl.wpc.alphacdn.net
                    152.199.21.175
                    truefalse
                      unknown
                      sni1gl.wpc.omegacdn.net
                      152.199.21.175
                      truefalse
                        unknown
                        www.google.com
                        142.250.74.196
                        truefalse
                          unknown
                          s-part-0035.t-0009.t-msedge.net
                          13.107.246.63
                          truefalse
                            unknown
                            s-part-0039.t-0009.fb-t-msedge.net
                            13.107.253.67
                            truefalse
                              unknown
                              s-part-0032.t-0009.t-msedge.net
                              13.107.246.60
                              truefalse
                                unknown
                                forms.office.com
                                unknown
                                unknownfalse
                                  unknown
                                  aadcdn.msftauth.net
                                  unknown
                                  unknownfalse
                                    unknown
                                    logincdn.msftauth.net
                                    unknown
                                    unknownfalse
                                      unknown
                                      ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com
                                      unknown
                                      unknowntrue
                                        unknown
                                        cdn.forms.office.net
                                        unknown
                                        unknownfalse
                                          unknown
                                          lists.office.com
                                          unknown
                                          unknownfalse
                                            unknown
                                            www.mmhnzmefkqeqeuthdhbhgeez.from-wa.com
                                            unknown
                                            unknownfalse
                                              unknown
                                              login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com
                                              unknown
                                              unknowntrue
                                                unknown
                                                identity.nel.measure.office.net
                                                unknown
                                                unknownfalse
                                                  unknown
                                                  c.office.com
                                                  unknown
                                                  unknownfalse
                                                    unknown
                                                    public-eur.mkt.dynamics.com
                                                    unknown
                                                    unknownfalse
                                                      unknown
                                                      acctcdn.msftauth.net
                                                      unknown
                                                      unknownfalse
                                                        unknown
                                                        assets-eur.mkt.dynamics.com
                                                        unknown
                                                        unknownfalse
                                                          unknown
                                                          NameMaliciousAntivirus DetectionReputation
                                                          https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0true
                                                            unknown
                                                            https://assets-eur.mkt.dynamics.com/21f9f50d-1320-ef11-8406-000d3adc9e50/digitalassets/standaloneforms/b957aef6-0232-ef11-8409-6045bddd5e05?=outlook.office.com/mail/inbox/id/xMwAQAP%2FO5QhSWQBJt%2Bdd51R9eCU%3D?actSwt=truefalse
                                                              unknown
                                                              https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&ui_locales=en-US&mkt=en-US&client-request-id=976181e5-4da9-40e2-9d91-9d30b3841ead&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&x-client-SKU=ID_NET8_0&x-client-ver=7.3.1.0&sso_reload=truetrue
                                                                unknown
                                                                https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/ppsecure/post.srf?username=bum%40bum.com&client_id=4765445b-32c6-49b0-83e6-1d93765276ca&contextid=2E846C5FA95026DB&opid=9D0903C250E0D8EE&bk=1719840359&uaid=976181e54da940e29d919d30b3841ead&pid=15216true
                                                                  unknown
                                                                  https://forms.office.com/pages/responsepage.aspx?id=g05NLYN6pUWwSUaSYRcBTPWlbxK0xypPh7PdVHAOShFUN0NZNENZOVpEUkFMOFE3MzFYNFFaRkFESS4ufalse
                                                                    unknown
                                                                    https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2flandingv2&response_type=code+id_token&state=J-aIlT0ncMMFEJkIjOKP97PN9Ina9hgezRwtylZBETZbtp_xlf6GsAnsjAPjFDuZ_hze1k400EWMjFYiC4MBs0JH2JGHGI6UGQa2v7HG3JBLiEWT_xOidctdS02c9Q-mYJfcisIwCvqseyKuE5Y26rr7QKTK_L8vTRubZ5pBpoH_NwBcQKnY9hUxX7XxMW1IZUa0L0OQeEy1LZq4O2czoAAdrRDi84B0fnzI4oe8YSDeTKhasZh6m5bapoTK2PEQLTJJMYc33Xyd3r16StEc9Q&response_mode=form_post&nonce=638554371033554689.NjVlNWI5MWMtYjNjYy00ZWE4LWI1YTMtYjViMjAyNDVjYTczZjZkNWNhZTctZWExYS00OTBkLTliNGMtZDZiNGMzYjc2YzIy&x-client-SKU=ID_NET8_0&x-client-Ver=7.3.1.0&uaid=976181e54da940e29d919d30b3841ead&msproxy=1&issuer=mso&tenant=common&ui_locales=en-US&epct=PAQABDgEAAAApTwJmzXqdR4BN2miheQMYnqHLls0CaoB_DpHqTN_HArxmPF1V1KvJ63jDI7-4VQ9Lk8TDOD7W_RcY0hixyy57QQY7mQj-UaGrO607yvAiXRJaYknfqDOVJAG1dLwSK554Z54xsBKJ-ualLWloKQ265Asu1UDzwhQ9k9MoUgVZ46BYQ0SgsTj7yv3Y5IX_zvVy32yGKsihu0WmVH2CdP-LSE4_Ky2IMoynSGdnKI1odCAA&jshs=0&username=bum%40bum.com&login_hint=bum%40bum.comtrue
                                                                      unknown
                                                                      • No. of IPs < 25%
                                                                      • 25% < No. of IPs < 50%
                                                                      • 50% < No. of IPs < 75%
                                                                      • 75% < No. of IPs
                                                                      IPDomainCountryFlagASNASN NameMalicious
                                                                      13.107.246.63
                                                                      s-part-0035.t-0009.t-msedge.netUnited States
                                                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                      52.168.117.171
                                                                      unknownUnited States
                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                      216.58.206.78
                                                                      unknownUnited States
                                                                      15169GOOGLEUSfalse
                                                                      13.107.6.194
                                                                      unknownUnited States
                                                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                      13.107.246.60
                                                                      s-part-0032.t-0009.t-msedge.netUnited States
                                                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                      52.182.141.63
                                                                      unknownUnited States
                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                      40.126.32.76
                                                                      unknownUnited States
                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                      88.221.110.176
                                                                      unknownEuropean Union
                                                                      20940AKAMAI-ASN1EUfalse
                                                                      13.74.129.1
                                                                      unknownUnited States
                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                      2.18.121.147
                                                                      unknownEuropean Union
                                                                      16625AKAMAI-ASUSfalse
                                                                      85.10.151.176
                                                                      mmhnzmefkqeqeuthdhbhgeez.from-wa.comFrance
                                                                      21283A1SI-ASA1SlovenijaSItrue
                                                                      2.18.64.204
                                                                      unknownEuropean Union
                                                                      6057AdministracionNacionaldeTelecomunicacionesUYfalse
                                                                      142.250.74.196
                                                                      www.google.comUnited States
                                                                      15169GOOGLEUSfalse
                                                                      66.102.1.84
                                                                      unknownUnited States
                                                                      15169GOOGLEUSfalse
                                                                      204.79.197.237
                                                                      unknownUnited States
                                                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                      1.1.1.1
                                                                      unknownAustralia
                                                                      13335CLOUDFLARENETUSfalse
                                                                      216.58.212.131
                                                                      unknownUnited States
                                                                      15169GOOGLEUSfalse
                                                                      52.111.243.106
                                                                      unknownUnited States
                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                      2.16.241.17
                                                                      unknownEuropean Union
                                                                      20940AKAMAI-ASN1EUfalse
                                                                      2.16.164.113
                                                                      unknownEuropean Union
                                                                      20940AKAMAI-ASN1EUfalse
                                                                      216.58.206.46
                                                                      unknownUnited States
                                                                      15169GOOGLEUSfalse
                                                                      88.221.110.240
                                                                      unknownEuropean Union
                                                                      20940AKAMAI-ASN1EUfalse
                                                                      88.221.169.152
                                                                      unknownEuropean Union
                                                                      16625AKAMAI-ASUSfalse
                                                                      13.107.253.72
                                                                      s-part-0044.t-0009.fb-t-msedge.netUnited States
                                                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                      239.255.255.250
                                                                      unknownReserved
                                                                      unknownunknownfalse
                                                                      172.217.18.106
                                                                      unknownUnited States
                                                                      15169GOOGLEUSfalse
                                                                      142.250.185.131
                                                                      unknownUnited States
                                                                      15169GOOGLEUSfalse
                                                                      152.199.21.175
                                                                      sni1gl.wpc.alphacdn.netUnited States
                                                                      15133EDGECASTUSfalse
                                                                      52.146.128.240
                                                                      prdia888neu0aks.mkt.dynamics.comUnited States
                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                      2.18.121.134
                                                                      unknownEuropean Union
                                                                      16625AKAMAI-ASUSfalse
                                                                      20.50.73.9
                                                                      unknownUnited States
                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                      IP
                                                                      192.168.2.17
                                                                      192.168.2.16
                                                                      192.168.2.22
                                                                      Joe Sandbox version:40.0.0 Tourmaline
                                                                      Analysis ID:1465354
                                                                      Start date and time:2024-07-01 15:24:08 +02:00
                                                                      Joe Sandbox product:CloudBasic
                                                                      Overall analysis duration:
                                                                      Hypervisor based Inspection enabled:false
                                                                      Report type:full
                                                                      Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                      Sample URL:https://forms.office.com/e/tBp2XcGpEy
                                                                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                      Number of analysed new started processes analysed:14
                                                                      Number of new started drivers analysed:0
                                                                      Number of existing processes analysed:0
                                                                      Number of existing drivers analysed:0
                                                                      Number of injected processes analysed:0
                                                                      Technologies:
                                                                      • EGA enabled
                                                                      Analysis Mode:stream
                                                                      Analysis stop reason:Timeout
                                                                      Detection:MAL
                                                                      Classification:mal68.phis.win@16/57@48/268
                                                                      • Exclude process from analysis (whitelisted): svchost.exe
                                                                      • Excluded IPs from analysis (whitelisted): 216.58.212.131, 13.107.6.194, 66.102.1.84, 216.58.206.78, 34.104.35.123, 2.18.121.134, 2.18.121.147, 52.111.243.106, 199.232.214.172, 13.74.129.1
                                                                      • Excluded domains from analysis (whitelisted): a1894.dscms.akamai.net, b-0039.b-msedge.net, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, prod.lists.office.com.akadns.net, c-msn-com-nsatc.trafficmanager.net, cdn.forms.office.net.edgesuite.net, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, forms.office.com.b-0039.b-msedge.net
                                                                      • Not all processes where analyzed, report is missing behavior information
                                                                      • VT rate limit hit for: https://forms.office.com/e/tBp2XcGpEy
                                                                      InputOutput
                                                                      URL: https://forms.office.com/pages/responsepage.aspx?id=g05NLYN6pUWwSUaSYRcBTPWlbxK0xypPh7PdVHAOShFUN0NZNENZOVpEUkFMOFE3MzFYNFFaRkFESS4u Model: Perplexity: mixtral-8x7b-instruct
                                                                      {"loginform": false,"urgency": false,"captcha": false,"reasons": ["The webpage does not contain a login form as there is no explicit request for sensitive information such as passwords, email addresses, usernames, phone numbers or credit card numbers (CVV).","The text does not create a sense of urgency as it only informs the user about a new PDF document for review and provides two options to access it.","The webpage does not contain a CAPTCHA or any other anti-robot detection mechanism."]}
                                                                      Title: PROJECT REPORT OCR: PROJECT REPORT You have received a new PDF document for your review (Copy the URL to your browser or Click to access it) 1-8406- 7aef6-0232-ef11-8409-6045bdddSe05? 
