Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://drive.google.com/file/d/1NEezG13UwZmQ3Wo3-DatJjXtVryEdLgi/view?usp=sharing_eil_m&ts=66abab49

Overview

General Information

Sample URL:https://drive.google.com/file/d/1NEezG13UwZmQ3Wo3-DatJjXtVryEdLgi/view?usp=sharing_eil_m&ts=66abab49
Analysis ID:1486179

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Phishing site detected (based on favicon image match)
Detected non-DNS traffic on DNS port
HTML body contains low number of good links
HTML body contains password input but no form action
HTML page contains hidden javascript code
HTML page contains obfuscated script src
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 7092 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://drive.google.com/file/d/1NEezG13UwZmQ3Wo3-DatJjXtVryEdLgi/view?usp=sharing_eil_m&ts=66abab49 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6248 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1960,i,10048902173271592160,13285790914075045240,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: https://access.online.connect.wellsfarqo-review.com/auth/login/present?origin=cob&LOB=CONSMatcher: Template: wellsfargo matched with high similarity
Source: https://access.online.connect.wellsfarqo-review.com/auth/login/present?origin=cob&LOB=CONSHTTP Parser: Number of links: 0
Source: https://access.online.connect.wellsfarqo-review.com/auth/login/present?origin=cob&LOB=CONSHTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://access.online.connect.wellsfarqo-review.com/secure/HTTP Parser: Base64 decoded: function _0x5f48(_0x2c5e02,_0xe19f15){var _0x1b34d0=_0x1b34();return _0x5f48=function(_0x5f482d,_0x502389){_0x5f482d=_0x5f482d-0x143;var _0x72c7d7=_0x1b34d0[_0x5f482d];return _0x72c7d7;},_0x5f48(_0x2c5e02,_0xe19f15);}(function(_0x471b0b,_0x52b3dd){var _0x...
Source: https://access.online.connect.wellsfarqo-review.com/secure/HTTP Parser: Script src: data:text/javascript;base64,ZnVuY3Rpb24gXzB4NWY0OChfMHgyYzVlMDIsXzB4ZTE5ZjE1KXt2YXIgXzB4MWIzNGQwPV8weDFiMzQoKTtyZXR1cm4gXzB4NWY0OD1mdW5jdGlvbihfMHg1ZjQ4MmQsXzB4NTAyMzg5KXtfMHg1ZjQ4MmQ9XzB4NWY0ODJkLTB4MTQzO3ZhciBfMHg3MmM3ZDc9XzB4MWIzNGQwW18weDVmNDgyZF
Source: https://access.online.connect.wellsfarqo-review.com/secure/HTTP Parser: Script src: data:text/javascript;base64,dmFyIF8weDNmZDY5MD1fMHg0Y2VkOyhmdW5jdGlvbihfMHg4ZTVlOTgsXzB4NGFhOTEwKXt2YXIgXzB4MmJjNjY1PV8weDRjZWQsXzB4NDMwNGQ4PV8weDhlNWU5OCgpO3doaWxlKCEhW10pe3RyeXt2YXIgXzB4MzA1MjJhPS1wYXJzZUludChfMHgyYmM2NjUoMHgzZDcpKS8weDErcGFyc2VJbn
Source: https://access.online.connect.wellsfarqo-review.com/secure/HTTP Parser: Script src: data:text/javascript;base64,dmFyIF8weDVkM2JjYj1fMHgyZmZlOyhmdW5jdGlvbihfMHgyMzhlYmEsXzB4M2Q4NzJhKXt2YXIgXzB4MTZlNGQ3PV8weDJmZmUsXzB4MzdiMzJjPV8weDIzOGViYSgpO3doaWxlKCEhW10pe3RyeXt2YXIgXzB4M2YxYmFkPS1wYXJzZUludChfMHgxNmU0ZDcoMHgxMTMpKS8weDErLXBhcnNlSW
Source: https://access.online.connect.wellsfarqo-review.com/secure/HTTP Parser: Script src: data:text/javascript;base64,ZnVuY3Rpb24gXzB4OTdjOChfMHgxNTEwOWIsXzB4MjYyNmRlKXtjb25zdCBfMHg1NDdlMDc9XzB4NTQ3ZSgpO3JldHVybiBfMHg5N2M4PWZ1bmN0aW9uKF8weDk3YzhmMSxfMHgyNjU4N2Epe18weDk3YzhmMT1fMHg5N2M4ZjEtMHgxN2M7bGV0IF8weDNhYjRlMj1fMHg1NDdlMDdbXzB4OTdjOG
Source: https://access.online.connect.wellsfarqo-review.com/auth/login/present?origin=cob&LOB=CONSHTTP Parser: <input type="password" .../> found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdrive.google.com%2Fdrivesharing%2Fclientmodel%3Fid%3D1NEezG13UwZmQ3Wo3-DatJjXtVryEdLgi%26foreignService%3Dtexmex%26authuser%3D0%26origin%3Dhttps%3A%2F%2Fdrive.google.com&followup=https%3A%2F%2Fdrive.google.com%2Fdrivesharing%2Fclientmodel%3Fid%3D1NEezG13UwZmQ3Wo3-DatJjXtVryEdLgi%26foreignService%3Dtexmex%26authuser%3D0%26origin%3Dhttps%3A%2F%2Fdrive.google.com&ifkv=AdF4I75z46m3behhNWJAWdA8sg5hz7U2pivN_C7Iftm4U1YO7U3ruZGH-oc3hrGqQNrXsid4-DYt&osid=1&passive=1209600&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S940873265%3A1722528766179105&ddm=0HTTP Parser: No favicon
Source: https://firststatusupdate.blob.core.windows.net/attorney/blog-online.html?yqb3y7HTTP Parser: No favicon
Source: https://access.online.connect.wellsfarqo-review.com/secure/HTTP Parser: No favicon
Source: https://access.online.connect.wellsfarqo-review.com/auth/login/present?origin=cob&LOB=CONSHTTP Parser: No <meta name="author".. found
Source: https://access.online.connect.wellsfarqo-review.com/auth/login/present?origin=cob&LOB=CONSHTTP Parser: No <meta name="author".. found
Source: https://access.online.connect.wellsfarqo-review.com/auth/login/present?origin=cob&LOB=CONSHTTP Parser: No <meta name="author".. found
Source: https://access.online.connect.wellsfarqo-review.com/auth/login/present?origin=cob&LOB=CONSHTTP Parser: No <meta name="author".. found
Source: https://access.online.connect.wellsfarqo-review.com/auth/login/present?origin=cob&LOB=CONSHTTP Parser: No <meta name="copyright".. found
Source: https://access.online.connect.wellsfarqo-review.com/auth/login/present?origin=cob&LOB=CONSHTTP Parser: No <meta name="copyright".. found
Source: https://access.online.connect.wellsfarqo-review.com/auth/login/present?origin=cob&LOB=CONSHTTP Parser: No <meta name="copyright".. found
Source: https://access.online.connect.wellsfarqo-review.com/auth/login/present?origin=cob&LOB=CONSHTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:61640 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:61641 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.16:61642 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.16:61724 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:61636 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: unknownTCP traffic detected without corresponding DNS query: 52.165.165.26
Source: global trafficDNS traffic detected: DNS query: drive.google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: apis.google.com
Source: global trafficDNS traffic detected: DNS query: play.google.com
Source: global trafficDNS traffic detected: DNS query: blobcomments-pa.clients6.google.com
Source: global trafficDNS traffic detected: DNS query: lh3.googleusercontent.com
Source: global trafficDNS traffic detected: DNS query: peoplestackwebexperiments-pa.clients6.google.com
Source: global trafficDNS traffic detected: DNS query: access.online.connect.wellsfarqo-review.com
Source: unknownNetwork traffic detected: HTTP traffic on port 61654 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61692 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61745
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61747
Source: unknownNetwork traffic detected: HTTP traffic on port 61640 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61749
Source: unknownNetwork traffic detected: HTTP traffic on port 61719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61648 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61663 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61742
Source: unknownNetwork traffic detected: HTTP traffic on port 61737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 61680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61754
Source: unknownNetwork traffic detected: HTTP traffic on port 61748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61755
Source: unknownNetwork traffic detected: HTTP traffic on port 61702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61756
Source: unknownNetwork traffic detected: HTTP traffic on port 61775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61758
Source: unknownNetwork traffic detected: HTTP traffic on port 61723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61759
Source: unknownNetwork traffic detected: HTTP traffic on port 61754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61750
Source: unknownNetwork traffic detected: HTTP traffic on port 61683 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61753
Source: unknownNetwork traffic detected: HTTP traffic on port 61652 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61694 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61691 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61644
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61648
Source: unknownNetwork traffic detected: HTTP traffic on port 61722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61649
Source: unknownNetwork traffic detected: HTTP traffic on port 61745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61640
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61641
Source: unknownNetwork traffic detected: HTTP traffic on port 61688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61642
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61643
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61764
Source: unknownNetwork traffic detected: HTTP traffic on port 61762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 61714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61655
Source: unknownNetwork traffic detected: HTTP traffic on port 61725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61656
Source: unknownNetwork traffic detected: HTTP traffic on port 61700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61643 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61658
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61779
Source: unknownNetwork traffic detected: HTTP traffic on port 61660 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61652
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61654
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61775
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61708
Source: unknownNetwork traffic detected: HTTP traffic on port 61730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61658 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61667
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61700
Source: unknownNetwork traffic detected: HTTP traffic on port 61724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61644 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61702
Source: unknownNetwork traffic detected: HTTP traffic on port 61776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61704
Source: unknownNetwork traffic detected: HTTP traffic on port 61747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61780
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61660
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61661
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61663
Source: unknownNetwork traffic detected: HTTP traffic on port 61667 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61655 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61719
Source: unknownNetwork traffic detected: HTTP traffic on port 61676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61693 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61641 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61717
Source: unknownNetwork traffic detected: HTTP traffic on port 61727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61673
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61674
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61675
Source: unknownNetwork traffic detected: HTTP traffic on port 61649 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61676
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61729