                                                                      URL: https://assets-eur.mkt.dynamics.com/21f9f50d-1320-ef11-8406-000d3adc9e50/digitalassets/standaloneforms/b957aef6-0232-ef11-8409-6045bddd5e05?=outlook.office.com/mail/inbox/id/xMwAQAP%2FO5QhSWQBJt%2Bdd51R9eCU%3D?actSwt=true Model: Perplexity: mixtral-8x7b-instruct
                                                                      {"loginform": false,"urgency": false,"captcha": false,"reasons": ["The webpage does not contain a login form explicitly requesting sensitive information.","The text does not create a sense of urgency or interest.","The webpage does not contain a CAPTCHA or any other anti-robot detection mechanism."]}
                                                                      Title: Microsoft OCR: Ski to main content Microsoft Microsoft Account Home Microsoft Security We use cookies and similar tools which are necessary to improve your experience on our websites, such as through social media connections, and to display personalised advertising based on your online activity. Coninue Sign in Powered by M icrosoft Performance & security by Cloudflare 
                                                                      URL: https://assets-eur.mkt.dynamics.com/21f9f50d-1320-ef11-8406-000d3adc9e50/digitalassets/standaloneforms/b957aef6-0232-ef11-8409-6045bddd5e05?=outlook.office.com/mail/inbox/id/xMwAQAP%2FO5QhSWQBJt%2Bdd51R9eCU%3D?actSwt=true Model: Perplexity: mixtral-8x7b-instruct
                                                                      {"loginform": false,"urgency": false,"captcha": false,"reasons": ["The webpage does not contain a login form requesting sensitive information.","The text does not create a sense of urgency or interest.","The webpage does not contain a CAPTCHA or any other anti-robot detection mechanism."]}
                                                                      Title: Microsoft OCR: Microsoft Microsoft Security We use cookies and similar tools which are necessary to improve your experience on our websites, such as through social media connections, and to display personalised advertising based on your online activity. Powered by M icrosoft Performance & security by Cloudflare 
                                                                      URL: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.o Model: Perplexity: mixtral-8x7b-instruct
                                                                      {"loginform": true,"urgency": false,"captcha": false,"reasons": ["The webpage contains a login form which explicitly requests sensitive information such as passwords, email addresses, and usernames.","There is no sense of urgency created in the text.","There is no CAPTCHA or anti-robot detection mechanism present on the webpage."]}
                                                                      Title: Sign in to your account OCR: Microsoft Sign in k mail, phone, or Skype No account? Create one! Can't access your account? Back Next Sign-in options Terms of use Privacy & ckies 
                                                                      URL: https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com Model: gpt-4o
                                                                      ```json{  "phishing_score": 9,  "brands": "Microsoft",  "phishing": true,  "suspicious_domain": true,  "has_prominent_loginform": true,  "has_captcha": false,  "setechniques": true,  "has_suspicious_link": true,  "legitmate_domain": "login.microsoftonline.com",  "reasons": "The URL 'https://login.mmhnzmefkqeqeuthdhbhgeez.from-wa.com' is highly suspicious. It does not match the legitimate domain for Microsoft login, which is 'login.microsoftonline.com'. The presence of a prominent login form is a common tactic used in phishing attacks to capture user credentials. Additionally, the use of a subdomain with random characters is a known social engineering technique to mislead users. There is no CAPTCHA present, which is often used by legitimate sites to prevent automated attacks. The combination of these factors strongly indicates that this is a phishing site."}
                                                                      URL: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.mmhnzm Model: Perplexity: mixtral-8x7b-instruct
                                                                      {"loginform": true,"urgency": false,"captcha": false,"reasons": ["The webpage contains a login form which explicitly requests sensitive information such as email addresses and passwords.","The text does not create a sense of urgency or interest.","There is no CAPTCHA or anti-robot detection mechanism present on the webpage."]}
                                                                      Title: Sign in to your Microsoft account OCR: Microsoft bum@bum.com Enter password password Forgot password? Sign in Terms of use Privacy & cookies 
                                                                      URL: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com/oauth20_authorize.srf?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&scope=openid+profile+https%3a%2f%2fwww.mmhnzmefkqeqeuthdhbhgeez.from-wa.com%2fv2%2fOfficeHome.All&redirect_uri=https%3a%2f%2fwww.mmhnzm Model: Perplexity: mixtral-8x7b-instruct
                                                                      {"loginform": true,"urgency": false,"captcha": false,"reasons": ["The webpage contains a form that explicitly requests sensitive information such as email addresses and passwords, which is indicative of a login form.","The text does not create a sense of urgency as it does not contain phrases such as 'click here to view document' or 'to view secured document click here'.","There is no CAPTCHA or anti-robot detection mechanism present on the webpage."]}
                                                                      Title: Sign in to your Microsoft account OCR: Microsoft bum@bum.com Enter password Forgot password? Sign in Terms of use Privacy & cookies 
                                                                      URL: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com Model: gpt-4o
                                                                      ```json{  "phishing_score": 9,  "brands": "Microsoft",  "phishing": true,  "suspicious_domain": true,  "has_prominent_loginform": true,  "has_captcha": false,  "setechniques": true,  "has_suspicious_link": true,  "legitmate_domain": "microsoft.com",  "reasons": "The URL 'https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com' is highly suspicious. It does not match the legitimate domain for Microsoft, which is 'microsoft.com'. The presence of a prominent login form asking for a password is a common phishing tactic. Additionally, the URL structure and the use of a subdomain with random characters are typical of phishing attempts. The site also uses social engineering techniques by mimicking the legitimate Microsoft login page to deceive users into entering their credentials. There is no CAPTCHA present, which is often used in legitimate sites to prevent automated attacks. The 'Forgot password?' link could potentially lead to further phishing attempts."}
                                                                      URL: https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com Model: gpt-4o
                                                                      ```json{  "phishing_score": 9,  "brands": "Microsoft",  "phishing": true,  "suspicious_domain": true,  "has_prominent_loginform": true,  "has_captcha": false,  "setechniques": true,  "has_suspicious_link": true,  "legitmate_domain": "microsoft.com",  "reasons": "The URL 'https://ywnjb.mmhnzmefkqeqeuthdhbhgeez.from-wa.com' is highly suspicious. It does not match the legitimate domain 'microsoft.com' associated with the brand Microsoft. The domain name is convoluted and uses a subdomain structure often seen in phishing attacks. The webpage prominently displays a login form asking for a password, which is a common tactic used in phishing to steal credentials. Additionally, the presence of a 'Forgot password?' link is another common element used to make phishing sites appear legitimate. There is no CAPTCHA present, which is often used on legitimate login pages to prevent automated attacks. Overall, the combination of these factors strongly suggests that this is a phishing site."}
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 1 12:24:39 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                      Category:dropped
                                                                      Size (bytes):2673
                                                                      Entropy (8bit):3.986687718835554
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:C6156AF5359A99F6923CEA83EA1224EC
                                                                      SHA1:BCF1A9271F724A15A8B0BF2A90E2CD99A9834576
                                                                      SHA-256:6A4F9F456D9E449E8BC331566754B1F8BF34D29234D1220A112A435A96E2FFE1
                                                                      SHA-512:1977DD76CFED49960D383B7508B524A148EFEAEFB1C9686B73520854337FD7D76D7CC377AF92E0DFFEAB3E1FBA5B6549D41FE3299DA66757750DEE9AC501C929
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:L..................F.@.. ...$+.,....h.......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.k....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.k....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.k....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.k..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.k...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............1.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 1 12:24:39 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                      Category:dropped
                                                                      Size (bytes):2675
                                                                      Entropy (8bit):4.004510575382147
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:07D1255CA0519CB8B8E9BBC8BB94027F
                                                                      SHA1:7C6726C951DDAED94EB8BE5BC4B924E1C6B64F8A
                                                                      SHA-256:E271D0073B24898C4338A42DF7DAB12D9E3068F15B4117B0883007F08F028E79
                                                                      SHA-512:BB933CC589FF930716D4F76112C2FFB685A37B214F21B285E76132B5B89D06AA866557B49D47AD2FFE5BB2C8B55837E8DE45A7C1216C8798C924221CA395D42C
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:L..................F.@.. ...$+.,............N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.k....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.k....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.k....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.k..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.k...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............1.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                      Category:dropped
                                                                      Size (bytes):2689
                                                                      Entropy (8bit):4.00902241649492
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:2080CD8A12349D4CE72C88591895BA5F
                                                                      SHA1:6B23388C743F17BA3C39AB427B69787F3DBD760B
                                                                      SHA-256:B7F3584B7D0E2C173E4496DA7AFEB196A71E03C2FE047FBDDF61F829A9E0E072
                                                                      SHA-512:7BD6988793AC5352412B6B2C10931C623A753DF7FEC0E3D2FA3C5925CF78FBEF66A3A036C7881CC5C38C312732083A2C191FD2354B1AB84ABAEE54AAD520EC49
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.k....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.k....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.k....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.k..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............1.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 1 12:24:39 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                      Category:dropped
                                                                      Size (bytes):2677
                                                                      Entropy (8bit):4.00084164511291
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:C245BA3418531FA996A56C34CDB7200A
                                                                      SHA1:A899565A48A6EA057398F3F18E5B6D87408D7037
                                                                      SHA-256:94DC4C2B6D9392E5620EB46256BDBF8786AA43DF39BF964576B6E165455CF288
                                                                      SHA-512:D1DC1288D7ECDA403D583B59E5431DE1D6FA664D6F44E0F2366748536B64F56CB00A9CE894E57DC29B5A0C82A081F9452B0F60A963743BE0BC76911E5C651C8F
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:L..................F.@.. ...$+.,.....G......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.k....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.k....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.k....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.k..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.k...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............1.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 1 12:24:39 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                      Category:dropped
                                                                      Size (bytes):2677
                                                                      Entropy (8bit):3.9893216987606404
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:5CD68E5CDD041A69FCD24695F1B34EF9
                                                                      SHA1:E02794650A2B827C21CDF70CFC33CD124AD7CED0
                                                                      SHA-256:2669673C10BCDF4BD08B04B9F0B8B054DCCC08A73BE9CFD7388B1ABBADCDF044
                                                                      SHA-512:A5DC227AA07DA0FA3F3BFFA40C15E29C0A9E93ECC7924329888BD781069D932D85FB08B56715C1001BFBF18CD107118327E433C0BA0103978078C7770B1B9899
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:L..................F.@.. ...$+.,............N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.k....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.k....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.k....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.k..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.k...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............1.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 1 12:24:39 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                      Category:dropped
                                                                      Size (bytes):2679
                                                                      Entropy (8bit):4.000858666512784
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:D209CFCFB064D406231A493C68C632E9
                                                                      SHA1:7900F6F0BE7103D4601191392E34C580791EB982
                                                                      SHA-256:4D41C7BA1B59D4E7BEBA6E986AEA1FBCF0F0A8C966AF4C26649653B233A8E4CB
                                                                      SHA-512:17A4519CF269D544724F7027CCF1E8A1DEB497D8B06B88625D661BCEB29AE124CA7BACA83EFEA89788FA98E2A6DF55F442DE5047866130592B18A9B23059D561
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:L..................F.@.. ...$+.,....J5......N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.k....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.k....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.k....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.k..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.k...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............1.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (38720)
                                                                      Category:downloaded
                                                                      Size (bytes):493029
                                                                      Entropy (8bit):5.467496504307675
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:8C174499C7E3C62F1ABCB0E95068E13A
                                                                      SHA1:32315081EC027B1A6816E61CAD296D461D61618C
                                                                      SHA-256:CCF9D800FBAE0234C23D7E1536264977840B18177328F7E8221B74C3710530AE
                                                                      SHA-512:33295510858A399D6E0F86C7CE8EEF6D79A735E7C612857E76011666F05A043B20C8E16C15112A318533F2270E339119E4F9D574194520CE4DFE39DE1E90A8AF
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/scripts/dists/light-response-page.min.d3c98fd.js
                                                                      Preview:!function(){var n,t,r,e,i,o={65690:function(n,t,r){"use strict";function e(n){o!==n&&(o=n)}function i(){return void 0===o&&(o="undefined"!=typeof document&&!!document.documentElement&&"rtl"===document.documentElement.getAttribute("dir")),o}var o;function u(){return{rtl:i()}}r.d(t,{Eo:function(){return u},ok:function(){return e}}),o=i()},36178:function(n,t,r){"use strict";r.d(t,{Y:function(){return c},q:function(){return o}});var e,i=r(59312),o={none:0,insertNode:1,appendChild:2},u="undefined"!=typeof navigator&&/rv:11.0/.test(navigator.userAgent),a={};try{a=window||{}}catch(n){}var c=function(){function n(n,t){var r,e,u,a,c,f;this._rules=[],this._preservedRules=[],this._counter=0,this._keyToClassName={},this._onInsertRuleCallbacks=[],this._onResetCallbacks=[],this._classNameToArgs={},this._config=(0,i.pi)({injectionMode:"undefined"==typeof document?o.none:o.insertNode,defaultPrefix:"css",namespace:void 0,cspSettings:void 0},n),this._classNameToArgs=null!==(r=null==t?void 0:t.classNameT
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
                                                                      Category:dropped
                                                                      Size (bytes):4054
                                                                      Entropy (8bit):7.797012573497454
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:9F14C20150A003D7CE4DE57C298F0FBA
                                                                      SHA1:DAA53CF17CC45878A1B153F3C3BF47DC9669D78F
                                                                      SHA-256:112FEC798B78AA02E102A724B5CB1990C0F909BC1D8B7B1FA256EAB41BBC0960
                                                                      SHA-512:D4F6E49C854E15FE48D6A1F1A03FDA93218AB8FCDB2C443668E7DF478830831ACC2B41DAEFC25ED38FCC8D96C4401377374FED35C36A5017A11E63C8DAE5C487
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:.PNG........IHDR.............J.......tEXtSoftware.Adobe ImageReadyq.e<...(iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c132 79.159284, 2016/04/19-13:13:40 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmpMM:DocumentID="xmp.did:A00BC639840A11E68CBEB97C2156C7FD" xmpMM:InstanceID="xmp.iid:A00BC638840A11E68CBEB97C2156C7FD" xmp:CreatorTool="Adobe Photoshop CC 2015.5 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:A2C931A470A111E6AEDFA14578553B7B" stRef:documentID="xmp.did:A2C931A570A111E6AEDFA14578553B7B"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>.......DIDATx..\..UU.>.7..3....h.L..& j2...h.@..".........`U.......R"..Dq.&.BJR 1.4`$.200...l........wg.y.[k/
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (65470)
                                                                      Category:downloaded
                                                                      Size (bytes):911559
                                                                      Entropy (8bit):5.416413084191307
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:0796A9CE73B7BE5B58A217A51C099ADB
                                                                      SHA1:7EBEE011246E111793827CF94B4E6AFBE260AFCD
                                                                      SHA-256:725B38886F059F44300D563C21D4324B5CC464ED19479DCB1891104DA83C4D2A
                                                                      SHA-512:4C2F2371CAB9C14BEC174B498DB4D928EA464378EC05B14DBB1022A388AF8AE4A0C7B919B95B23B3E51E2DAF9F69450D86BDEA0A092F00C46BE2E8C0CFCAC8FA
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://logincdn.msftauth.net/shared/5/js/login_en_B5apznO3vltYohelHAma2w2.js
                                                                      Preview:/*! For license information please see login_en.js.LICENSE.txt */.!function(){var e,t,n,r,o,i={97206:function(e,t,n){"use strict";var r=n(9384),o={childContextTypes:!0,contextType:!0,contextTypes:!0,defaultProps:!0,displayName:!0,getDefaultProps:!0,getDerivedStateFromError:!0,getDerivedStateFromProps:!0,mixins:!0,propTypes:!0,type:!0},i={name:!0,length:!0,prototype:!0,caller:!0,callee:!0,arguments:!0,arity:!0},a={$$typeof:!0,compare:!0,defaultProps:!0,displayName:!0,propTypes:!0,type:!0},l={};function s(e){return r.isMemo(e)?a:l[e.$$typeof]||o}l[r.ForwardRef]={$$typeof:!0,render:!0,defaultProps:!0,displayName:!0,propTypes:!0},l[r.Memo]=a;var c=Object.defineProperty,u=Object.getOwnPropertyNames,d=Object.getOwnPropertySymbols,f=Object.getOwnPropertyDescriptor,p=Object.getPrototypeOf,g=Object.prototype;e.exports=function e(t,n,r){if("string"!=typeof n){if(g){var o=p(n);o&&o!==g&&e(t,o,r)}var a=u(n);d&&(a=a.concat(d(n)));for(var l=s(t),m=s(n),h=0;h<a.length;++h){var b=a[h];if(!(i[b]||r&&r[
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 15755
                                                                      Category:downloaded
                                                                      Size (bytes):5528
                                                                      Entropy (8bit):7.970866064773261
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:C64BD28F597CBB6156F45A3A07B0CA92
                                                                      SHA1:C51015874C198D87278B62135727941675274760
                                                                      SHA-256:22BD6DC040C2B88155847410B59793DEBCDB8CACA308B07D65F86695B7CF5420
                                                                      SHA-512:445739E75528CD87400836F94BA9AE11A47B35AFAFBB3C466ABDE56C6E788150B8A06FA152FDD3D6DB0D7D07CB65DC62367A441C66E1852FE09E2914EDCE7CDD
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://aadcdn.msauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pfetchsessionsprogress_0b5ca5d48eeaf75b0528.js
                                                                      Preview:...........[}w.F....Bh..i3...v.>./.......&9...P,$U#lS.w.~wFB..v.lN...;w...+..U.F..v..?Z.wv....Z.].]......i....6..../...p...WpO.B-J4?.FI.%n.6......(..Z:.Z.D_.0.Z.....<..5...O.r.t.u.L..9..c?..a...}.ja..C...'..x...f....~..'.?L"..R-.C..a.1....Ls....j.(I'..K..d.U.m.B...;...<(.....H.g84...`n..X!#z.i..H.G....<~8.......x..$x.aj..S..H..-.x.If..]..1.D0.......pq.8.|...y\...5....y2.q.Fq...[.......@..(|e}........G....M55I.X..c?....0..z.l.....oq8......./B-8W.......h.h..a..U...5._....s...........v.z.~c....i.........N..b..i.311>~<..3{|}.....!...,d.|.sqY.0^.,....|.....w&s3.l.$V#....*.....u.y7M U,..KJ.A...y.y..',.lg.z.f.k.fA...B|@..,..;.'9.Z.....!qb..,_..17L.:...4..........L\,..g.tr...A.p$n....S..q..E.......P.#.....<vE.d.....F....x...,`c.V...,~.=..R=....%yu..h'.i.o>.g.Nj.I.._.u.{....M..._.z.Q8...A.H..._fIp......-O.6.,....G.It.!.g#...l.$\W8...7.s.....{~"..k..X....q......l.>x..={f.n..W.....c..Q..I?..;a..MS>.!5v.h.B+.......q...z.q..^o.>..@..O....X.vd.4.z..Y...S
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
                                                                      Category:downloaded
                                                                      Size (bytes):1435
                                                                      Entropy (8bit):7.8613342322590265
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:9F368BC4580FED907775F31C6B26D6CF
                                                                      SHA1:E393A40B3E337F43057EEE3DE189F197AB056451
                                                                      SHA-256:7ECBBA946C099539C3D9C03F4B6804958900E5B90D48336EEA7E5A2ED050FA36
                                                                      SHA-512:0023B04D1EEC26719363AED57C95C1A91244C5AFF0BB53091938798FB16E230680E1F972D166B633C1D2B314B34FE0B9D7C18442410DB7DD6024E279AAFD61B0
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://aadcdn.msauth.net/shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg
                                                                      Preview:...........WMo.7..+..uV.HJ...{..........&..v...(Q.F.....aW.Q.|..~.|{~...b{8...zv.....8|...b.gxb.y{.x<\lS...p...p..l7...o.}.v.....t.........r..r.|9?.......HP...r.4.aGA.j....7.!....K.n.B.Z.C.]....kj..A..p...xI...b..I!K..><.B..O....#...$.]h.bU.;.Y...).r.u....g*.-w.2..vPh....q....4_..N\..@y).t{.2pj.f..4h.....NC.....x.R..P..9.....".4.`%N..&...a.@.......fS)A4.F..8e9KHE....8d.CR.K..g..Q.......a....f.....dg*N.N.k..#w..........,.".%..I.q.Y.R]..7.!.:.Ux...T.qI..{..,b..2..B...Bh...[o..[4....dZ.z.!.l....E.9$..Y.'...M.,p..$..8Ns3.B.....{.....H..Se3....%.Ly...VP{.Bh.D.+....p..(..`....t....U.e....2......j...%..0.f<...q...B.k..N....03...8....l.....bS...vh..8..Q..LWXW..C.......3..Pr.V.l...^=VX\,d9f.Y;1!w.d,.qvs....f*;.....Zhrr.,.U....6.Y....+Zd.*R...but....".....4.L...z........L.Q......)....,.].Y.&....*ZsIVG.^...#...e..r....Z..F..c..... .QDCmV..1.~...J9..b_Oov\..X.R..._.TqH.q.5G.0{ZphQ..k...s..\.../.Dp..d`#......8.#Y...Mb.j.Q......=n4.c....p.[.SI.....0.N.