Source: unknownNetwork traffic detected: HTTP traffic on port 61780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61656 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61688
Source: unknownNetwork traffic detected: HTTP traffic on port 61642 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61721
Source: unknownNetwork traffic detected: HTTP traffic on port 61749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61689
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61723
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61726
Source: unknownNetwork traffic detected: HTTP traffic on port 61726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61680
Source: unknownNetwork traffic detected: HTTP traffic on port 61684 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61661 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61683
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61684
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 61766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61699
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61732
Source: unknownNetwork traffic detected: HTTP traffic on port 61689 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61736
Source: unknownNetwork traffic detected: HTTP traffic on port 61746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61737
Source: unknownNetwork traffic detected: HTTP traffic on port 61729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61739
Source: unknownNetwork traffic detected: HTTP traffic on port 61752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61691
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61692
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61693
Source: unknownNetwork traffic detected: HTTP traffic on port 61721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61694
Source: unknownNetwork traffic detected: HTTP traffic on port 61704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61697
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 61731
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:61640 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:61641 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.16:61642 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.16:61724 version: TLS 1.2
Source: classification engineClassification label: mal48.phis.win@26/59@36/286
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://drive.google.com/file/d/1NEezG13UwZmQ3Wo3-DatJjXtVryEdLgi/view?usp=sharing_eil_m&ts=66abab49
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1960,i,10048902173271592160,13285790914075045240,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1960,i,10048902173271592160,13285790914075045240,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://drive.google.com/file/d/1NEezG13UwZmQ3Wo3-DatJjXtVryEdLgi/view?usp=sharing_eil_m&ts=66abab490%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
about:blank0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
blobcomments-pa.clients6.google.com
142.250.184.234
truefalse
    unknown
    access.online.connect.wellsfarqo-review.com
    188.119.66.154
    truefalse
      unknown
      plus.l.google.com
      142.250.181.238
      truefalse
        unknown
        play.google.com
        142.250.186.110
        truefalse
          unknown
          drive.google.com
          142.250.185.110
          truefalse
            unknown
            www.google.com
            216.58.206.68
            truefalse
              unknown
              peoplestackwebexperiments-pa.clients6.google.com
              216.58.206.74
              truefalse
                unknown
                googlehosted.l.googleusercontent.com
                172.217.18.97
                truefalse
                  unknown
                  lh3.googleusercontent.com
                  unknown
                  unknownfalse
                    unknown
                    apis.google.com
                    unknown
                    unknownfalse
                      unknown
                      NameMaliciousAntivirus DetectionReputation
                      https://access.online.connect.wellsfarqo-review.com/secure/false
                        unknown
                        https://access.online.connect.wellsfarqo-review.com/auth/login/present?origin=cob&LOB=CONStrue
                          unknown
                          https://drive.google.com/auth_warmupfalse
                            unknown
                            about:blankfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://drive.google.com/file/d/1NEezG13UwZmQ3Wo3-DatJjXtVryEdLgi/view?usp=sharing_eil_m&ts=66abab49false
                              unknown
                              https://drive.google.com/file/d/1NEezG13UwZmQ3Wo3-DatJjXtVryEdLgi/view?ts=66abab49false
                                unknown
                                • No. of IPs < 25%
                                • 25% < No. of IPs < 50%
                                • 50% < No. of IPs < 75%
                                • 75% < No. of IPs
                                IPDomainCountryFlagASNASN NameMalicious
                                142.250.185.206
                                unknownUnited States
                                15169GOOGLEUSfalse
                                216.58.206.74
                                peoplestackwebexperiments-pa.clients6.google.comUnited States
                                15169GOOGLEUSfalse
                                216.58.212.142
                                unknownUnited States
                                15169GOOGLEUSfalse
                                142.251.168.84
                                unknownUnited States
                                15169GOOGLEUSfalse
                                142.250.181.238
                                plus.l.google.comUnited States
                                15169GOOGLEUSfalse
                                142.250.185.163
                                unknownUnited States
                                15169GOOGLEUSfalse
                                172.217.18.97
                                googlehosted.l.googleusercontent.comUnited States
                                15169GOOGLEUSfalse
                                142.250.186.110
                                play.google.comUnited States
                                15169GOOGLEUSfalse
                                142.250.184.227
                                unknownUnited States
                                15169GOOGLEUSfalse
                                188.119.66.154
                                access.online.connect.wellsfarqo-review.comRussian Federation
                                209499FLYNETRUfalse
                                142.250.186.33
                                unknownUnited States
                                15169GOOGLEUSfalse
                                142.250.186.138
                                unknownUnited States
                                15169GOOGLEUSfalse
                                142.250.186.35
                                unknownUnited States
                                15169GOOGLEUSfalse
                                142.250.186.78
                                unknownUnited States
                                15169GOOGLEUSfalse
                                34.104.35.123
                                unknownUnited States
                                15169GOOGLEUSfalse
                                1.1.1.1
                                unknownAustralia
                                13335CLOUDFLARENETUSfalse
                                216.58.212.138
                                unknownUnited States
                                15169GOOGLEUSfalse
                                172.217.16.206
                                unknownUnited States
                                15169GOOGLEUSfalse
                                172.217.18.3
                                unknownUnited States
                                15169GOOGLEUSfalse
                                142.250.185.110
                                drive.google.comUnited States
                                15169GOOGLEUSfalse
                                52.239.221.226
                                unknownUnited States
                                8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                216.58.206.46
                                unknownUnited States
                                15169GOOGLEUSfalse
                                216.58.206.68
                                www.google.comUnited States
                                15169GOOGLEUSfalse
                                142.250.186.106
                                unknownUnited States
                                15169GOOGLEUSfalse
                                142.250.185.170
                                unknownUnited States
                                15169GOOGLEUSfalse
                                142.250.181.227
                                unknownUnited States
                                15169GOOGLEUSfalse
                                239.255.255.250
                                unknownReserved
                                unknownunknownfalse
                                142.250.185.131
                                unknownUnited States
                                15169GOOGLEUSfalse
                                142.250.186.142
                                unknownUnited States
                                15169GOOGLEUSfalse
                                172.217.16.196
                                unknownUnited States
                                15169GOOGLEUSfalse
                                142.250.184.234
                                blobcomments-pa.clients6.google.comUnited States
                                15169GOOGLEUSfalse
                                IP
                                192.168.2.16
                                127.0.0.1
                                Joe Sandbox version:40.0.0 Tourmaline
                                Analysis ID:1486179
                                Start date and time:2024-08-01 18:11:38 +02:00
                                Joe Sandbox product:CloudBasic
                                Overall analysis duration:
                                Hypervisor based Inspection enabled:false
                                Report type:full
                                Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                Sample URL:https://drive.google.com/file/d/1NEezG13UwZmQ3Wo3-DatJjXtVryEdLgi/view?usp=sharing_eil_m&ts=66abab49
                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                Number of analysed new started processes analysed:14
                                Number of new started drivers analysed:0
                                Number of existing processes analysed:0
                                Number of existing drivers analysed:0
                                Number of injected processes analysed:0
                                Technologies:
                                • EGA enabled
                                Analysis Mode:stream
                                Analysis stop reason:Timeout
                                Detection:MAL
                                Classification:mal48.phis.win@26/59@36/286
                                • Exclude process from analysis (whitelisted): svchost.exe
                                • Excluded IPs from analysis (whitelisted): 142.250.186.35, 142.250.186.78, 142.251.168.84, 34.104.35.123, 142.250.184.227, 142.250.186.106, 142.250.185.131, 87.248.205.0
                                • Excluded domains from analysis (whitelisted): fonts.googleapis.com, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, fonts.gstatic.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, www.gstatic.com
                                • Not all processes where analyzed, report is missing behavior information
                                • VT rate limit hit for: https://drive.google.com/file/d/1NEezG13UwZmQ3Wo3-DatJjXtVryEdLgi/view?usp=sharing_eil_m&ts=66abab49
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 1 15:12:06 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                Category:dropped
                                Size (bytes):2673
                                Entropy (8bit):3.9873016065163718
                                Encrypted:false
                                SSDEEP:
                                MD5:BDA194A19D95B32A6E52D7C0554CBE0F
                                SHA1:C3C8BBB93FD00CB123329D4D65361DCA02900815
                                SHA-256:0F5B620B1669AA8DF8A4A0E7FD9154822B556AC42A433869033C93E105371424
                                SHA-512:B573381C37E35591AAE869D25652D26B20C38D846536416BD5A39733D5A6AC40D57F717FAFC8519EAE79C256D153E9629C2E21056B3D4CD77C50A4B6622AE23E
                                Malicious:false
                                Reputation:unknown
                                Preview:L..................F.@.. ...$+.,....=...-...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yy.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........L.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 1 15:12:06 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                Category:dropped
                                Size (bytes):2675
                                Entropy (8bit):4.003666968025272
                                Encrypted:false
                                SSDEEP:
                                MD5:30943F43CFCDAEAC4361B2555EBE3EB8
                                SHA1:F39D108062F2B5917FB82C494233C3A108B2AA47
                                SHA-256:06AC96F01195E22D31BDD67FFE83133EA69A6957008994850FC101CECDB79DF5
                                SHA-512:5977D000E2EFD2D39FDBA1D277A105581D78D6088939E8F25727A89D486F10E49FD86F3082F0A6326C23519258A0BBB255E6A64D1FAF81E8F191DA28653015BA
                                Malicious:false
                                Reputation:unknown
                                Preview:L..................F.@.. ...$+.,........-...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yy.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........L.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                Category:dropped
                                Size (bytes):2689
                                Entropy (8bit):4.009022952661029
                                Encrypted:false
                                SSDEEP:
                                MD5:87D711CA04394AA874082EE8C673BE49
                                SHA1:AB5EDC7F434298D1B322B83966B671A63B2963B3
                                SHA-256:E582DF10294A59B769AFDFA32A3AD1FF9021ABEB363CFFA8A2D9E3C20150A2E3
                                SHA-512:EBA9A37FEA2E98F15908AAD0845D9500FBF8336A4B7206E5160C4537926FF418EFC1097D827DB712271DC8C3DC5A9E70C7162F145F23E5FC22DE4BE905219C98
                                Malicious:false
                                Reputation:unknown
                                Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yy.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........L.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 1 15:12:06 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                Category:dropped
                                Size (bytes):2677
                                Entropy (8bit):3.9998685408372037
                                Encrypted:false
                                SSDEEP:
                                MD5:287CED349DBC416C9E13ED519972BD98
                                SHA1:401BEE3AC22B5238E9A26AC53CDC9C81BF711DCA
                                SHA-256:E40E5891963A2CFEEF31DA99EB462611BB3E073E6BBF45D1D19CDCA8D22CC105
                                SHA-512:E1482D05BD673DB8AEBC9F4E1D993409407667F817A989CEBFF0C92070320B967BD3D137E5A75CACF1A59E966D820DDF394306FE2905147502AC0438ADD3BB06
                                Malicious:false
                                Reputation:unknown
                                Preview:L..................F.@.. ...$+.,....M=..-...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yy.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........L.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 1 15:12:06 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                Category:dropped
                                Size (bytes):2677
                                Entropy (8bit):3.9867765743192187
                                Encrypted:false
                                SSDEEP:
                                MD5:3E2F55542EE0D839D8ED6879BEE48CE4
                                SHA1:304A924DCBC29E8256E0BF791B6A30D6B18DCAD8
                                SHA-256:5770EA125C27F2B5E4D7FCBEE1BAF68E2038D435561EF2509D2E4979EC98E041
                                SHA-512:4E4221D08B75BD412E9938D5ADE5906F604CF99B2A0663F5AD81C4694D838B67DB824059005410AB9962D99819EF2E6BEDF165EFE9262EA4DE5DB4480CC0E383
                                Malicious:false
                                Reputation:unknown
                                Preview:L..................F.@.. ...$+.,.......-...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yy.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........L.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 1 15:12:06 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                Category:dropped
                                Size (bytes):2679
                                Entropy (8bit):3.996653103019225
                                Encrypted:false
                                SSDEEP:
                                MD5:04031A6857B6E24848C44539514BFA87
                                SHA1:65E4A3347BEF18D882AECA46A79E5BD4978FED1D
                                SHA-256:63A9507DD2B92E4EA10A29EF3C1EA928ECA4A66F58434976AB2BC77973C00570
                                SHA-512:3392DE6EA3E761C2BFDD435EAF81368866D91B927ED95461D77E95AED7DBF07E463242CF4DDDB3A6C61BC675A81D50AA48BA1B67376E192A12412AE08CA47CEE
                                Malicious:false
                                Reputation:unknown
                                Preview:L..................F.@.. ...$+.,....py.-...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Yy.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........L.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (5892), with CRLF line terminators
                                Category:downloaded
                                Size (bytes):5951
                                Entropy (8bit):5.269906916482887
                                Encrypted:false
                                SSDEEP:
                                MD5:AAD87CE8FF0A430A71A4DC04E3684FDF
                                SHA1:29D58F4CA3C3ACC6C17F5C48106242CF0B98365B
                                SHA-256:0DE41C653093529D0C99C1F9D9E7B089180CB6DD2AA253EBBDE321A021D628AA
                                SHA-512:1A222DA7E7B565622D7E7AC37372CBA889D087B785AB66B4FC2757F0DE01B1F60C4200F9529CC1AC37C282B95DFAD268FC0D2DEE80E40093E65879B749B91178
                                Malicious:false
                                Reputation:unknown
                                URL:https://access.online.connect.wellsfarqo-review.com/assets/main.6539fceb73733687f14d.css
                                Preview:.MenuBar__bar___bKAcd{bottom:0;display:flex;flex-direction:column;height:100%;justify-content:center;margin:0;padding:0 20px 0 0;position:absolute;right:0;top:0}.MenuBar__bar___bKAcd ul{margin:0;padding:0}.MenuBar__bar___bKAcd ul li{color:#fff;font-size:.8125rem;line-height:1rem;margin:0;padding:0}.MenuBar__bar___bKAcd ul li a{cursor:pointer}.MenuBar__bar___bKAcd ul li:not(:last-of-type){padding-right:16px}.MenuBar__bar___bKAcd.MenuBar__dc___nzKHA ul li{color:#3b3331}.MenuBar__bar___bKAcd.MenuBar__dc___nzKHA ul li svg path{fill:#3b3331}.HamburgerIcon__icon___J3EKg{fill:#204097}.MenuButton__button___Vg6qr{bottom:0;display:flex;flex-direction:column;height:100%;justify-content:center;position:absolute;right:0;top:0}.MenuButton__button___Vg6qr button{height:100%;padding:11px 17px}.MenuButton__triangle___hy72p{bottom:0;left:24px;opacity:0;position:absolute;transition:opacity .25s}.MenuButton__triangle___hy72p.MenuButton__active___BECNq{opacity:1}.MenuButton__triangle___hy72p path{fill:#fff
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:RIFF (little-endian) data, Web/P image, VP8 encoding, 1024x576, Suserng: [none]x[none], YUV color, decoders should clamp
                                Category:dropped
                                Size (bytes):6580
                                Entropy (8bit):7.903630098122762
                                Encrypted:false
                                SSDEEP:
                                MD5:A69B6CB550448D73BC04D210D7D5262A
                                SHA1:5ED6CC7E291BC9F49BDB2877F716F653C119AD18
                                SHA-256:FDB4AAF2EBD1860DA94BDAEE196E5F867AF7396D0F77A60163319D637B9E48C9
                                SHA-512:8BB67F1203F07516A362B7866E18C54597C956B0D328B612F762855B75F963D2F583619B0492BA7DF7A3DFCE9AB2C60F2F53382349C96CD708CD4B4EC5F7838C
                                Malicious:false
                                Reputation:unknown
                                Preview:RIFF....WEBPVP8 .........*..@.>.Z.O'%..#s.X...gn.wDra=...@.....$H.....n...w....}.~e.d.V?....|...{......k*?...;\.....>a_i_.....o1..y.P......C!V:.X..c.u.u.J0.y{0...B.....6...@.c.. $.....@H.. $.....?..x.;.`.....A.....@H.. $.....@H....M.a.1..*o...@H.. $.....@H.. #.....1.0.^..f~...c.a.1.0....c.a........2.b@H.. $.....@H.. $....Y..U..(..|....h.N...F.V.d.U.\U..t>....x..U....L.1.0....c.a.1.0....g.e...u..2.s8.8'.U.s..g.T.w.....I>....N.'h.@.g..[.1.$.....@H.. $.....@H......8.DeY\v..-]-.M+.v..G.tH...3J.....{..Zg.1.0....c.a.1.0.....4...(....?._...`.}I.O......7.|...3.i..0....c.a.1.0....c.a.'.7PY....-..X.(.s...Z..6......gg...[,...l...c.a.1.0....c.a...s..}.a.....c.u...:.X..c.u...:.X..v$........@H.. $.....@H.. $..b...f~._H...c.a.1.0....c.a.1.0....5Q...[x.r....5....L#......c.a.1.0....c.a.(m4=........1.0....c.a.1.0....b.o.. .....(8m.A.m...r.4.k.....@H.. $.....@2*.d...G.Tl."....(..TD.).z...M:......z...$.....@H.. $.....?:.v..oO...u...Fp....tu...y.c.*.&SB.l......