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:PNG image data, 800 x 400, 8-bit/color RGBA, non-interlaced
                                                                      Category:downloaded
                                                                      Size (bytes):22558
                                                                      Entropy (8bit):7.774597767634678
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:8C74B93EF72790EC76B5020C4C24B58F
                                                                      SHA1:8C9C97C0B592328E3F2309EAEAE8EDB9FADF15A9
                                                                      SHA-256:6482F94C071441D418F0566C325546CE51F07FA09782027851CB183DD3350E4A
                                                                      SHA-512:1DCD61A95EA619E9B61CA8167349462C45C026A16471358D0E570437F66CF40124CA3BCEAC96EC30CA444C5BCB0A049D8A072F51960A5FAD384EFF52011BC4D8
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://lists.office.com/Images/2d4d4e83-7a83-45a5-b049-46926117014c/126fa5f5-c7b4-4f2a-87b3-dd54700e4a11/T7CY4CY9ZDRAL8Q731X4QZFADI/5adcd565-32f8-46f3-8a13-67e99f4a064e
                                                                      Preview:.PNG........IHDR... .........V%.4....sRGB.........gAMA......a.....pHYs..."..."......W.IDATx^....$ey........F#..DM.LT4..1.....1..NwW.WU..n..-QL......q..x......@PD.K.k..?Ou5.G.L.}...~>.gfg...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................x.^.....AO.v.>OZ.1..}....E....zv......t.X...'....<i........{.....\E.........m...]..e.^...}....}......P..]...~.._...W.y.W..8...?...{...^x...*....f..e..3..NM..`.....^.............>u.y#S.|.x.F....=....O.U.
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (32830)
                                                                      Category:downloaded
                                                                      Size (bytes):33092
                                                                      Entropy (8bit):5.517938818105581
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:C8A069A298CC1BB663397067D28F2101
                                                                      SHA1:4503DFC0E5C0B14A0C5E1AC8C346D7A281B4B75A
                                                                      SHA-256:94E6E9E700A94F8D3F75AB64E5B6C865203963CDECFD9DBEBEA4D8E425CEE202
                                                                      SHA-512:D7850EBE8869B0D38D6AA310767EC918D90B9ECE6DF6648F62557AD7769B3CA598B9CC8B907A0B0E775577CE26A6E6D0480FEFD7F4C701155DA7A3E426024249
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.lrp_saveresponse.9e5a54b.js
                                                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[852],{61029:function(n,e,i){i.d(e,{iF:function(){return o}});var t=i(94290),r=i(48186);function o(n){var e=n.redirectURLAfterSignIn,i=n.idp,o=n.origin,a=n.authProvider,u=n.enableEmailHrd,d=void 0===u||u,s=window.location.origin,c=[];if(e){var l=encodeURIComponent(e);c.push("redirecturl=".concat(l))}(0,r.l)(i)||c.push("idp=".concat(i)),(0,r.l)(o)||c.push("origin=".concat(o)),(0,r.l)(a)||c.push("".concat(t.gx,"=").concat(a));var f=c.length?"/?".concat(c.join("&")):"";return d?"".concat(s).concat(f,"#Login=True"):"".concat(s).concat(f)}},92658:function(n,e,i){i.d(e,{b:function(){return r}});var t=i(68289),r=function(n){var e=void 0===n?{}:n,i=e.$tY,r=e.$s$,o=e.$tc,a=e.$g$,u=e.$i_,d=e.$ia,s=e.$oR,c=e.$jt,l=e.$nC,f=e.$kH,g=e.$v$,p=e.$mU,_=e.$jU,h=[];return i&&h.push("CollectionId=".concat(i)),r&&h.push("GroupId=".concat(r)),o&&h.push("Token=".concat(o)),c&&h.push("ResponseTime=".concat(c)),a&&h.push("SaveResponseFormId=".concat(a
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 447070
                                                                      Category:downloaded
                                                                      Size (bytes):121713
                                                                      Entropy (8bit):7.997650146861334
                                                                      Encrypted:true
                                                                      SSDEEP:
                                                                      MD5:999B203DEA342A1621F1A453F84ADB3F
                                                                      SHA1:811E81207007056E89FD3EC7217359149E01E555
                                                                      SHA-256:9C9F177DCEF35078BF57565329D04CB35CBE39C61D252F6BCA1DC2D72C86D837
                                                                      SHA-512:D07629B8E5AC5B861F7981C7CD8B1A1B46C4AC28FD8E8103F0A73489423659B3EB4F13FC9CD26D13D85411C29D29282E263AC9A2FA02730A4D145FBA4D27CEFD
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://aadcdn.msauth.net/shared/1.0/content/js/ConvergedLogin_PCore_Kjlmc42uL0ATl_21eYcwVg2.js
                                                                      Preview:...........m{.8....~.......e.-....I....8...L.Y..ud.+.y......I...T....s...T,.|.A..A..O;.G.....W....o*.........|.G.rts6<..z.Q....W...*.wb...A%.*^..."...9..y._.F.<.."..dN.W|/N....s...En......U...3..y..v..+.~H*A.x...K.......\.U..<.r.9Q....1.yO.H...|.z.X%fIe.F...G.2FHQkL...c...?y.T8...0@/....0h,...k].DZ..7.J.V^..}6./.U.o.....:.t.zn.1....._..<...b.{..,. ._+.....9.8{.16gA.......V...:B#.+,N...8.T.....$.J..8...?.J..0....~..$Y...3/yXN.N8....o..u....~....r...8.2+W....r..m/.m]..?.a.Jb....?.6h}.\..OW....;.e.`.....+A5..0.>.|..C+.m....1...j.u{w....}....xo..Y.m|..&.j.0.I...X...G...d......}....}....:..2~....R...8..$@....]UFz.UV.mrgE.O.jpww]..#{Zs..7M..jm-.h..m..m..>L.."..i...j.K.QP..u.SX..!..0.Zyf....Ls.^..B..Q..YVO..wX....idi.S..e../p...5.".U.q-.[JX...h4...X..Ni}....[..+7.z.E.<mK..}X.v..4.^.....*...,..j.....i5BT`%b....q..5@} &.&.....v..............N.^,..j..u....P.._..i..}...L.j.taJV.HJ...g..H.C.z...n.P?...v....[.9c.O<-..zc...9.j...p.)#O..!Qr.#ty
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (65536), with no line terminators
                                                                      Category:downloaded
                                                                      Size (bytes):72215
                                                                      Entropy (8bit):5.495467621836068
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:D5F3EE2DB5561A82699270EC94700A30
                                                                      SHA1:8CB342002352BAF4956346CAE4A4056BF240F09C
                                                                      SHA-256:E8E5F7D967C160D05E013E439FDD2165C35DECAC998D6411DF3AEAFCE1AF645D
                                                                      SHA-512:2984433C1D0577815CDD69930F55A7AB54710984AD1789D075D92F04C51DD87D394F02D9DCF00BB24AD993C30436722BC9322B692110F763665A2C7242BCC02B
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.lrp_cover.b0cd9b4.js
                                                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[376],{86219:function(e,t,n){n.d(t,{l:function(){return o}});var i=n(35852);function o(e){for(var t=[],n=1;n<arguments.length;n++)t[n-1]=arguments[n];for(var o=[],r=0,_=t;r<_.length;r++){var a=_[r];a&&o.push("function"==typeof a?a(e):a)}return 1===o.length?o[0]:o.length?i.m.apply(void 0,o):{}}},82699:function(e,t,n){n.d(t,{j:function(){return _}});var i=n(65690),o=n(36178),r=n(49295);function _(e){var t=o.Y.getInstance(),n=(0,r.dH)((0,i.Eo)(),e);if(!t.classNameFromKey(n)){var _=t.getClassName();t.insertRule("@font-face{".concat(n,"}"),!0),t.cacheClassName(_,n,[],["font-face",n])}}},41633:function(e,t,n){n.d(t,{x:function(){return r}});var i={},o=void 0;try{o=window}catch(e){}function r(e,t){if(void 0!==o){var n=o.__packages__=o.__packages__||{};if(!n[e]||!i[e])i[e]=t,(n[e]=n[e]||[]).push(t)}}r("@fluentui/set-version","6.0.0")},20660:function(e,t,n){n.r(t),n.d(t,{AnimationClassNames:function(){return J},AnimationStyles:functio
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with no line terminators
                                                                      Category:downloaded
                                                                      Size (bytes):15
                                                                      Entropy (8bit):3.189898095464287
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:39A19D0882684989864FA50BCED6A2D1
                                                                      SHA1:5CED55DAC2E0427E9DC605CEC1FEDAB0949EB15E
                                                                      SHA-256:8FBEDED073249C3611742297EE96A976A95EE113F33B9A422A5D3A7A2DEB63E5
                                                                      SHA-512:E795CB7DE27B42948B7DDFF19F3B401A8F95753AC7D37D9B5F52D8DACD2AA43A2AD9EACEC29F77D28080E20C21C48B9FA88A733FAC108939FB2F0EB036C7AEEE
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://statics-marketingsites-eus-ms-com.akamaized.net/statics/override.css
                                                                      Preview:/* empty css */
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (34041)
                                                                      Category:downloaded
                                                                      Size (bytes):101666
                                                                      Entropy (8bit):5.420011181790742
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:69B53C08ACFD81CB8659BB5193E96BBA
                                                                      SHA1:439AE06C71C6CE8C01AF6599E3F7CEB7C96900CF
                                                                      SHA-256:78537CEE7626C092BBB0ABE5749C3D07FC0C03FDDB3ECF770EBFDA6EAE395BD6
                                                                      SHA-512:0DDD047F0C8420A819971CAB5927EC6D3AD9939A79CADADBAEA44D410BF6F86AD83A1EC6DE82CE5353A021C6B5C7E2FABEF8749574CBA61300301665B7EED000
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.utel_1ds.6255456.js
                                                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[173],{79966:function(n,t,r){r.d(t,{Z:function(){return L}});var e=r(49577),u=r(71106),i=r(40154),o=r(80403),f=r(39523),c=r(61746),a=r(18449),l=r(72480),v=r(52863),s=r(86969),d=r(90962),h=r(58398),p=500;function y(n,t,r){t&&(0,f.kJ)(t)&&t[l.R5]>0&&(t=t.sort((function(n,t){return n[s.yi]-t[s.yi]})),(0,f.tO)(t,(function(n){n[s.yi]<p&&(0,f._y)("Channel has invalid priority - "+n[l.pZ])})),n[l.MW]({queue:(0,f.FL)(t),chain:(0,d.jV)(t,r[l.TC],r)}))}var g=r(47151),m=r(45480),S=r(66450),T=function(n){function t(){var r,e,u=n.call(this)||this;function o(){r=0,e=[]}return u.identifier="TelemetryInitializerPlugin",u.priority=199,o(),(0,a.Z)(t,u,(function(n,t){n.addTelemetryInitializer=function(n){var t={id:r++,fn:n};return e[l.MW](t),{remove:function(){(0,f.tO)(e,(function(n,r){if(n.id===t.id)return e[l.cb](r,1),-1}))}}},n[s.hL]=function(t,r){for(var u=!1,o=e[l.R5],a=0;a<o;++a){var v=e[a];if(v)try{if(!1===v.fn[l.ZV](null,[t])){u=!0;brea
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (65470)
                                                                      Category:downloaded
                                                                      Size (bytes):912017
                                                                      Entropy (8bit):5.414635876106438
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:C055B54826187E9BFAD668452523BA80
                                                                      SHA1:33B9642B9C83F69640C4DC83EA34A47F8B347A41
                                                                      SHA-256:AC96990B2665B91FD7FBBABDAB21EEEF5CBA8EBB93ECB802970B03B3C4733106
                                                                      SHA-512:6E1BB67C0B970B76573D9E6A255654846A35F7E08E5FE13E652F3D4745ADBB127D3B0649A2C1826C127C3F325190B88AF09FE4226C7C4E7A3F4B0D3D7158C25E
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://logincdn.msftauth.net/shared/5/js/login_en_wFW1SCYYfpv61mhFJSO6gA2.js
                                                                      Preview:/*! For license information please see login_en.js.LICENSE.txt */.!function(){var e,t,n,r,o,i={97206:function(e,t,n){"use strict";var r=n(9384),o={childContextTypes:!0,contextType:!0,contextTypes:!0,defaultProps:!0,displayName:!0,getDefaultProps:!0,getDerivedStateFromError:!0,getDerivedStateFromProps:!0,mixins:!0,propTypes:!0,type:!0},i={name:!0,length:!0,prototype:!0,caller:!0,callee:!0,arguments:!0,arity:!0},a={$$typeof:!0,compare:!0,defaultProps:!0,displayName:!0,propTypes:!0,type:!0},l={};function s(e){return r.isMemo(e)?a:l[e.$$typeof]||o}l[r.ForwardRef]={$$typeof:!0,render:!0,defaultProps:!0,displayName:!0,propTypes:!0},l[r.Memo]=a;var c=Object.defineProperty,u=Object.getOwnPropertyNames,d=Object.getOwnPropertySymbols,f=Object.getOwnPropertyDescriptor,p=Object.getPrototypeOf,g=Object.prototype;e.exports=function e(t,n,r){if("string"!=typeof n){if(g){var o=p(n);o&&o!==g&&e(t,o,r)}var a=u(n);d&&(a=a.concat(d(n)));for(var l=s(t),m=s(n),h=0;h<a.length;++h){var b=a[h];if(!(i[b]||r&&r[
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (65436)
                                                                      Category:downloaded
                                                                      Size (bytes):90690
                                                                      Entropy (8bit):5.331029016047939
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:D390AA6A6D257834D807D8E7DDC90968
                                                                      SHA1:6A6EFD105DBBEB099D25998A38875808D83AF5C8
                                                                      SHA-256:D755D7CE744425DEE51A3BD8CBA9B2A789D96C584C9958082B557FEB70F226D9