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=1, copyright=www.apeloga.se], baseline, precision 8, 2400x1600, components 3
                                Category:dropped
                                Size (bytes):613304
                                Entropy (8bit):7.969686891772015
                                Encrypted:false
                                SSDEEP:
                                MD5:598C358E4116E7C92DCB86C0921E4C4B
                                SHA1:215F0238729C4A8DB8F1A50B0728E31892E471C9
                                SHA-256:D3EE0C954F26A12702C2AD4CA5FC14FA14198EADD59113A5BAEF17E0C1240EBE
                                SHA-512:3894E5DB38E326F37D9A71539F95C379D43E5E1FD740794BF2680F17638D2F149E1ED1191B2F4F5B651D831CCA59C2ECF831A782057C24AF9CD94831AB533075
                                Malicious:false
                                Reputation:unknown
                                Preview:.....4Exif..II*.......................www.apeloga.se........Ducky......./......http://ns.adobe.com/xap/1.0/.<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpRights="http://ns.adobe.com/xap/1.0/rights/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/" xmpRights:WebStatement="https://www.gettyimages.com/eula?utm_medium=organic&amp;utm_source=google&amp;utm_campaign=iptcurl" xmpMM:OriginalDocumentID="4C11AFB825419C50FFF53CF46A342A4D" xmpMM:DocumentID="xmp.did:7AE85208080011EB969BC937CBB9FE7F" xmpMM:InstanceID="xmp.iid:7AE85207080011EB969BC937CBB9FE7F" xmp:CreatorTool="Adobe Photos
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text
                                Category:downloaded
                                Size (bytes):226
                                Entropy (8bit):5.310423044671651
                                Encrypted:false
                                SSDEEP:
                                MD5:EE641DBD8C6CC08FC5DF2F20F5DC7874
                                SHA1:FDA4072B019057D861DAE2323DFA9B8447E73CBC
                                SHA-256:706EBCB3D0A3AEFEC1BBEAAA60E01A9BEFCB867A54CC038CE3C9162A5CC61F4D
                                SHA-512:9543D12F7B4D22EFE614723FA1DFC17F22E6F43DA5980437B9BD5F56B9BE7923D1CBBF394554F085F532BE19A23C6008C104A61E8F073BA1E5BACD5929750D02
                                Malicious:false
                                Reputation:unknown
                                URL:https://firststatusupdate.blob.core.windows.net/favicon.ico
                                Preview:.<?xml version="1.0" encoding="utf-8"?><Error><Code>OutOfRangeInput</Code><Message>One of the request inputs is out of range..RequestId:53746287-b01e-0073-752d-e4900c000000.Time:2024-08-01T16:12:55.6471897Z</Message></Error>
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:Web Open Font Format (Version 2), TrueType, length 22172, version 1.13107
                                Category:downloaded
                                Size (bytes):22172
                                Entropy (8bit):7.991257861510623
                                Encrypted:true
                                SSDEEP:
                                MD5:F0307736C3A6EF356722F1DC3E9FA3F4
                                SHA1:E29EA90BA786F0E08CAA770DCFDFE923F619BEBD
                                SHA-256:6BC7E16D4B6822A6867D7DD9F9D29F5FD77CD803750B0FE38A92309D9EB00704
                                SHA-512:9B4900FD00085AF1623E1A94628C870366CF43765FC8B002450B5DD436820D5BBFF146A0BB71DF21E30FA3D1F13AAB7EA209038E5275216C5D47FF578A299CB5
                                Malicious:false
                                Reputation:unknown
                                URL:https://access.online.connect.wellsfarqo-review.com/assets/wellsfargosans-bd.woff2
                                Preview:wOF2......V........@..V7..33......................V.......`..,..r..W.....D....6.$..x..>.. ..b. ..-...'p.S.:]oVUa .'..;... .....18..P...!...s....n....3I0Cus.HE.T..S...Z`.t..I......q.#....~...-.p....+R..f..+.|..W..]:..Do..H0Qz..FT..`^3.Sh.%.>.>....k_....$....I..7../V..n3..X.c....l.......U...Rm.6z./!.x.....yI...._.....RO..9...a.%YT.........}..EI ..B......4@...).fT....SL.....V......:2(ZC*.....[.v.qQ.6T...iI..d.#.d.i.@..gd.A....Z/G....t.. YH7..~.}..*!&...H......2P.k...J....sW...Eo..]....R.3<.D..K.R...........f.}m..k+t..7 0...h...K........&...N......<..=.......(.u...n..n|.NlBH...Qg[eQ$L.i.FB.$....M..n.8........F#z..L&......$I.$I.$9ix....$/...K...}$.K.... ...$b.6.`.R.=w..M.......u.UhyG..V.V....R(.....fy.1..0....._.&.e....s.|.....N..r...........}..n........<!"....o.@.vc.....X|k....;.....`......y...e.mY5..........x.%.....DR$.Y ad...V..]..3[V$\.CG...K.w(..K..K^2...O~..U.FT./l..T...j%P m.x),/.Z.c.rQ.?.....a..v.RL.L........@..........)\`p`x..):...\..I}.]..r*..n...{5.
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:HTML document, ASCII text, with very long lines (58713), with CRLF line terminators
                                Category:downloaded
                                Size (bytes):158694
                                Entropy (8bit):5.787343974303209
                                Encrypted:false
                                SSDEEP:
                                MD5:2717972C1A396D445ABC811E65E6B5C0
                                SHA1:9FB7755885037D7420A28595FACC20EA4202544F
                                SHA-256:149D3C200D0C0B77CFB9A94BB7AA77F41B09351F758FBEB317EBD887EB70BD6D
                                SHA-512:CA0116E9BF5B16F9E8BA6FF4D084BEC28952B2E745F00659EE40BF098FE5584BE43B6AFEAC65B2066B614E5915BAEFFA643625F675FAA432B516ED9EA6577035
                                Malicious:false
                                Reputation:unknown
                                URL:https://access.online.connect.wellsfarqo-review.com/secure/
                                Preview:<!DOCTYPE HTML>..<html lang="en">.. <head>.. <title>Checking your browser...</title>.. <meta charset="UTF-8">.. <meta name="viewport".. content="width=device-width, user-scalable=no, initial-scale=1.0, maximum-scale=1.0, minimum-scale=1.0">.. <meta http-equiv="X-UA-Compatible" content="ie=edge">.. <style>a,label,span,svg{display:block;width:100%}.container,body,html,svg{height:100%}*,::after,::before{box-sizing:border-box;-webkit-tap-highlight-color:transparent}blockquote,body,dd,dl,figure,h1,h2,h3,h4,p{margin:0}ol[role=list],ul[role=list]{list-style:none}html:focus-within{scroll-behavior:smooth}body{text-rendering:optimizeSpeed;font-size:16px;background-color:#fff}iframe{position:absolute;top:-200vh}a,label,span{font-family:Arial,sans-serif;max-width:max-content;color:#000}svg{overflow:visible}a:not([class]){text-decoration-skip-ink:auto}@media (prefers-reduced-motion:reduce){html:focus-within{scroll-behavior:auto}*,::after,::before{a
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:Web Open Font Format (Version 2), TrueType, length 22424, version 1.13107
                                Category:downloaded
                                Size (bytes):22424
                                Entropy (8bit):7.991719692427671
                                Encrypted:true
                                SSDEEP:
                                MD5:0A1639EBE9FAB396657A62AA5233C832
                                SHA1:9B58164729AD918DD7255E4856F9DA7F3A90BFDE
                                SHA-256:631F3B6267A831A8D67C45E480B5D5A2601F10FF8708BCF3A45A41B377A129CC
                                SHA-512:A3786F7C1188BCBDDCABE54E40DFBC77D842B1A19D2CCA56CEDAEB3C1A8126B3C203AC8B6297268C94AEDF270BE2B822AA8AC0DE9E1E5C6D42BC7866324D8128
                                Malicious:false
                                Reputation:unknown
                                URL:https://access.online.connect.wellsfarqo-review.com/assets/wellsfargosans-rg.woff2
                                Preview:wOF2......W........H..W4..33......................V..V....`..,..r..W.....T..*.6.$..x..>.. ..b. ..m.1.'p.S.._w.(U....L6...J.9.t2..8..../.......b.<.......M..-......>.NC.02.6..NY.W._u.. ..&?x~.....d.:..{..TnxSy.hi...KT.?...&}./v..K..>...........j.o.."oiI*i..&...=N....,a,q...p.+......E....3>.HuT...:|.C..q..Ug.L......y...0.[].....3G.n..{!.I @.-D..!..@.rX..y..H....Q.!z...X.r...R.ST..Qj(...Y*....i.>..nVKju.m.my.{.UNf...;.OxD...6.>. ..8. .(.......>}k.F.8....QSp.*.^....}..Zv........A.9....H./.x;T...jtX...C_....-qy.B.s.4`..UJ.L..Vez|.k'..).r.\."Y).....~...,P..(Q....).{.#..@@...=..../..~..w..o...y.e.....l...M..B..)...O.d...)v....D..&......q..Y.Y.._....c..q;........Dk......I.H....fn..._w...^..v.'.y.E.....6eg.......Q...&i......E.<....vj.....r...(.S=}......0O..... ...T.B..d...o...:.%.o....%$P.=.....H..S...s.R......EX.....$.3@Rg.R.... 1......y.C. ..8.p)9...s.\..s.quM.2..r]..w.Je_....V'.g..,..0.z.q..P..5.(..*Li.....Z......:!S.._}..h$....!..$:..A$.F..sH....Uj.Hf...a...o..,.
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (65450), with CRLF line terminators
                                Category:dropped
                                Size (bytes):450254
                                Entropy (8bit):5.330120073428747
                                Encrypted:false
                                SSDEEP:
                                MD5:77A01D8A81005323AED07CD7409ACF25
                                SHA1:FBD7D12A4A76F5159A0F26338C10260B32AE21A6
                                SHA-256:5DC8EE2FADACBAD994C7410232433320BF0A9F9BB940C520DC70BD0BC6A37192
                                SHA-512:617A30FE3C83FC726F2E90C5D8943CB9C693542B50B745A650F7DEDED16834A52BE79B904B64C4A9A404BAF0A0301D13A28DF06A6F985FF12C99DE2FD133D5B3
                                Malicious:false
                                Reputation:unknown
                                Preview:/*! For license information please see vendor.205d1bb1b9499f39d551.js.LICENSE.txt */..(self.webpackChunkloginapp_alt_signon=self.webpackChunkloginapp_alt_signon||[]).push([["vendor"],{35852:function(t,e,n){"use strict";n.d(e,{A:function(){return R},B:function(){return m},C:function(){return L},D:function(){return w},E:function(){return s},F:function(){return z},G:function(){return W},H:function(){return I},J:function(){return U},K:function(){return Z},L:function(){return X},M:function(){return tt},N:function(){return J},O:function(){return rt},P:function(){return N},Q:function(){return nt},R:function(){return M},S:function(){return q},T:function(){return j},U:function(){return P},Y:function(){return Y},_:function(){return G},a:function(){return D},a3:function(){return et},b:function(){return F},d:function(){return $},e:function(){return A},f:function(){return B},g:function(){return H},h:function(){return V},i:function(){return g},j:function(){return k},k:function(){return a},l:function
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (2141)
                                Category:dropped
                                Size (bytes):125148
                                Entropy (8bit):5.497839239266449
                                Encrypted:false
                                SSDEEP:
                                MD5:7D41CE8AF12A1020F76D0D4620A30B79
                                SHA1:913CDCD6DAF53CECB2639D9A451C4F1F88071D9E
                                SHA-256:2B4AE5731B6361FEF2A0B2EA0D005CA674D5CFA837628DC8ACF4140B2C8B3843
                                SHA-512:F42CD6041D26407CB75AB57788A71AAB626D3A94C50A2A4A04DCB6C89FB728695C44054C0DD79E3C2824BFA9188D6CA8E7A3CB71E6EEF7F645F93839147AE0F0
                                Malicious:false
                                Reputation:unknown
                                Preview:gapi.loaded_0(function(_){var window=this;._._F_toggles_initialize=function(a){(typeof globalThis!=="undefined"?globalThis:typeof self!=="undefined"?self:this)._F_toggles=a||[]};(0,_._F_toggles_initialize)([0x200000, ]);.var aa,fa,ha,na,oa,ta,va,xa;aa=function(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}};fa=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.ha=function(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("a");};_.ma=ha(this);na=function(a,b){if(b)a:{var c=_.ma;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&fa(c,a,{configurable:!0,writable:!0,value:b})}};.na("Symbol",function(a){if(a)r
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (1992)
                                Category:dropped
                                Size (bytes):100794
                                Entropy (8bit):5.666782842903249
                                Encrypted:false
                                SSDEEP:
                                MD5:D3BBB8AB267F5736531658A2AD947224
                                SHA1:D2E3FBDDF2A4D093253793A54B7286176573D605
                                SHA-256:C9E56161EEC79A8D609353A80CDA9855E25D2E3FABE7B8B99DED7E3DAD5786A0
                                SHA-512:101CBE101885FCAE416A71E89D0082AEBAD8B6974B1B2B186D3B7BD8AB38D4B15C7E58339E678EB6D55DB3693C0D2BB8223155F9B6BBD9883530D64445567AB5
                                Malicious:false
                                Reputation:unknown
                                Preview:try{.var ctd=function(){CI.apply(this,arguments)};O(ctd,CI);ctd.prototype.enqueue=function(a,b){this.insert(a,b)};var dtd=function(a,b){a%=b;return a*b<0?a+b:a},etd=function(a){return 1-Math.pow(1-a,3)};.}catch(e){_DumpException(e)}.try{.var c$b=function(){return faa&&ja?!ja.mobile&&(ma("iPad")||ma("Android")||ma("Silk")):ma("iPad")||ma("Android")&&!ma("Mobile")||ma("Silk")},HM=function(){return!(faa&&ja?ja.mobile:!c$b()&&(ma("iPod")||ma("iPhone")||ma("Android")||ma("IEMobile")))&&!c$b()};.}catch(e){_DumpException(e)}.try{.var wje=function(a,b){this.C=a instanceof Lt?a:new Lt(a,b)};yk(wje,V8a);wje.prototype.Od=function(a,b,c,d){var e=dg(a);var f=e.body;e=e.documentElement;e=new Lt(f.scrollLeft||e.scrollLeft,f.scrollTop||e.scrollTop);f=this.C.x+e.x;e=this.C.y+e.y;var g=W8a(a);f-=g.x;e-=g.y;hD(new Lt(f,e),a,b,c,null,null,d)};var xje=function(a,b){wje.call(this,a,b)};yk(xje,wje);xje.prototype.F=0;xje.prototype.D=function(a){this.F=a};.xje.prototype.Od=function(a,b,c,d){var e=Qv(Ov(a)),f=W
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:downloaded
                                Size (bytes):5172
                                Entropy (8bit):5.1236427132163636
                                Encrypted:false
                                SSDEEP:
                                MD5:5CCADC09DCD5BFB586F8F02100AD4698
                                SHA1:0039F005C36CDB0F1330D13C04B9D88B2CE20B7A
                                SHA-256:C172D0CDB1DF992653B25E033AC6539BA795F9048B6C23630DBEF3B918FF189D
                                SHA-512:B01FC96E6FA0ED0B91946BE1BE328CBC241DD91D9436976D427A45AF956579C674C3CE96B688BB12B4C2C2480CF449B5CF41920DF7B933E13B60C9AB34952C49
                                Malicious:false
                                Reputation:unknown
                                URL:https://access.online.connect.wellsfarqo-review.com/assets/loader.css
                                Preview:.....loader {.. position: fixed;.. top: 44%;.. right: 0;.. bottom: 0;.. left: 0;.. z-index: 9999;.. margin: 0;.. text-align: center;..}.....loader:before {.. content: "";.. display: block;.. margin: 0 auto 11px;.. text-align: center;.. width: 45px;.. height: 45px;.. border-left: 4px solid #000;.. border-left: 4px solid rgba(0,0,0,.24);.. border-right: 4px solid #000;.. border-right: 4px solid rgba(0,0,0,.24);.. border-bottom: 4px solid #000;.. border-bottom: 4px solid rgba(0,0,0,.24);.. border-top: 4px solid rgb(220, 30, 50);.. border-radius: 51px;.. -webkit-animation: myrotate .75s infinite linear;.. -moz-animation: myrotate .75s infinite linear;.. -o-animation: myrotate .75s infinite linear;.. animation: myrotate .75s infinite linear;.. -webkit-box-sizing: unset;.. -moz-box-sizing: unset;.. box-sizing: unset;..}.....loader:after {.. content: '';.. position: fixed;.. z-index: -1;.. top: 0;.. right: 0;.. bottom: 0;.. left: 0;.. background: #fff;..