                                                                      SHA-512:9629ED6071CFED4EFF34C163F36482336F0D402FD95951FC792A5F125C1BE1CA3C6918E61A4A79815B15AB5CDD6BCEF30D4FE0090C283C02590B62879D960818
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://logincdn.msftauth.net/shared/5/chunks/oneds-analytics-js_54b1724af1b05e2ba3db_en.js
                                                                      Preview:/*! For license information please see oneds-analytics-js_54b1724af1b05e2ba3db_en.js.LICENSE.txt */."use strict";(self.webpackChunk_msidentity_sisu_msa=self.webpackChunk_msidentity_sisu_msa||[]).push([[251],{41696:function(n,e,t){t.r(e),t.d(e,{AppInsightsCore:function(){return qo},ApplicationInsights:function(){return ja},BE_PROFILE:function(){return Vo},BaseTelemetryPlugin:function(){return di},Cloud:function(){return Vi},CoreUtils:function(){return Hr},Device:function(){return Xi},DiagnosticLogger:function(){return et},EventLatency:function(){return Ga},EventPersistence:function(){return Qa},EventsDiscardedReason:function(){return Ho},InternalAppInsightsCore:function(){return Ko},Loc:function(){return $i},LoggingSeverity:function(){return Wa},MinChannelPriorty:function(){return $a},NRT_PROFILE:function(){return Wo},NotificationManager:function(){return Uo},PostChannel:function(){return qa},PropertiesPlugin:function(){return Po},RT_PROFILE:function(){return jo},Session:function(){retu
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:Unicode text, UTF-8 text, with very long lines (64241)
                                                                      Category:downloaded
                                                                      Size (bytes):170222
                                                                      Entropy (8bit):5.043706734923043
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:501A61540F1AD706F32DC3B22FFA92C3
                                                                      SHA1:6E8283877B215FEF5232F42C2AA6CDFDC0B7A8D6
                                                                      SHA-256:F5E98E2373C741C7A3D6F1C3A4B114E3F0F022C41E24EE6BA022DE985EAC773B
                                                                      SHA-512:3F08136147A867E43576136A2F5D82CD16AD65DC9CA77122B104151698451F2C702F14E63F35476F7CC461CDE33E28E552A7D46C6BA6B6B6AFF515E396E1DD04
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://www.microsoft.com/onerfstatics/marketingsites-eus-prod/west-european/shell/_scrf/css/themes=default.device=uplevel_web_pc/79-4cdd0a/33-ae3d41/a5-4bf7a2/13-8e1ceb/81-32f0c0/5c-b7b685/bd-97baf6/ef-a24652?ver=2.0&_cf=20210618
                                                                      Preview:@charset "UTF-8";./*! | Copyright 2017 Microsoft Corporation | This software is based on or incorporates material from the files listed below (collectively, "Third Party Code"). Microsoft is not the original author of the Third Party Code. The original copyright notice and the license under which Microsoft received Third Party Code are set forth below together with the full text of such license. Such notices and license are provided solely for your information. Microsoft, not the third party, licenses this Third Party Code to you under the terms in which you received the Microsoft software or the services, unless Microsoft clearly states that such Microsoft terms do NOT apply for a particular Third Party Code. Unless applicable law gives you more rights, Microsoft reserves all other rights not expressly granted under such agreement(s), whether by implication, estoppel or otherwise.*/./*! normalize.css v3.0.3 | MIT License | github.com/necolas/normalize.css */.body{margin:0}.context-uh
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
                                                                      Category:dropped
                                                                      Size (bytes):7886
                                                                      Entropy (8bit):3.973130033666625
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:9425D8E9313A692BB3F022E8055FAB82
                                                                      SHA1:EDDCF3EA767D4C3042D01AC88594D7E795D8615C
                                                                      SHA-256:F2A1ABCF12EBD0F329E5B66B811B0BD76C8E954CB283CE3B61E72FBF459EF6F1
                                                                      SHA-512:93B3EB3C4CE385D80D4A8F6902355BBD156AC1AA20B8869AF05C8E714E90E74C5630BB8DE34D5B8FC9F876AC44BE314F3A2A08B3163295ADADBC6DD7B8D23561
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:...... .... .....6......... ............... .h...f...(... ...@..... .........................................................................................................................................................................................................................................................................................................................pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..................................pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..................................pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..pl..................................ZV..ZV..ZV..ZV..ZV..ZV..ZV..ZV..^Z..pl..pl..pl..pl..................................|x..pl..pl..................................QN..QN..QN..QN..QN..QN..QN..QN..QN..c`..pl..pl..pl..................................|x..pl..pl............
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with no line terminators
                                                                      Category:downloaded
                                                                      Size (bytes):16
                                                                      Entropy (8bit):3.875
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:D6B82198AF25D0139723AF9E44D3D23A
                                                                      SHA1:D60DEEF1847EEEF1889803E9D3ADC7EDA220F544
                                                                      SHA-256:A5C8CC49FA6649BE393EF22C2B31F1C46B671F8D763F783ED6D7B4E33669BDA3
                                                                      SHA-512:B21BEE2EEC588308A9DC3C3C2405377704B39B08AA20CBA40BA6E6834E67CF6F2C086E0701F5B05AEE27E2677E9C5C24FF137318275ACA00DD063DF3DCC07D4D
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAkURW043JHwYRIFDVd69_0=?alt=proto
                                                                      Preview:CgkKBw1Xevf9GgA=
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:HTML document, ASCII text, with very long lines (5844), with CRLF line terminators
                                                                      Category:downloaded
                                                                      Size (bytes):7914
                                                                      Entropy (8bit):4.4735908000780045
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:56F9CD8A07135E776326431C8560F8F2
                                                                      SHA1:FCFF27C475A9FB014661B045B59C8BB4799A0392
                                                                      SHA-256:0E1D105D6EE902B7279AEFD9E8AF21AB3E5D0CF058332A2A0E53A351524C75E6
                                                                      SHA-512:E75E2B65828CDE51CA880AEE30A74A3EE04B25B0FC0D2AF5B4BB675B62B592CF12D284771A0CE0A8174295F93C4D9007DA5C407C65229456EC0F1A18A6C8EE28
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://forms.office.com/offline.aspx
                                                                      Preview:<!DOCTYPE html>....<html xmlns="http://www.w3.org/1999/xhtml" lang="en-us">..<head>.. <meta charset="utf-8" />.. <meta name="viewport" content="width=device-width, initial-scale=1, viewport-fit=cover" />.. <title>Microsoft Forms</title>.. <style>.. * {.. box-sizing: border-box;.. }.... body {.. height: 100vh;.. margin: 0 auto;.. background-color: #f3f2f1;.. font-family: "Segoe UI", "Segoe UI Web (West European)", "Segoe UI", -apple-system, BlinkMacSystemFont, Roboto, "Helvetica Neue", sans-serif;.. }.... .content-root {.. height: 100%;.. display: flex;.. align-items: center;.. justify-content: center;.. padding: 20px;.. }.... .offline-message {.. max-width: 600px;.. }.... .offline-title {.. font-size: 32px;.. line-height: 40px;.. margin-top: 24px;.. }...
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (15445)
                                                                      Category:downloaded
                                                                      Size (bytes):15701
                                                                      Entropy (8bit):5.4651251774189475
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:859C7881B914BD13781C0446EEB497C7
                                                                      SHA1:5357563CDF1AACBE7447814A5DA4EA4DC3388CCF
                                                                      SHA-256:C91A80A096CEE5D241FB8A8B6A5B7F23909AB258B08B43FA1B3F8F90B399E469
                                                                      SHA-512:47C6E715A99E44EFB2CDB441A8C6D90694AAD8A545FB15CCA2868CD30A40CF683DD690AAF9D9642507250261CAF83D50AF832356BD9E38AF70F6C3B1D862B6C0
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.lrp_post.boot.f2af163.js
                                                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[537],{85708:function(n,e,r){function t(){return Date.now||(Date.now=function(){return(new Date).getTime()}),Math.floor(Date.now())}r.d(e,{dg:function(){return t}})},38264:function(n,e,r){r.r(e),r.d(e,{BrandingFooter:function(){return P}});var t=r(59312),o=r(69686),i=r(69065),a=r(80820),u=r(46411),c=r(35995),l=r(80098),f=r(28729),s=r(36082),d=r(262),p=r(51710),$=r(39886),_=r(15463),m=r(82610),g=r(58926),v=r(6700),h=r(49303),w=r(1521),b=r(8083),k=function(n,e){return function(r,t){var o=t();return r((0,b.n)("Branding.Footer.M365.Click",{isShare:(0,m.ET)(o),isPreview:(0,m.qM)(o),fullScreen:n,isFormRuntime:(0,w.Lx)(o),pageType:e}))}},y=r(457),x=r(96926),R=r(48978),C=r(10282),M=function(n,e,r,o,i){var u;return[{$r:{background:r,width:"100%","@media print":{background:s.s.$f,color:s.s.$h},paddingTop:0},$a:{width:"100%"},$cY:{width:"100%",lineHeight:"1.3",fontSize:12,color:s.s.$h,marginTop:0,marginBottom:4},$ke:{display:"inline-blo
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113355
                                                                      Category:downloaded
                                                                      Size (bytes):20390
                                                                      Entropy (8bit):7.9794389214686126
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:5EDF83D03EA7B67BD2F35472E435D17E
                                                                      SHA1:737BF84D2931906E6700439FD90CE6147633B0D0
                                                                      SHA-256:6524138B61AAF24DEADDA7C64AF577789C350C1ED90C48B6482011323C455513
                                                                      SHA-512:DE3F83D1C11E1498C2D83DD72374755385DE76F870F54A2698D22DC7CE2F85B685690C93128A9A68D43DB94B7CCE1C45072521A5912E97F4FCACD341F162FA45
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://aadcdn.msauth.net/ests/2.1/content/cdnbundles/converged.v2.login.min_mc5ac6ol0l4d2iaqspstyg2.css
                                                                      Preview:...........}ks.6.....\.R;.J.H=-WR;..&>g^53.G.R[.DY<C..$e.WG..... )...{+'g...l............bw_f7.:x..<x.-.*V5)/wE..Y...gy.0.*(.*-o.e.|..._..I.....?<{.!x...W..._..^..p..E..'..Y...<.....*]..6(. ..D..*...Y.......:.ve.?..!..|t...].+.......a.......|.P...u.H.d.d.r.c[..~.L..n.-.}e.H3...r..^..iP.u.*.z.....)..Z.jx..C'......u..{.C...N.o.m~..F(b..f.....h..O.....6....kr.......n2m M$.R..R..i{.~...*..n.dKY..#.Kn.4..G...O..l.#.a=..iU..].S.2.wY..O.|...Z.A....].uU.._%U.<...pp..u=.....C.R..S.....0...A<......&...W..'o.T.."..jO..^+.....DiW.b..7i..7..........lKe.0.~B0.....zQu#...YB.,.{*.&.6..G.6..._...J.i.?.LS$( .^.{..u.-.0....K....M&j..s.yB..+....^.)...7e.....]..eFI_.kRX.B......D[.4......+.u=>....R.`QEK...R..d...*S.. ,c5RKBK(......][..eF{T.....6...".....Uk:..S.0Ro.}B.dwJZ}U..S.F.....&.&.~|......{..Ep.>x..._....}p..=.}...v...7?}...g..1&.......}...^...o.x.>x...../.^....._.........w.v./.........BA...{J..w..$?.}w....?zO.r..5...7.gl..z...g.?.{....R.......yGj
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:HTML document, ASCII text, with CRLF line terminators
                                                                      Category:downloaded
                                                                      Size (bytes):548
                                                                      Entropy (8bit):4.688532577858027
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:370E16C3B7DBA286CFF055F93B9A94D8
                                                                      SHA1:65F3537C3C798F7DA146C55AEF536F7B5D0CB943
                                                                      SHA-256:D465172175D35D493FB1633E237700022BD849FA123164790B168B8318ACB090
                                                                      SHA-512:75CD6A0AC7D6081D35140ABBEA018D1A2608DD936E2E21F61BF69E063F6FA16DD31C62392F5703D7A7C828EE3D4ECC838E73BFF029A98CED8986ACB5C8364966
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://assets-eur.mkt.dynamics.com/bundles/styles/signedout-oneui?v=fxWDPSdgdYVZRC_ceRR_L6he1M_EOZx8zyPNGpHAdOs1
                                                                      Preview:<html>..<head><title>404 Not Found</title></head>..<body>..<center><h1>404 Not Found</h1></center>..<hr><center>nginx</center>..</body>..</html>.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->.. a padding to disable MSIE and Chrome friendly error page -->..
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:PNG image data, 192 x 192, 8-bit colormap, non-interlaced
                                                                      Category:dropped
                                                                      Size (bytes):1779
                                                                      Entropy (8bit):7.589819392147309
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:4150A5D4F2B0284A9E62D247929DD2AA
                                                                      SHA1:97CA2D9ECE8F0855B2A93E6BFDFC4883685C51CB
                                                                      SHA-256:F058653DCBA7E8B00D4BDB9409E06817F098AB18125CE5A5821520F04030D176
                                                                      SHA-512:D034378E76D58A899047B4639115102CC8F89AEF3F300DDAF0C0B3EAE40C8381040D1656109632E9095ED3F399218F196087D070C099FD89B9605DFBC34FB585
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:.PNG........IHDR.............e..5....PLTE....pp......@...pp......8...jp...:...lp...6..9......mp...8...kp...6..8...lp.lp7..7...mp...7...lp...7...lp.......lp.lp.lp7......mp...7...lp...6..7...68.;=.@B.AC.IL.NQ.SV.X[.DF.JM.NP.UX.X[.]`._b.ei.fj.hl.il.lp.pt.y}.z}....os.os.rv....uy....hl.x|.{.....{..~..............MP.......sx..............................................ch..........io.......ou... ..!..".."..#..#..#..$..%..%..&..'..'..'..(..(..)..*..*..*..*..+..,..,..,..-........0..0..1..1..2..2..3..3..4..4..4..5..5..6..6..6..6..7..B..b....................1tRNS..... 000@PPP````pp...........................hX....sIDATx....{.E....(.9T@n.V@@"r..jLDR9.TlK...J....J.G-.j...vj..KS...fvwv.......k........n...B.!..B(..xjs.mX.p..W..)..1...I._m..@.2.....0.#..9_.....`[.C..../...q..i............Umd".....b;.[{..H..V..g*\...0T`.z+..X..O._!.....U.F.P)0....X...q....J.q...L....J."....x.....".W}~.Q...b~...,..'.2.#gZU.Q....1gJ7.j..81......K7..?.......i......5......x.o.g...Q..V..SZ.xe-..}..
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (917)
                                                                      Category:downloaded
                                                                      Size (bytes):1151
                                                                      Entropy (8bit):5.369908043108395
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:436A7BC82156A644ED0206BFBC3A67BD
                                                                      SHA1:189C49265A47CBD4DDA7D86E785C9E9970C41F7E
                                                                      SHA-256:5E18809EF5C2DFEB8B35CB5CD230ED8C64CD04A564090761F24E5FB8F628C6CA
                                                                      SHA-512:CA54A7B2D60FC04D4E6D44287A1B5051DB9E843A10514142E1C79BA1091A9CB0DD1BBCCDFDEB5DF7BC845C648A5C0B798313D44A76ED48135BC64B0E1C0DEF35
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.sw.a6ac500.js
                                                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[670],{70082:function(r,e,n){n.r(e),n.d(e,{register:function(){return f}});var t=n(59312),i=n(16586),s=n(9947),u=n(90710),c=n(55890),o=n(10836),a=n(78457);function f(r){return(0,t.mG)(this,void 0,void 0,(function(){var e,n;return(0,t.Jh)(this,(function(t){switch(t.label){case 0:return t.trys.push([0,5,,6]),(0,a.qI)()?(0,o.KA)("UnregisterServiceWorker")?[4,navigator.serviceWorker.getRegistrations().then((function(r){return Promise.all(r.map((function(r){return r.unregister()})))}))]:[3,2]:[2];case 1:return t.sent(),[2];case 2:return(0,o.KA)("ServiceWorkerEnabled")||"1"===(0,u.NW)().fsw?(e=r?"Business":(0,s.k0)().ring,[4,navigator.serviceWorker.register((0,i.wT)("/sw.js?ring=".concat(e)))]):[3,4];case 3:t.sent(),t.label=4;case 4:return[3,6];case 5:return n=t.sent(),(0,c.$U)("ServiceWorker.Registration.Error",n),[3,6];case 6:return[2]}}))}))}}}]);..//# sourceMappingURL=https://artifacts.dev.azure.com/office/_apis/symbol/symsrv/l
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:SVG Scalable Vector Graphics image
                                                                      Category:dropped
                                                                      Size (bytes):1864
                                                                      Entropy (8bit):5.222032823730197
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:BC3D32A696895F78C19DF6C717586A5D
                                                                      SHA1:9191CB156A30A3ED79C44C0A16C95159E8FF689D
                                                                      SHA-256:0E88B6FCBB8591EDFD28184FA70A04B6DD3AF8A14367C628EDD7CABA32E58C68
                                                                      SHA-512:8D4F38907F3423A86D90575772B292680F7970527D2090FC005F9B096CC81D3F279D59AD76EAFCA30C3D4BBAF2276BBAA753E2A46A149424CF6F1C319DED5A64
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:<svg xmlns="http://www.w3.org/2000/svg" width="1920" height="1080" fill="none"><g opacity=".2" clip-path="url(#E)"><path d="M1466.4 1795.2c950.37 0 1720.8-627.52 1720.8-1401.6S2416.77-1008 1466.4-1008-254.4-380.482-254.4 393.6s770.428 1401.6 1720.8 1401.6z" fill="url(#A)"/><path d="M394.2 1815.6c746.58 0 1351.8-493.2 1351.8-1101.6S1140.78-387.6 394.2-387.6-957.6 105.603-957.6 714-352.38 1815.6 394.2 1815.6z" fill="url(#B)"/><path d="M1548.6 1885.2c631.92 0 1144.2-417.45 1144.2-932.4S2180.52 20.4 1548.6 20.4 404.4 437.85 404.4 952.8s512.276 932.4 1144.2 932.4z" fill="url(#C)"/><path d="M265.8 1215.6c690.246 0 1249.8-455.595 1249.8-1017.6S956.046-819.6 265.8-819.6-984-364.005-984 198-424.445 1215.6 265.8 1215.6z" fill="url(#D)"/></g><defs><radialGradient id="A" cx="0" cy="0" r="1" gradientUnits="userSpaceOnUse" gradientTransform="translate(1466.4 393.6) rotate(90) scale(1401.6 1720.8)"><stop stop-color="#107c10"/><stop offset="1" stop-color="#c4c4c4" stop-opacity="0"/></radialGradient><r
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:Unicode text, UTF-8 text, with very long lines (36802), with no line terminators
                                                                      Category:downloaded
                                                                      Size (bytes):36826
                                                                      Entropy (8bit):4.784953255851495
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:83C5167228BD89135F9397462EB03D3F
                                                                      SHA1:B86A808A28F0EB68D3B32B7372C21588D3703AF1
                                                                      SHA-256:AC23890CF57171832DDE373895120A6141AC209931C2125F2B5DB7A32344D1F8
                                                                      SHA-512:DA5D56881ECD009DA56CAB73E52CC2F8AA95A6E9133FE5BB41A2B783D5A7EFA5AF0705C5773096FE2F9FA2A83FD82799C1C83215901EFC81F6EC8319B39189C1
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/scripts/dists/ls-response.en-us.8baacbebd.js
                                                                      Preview:window.FormsLsMap = (window.FormsLsMap || {});window.FormsLsMap["en-us"]={"mdbicgo":"Required to answer","lbnbnjb":"Please share your comments here","jchpiio":"Help improve phishing detection","hkplpef":"It's not collecting sensitive info","lifjakb":"It needs to collect sensitive info","eackega":"Other","mnpehin":"Did this form trigger a false positive? Click to provide details.","amlalmd":"Why did you unblock this form?","acmngdo":"This user is not currently restricted from using Microsoft Forms. No further action is needed..","pdnfcop":"Correct","gplbmcp":"Print response","pfjnaob":"Required","dlogacb":"Pause background music","oancfdj":"Play background music","pjgjcee":"Pause live background","dplcjia":"Play live background","giamlmc":"Please select at least {0} options.","ggbmbok":"Please select at most {0} options.","mbpambh":"Please select {0} options.","dagpjbe":"1 - Poor","bcndghh":"2","oamcaon":"3","lhfhejf":"4","amdplne":"5 - Excellent","ifphmkc":"1 - Very dissatisfied","hh
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:Java source, ASCII text, with very long lines (17610)
                                                                      Category:downloaded
                                                                      Size (bytes):110678
                                                                      Entropy (8bit):5.425859733908257
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:07B98765F2550D83EEAEF5CB36A2E6A1
                                                                      SHA1:4F5CB9D05789079FA605E58546015C8A6969FFA6
                                                                      SHA-256:E86B0BF07871186DD32B20C7B4FD8E8729C717EABE73763847BE9CB091D348F7
                                                                      SHA-512:BBB2F8EFC7C12DF1B01DE74DF607B4E86CD6A5BF6FA6EC90C5D824D0D76E675616613040B578FE099AF5BE6FE728B919F014CAEE0DFA0E47714558DFD7AEFDE2
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.1ds.a8079b3.js
                                                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[641],{28165:function(n,r,t){t.d(r,{Z:function(){return kn}});var e,u=t(49577),i=t(71106),o=t(80403),f=t(39523),c=t(40154),a=t(61746),l=t(79966),v=t(8823),s=t(93626),d=t(42256),p="locale",h="ver",y="name",g=(0,d.cc)({UserExt:[0,"user"],DeviceExt:[1,"device"],TraceExt:[2,"trace"],WebExt:[3,"web"],AppExt:[4,"app"],OSExt:[5,"os"],SdkExt:[6,"sdk"],IntWebExt:[7,"intweb"],UtcExt:[8,"utc"],LocExt:[9,"loc"],CloudExt:[10,"cloud"],DtExt:[11,"dt"]}),m=(0,d.cc)({id:[0,"id"],ver:[1,h],appName:[2,y],locale:[3,p],expId:[4,"expId"],env:[5,"env"]}),S=(0,d.cc)({domain:[0,"domain"],browser:[1,"browser"],browserVer:[2,"browserVer"],screenRes:[3,"screenRes"],userConsent:[4,"userConsent"],consentDetails:[5,"consentDetails"]}),w=(0,d.cc)({locale:[0,p],louserd:[1,"louserd"],id:[2,"id"]}),C=(0,d.cc)({osName:[0,y],ver:[1,h]}),T=(0,d.cc)({ver:[0,h],seq:[1,"seq"],installId:[2,"installId"],epoch:[3,"epoch"]}),b=(0,d.cc)({msfpc:[0,"msfpc"],anid:[1,"anid"]
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:JSON data
                                                                      Category:dropped
                                                                      Size (bytes):1282
                                                                      Entropy (8bit):4.695064346385326
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:8D30025E69BC896ACC2064D1791F5A88
                                                                      SHA1:1F14560FD3D30F0A2C291CE503CCB490C94E0C3E
                                                                      SHA-256:769442A29597F6DB303853931D749780EF46D2855412843431DAC07A9D72CCB0
                                                                      SHA-512:7363382D59DF760A37A8C48F6D7037EF9C57CE97EFA0AFDDD19FE133952EE825B9043C84227F4E0B6D4AED310E9DF0053294BF6EB991CC3FBE7338C853C51888
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:{.. "FormFailedToLoad": "Failed to load form",.. "FormFailedToLoadCors": "The form can not be loaded on a domain that hasn't been allowed for external form hosting or there is a network connectivity issue",.. "LearnMore": "Learn more",.. "FormSubmitted": "Form submitted",.. "FormSubmitError": "Error submitting the form",.. "Reload": "Reload",.. "LookupLoading": "loading...",.. "LookupGenericError": "There was a problem retrieving items. Try again later.",.. "ValidationRequiredField": "This field is required",.. "EventFailedToLoad": "Failed to load event.",.. "EventAtCapacity": "This event is fully booked",.. "EventNotLive": "We are still setting up this event. Please check again in some time or contact the event organizer ",.. "SubmissionErrorEventNotLive": "Registrations for this event have been closed. We look forward to seeing you at our next event.",.. "SubmissionErrorEventCapacityIsFull": "Registrations for this event have been closed. We.re at full capacity! We lo
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:HTML document, ASCII text
                                                                      Category:downloaded
                                                                      Size (bytes):491
                                                                      Entropy (8bit):5.058319039482085
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:B8853C5CB492B4374675A6EEE35F3E13
                                                                      SHA1:723BEB5FE213DDE8A9AA5849D2F5857B4E03BB1E
                                                                      SHA-256:9F8A8A20DBCB4123D3380DF2EE65FEE14DB070948A40034DA6C24A386446B98D
                                                                      SHA-512:EEBF0D7A0F9682870E9EAE27AC9A014569BC6E4CF29A2D8D70E734E8CDCC1EB5FEA54B931C5DDBB51EE6353F03331A22C9255BC41115F5349245324A50B5D9A0
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://assets-eur.mkt.dynamics.com/21f9f50d-1320-ef11-8406-000d3adc9e50/digitalassets/standaloneforms/b957aef6-0232-ef11-8409-6045bddd5e05?=outlook.office.com/mail/inbox/id/xMwAQAP%2FO5QhSWQBJt%2Bdd51R9eCU%3D?actSwt=true
                                                                      Preview:<div. data-form-id='b957aef6-0232-ef11-8409-6045bddd5e05'. data-form-api-url='https://public-eur.mkt.dynamics.com/api/v1.0/orgs/21f9f50d-1320-ef11-8406-000d3adc9e50/landingpageforms'. data-cached-form-url='https://assets-eur.mkt.dynamics.com/21f9f50d-1320-ef11-8406-000d3adc9e50/digitalassets/forms/b957aef6-0232-ef11-8409-6045bddd5e05' ></div>. <script src = 'https://cxppusa1formui01cdnsa01-endpoint.azureedge.net/eur/FormLoader/FormLoader.bundle.js' ></script>
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (65461)
                                                                      Category:downloaded
                                                                      Size (bytes):742296
                                                                      Entropy (8bit):5.442960982190392
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:545A1BBC31581E3D1B1EB383DD3E9B98
                                                                      SHA1:09249350A3B3EA2665724E0A789096BBA27E0E16
                                                                      SHA-256:C3D9901D45BE8548749013D46A5FD17A564495A52DF6E265668E0D2401915165
                                                                      SHA-512:BE38C2CEBFFFEEE6F6EFD6071F65C8C047D79133119C60409E89480762F3B4677407E452BE702851E5BFB33B8E8DE8077159038049D86B7C85FDB03F64046133
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cxppusa1formui01cdnsa01-endpoint.azureedge.net/eur/FormLoader/FormLoader.bundle.js
                                                                      Preview:/*! For license information please see FormLoader.bundle.js.LICENSE.txt */.var d365mktforms;(()=>{var e,t,n={317:function(e,t){var n="undefined"!=typeof self?self:this,r=function(){function e(){this.fetch=!1,this.DOMException=n.DOMException}return e.prototype=n,new e}();!function(e){!function(t){var n="URLSearchParams"in e,r="Symbol"in e&&"iterator"in Symbol,i="FileReader"in e&&"Blob"in e&&function(){try{return new Blob,!0}catch(e){return!1}}(),a="FormData"in e,o="ArrayBuffer"in e;if(o)var s=["[object Int8Array]","[object Uint8Array]","[object Uint8ClampedArray]","[object Int16Array]","[object Uint16Array]","[object Int32Array]","[object Uint32Array]","[object Float32Array]","[object Float64Array]"],u=ArrayBuffer.isView||function(e){return e&&s.indexOf(Object.prototype.toString.call(e))>-1};function c(e){if("string"!=typeof e&&(e=String(e)),/[^a-z0-9\-#$%&'*+.^_`|~]/i.test(e))throw new TypeError("Invalid character in header field name");return e.toLowerCase()}function l(e){return"strin
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (65381)