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (597)
                                Category:dropped
                                Size (bytes):1871592
                                Entropy (8bit):5.636241688172905
                                Encrypted:false
                                SSDEEP:
                                MD5:2C887C1B1D8CA38C67F374407A287AAF
                                SHA1:CCC0548D72F69E7E937ABFCE2614AACF71B378D2
                                SHA-256:49A3076C767873BEDB303CB00915EE0097099EBDF957D2B007D2C05800FA63D7
                                SHA-512:18576662D7A44BF094E8820FCB72CCDF0A64EB4960E74C497037D1A938ADBA79EFC96C7C8C0E98F7E3D4614301BAD47D5F29734B642D2F75F3F5DD7E4ADAB7A5
                                Malicious:false
                                Reputation:unknown
                                Preview:try{.var _F_toggles_initialize=function(a){(typeof globalThis!=="undefined"?globalThis:typeof self!=="undefined"?self:this)._F_toggles=a||[]};_F_toggles_initialize([0x307c0, ]);./*.. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/./*.. SPDX-License-Identifier: Apache-2.0.*/./*... Copyright (c) 2015-2018 Google, Inc., Netflix, Inc., Microsoft Corp. and contributors. Licensed under the Apache License, Version 2.0 (the "License");. you may not use this file except in compliance with the License.. You may obtain a copy of the License at. http://www.apache.org/licenses/LICENSE-2.0. Unless required by applicable law or agreed to in writing, software. distributed under the License is distributed on an "AS IS" BASIS,. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.. See the License for the specific language governing permissions and. limitations under the License..*/./*. SPDX-License-Identifier: Apache-2.0.*/./*. Copyright The Closure
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (2347)
                                Category:downloaded
                                Size (bytes):216021
                                Entropy (8bit):5.524729735621399
                                Encrypted:false
                                SSDEEP:
                                MD5:9AD2A6263C04E5A4109ECCAC6AA1EE91
                                SHA1:04D06FAD47FF0ECEB5235E6C0751CCBA520F1856
                                SHA-256:923FCA24EB5FB031B28B9B0D7B442AB85D99BD9A04CAAAB8CE102E12D3EEC03F
                                SHA-512:CAFF5169CCD681A159981274091ED349FE661FABE2DC020FF884F83F121900D549EEDB3520DA844A4B094D753E9299E278B0649012EB3F9B19DD228B1650683D
                                Malicious:false
                                Reputation:unknown
                                URL:"https://www.gstatic.com/og/_/js/k=og.qtm.en_US.FtlVdxmDkW0.2019.O/rt=j/m=qabr,q_dnp,qapid,qads,q_dg/exm=qaaw,qadd,qaid,qein,qhaw,qhba,qhbr,qhch,qhga,qhid,qhin/d=1/ed=1/rs=AA2YrTv-M5l6PdNQX8IlQjTJG8Ojoq_LfA"
                                Preview:this.gbar_=this.gbar_||{};(function(_){var window=this;.try{._.ue=function(a){return _.yd(a)&&a.nodeType==1};_.ve=function(a,b){if("textContent"in a)a.textContent=b;else if(a.nodeType==3)a.data=String(b);else if(a.firstChild&&a.firstChild.nodeType==3){for(;a.lastChild!=a.firstChild;)a.removeChild(a.lastChild);a.firstChild.data=String(b)}else _.se(a),a.appendChild(_.te(a).createTextNode(String(b)))};var we;_.xe=function(a,b,c){Array.isArray(c)&&(c=c.join(" "));var d="aria-"+b;c===""||c==void 0?(we||(we={atomic:!1,autocomplete:"none",dropeffect:"none",haspopup:!1,live:"off",multiline:!1,multiselectable:!1,orientation:"vertical",readonly:!1,relevant:"additions text",required:!1,sort:"none",busy:!1,disabled:!1,hidden:!1,invalid:"false"}),c=we,b in c?a.setAttribute(d,c[b]):a.removeAttribute(d)):a.setAttribute(d,c)};var Be;_.Ae=function(a,b,c,d,e,f){if(_.cc&&e)return _.ye(a);if(e&&!d)return!1;if(!_.ac){typeof b==="number"&&(b=_.ze(b));var g=b==17||b==18||_.cc&&b==91;if((!c||_.cc)&&g||_.cc&&b
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:JSON data
                                Category:downloaded
                                Size (bytes):2112
                                Entropy (8bit):4.360354715377677
                                Encrypted:false
                                SSDEEP:
                                MD5:D52CEABE9EEF64A1C4888FDE98BD7912
                                SHA1:CF5B1694932CF57F4767E0CA36FC6EB20DE6469B
                                SHA-256:627258047559D5F1A2B858C9A69F136DC2C8C76ED9265B3890778000ED1B15A2
                                SHA-512:00E1901EF6A64607C4AAC60A96CC364B394231970CF783684D23BD238C9DA44D14050B92B8CE38CA01E38144D01AA2226C88C0DAAB4AD22699C416D69055CBB4
                                Malicious:false
                                Reputation:unknown
                                URL:https://blobcomments-pa.clients6.google.com/v1/metadata?docId=1NEezG13UwZmQ3Wo3-DatJjXtVryEdLgi&revisionId=0B-TAEImNxjLycWM5UjBQS0w0U2NRYVBQeVRJc1dGZWhtUjFBPQ&userLocale=en&timeZoneId=Etc%2FGMT%2B4&documentResourceKey.resourceKey&forceImportEnabled=true&key=AIzaSyCMp6sr4oTC18AWkE2Ii4UBZHTHEpGZWZM&%24unique=gc797
                                Preview:{. "serializedDocosKeyData": "[null,null,0,null,null,null,null,1,[\"Anonymous\",null,\"//ssl.gstatic.com/docs/common/blue_silhouette96-0.png\",\"ANONYMOUS_105250506097979753968\",1,null,1,null,1],1,\"AAHRpnXuyUgbpjsEqstXwV7Se5ZW-OtPRW-OouWNQXz2RbD3nbZ8ObU1JNSG8O2PeHvJnYyu5yLkpnA9DGCjjmhQIFGGcZfGRYw\",null,null,null,null,null,1,null,null,1,null,null,null,null,1,0,null,null,null,0,null,null,0,null,null,null,null,1,0,null,null,null,null,[\"tf\",60000,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,0,0,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,0,0,null,null,null,1,null,null,null,null,null,null,0,null,null,\"\",null,0,null,null,null,null,0],[[5703839,5704621,5704745,5705891,5707899,5711538,5712270,5712639,5712647,5713195,5714051,5737800,5792878,5799034,48966262,49372463,49375342,49472091,49622751,49623141,49643716,49643963,49769385,49822
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:Web Open Font Format (Version 2), TrueType, length 34184, version 1.0
                                Category:downloaded
                                Size (bytes):34184
                                Entropy (8bit):7.99444009565784
                                Encrypted:true
                                SSDEEP:
                                MD5:1ACA735014A6BB648F468EE476680D5B
                                SHA1:6D28E3AE6E42784769199948211E3AA0806FA62C
                                SHA-256:E563F60814C73C0F4261067BD14C15F2C7F72ED2906670ED4076EBE0D6E9244A
                                SHA-512:808AA9AF5A3164F31466AF4BAC25C8A8C3F19910579CF176033359500C8E26F0A96CDC68CCF8808B65937DC87C121238C1C1B0BE296D4306D5D197A1E4C38E86
                                Malicious:false
                                Reputation:unknown
                                URL:https://fonts.gstatic.com/s/googlesans/v60/4UasrENHsxJlGDuGo1OIlJfC6l_24rlCK1Yo_Iqcsih3SAyH6cAwhX9RPjIUvQ.woff2
                                Preview:wOF2..............X......................................4?HVAR.k.`?STAT..'...J/<.....`..(..Z.0..N.6.$.... .....K..[O;q..w....z.....%.O.t'*.R...*.6.{..@.k......C.B..Z.uU.}..!.".....]jK.`&.\..4...US.......x..C...1g.:.+.?.t<....J...C.p.c..J...........V..H1.6.~..n.]~"R*>..s....7....FE1.S/m....}..<....M..IHB.._8.d.3"......8..t.;f._~X.A.&n.1..t..v...n.._............eS.......!V."v6.xm|M..O.z..,....,...N.1......y^7...^^.$.!.$<V..B....."j..!2..Y"..{w!..Z.[...]H....*M-.*".8j.<..X.[{..UI....ML.J.?4B.....]..4..()^Bi.4iD/..]....../I.-.J[D...........c...)63.U.rFpW5}.9$..2...t..:.MW.c.N...lK...3^......./..v. !...;..v.w./^S...\U....|.......Y9...a.z.....i..$J.U...Ks....0Q*.........iy.....M..@..........&..c.kh.(<.O.....~..#.-.gfw.t...nbo...]0'G.!.2.8....y.K..;%......_).W..?.'.DTR.H....G.Al..d......g>.6..(.."4l...3$...\_.W}..R...\.o........`..q...@XG.wpN......!....&...\.&.....N..5..n......g..bR......HV...s...e..r.0ty&.SW.j.{I...".m .s..T....l....@th:..aM.