                                                                      Category:downloaded
                                                                      Size (bytes):998130
                                                                      Entropy (8bit):5.576589911673417
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:BDD50587EA7EDA5BCB74B767590C5B93
                                                                      SHA1:3DA343D6351DED8E125B3A5DABB6F12F8311EBBC
                                                                      SHA-256:3C0E8698A860D8D8205B4F88BBEAC02E52E1B427FBB4E7A77793D1E6E53FCA3E
                                                                      SHA-512:B305989CFE2FE3A2ACD175D8BE120EFB96FBE97D31FD45D51ED2991235247BE8E91FC89F2C2318C4EAFE288D574B3986CDE106C28347C737B75D74BA855B190D
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.officebrowserfeedback.bd03d92.js
                                                                      Preview:(self.webpackChunk=self.webpackChunk||[]).push([[18],{55074:function(){./*! For license information please see officebrowserfeedback.min.js.LICENSE.txt */.!function(A){var t={};function n(r){if(t[r])return t[r].exports;var e=t[r]={i:r,l:!1,exports:{}};return A[r].call(e.exports,e,e.exports,n),e.l=!0,e.exports}n.m=A,n.c=t,n.d=function(A,t,r){n.o(A,t)||Object.defineProperty(A,t,{enumerable:!0,get:r})},n.r=function(A){"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(A,Symbol.toStringTag,{value:"Module"}),Object.defineProperty(A,"__esModule",{value:!0})},n.t=function(A,t){if(1&t&&(A=n(A)),8&t)return A;if(4&t&&"object"==typeof A&&A&&A.__esModule)return A;var r=Object.create(null);if(n.r(r),Object.defineProperty(r,"default",{enumerable:!0,value:A}),2&t&&"string"!=typeof A)for(var e in A)n.d(r,e,function(t){return A[t]}.bind(null,e));return r},n.n=function(A){var t=A&&A.__esModule?function(){return A.default}:function(){return A};return n.d(t,"a",t),t},n.o=function(A,t){r
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (4357)
                                                                      Category:downloaded
                                                                      Size (bytes):4613
                                                                      Entropy (8bit):5.404641833275565
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:36F27B960C9F790F49FB76B120E17A17
                                                                      SHA1:2BACA86C15A245DD64199BDD2D33DE3B3BE5D005
                                                                      SHA-256:E2B7D115BE4E3A08D9B119E09CAD08A893E499D2C54AF6BC1280582142281518
                                                                      SHA-512:3F51A717F613D993C3D5D80463D7707CD493774CC72C54FB6434037387458879122AD541B469CE709C3AE5C4EAA323E8FACDC1F3EA5BF0E1452B5CCBCBC63D7B
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.lrp_groupnote.a8081b2.js
                                                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[341],{64289:function(e,t,n){n.r(t),n.d(t,{GroupNoteResponsesView:function(){return w}});var i=n(59312),a=n(69686),o=n(35995),l=n(36082),r=n(51710),s=n(6700),c=n(40374),d=n(82610),p=n(56498),u=n(89397),_=n(39886),f=n(68258),h=function(e){var t=e.$sm,n=void 0===t?[]:t,i=e.$iH,r=void 0===i?[]:i,s=e.$_h,d=e.$pn,p=(0,o.d)((function(e){return{$a:{},$qU:{display:"block",width:e?"calc(100% - 30px)":"calc(100% - 40px)",margin:e?"0 15px":"0 20px"},$ch:{display:"block",width:"100%"},$qV:{display:"flex",justifyContent:"space-between",alignItems:"center",fontSize:12,fontWeight:600,lineHeight:"20px",color:l.s.$h,background:l.s.$B,height:e?25:32,width:"100%"},$pY:{width:"100%",padding:"0 10px",textOverflow:"ellipsis",whiteSpace:"nowrap",overflow:"hidden"},$tP:{background:l.s.$f,maxHeight:e?90:120,overflowY:"auto",display:"block","::-webkit-scrollbar":{width:2},"::-webkit-scrollbar-thumb":{background:"#adadad",borderRadius:2}},$ur:{display:
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1592
                                                                      Category:dropped
                                                                      Size (bytes):621
                                                                      Entropy (8bit):7.673946009263606
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:4761405717E938D7E7400BB15715DB1E
                                                                      SHA1:76FED7C229D353A27DB3257F5927C1EAF0AB8DE9
                                                                      SHA-256:F7ED91A1DAB5BB2802A7A3B3890DF4777588CCBE04903260FBA83E6E64C90DDF
                                                                      SHA-512:E8DAC6F81EB4EBA2722E9F34DAF9B99548E5C40CCA93791FBEDA3DEBD8D6E401975FC1A75986C0E7262AFA1B9D1475E1008A89B92C8A7BEC84D8A917F221B4A2
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:..........}UMo"1..+.....G; .8l...M..$.U.AW......UaX..`'.=......|..z3...Ms>..Y...QB..W..y..6.......?..........L.W=m....=..w.)...nw...a.z......#.y.j...m...P...#...6....6.u.u...OF.V..07b..\...s.f..U..N..B...>.d.-z..x.2..Lr.Rr)....JF.z.;Lh.....q.2.A....[.&".S..:......]........#k.U#57V..k5.tdM.j.9.FMQ2..H:.~op..H.......hQ.#...r[.T.$.@........j.xc.x0..I.B:#{iP1.e'..S4.:...mN.4)<W.A.).g.+..PZ&.$.#.6v.+.!...x*...}.._...d...#.Cb..(..^k..h!..7.dx.WHB......(.6g.7.Wwt.I<.......o.;.....Oi$}f.6.....:P..!<5.(.p.e.%et.)w8LA.l9r..n.....?.F.DrK...H....0F...{.,.......{E.."....*...x.@..?u......../....8...
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:GIF image data, version 89a, 352 x 3
                                                                      Category:dropped
                                                                      Size (bytes):3620
                                                                      Entropy (8bit):6.867828878374734
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:B540A8E518037192E32C4FE58BF2DBAB
                                                                      SHA1:3047C1DB97B86F6981E0AD2F96AF40CDF43511AF
                                                                      SHA-256:8737D721808655F37B333F08A90185699E7E8B9BDAAA15CDB63C8448B426F95D
                                                                      SHA-512:E3612D9E6809EC192F6E2D035290B730871C269A267115E4A5515CADB7E6E14E3DD4290A35ABAA8D14CF1FA3924DC76E11926AC341E0F6F372E9FC5434B546E5
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:GIF89a`.........iii!.......!.&Edited with ezgif.com online GIF maker.!..NETSCAPE2.0.....,....`.....6......P.l.......H....I..:qJ......k....`BY..L*..&...!.......,....`.....9..i....Q4......H..j.=.k9-5_..........j7..({.........!.......,....`.....9.......trV.......H....`.[.q6......>.. .CZ.&!.....M...!.......,....`.....8..........:......H..jJ..U..6_....../.el...q.)...*..!.......,....`.....9.....i..l.go.....H..*".U...f......._......5......n..!.......,....`.....:..i......./.....H...5%.kE/5.........In.a..@&3.....J...!.......,....`.....9.......kr.j.....H..*.-.{Im5c..............@&.........!.......,....`.....9.........j..q....H...].&..\.5.........8..S..........!.......,....`.....9.......3q.g..5....H...:u..............Al..x.q.........!.......,....`.....9......\.F....z....H...zX...ov.........h3N.x4......j..!.......,....`.....9........Q.:......H....y..^...1.........n.!.F......E...!.......,....`.....8.........i,......H....*_.21.I.........%...
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (43631)
                                                                      Category:downloaded
                                                                      Size (bytes):43797
                                                                      Entropy (8bit):5.3330082676730814
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:72BC74DBD7E2D7EC8098628569C7C8D1
                                                                      SHA1:CF83D74066EF9F807DB72B7985522E44A9DBE68E
                                                                      SHA-256:6DD99733E4AF8728ABF32904C57D8B884D75D3424011EC2C9AA255D942A8BFF6
                                                                      SHA-512:CA933824BE7CB9863946B247B79CCDAF8168A7C9982336DB25A5A2FE8376DA69F1C9B88E8D8A770AD6049BA388579704D49383B7190325518906908BF3F68BF2
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://forms.office.com/sw.js?ring=Business
                                                                      Preview:!function(){"use strict";var e={487:function(){try{self["workbox:core:6.1.0"]&&_()}catch(e){}},403:function(){try{self["workbox:expiration:6.4.0"]&&_()}catch(e){}},295:function(){try{self["workbox:core:6.4.0"]&&_()}catch(e){}},372:function(){try{self["workbox:navigation-preload:6.1.0"]&&_()}catch(e){}},815:function(){try{self["workbox:routing:6.1.0"]&&_()}catch(e){}},445:function(){try{self["workbox:strategies:6.1.0"]&&_()}catch(e){}}},t={};function n(r){var s=t[r];if(void 0!==s)return s.exports;var o=t[r]={exports:{}};return e[r](o,o.exports,n),o.exports}!function(){n(487);n(372);function e(){return Boolean(self.registration&&self.registration.navigationPreload)}const t=(e,...t)=>{let n=e;return t.length>0&&(n+=` :: ${JSON.stringify(t)}`),n};class r extends Error{constructor(e,n){super(t(e,n)),this.name=e,this.details=n}}const s={googleAnalytics:"googleAnalytics",precache:"precache-v2",prefix:"workbox",runtime:"runtime",suffix:"undefined"!=typeof registration?registration.scope:""},o=
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
                                                                      Category:dropped
                                                                      Size (bytes):17174
                                                                      Entropy (8bit):2.9129715116732746
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:12E3DAC858061D088023B2BD48E2FA96
                                                                      SHA1:E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5
                                                                      SHA-256:90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21
                                                                      SHA-512:C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:..............h(..f...HH...........(..00......h....6.. ...........=...............@..........(....A..(....................(....................................."P.........................................."""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333""""""""""""""""""""""""""
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:PNG image data, 1920 x 1080, 8-bit/color RGBA, non-interlaced
                                                                      Category:downloaded
                                                                      Size (bytes):340501
                                                                      Entropy (8bit):7.881878211626162
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:E83BC964DFCA2B34B1F2BE36CA1C9BCB
                                                                      SHA1:7A4E9C94C5A13CF3DA0F2D3D7B660EC91FE51C82
                                                                      SHA-256:578D99B041999BCE58A52E74121AA1BFCCB7B5194207D1D5FDF7A275C72753FA
                                                                      SHA-512:82DDF44483653AE9FA82C84B63B2719834F25076A5FC8EA161A7DDF4778574FA9C0E830890EB31924CE86083FD92BEFEDD8372D51FF815F74CBD41003704CB1D
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://lists.office.com/Images/2d4d4e83-7a83-45a5-b049-46926117014c/126fa5f5-c7b4-4f2a-87b3-dd54700e4a11/T91SNW06S7A66KF3ZKQMW2CTOH/85a251d6-8880-4632-8ea1-b8b4caa7ef08
                                                                      Preview:.PNG........IHDR.......8........C....sRGB.........gAMA......a.....IDATx^.._.u.....p...". R....@.....svUE..&.....R.Xl... Ut."\2e.b.2p.'...j.]}.m....g..c../~j...g...u.{..............,........E.>.._.../..?............q........x=......X.o....<..cF<w.....{E........~.....?..b...g....u............o..<[..s...........^Q.E.... .Z.G........7/^..8g.;..........x..<@}w..Wh.....3..~f...>.;...5W.f{.P.y^x\..*..F..x7.8G.@x...e.|{....y...O..\0X...1_YC.7G.w6..\....w..D..o.{n...b...}O.p...=... .>....{......v..p!..q......}./..n.... xs}.}...;B.|Jk>.?.....w...E...+j..=0....@.:..+i.g....Q.gO.......wi.....\.jD.Vl..A.o.;K5..#<C.j.(...j.;....3..5....p..8.....h~...........(...w.AC.....`w......i.......Ytk8d|G.w....A..v>....y..U@.u.2-.+j.e,....!..}.8.8g5|#.....b.J......[.{........?.B-WG..g.gd.9t..9......5.B.;...j..8..R.....ngK.3.Q_q...J...EQ.....a....kQ....d...P..^.qa.(.G ....W.Ac........\..pw...o...=.Ao.'......3...Qk......=".eu=h.0.Ug..~.....:...fuO....yfV...E.W.._..BA..!.4BF
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:JSON data
                                                                      Category:dropped
                                                                      Size (bytes):72
                                                                      Entropy (8bit):4.241202481433726
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:9E576E34B18E986347909C29AE6A82C6
                                                                      SHA1:532C767978DC2B55854B3CA2D2DF5B4DB221C934
                                                                      SHA-256:88BDF5AF090328963973990DE427779F9C4DF3B8E1F5BADC3D972BAC3087006D
                                                                      SHA-512:5EF6DCFFD93434D45760888BF4B95FF134D53F34DA9DC904AD3C5EBEDC58409073483F531FEA4233869ED3EC75F38B022A70B2E179A5D3A13BDB10AB5C46B124
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:{"Message":"The requested resource does not support http method 'GET'."}
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:GIF image data, version 89a, 352 x 3
                                                                      Category:downloaded
                                                                      Size (bytes):2672
                                                                      Entropy (8bit):6.640973516071413
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:166DE53471265253AB3A456DEFE6DA23
                                                                      SHA1:17C6DF4D7CCF1FA2C9EFD716FBAE0FC2C71C8D6D
                                                                      SHA-256:A46201581A7C7C667FD42787CD1E9ADF2F6BF809EFB7596E61A03E8DBA9ADA13
                                                                      SHA-512:80978C1D262BC225A8BA1758DF546E27B5BE8D84CBCF7E6044910E5E05E04AFFEFEC3C0DA0818145EB8A917E1A8D90F4BAC833B64A1F6DE97AD3D5FC80A02308
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://aadcdn.msauth.net/shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif
                                                                      Preview:GIF89a`............!..NETSCAPE2.0.....!.......,....`.....6......P.l.......H....I..:qJ......k....`BY..L*..&...!.......,....0.............<....[.\K8j.tr.g..!.......,....3............^;.*..\UK.]\.%.V.c...!.......,....7........`....lo...[.a..*Rw~i...!.......,....;........h.....l.G-.[K.,_XA]..'g..!.......,....?........i.....g....Z.}..)..u...F..!.......,....C...............P.,nt^.i....Xq...i..!.......,....F...........{^b....n.y..i...\C.-...!.......,....H..............R...o....h.xV!.z#...!.......,"...L.............r.jY..w~aP(.......[i...!.......,(...N.............r....w.aP.j.'.)Y..S..!.......,....H.........`......hew..9`.%z.xVeS..!.......,5...A.........`...\m.Vmtzw.}.d.%...Q..!.......,9...=.........h......3S..s.-W8m...Q..!.......,A...5.........h.....N...:..!..U..!.......,H.............h....M.x...f.i.4..!.......,O...'.........i...tp......(..!.......,X.............j...@.x....!.......,].............j..L..3em..!.......,e.............`......!.......,n..............{i..!..