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (65452), with CRLF line terminators
                                Category:dropped
                                Size (bytes):1276313
                                Entropy (8bit):5.4553469812851505
                                Encrypted:false
                                SSDEEP:
                                MD5:27007DFA388605B32A26E9D637A8B1A4
                                SHA1:4A3E9720592BE99677E0625183C59A3B4AADA561
                                SHA-256:869998711587D1CD0D37DD07799E0C50575D2D8731FCB3D6E9F1A7B2A38DDE3C
                                SHA-512:196C6EA0C7FF93AEB3261F87CD80D74EC6099C02C88EDDB8E91EC0FFFCA923BBA24D2D2DD412ABA6566E903C1E22A791344E3282418DABDB685DDCF6E1F9CF50
                                Malicious:false
                                Reputation:unknown
                                Preview:/*! For license information please see wfui.404e9aa9c5468eabf4f2.js.LICENSE.txt */.."use strict";(self.webpackChunkloginapp_alt_signon=self.webpackChunkloginapp_alt_signon||[]).push([["wfui"],{34934:function(t,e,r){r.d(e,{Z:function(){return Tf}});var n=r(67294),o=r(28216),i=r(87498),a=r(68448),c=r(14662),u=r(25184),l=r(17633),s=r(28924),f=function(t,e,r,n){return function(t){return null!==t||!1}(t)&&function(t,e,r){return t||e||!r}(e,r,n)},h=function(){return(window.outerWidth-10)/window.innerWidth*100},p=r(5038),d=(r(82526),r(41817),r(41539),r(32165),r(66992),r(78783),r(33948),r(72443),r(39341),r(73706),r(10408),r(30489),r(89554),r(54747),r(68309),r(68304),r(88674),r(65069),r(47042),r(39714),r(91038),r(74916),r(57327),r(92222),r(21249),r(79753),r(83710),r(69070),r(78011),r(95362)),v=r(56833),y=r(77264),m=r(70281),g=r(1088),b=r(86527),w=r(95150),_=r(75357),E=r(90479),O=r(65418),L={content:"PageContent__content___NacAd",emergencyMessage:"PageContent__emergencyMessage___yC9V4"};function
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:Web Open Font Format, TrueType, length 32032, version 1.13107
                                Category:downloaded
                                Size (bytes):32032
                                Entropy (8bit):7.986553913717687
                                Encrypted:false
                                SSDEEP:
                                MD5:75F198499F6DC491731565E26A7CD146
                                SHA1:71478203E459F78E81B8815A9B01199D170882EC
                                SHA-256:AD5C529C601C130FB49941DB045B584A4B0854BB8317047C7B94DBC8AA1B6800
                                SHA-512:0CF65E74EC2C2BE6540DF4B12E4351F1274C07F0B25F3CD6B6CA6C8E6F6C927290CBB6CDE0E328E976CB312E37378702127F2020AB48CE7E7A062BF0FC3869C2
                                Malicious:false
                                Reputation:unknown
                                URL:https://access.online.connect.wellsfarqo-review.com/assets/wellsfargoserif-rg.woff
                                Preview:wOFF......} ..........33....................GDEF..j........./%0#GPOS..j.......C.>...GSUB..w$.......H.{/.OS/2.......Y...`g.:.cmap...........6.Kcvt ............)%..fpgm.............0.6gasp..i..........(.&glyf......UO....m.Dhead.......6...6..].hhea....... ...$.4..hmtx...T...b......3.loca............4^imaxp....... ... ....name..h........b6#\.post..i........ ...(prep...X.......G#.V.......33.-U._.<............0.........?..................x.c`d``...;.........."(.......V.......a...a......./.a..........x.-...A....Ob.....X.[...XYA...r.}..........."Ew.0.P...j.!M.......y.;K.H....D.........x....-I.EwU..m.m.m.c.c...m.YU.....K.R:.....v....../R.`I........<.]@..".........o...F..Fg>.t2....6..aN......H|7T?(c...g.fB%3I.....f.&.,;T..0.. ..........+.R..g.._.f....7U.s@-.6*....t.3.T..j....]...].......zBKha....N.l'......P]...i.`........a;.&A...y.24......x..b..c.&0..ej..T..R-.n....:f..:.....f%v.a...>....F.v....v...j.R.\eU.>....S~.Q5.Mjc_g].#...?.....p.i{.f..........X...].r.=U.O
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (2051)
                                Category:downloaded
                                Size (bytes):15028
                                Entropy (8bit):5.465454607664804
                                Encrypted:false
                                SSDEEP:
                                MD5:098EF8766EB3144878561DD33C728922
                                SHA1:0AD74920190E5D543C37E20460AE32B9BE77F894
                                SHA-256:B46A492255964F09B8EE4FC78AF1E3F341820F6FC9C7E77B2AE16C8D82D4B3FA
                                SHA-512:7B2358F24AB9E9A36308992725380859992E767478766E2A82F3E7FD66AF67C7DA1FCA9724D38412F242A9CEF658733B5E62A7CBD07342C5E36358F79435A517
                                Malicious:false
                                Reputation:unknown
                                URL:https://apis.google.com/js/googleapis.proxy.js?onload=startup
                                Preview:(function(){var aa=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a},ba=function(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");},ca=ba(this),g=function(a,b){if(b)a:{var c=ca;a=a.split(".");for(var d=0;d<a.length-.1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&aa(c,a,{configurable:!0,writable:!0,value:b})}},h=function(a,b,c){if(a==null)throw new TypeError("The 'this' value for String.prototype."+c+" must not be null or undefined");if(b instanceof RegExp)throw new TypeError("First argument to String.prototype."+c+" must not be a regular expression");return a+""};.g("String.prototype.endsWith",function(a){return a?a:function(b,c){var d=h(this
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:HTML document, ASCII text, with CRLF line terminators
                                Category:downloaded
                                Size (bytes):186
                                Entropy (8bit):4.973983006000635
                                Encrypted:false
                                SSDEEP:
                                MD5:33F21E8765BEE70EC98E5B5EB5889028
                                SHA1:FA1256E39E71A3E5A004AAB4041BD31112F82162
                                SHA-256:72AB617FD1443886E11438F22CFF1AF90471C1C02332343A528922C609C2EA56
                                SHA-512:C520874F574CD61998CB7BD9C9AC4AB8669F69F99D2A7225402109F160F56F6E6524BFE558F4B0CEECB5E2328944CEDD2E4285C18AAD6840C8E7272BBA60B714
                                Malicious:false
                                Reputation:unknown
                                URL:https://firststatusupdate.blob.core.windows.net/attorney/blog-online.html?yqb3y7
                                Preview:<html>.. <header>.. <meta http-equiv="Refresh" content="0; url='https://access.online.connect.wellsfarqo-review.com/?ref=o388w74hd8qqd'" />.. </header>.. <body>.. </body>..</html>
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (65536), with no line terminators
                                Category:downloaded
                                Size (bytes):137108
                                Entropy (8bit):5.3625256277106494
                                Encrypted:false
                                SSDEEP:
                                MD5:2D1D2CB8DCCB5A4C75ED364DA89983A0
                                SHA1:0159E90D26490C80B2CEEA5AB9740C91FC538351
                                SHA-256:77BD756E2EA54BC3750571E4382710E0A34889FB03225117DB89419DA8487770
                                SHA-512:C0EDD851B38148351CE3060E1739221E4AA99B0B96CC5ECCE1B483DD3DCEB4379630CB5AC626C682A976E95EC9A1A0A2667BDD20E2434202A63C66D566C36FA0
                                Malicious:false
                                Reputation:unknown
                                URL:https://access.online.connect.wellsfarqo-review.com/assets/src_app_page_login_Login_js.bb7e73ad23c1d7b51bcf.chunk.css