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:SVG Scalable Vector Graphics image
                                                                      Category:downloaded
                                                                      Size (bytes):3651
                                                                      Entropy (8bit):4.094801914706141
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:EE5C8D9FB6248C938FD0DC19370E90BD
                                                                      SHA1:D01A22720918B781338B5BBF9202B241A5F99EE4
                                                                      SHA-256:04D29248EE3A13A074518C93A18D6EFC491BF1F298F9B87FC989A6AE4B9FAD7A
                                                                      SHA-512:C77215B729D0E60C97F075998E88775CD0F813B4D094DC2FDD13E5711D16F4E5993D4521D0FBD5BF7150B0DBE253D88B1B1FF60901F053113C5D7C1919852D58
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://logincdn.msftauth.net/shared/5/images/microsoft_logo_ee5c8d9fb6248c938fd0.svg
                                                                      Preview:<svg xmlns="http://www.w3.org/2000/svg" width="108" height="24" viewBox="0 0 108 24"><title>assets</title><path d="M44.836,4.6V18.4h-2.4V7.583H42.4L38.119,18.4H36.531L32.142,7.583h-.029V18.4H29.9V4.6h3.436L37.3,14.83h.058L41.545,4.6Zm2,1.049a1.268,1.268,0,0,1,.419-.967,1.413,1.413,0,0,1,1-.39,1.392,1.392,0,0,1,1.02.4,1.3,1.3,0,0,1,.4.958,1.248,1.248,0,0,1-.414.953,1.428,1.428,0,0,1-1.01.385A1.4,1.4,0,0,1,47.25,6.6a1.261,1.261,0,0,1-.409-.948M49.41,18.4H47.081V8.507H49.41Zm7.064-1.694a3.213,3.213,0,0,0,1.145-.241,4.811,4.811,0,0,0,1.155-.635V18a4.665,4.665,0,0,1-1.266.481,6.886,6.886,0,0,1-1.554.164,4.707,4.707,0,0,1-4.918-4.908,5.641,5.641,0,0,1,1.4-3.932,5.055,5.055,0,0,1,3.955-1.545,5.414,5.414,0,0,1,1.324.168,4.431,4.431,0,0,1,1.063.39v2.233a4.763,4.763,0,0,0-1.1-.611,3.184,3.184,0,0,0-1.15-.217,2.919,2.919,0,0,0-2.223.9,3.37,3.37,0,0,0-.847,2.416,3.216,3.216,0,0,0,.813,2.338,2.936,2.936,0,0,0,2.209.837M65.4,8.343a2.952,2.952,0,0,1,.5.039,2.1,2.1,0,0,1,.375.1v2.358a2.04,2.04,0,0,0-.
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:PNG image data, 490 x 180, 8-bit/color RGBA, non-interlaced
                                                                      Category:downloaded
                                                                      Size (bytes):5895
                                                                      Entropy (8bit):7.720248605671278
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:311274C8C9C66E894F5AFA51FACD72CD
                                                                      SHA1:386D1FA0B2924DF2C21545CF2FF1DDE2CD985D33
                                                                      SHA-256:BC3C029408DAB6B5CB676B990B2E21BDD474E4B2E45DAF87E70210539390BF49
                                                                      SHA-512:2117BC16AC878BCC307CEA0DEFA0638800715330E83E9C8C1CAD7398BBF207E9432391B851E004308FB75C20C2D6F587D015FA3FB13F8630FE3E0C7E194979FC
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/images/microsoft365logo_v1.png
                                                                      Preview:.PNG........IHDR.............[.o.....IDATx......U.....xi.#..l.%3J.t.D\If5h.......>.Ft.....].8f..A...(../....D..1b.%.9:1y.LD.3...~Y....?..........(.s....~.nh........................................................................................................................................................................@...6`.W.....z.m..z....@.:.`..e.agn..w[-..}O.L...Gf.h.V....Wlu......n.....ek...z...Z...lu..AMP..@P...........&... ..j..AMP..@P..............3f.X).K._.J..+....d...5A.t..c._...R6K.2....@P.6A=}...'O...WZ[[{....;~..w[..7.x9.....uR~-.....7GB..0a..e?.........S...R&.<..X.2..r..}.>.hii.]......Q.N.iL..]..>y.r.\.."..U.g..A......K....'....q.LP..o..O..-.l...{....{)...+.....\N...9...P.d..+....B.[.Z..d.....e>...#i~%D.8Y&.E...L..M.+..OX..J1...|.do&......9..+8.[......ady...P_.....m.....mA-.P...A......a.e.zW.w..EnbIX.3.j.....k....[..Y...q[.r4...xY.....+w.g....Sk\#F..;9&.....4....f...I.'X....n.r.$.APw.P.A....M..8=..).0_.h./...b.....g......e.S...
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (35861)
                                                                      Category:downloaded
                                                                      Size (bytes):36099
                                                                      Entropy (8bit):5.314563534826003
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:2F7CCD8B357434E3FA86E690C0D9EED8
                                                                      SHA1:8D96BF3F6EA364AD00A39144D63F6262272C0661
                                                                      SHA-256:97FEDEC7AE01B311398DF5BBB3D625C7797587DC89AAE0B9EF1F3A864EB73728
                                                                      SHA-512:0FD4A54C5A28703DE4B907442A40DA926E1121EBC33203C0CBA50C070F006E08F8E8B2C4DE966A18AD41DADD69F8EF88DA3D190810E6FD9FB6A42B8FFEFBE313
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.utel.a33ffb6.js
                                                                      Preview:"use strict";(self.webpackChunk=self.webpackChunk||[]).push([[824],{85768:function(e,t,n){n.r(t),n.d(t,{initializeTelemetryLogger:function(){return be}});var i,a=n(92560),r=n(63061),s=n(60211),u=n(5809),o=function(e){for(var t=[],n=1;n<arguments.length;n++)t[n-1]=arguments[n]},l=n(73546),_=n(5699),m=n(59312),b=n(26261);!function(e){e.DataClassification={EssentialServiceMetadata:1,AccountData:2,SystemMetadata:4,OrganizationIdentifiableInformation:8,EndUserIdentifiableInformation:16,CustomerContent:32,AccessControl:64,PublicNonPersonalData:128,EndUserPseudonymousInformation:256,PublicPersonalData:512,SupportData:1024,DirectMeasurementData:2048,Everything:65535},e.DataFieldType={String:0,Boolean:1,Int64:2,Double:3,Guid:4},e.SamplingPolicy={NotSet:0,Measure:1,Diagnostics:2,CriticalBusinessImpact:191,CriticalCensus:192,CriticalExperimentation:193,CriticalUsage:194},e.PersistencePriority={NotSet:0,Normal:1,High:2},e.CostPriority={NotSet:0,Normal:1,High:2},e.DataCategories={NotSet:0,SoftwareS
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 55503
                                                                      Category:downloaded
                                                                      Size (bytes):15942
                                                                      Entropy (8bit):7.985848663515711
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:D8413A82C3ACAD792A58247EE86F13E3
                                                                      SHA1:A0E7094EC02457E0FFFAF3C35B2FB62740BC3BBA
                                                                      SHA-256:8D37EC047A496B43579F8B4C83432905C482D67E0672A32FF8C9BC4155C718CC
                                                                      SHA-512:FBDC7B9087518D334295F912113B310E4FA3EFE36B202C62B4E459380DB2EA8D434710A896D1ECADC6304CC9C5BAFBA84438EA9355D869ED4A89B86D581EFEAD
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://aadcdn.msauth.net/ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_fo8rkc18qnhjh4wnzabsdg2.js
                                                                      Preview:...........}Ms#G.....u...z |..#h........C)$....`/.n...p..8...;.j.|..G_|.O.........n..How...!..+++++3+3.w7k..{..R.=.......~....E.......O. ......7.U.Q..?~v.Y.w..;....*._...N...e.zpb'.....7k....|.a...((-...J........,.}~.c2.'p<..eu.................9n#,.......7.\?...^6...^.3..^.h.....R(.^..p...xY...c..D..l2..'#o.W..7iB...XL..S.(.B......i.D.M\p..`..Eg{.....7M..{...zh...'N]..L...s..2.A..u..."*p.. Xx....w..'l..w..'c/^.FP....q.h4.R+X^{...d..M.C.J,..RP.7E.T......8 .v....Iw.X..?.r......nk./..?Wj..A.|./........JAs.j......?.!..t.z.-..m.]..3y...S@...'.).).Aa..1.kQ.....l+.....-q..n.p../..l.H>G.^<.}..ID.][D..[!...........{O....9.C...8V>..=N..(.4.KXt../.1U...\F.*0..=.......p.-..kQ@P..(...-..ea&>.y.......:..Y.t[x..Xw:.QTp....ZE.u..\?`q......EhJ.A.L.......P..=.xk....(.wrL.."d.q`...$../.\...M.<_|.<.~|[....l....o...;p.(z.&.,~.....X....1?e1.1..v.L.........,.......?{...\fB....-.).Fb.;.p.N...n(..^....B.#D...g|.E..8R\.0....7 ...C....QQ.fPB3."F..dN....%.s..%....'
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:HTML document, Unicode text, UTF-8 text, with very long lines (1048)
                                                                      Category:dropped
                                                                      Size (bytes):49796
                                                                      Entropy (8bit):4.696858330625097
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:36C1943617E01085CE1FF9FCD054A05B
                                                                      SHA1:6840BA63B42F0BDCA901B560D9D08C5616D1F768
                                                                      SHA-256:C04E5EF32EBA9D8E2AE0C16665FED499372E9C641A9376447D34E10132C50637
                                                                      SHA-512:13626D86F4532A40EECE1F99C2513EDB5D03A214CDBE9AFA9BB2216862E0A848F30E5E281E586A1C338B424231BC61588C7A2810374B16CEADCA82843D9C0CD3
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:<!DOCTYPE html><html><head>. <meta http-equiv="Content-Type" content="text/html; charset=utf-8">. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <link rel="shortcut icon" href="https://aadcdn.msftauth.net/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico">. <title>Microsoft </title>. <meta name="referrer" content="never">. . <meta type="xrm/designer/setting" name="type" value="marketing-designer-content-editor-document">. <meta type="xrm/designer/setting" name="layout-editable" value="marketing-designer-layout-editable">. <style data-merge-styles="true"></style>. <style data-merge-styles="true"></style><title>Im not a Robot</title>. <meta http-equiv="X-UA-Compatible" content="IE=edge">. <meta charset="utf-8">. <meta name="viewport" content="width=device-width, initial-scale=1.0">. <meta name="format-detection" content="telephone=no">. <meta name="description" conten
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:JSON data
                                                                      Category:dropped
                                                                      Size (bytes):11401
                                                                      Entropy (8bit):4.914475659803146
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:550F480BD63DBC8D5B04FAFDA2696C24
                                                                      SHA1:5A15E9F6516B6D838E73085DDA4EBCCBAFBB878D
                                                                      SHA-256:F5181C7776E0F5540DC52C3405E22FE678F906F27DFE5B009FE9C66A0403B488
                                                                      SHA-512:97E67960A841EA1E6F797FEBCE2E2F450FDFF12076CFB59477D221187F09D78919A0D49148A4655A25537012AB48464DB14CFBEC9A981911292F80EEE2B0696C
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:{"responses":null,"form":{"description":"You have received a new PDF document for your review\n","onlineSafetyLevel":0,"reputationTier":1,"background":{"altText":"","contentType":"image/png","fileIdentifier":"6e7ebd16-b9ac-4bcd-a5e9-830f28001e28","originalFileName":"58412cee-2067-4a44-9fd0-1e67c9db36a1","resourceId":"85a251d6-8880-4632-8ea1-b8b4caa7ef08","resourceUrl":"https://lists.office.com/Images/2d4d4e83-7a83-45a5-b049-46926117014c/126fa5f5-c7b4-4f2a-87b3-dd54700e4a11/T7CY4CY9ZDRAL8Q731X4QZFADI/85a251d6-8880-4632-8ea1-b8b4caa7ef08","height":null,"width":null,"size":null},"header":{"altText":null,"contentType":null,"fileIdentifier":null,"originalFileName":null,"resourceId":null,"resourceUrl":null,"height":null,"width":null,"size":null},"logo":{"altText":"","contentType":"image/png","fileIdentifier":"d8505ef1-aaab-4ead-99b4-08b94f2711ac","originalFileName":"1c364cd6-912f-44c0-a7dd-740d1591eb71","resourceId":"5adcd565-32f8-46f3-8a13-67e99f4a064e","resourceUrl":"https://lists.office.c
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 141492
                                                                      Category:downloaded
                                                                      Size (bytes):49696
                                                                      Entropy (8bit):7.995313044786981
                                                                      Encrypted:true
                                                                      SSDEEP:
                                                                      MD5:3D5FBC4186EF45B04DE8BF8BA6861967
                                                                      SHA1:EFB2759A486E84730182091A9710DCE3EDCD8F6F
                                                                      SHA-256:099E7356BAE6752C1A7052BC9DE4AD113187EDA6A1385794E12955F7AE636D25
                                                                      SHA-512:949516390D8CEA5A1057647B2487634CFCFBD2510D9571965DC714954723EA9FA1FA79C240671888613964D8D43C921DCA8BAE3802E15C98F127B82092E51126
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://aadcdn.msauth.net/shared/1.0/content/js/BssoInterrupt_Core_sw-M8KkV3_nBot-G1ImRcw2.js
                                                                      Preview:............[.8.8...+.w..OL..hp._..nf.0$.......t....e .o?u.l.q.../g..J.T.*U.J..k.S......T.......T.~9:?.........h.........;?.L.......W..J.U.`.F.0r..W..o...$..+....O1N....(4...R..".r.F.s...C..j.o..J...3<.%. L.....G.M.%.Ee.x".<....?..8.$.H.........Uq#Q.ER..Qr..W..)k..3.........N....:.....:.e.`.\...V........p.[....n+.......Yu..o>N.n."z.&N......!+.W......s.6r.D.....{..q/.....*:z...3h....8.g31.....X...T*..a...W..Fsg....h..u.$.........>..7.p~;uch..+t...i.?..3...+.r6.A.*.....[g:..r.?S..............;.=6.&.`.....E=W.j.oaT}p..Vd.Np..\.i^[.....u'~..".M.:q.fF..._[..rM.F?....q.1.....S}.c_...\_./....y}6...._1-|p..l@..[q......*..k.?&.0^_.Cw:s.Rs^...IR5..Bv.yYX.....N.....O..epmF".GA...@...q..;...v`M.%3..#..,DMLTY+..g.........d+.>...{}.&N/..g-#FV.V.p.......Xs.(..{..]..-...!..F...XQge.X.MP.&.3....Re...b*23v..M.a...'......c.i...9...l..Z.`.F.._%>U.'.."..;.M......D$.}..~|....*u...ma.f:\......p..jy.<.r...cjG.N...{{}M_oEr8%...|.......d..nZ.S..H.Lx...x1t.
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 223759
                                                                      Category:downloaded
                                                                      Size (bytes):54318
                                                                      Entropy (8bit):7.995006031600911
                                                                      Encrypted:true
                                                                      SSDEEP:
                                                                      MD5:3F98A175D5232F665BEFFC23352D7176
                                                                      SHA1:8413FCCF22CEBAAED144736F5415F09EFD45CE48
                                                                      SHA-256:C6D80B97A3828280862163C72A94F5902F10D927FA1F6BDEAB5479B94F04F5AC
                                                                      SHA-512:93D0C9BBB7B204AE18A2392F137DC02B71A9E5352EC24267C2CEBAE5C286EEB68BCABF73F3F4B6DA1DF1D49E3998F6190D843144CD1ACDD5B4AA707CDF7CC24D
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://aadcdn.msauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_8e14dcf0e3ff5580d170.js
                                                                      Preview:...........k{.F.0.}...gF.L."..eR..v.y.O....g...............~...@....f<...F./...u...;............x.y.C...y...sx.....^=}.....N.W.I.Y$.....".w....$..|..a...+.7O.eg.gW..2...8*..2)J..<^f.:.4..;....<}.....ZK.......5..,;iV&Q...9......;U:....$....DyVd....Q...N......N..".;.,//.8...X..ZP7......&shpA...a.I.C\U0i.&K..}m..1..9.N.u....^.'I/:......r...a^Ee.f..oq..e'..y..U..;...T(...<L..;X.."..8-}.^L.._w.....f.w..V.x.kK..K../.A..[....oE....G..ao0...\........Qv.7..eX..70.....|.s.}.#...:..t...$.}=....s..g.}Q..........SO.....p.%..v..|.Fo.. ..,e.......=;;..7....E.F8+7.K?.n.y'.rw.........x~...=?.?...z~.?....<...(H./.....V.*....yx.?.O.>l...E..c]..n.?..>......%<.....?....w........../.2.^...d........1b...4~.)\W....k-.n.0..._..8....qZ..^...D=...~..w...^g.........*.r.......d.O............a....R.)O.[v...C......2.....s..y...o6...6...z}8d....e<+..y.cs....X...v.O...p.....3.v.~D..IAo.<.....,H..9.xx....h.....B\.f.a.&..V...no"MJ.R...6...Y.....F<...9....s`..Q...X
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
                                                                      Category:dropped
                                                                      Size (bytes):673
                                                                      Entropy (8bit):7.6596900876595075
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:0E176276362B94279A4492511BFCBD98
                                                                      SHA1:389FE6B51F62254BB98939896B8C89EBEFFE2A02
                                                                      SHA-256:9A2C174AE45CAC057822844211156A5ED293E65C5F69E1D211A7206472C5C80C
                                                                      SHA-512:8D61C9E464C8F3C77BF1729E32F92BBB1B426A19907E418862EFE117DBD1F0A26FCC3A6FE1D1B22B836853D43C964F6B6D25E414649767FBEA7FE10D2048D7A1
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      Preview:...........U.n.0....}i..P..C..7l/..d........n...G....yl. .E.......Tu.F.........?$.i.s..s...C..wi$.....r....CT.U.FuS..r.e.~...G.q...*..~M..mu}.0.=..&.~.e.WLX.....X..%p..i......7+.........?......WN..%>...$..c..}N....Y4?..x.1.....*.#v...Gal9.!.9.A.u..b..>..".#A2"+...<qc.v....)3...x.p&..K.&..T.r.'....J.T....Q..=..H).X...<.r...KkX........)5i4.+.h.....5.<..5.^O.eC%V^....Nx.E..;..52..h....C"I./.`..O...f..r..n.h.r]}.G^..D.7..i.].}.G.].....{....oW............h.4...}~=6u..k...=.X..+z}.4.].....YS5..J......)......m....w.......~}.C.b_..[.u..9_7.u.u.....y.ss....:_yQ<{..K.V_Z....c.G.N.a...?/..%. .-..K.td....4...5.(.e.`G7..]t?.3..\..... ....G.H...
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:Unicode text, UTF-8 text, with very long lines (64406), with no line terminators
                                                                      Category:downloaded
                                                                      Size (bytes):402685
                                                                      Entropy (8bit):5.611514974167333
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:D952E75B9440113C469361B3BBDE72DC
                                                                      SHA1:54B8FF95D654C61F866E2566C7426FEDD091A183
                                                                      SHA-256:B3E34B03A6DCD9B495FFF75F5780B954174ABD5468A4A54A847BE30057D57EE2
                                                                      SHA-512:7A6E1ABD75A9B65AF5FABC7E41B01409F581BEA0958A41173933357FC562AD79DB427F03770453E8613E906B4B3B16E11FAC763B88C48149807A1F3C3AF27B4C
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.lrp_ext.15c75c9.js
                                                                      Preview:(self.webpackChunk=self.webpackChunk||[]).push([[920],{86219:function(n,t,e){"use strict";e.d(t,{l:function(){return i}});var r=e(35852);function i(n){for(var t=[],e=1;e<arguments.length;e++)t[e-1]=arguments[e];for(var i=[],o=0,a=t;o<a.length;o++){var u=a[o];u&&i.push("function"==typeof u?u(n):u)}return 1===i.length?i[0]:i.length?r.m.apply(void 0,i):{}}},82699:function(n,t,e){"use strict";e.d(t,{j:function(){return a}});var r=e(65690),i=e(36178),o=e(49295);function a(n){var t=i.Y.getInstance(),e=(0,o.dH)((0,r.Eo)(),n);if(!t.classNameFromKey(e)){var a=t.getClassName();t.insertRule("@font-face{".concat(e,"}"),!0),t.cacheClassName(a,e,[],["font-face",e])}}},41633:function(n,t,e){"use strict";e.d(t,{x:function(){return o}});var r={},i=void 0;try{i=window}catch(n){}function o(n,t){if(void 0!==i){var e=i.__packages__=i.__packages__||{};if(!e[n]||!r[n])r[n]=t,(e[n]=e[n]||[]).push(t)}}o("@fluentui/set-version","6.0.0")},20660:function(n,t,e){"use strict";e.r(t),e.d(t,{AnimationClassNames:funct
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with very long lines (16094)
                                                                      Category:downloaded
                                                                      Size (bytes):38124
                                                                      Entropy (8bit):5.310312368406633
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:F85DF0DB3B351E61F18DD9CA98A3C999
                                                                      SHA1:055AB43C220151E0C8B521A39D40DC54C50F988D
                                                                      SHA-256:5BEA34A1B8999FB53F5B3B8541BE6A2C6F8C75A8932BCB7A05E3FD5B91D78608
                                                                      SHA-512:1FB8F1989F9DD1F6C0C327F5B4808465F679793697EC486A7B18F2345DCF8DECDDCCFEEC65CC586B0F51E62BDD9C2EB035CE9C6CC23165F791181F4E0EB0DF0C
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://cdn.forms.office.net/forms/scripts/dists/dll-dompurify.min.bcf1a85.js
                                                                      Preview:var _dll_dompurify_e7d452d73246f470bc6d;(()=>{var t={699:function(t){./*! @license DOMPurify | (c) Cure53 and other contributors | Released under the Apache license 2.0 and Mozilla Public License 2.0 | github.com/cure53/DOMPurify/blob/2.2.2/LICENSE */.t.exports=function(){"use strict";function t(t){if(Array.isArray(t)){for(var e=0,n=Array(t.length);e<t.length;e++)n[e]=t[e];return n}return Array.from(t)}var e=Object.hasOwnProperty,n=Object.setPrototypeOf,o=Object.isFrozen,r=Object.freeze,i=Object.seal,s=Object.create,a="undefined"!=typeof Reflect&&Reflect,c=a.apply,l=a.construct;c||(c=function(t,e,n){return t.apply(e,n)}),r||(r=function(t){return t}),i||(i=function(t){return t}),l||(l=function(e,n){return new(Function.prototype.bind.apply(e,[null].concat(t(n))))});var u=T(Array.prototype.forEach),p=T(Array.prototype.pop),d=T(Array.prototype.push),f=T(String.prototype.toLowerCase),m=T(String.prototype.match),h=T(String.prototype.replace),y=T(String.prototype.indexOf),w=T(String.prototype
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:JSON data
                                                                      Category:downloaded
                                                                      Size (bytes):530
                                                                      Entropy (8bit):4.860983185588505
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:4D945878F36DCBBF35C41B5BB6E5513E
                                                                      SHA1:786EDE7740452B1C38B1FFA47C28F4E70140EC5F
                                                                      SHA-256:19DADB739E9886DBDDC79E9E916B753AC53A2C8C1A9560EF14AF28B400C234E0
                                                                      SHA-512:37E16ACE0F5DF65065C150FB05E7968A5B3AA828F66EFDEF29DD78EF4C2D4B29D0C4F81502CDA069F1EFB0B0329FA69BC309579D74A447E2B7FE9E27AC9CCD99
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://forms.office.com/pwa/en-us/app.webmanifest
                                                                      Preview:{"lang":"en-us","name":"Microsoft Forms","short_name":"Forms","icons":[{"src":"https://cdn.forms.office.net/forms/images/pwa/forms-pwa-logo-192.png","sizes":"192x192","type":"image/png"},{"src":"https://cdn.forms.office.net/forms/images/pwa/forms-pwa-logo-256.png","sizes":"256x256","type":"image/png"},{"src":"https://cdn.forms.office.net/forms/images/pwa/forms-pwa-logo-512.png","sizes":"512x512","type":"image/png"}],"scope":"/","start_url":"/?pwa=1","display":"minimal-ui","theme_color":"#03787c","background_color":"#ffffff"}
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113657
                                                                      Category:downloaded
                                                                      Size (bytes):35807
                                                                      Entropy (8bit):7.994448207898337
                                                                      Encrypted:true
                                                                      SSDEEP:
                                                                      MD5:FCF71472EFC9E614B10DFD499805F729
                                                                      SHA1:CF1FA991F9F08068F8F5F4D188D741BF5C2B7722
                                                                      SHA-256:23FF9B1A108B620EB12123003F37200042B120F3A554D3772B55F6366BDD4652
                                                                      SHA-512:B01F793C888C512F4BD1252EBA17A30C16BE3EC5E5A48BBBDD8F724EDCAEB2FD810439050A3097C27DAFDD1DE9235B39B7CF45D5341CC43A942F3F529891F379
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://aadcdn.msauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_ea3e62a2bdfb2b2ee8c8.js
                                                                      Preview:...........{..8.(.........,.-.......gglu.. .m..I....~..oRv......i.(....P(......k............o.6>.|..d..........O...V..}.G..4......9.l..F.mDI.f.4...o,..EA.1...F1g..,...E..Gy...,No6.@..l....n..;....P.fQ...ty...b#I.(d.A2!j1$..m....6n.Q8.x..Y...b#c!....|.p..w#..F..i..s.Gc..b..9U.k......&@pJ..'40J......e.$.k.L(b...F.n.+..nO..6@n...A.&.,LVa......Y......V..o..% ....,......:..e.-XR. <FE.w..b..P......r.b.["~..!.....y.......V...4.;M..Y.X.{.......0].N..,.r`=...Mv....;...k....w.1p.q...(.u.3....;).. }...s....'....c...o.d....Ax.W..._...?.9..*.........3..MWI..3.p3..u.m$~Vo:n.'.8..!5h....y...6=7...hz.......f.-.).......Nc..:..u.g...~.8..4.....0P......$.=.a....#._..3.t..7Q...-....6..j.|...*.5-...B...}.VQ.&/.*..e.XeI.C../.y...{...1...Y..g..`'..F..h.o.]SHW...,..Ac_%y...M..u.O..U..`.&...Y.}....Tu..z..iv.....5..M.q.. .Bz.,..oSS.%..y.....gS1s.(.........%,fE.m.@~.4.........7.x.$0mQ..o....J.J^....~.....*.u!.~Z.iw.b...Q~).=..Tq.:.7HH.E.&6.D`.(..Cxmf.(o...^y_.v.{..K<Y.5.
                                                                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                      File Type:ASCII text, with no line terminators
                                                                      Category:downloaded
                                                                      Size (bytes):28
                                                                      Entropy (8bit):4.307354922057605
                                                                      Encrypted:false
                                                                      SSDEEP:
                                                                      MD5:9F9FA94F28FE0DE82BC8FD039A7BDB24
                                                                      SHA1:6FE91F82974BD5B101782941064BCB2AFDEB17D8
                                                                      SHA-256:9A37FDC0DBA8B23EB7D3AA9473D59A45B3547CF060D68B4D52253EE0DA1AF92E
                                                                      SHA-512:34946EF12CE635F3445ED7B945CF2C272EF7DD9482DA6B1A49C9D09A6C9E111B19B130A3EEBE5AC0CCD394C523B54DD7EB9BF052168979A9E37E7DB174433F64
                                                                      Malicious:false
                                                                      Reputation:unknown
                                                                      URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwlI5QkAMeIp4hIFDdFbUVISBQ1Xevf9?alt=proto
                                                                      Preview:ChIKBw3RW1FSGgAKBw1Xevf9GgA=
                                                                      No static file info