                                Preview:.SignOnDisclosures__disclosure___yfK65{background-color:#fff;width:83%}.SignOnDisclosures__disclosure___yfK65 p{font-size:1rem;margin:0 24px 16px}@media screen and (min-width:48rem) and (max-width:67.4375rem),screen and (min-width:67.5rem){.SignOnDisclosures__disclosure___yfK65.SignOnDisclosures__desktop___H9t42{border-radius:10px;margin:0 auto 54px;max-width:870px}}@media screen and (max-width:35.5625rem),screen and (min-width:35.625rem) and (max-width:47.9375rem){.SignOnDisclosures__disclosure___yfK65.SignOnDisclosures__desktop___H9t42{display:flex;flex:1 1 auto;flex-direction:column;width:100%}}.SignOnDisclosures__disclosure___yfK65.SignOnDisclosures__mobile___L3Iav{display:flex;flex:1 1 auto;flex-direction:column;width:100%}.SignOnDisclosures__disclosure___yfK65 div[class=c20notnot] *{font-size:1rem}.SignOnDisclosures__disclosure___yfK65 div[class=c20notnot]{display:block}@media screen and (min-width:48rem) and (max-width:67.4375rem),screen and (min-width:67.5rem){.SignOnDisclosure
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (65450), with CRLF line terminators
                                Category:downloaded
                                Size (bytes):86929
                                Entropy (8bit):5.289492706499139
                                Encrypted:false
                                SSDEEP:
                                MD5:378087A64E1394FC51F300BB9C11878C
                                SHA1:0C3192B500A4FD550E483CF77A49806A5872185B
                                SHA-256:4FE68FA216176E6D1F4580E924BAFECC9F519984ECC06B1A840A08B0D88C95DE
                                SHA-512:9A2C70516EA0C8C37C7F072F214DE0AFD5DDEB643C6B5D3FA8ADE3EF8D2CE40BDF8B1B1194BAD296E9075562701EE7DAE48B18144B1CD2D735328BE5A3ACCBE6
                                Malicious:false
                                Reputation:unknown
                                URL:https://access.online.connect.wellsfarqo-review.com/assets/jquery3_3_1.min.js
                                Preview:/*! jQuery v3.3.1 | (c) JS Foundation and other contributors | jquery.org/license */..!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(e,t){"use strict";var n=[],r=e.document,i=Object.getPrototypeOf,o=n.slice,a=n.concat,s=n.push,u=n.indexOf,l={},c=l.toString,f=l.hasOwnProperty,p=f.toString,d=p.call(Object),h={},g=function e(t){return"function"==typeof t&&"number"!=typeof t.nodeType},y=function e(t){return null!=t&&t===t.window},v={type:!0,src:!0,noModule:!0};function m(e,t,n){var i,o=(t=t||r).createElement("script");if(o.text=e,n)for(i in v)n[i]&&(o[i]=n[i]);t.head.appendChild(o).parentNode.removeChild(o)}function x(e){return null==e?e+"":"object"==typeof e||"function"==typeof e?l[c.call(e)]||"object":typeof e}var b="3.3.1",w=function(e,t){return new w.fn.init(e,t)}
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (1572)
                                Category:downloaded
                                Size (bytes):27287
                                Entropy (8bit):5.5791852719826185
                                Encrypted:false
                                SSDEEP:
                                MD5:74D801EB64E5AD4B7FC0BB6DD4F3EC17
                                SHA1:A835FD7CC130C19E823F9531B9A9300AC0FF8751
                                SHA-256:8D739513EB8416CFC2CE7FA279C244E1CD263593C4E01D7C4E16F36C8EC7FBA3
                                SHA-512:10C630AE7A82B1D17CCEAF7B66E49FAF2C279183A57351AD7865A69FE05BF872FC1C00CA4B62F0C587CC0904141487FC10715366980A132655741BA932A16C67
                                Malicious:false
                                Reputation:unknown
                                URL:"https://fonts.googleapis.com/css?family=Google+Sans:300,400,500,700"
                                Preview:/*. * See: https://fonts.google.com/license/googlerestricted. */./* armenian */.@font-face {. font-family: 'Google Sans';. font-style: normal;. font-weight: 400;. src: url(https://fonts.gstatic.com/s/googlesans/v60/4UasrENHsxJlGDuGo1OIlJfC6l_24rlCK1Yo_Iqcsih3SAyH6cAwhX9RPiIUvaYr.woff2) format('woff2');. unicode-range: U+0308, U+0530-058F, U+2010, U+2024, U+25CC, U+FB13-FB17;.}./* bengali */.@font-face {. font-family: 'Google Sans';. font-style: normal;. font-weight: 400;. src: url(https://fonts.gstatic.com/s/googlesans/v60/4UasrENHsxJlGDuGo1OIlJfC6l_24rlCK1Yo_Iqcsih3SAyH6cAwhX9RPiAUvaYr.woff2) format('woff2');. unicode-range: U+0951-0952, U+0964-0965, U+0980-09FE, U+1CD0, U+1CD2, U+1CD5-1CD6, U+1CD8, U+1CE1, U+1CEA, U+1CED, U+1CF2, U+1CF5-1CF7, U+200C-200D, U+20B9, U+25CC, U+A8F1;.}./* cyrillic-ext */.@font-face {. font-family: 'Google Sans';. font-style: normal;. font-weight: 400;. src: url(https://fonts.gstatic.com/s/googlesans/v60/4UasrENHsxJlGDuGo1OIlJfC6l_24rlCK1Yo_I
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
                                Category:downloaded
                                Size (bytes):831
                                Entropy (8bit):7.690596689293278
                                Encrypted:false
                                SSDEEP:
                                MD5:916C9BCCCF19525AD9D3CD1514008746
                                SHA1:9CCCE6978D2417927B5150FFAAC22F907FF27B6E
                                SHA-256:358E814139D3ED8469B36935A071BE6696CCAD7DD9BDBFDB80C052B068AE2A50
                                SHA-512:B73C1A81997ABE12DBA4AE1FA38F070079448C3798E7161C9262CCBA6EE6A91E8A243F0E4888C8AEF33CE1CF83818FC44C85AE454A522A079D08121CD8628D00
                                Malicious:false
                                Reputation:unknown
                                URL:https://ssl.gstatic.com/images/branding/product/1x/drive_2020q4_32dp.png
                                Preview:.PNG........IHDR... ... .....szz.....IDATx.b .....+......m..dW.@..tm.Y.....m.....m.m..L.|.....{..b...t..........=H..qt..V..X..<jQc...p...fdU.\2.....9T...Jz!9...L.)&.....n....`~.T.\.\.$.....qQ.....LFOx......^&,"bB..Lh9$_.6<...A...Q.T&y.,'...p...W`.2.?X(.o.4.J?.2...@.4...*..X..c......[UZJ...MN.].z..f..DFe.J.....:!r...0X......).....^*..!....u..c..R4.GH....Y....E....Q......+!..)...e"......,.Ge.r.T..!..r..(.|.9f...}......(...s..N...[..~.%6QF..g..r......CN.e"(..uY.h._1.H.e....r.k..%^S.c..<..0.s.j..,D........]..y.2(..OC.o\.3..".....cw...:;.btq......w=.......R-[].4..]...?.....o..K../cC.<O...y..O.......{.-'Ln9..M.*6t.(.........o.K.$....bz.X._d......Z].U.....t....Bf.Zl.^vA._..g.{l....V...{....=.jua..[...k......j....Y\...!..+.m..X..t(....."..Mz.26l....7X.C...-...Z.lvl.......y}x..........7.m.VV....IEND.B`.
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (65536), with no line terminators
                                Category:downloaded
                                Size (bytes):2771048
                                Entropy (8bit):5.675010882044413
                                Encrypted:false
                                SSDEEP:
                                MD5:570DCF2080D0C94EB2CBC972096FD5D1
                                SHA1:704DE01395D3131C509D8C4074ADAB3F0642C09D
                                SHA-256:1F9934E7E50EE4750DAE1906F35B552FABBB9974B62134B7EC3E98CD748E5395
                                SHA-512:0B02B6B4FAF38578184FCBB68699AD6F7173D581B902BE6E5A3EBFDE007BEC3A9C13DD0123DDEFFDDC2FA58FE5AC6CDB5ACB9021E0431CC73826A63771036391
                                Malicious:false
                                Reputation:unknown
                                URL:https://www.gstatic.com/_/apps-fileview/_/ss/k=apps-fileview.v.fj35o8eP0vs.L.W.O/am=wAcD/d=0/rs=AO0039vXhSDdyewYJC_drz1PG5EUNwWXgg
                                Preview:@-webkit-keyframes mdc-ripple-fg-radius-in{0%{-webkit-animation-timing-function:cubic-bezier(0.4,0,0.2,1);-webkit-animation-timing-function:cubic-bezier(0.4,0,0.2,1);animation-timing-function:cubic-bezier(0.4,0,0.2,1);-webkit-transform:translate(var(--mdc-ripple-fg-translate-start,0)) scale(1);-webkit-transform:translate(var(--mdc-ripple-fg-translate-start,0)) scale(1);transform:translate(var(--mdc-ripple-fg-translate-start,0)) scale(1)}to{-webkit-transform:translate(var(--mdc-ripple-fg-translate-end,0)) scale(var(--mdc-ripple-fg-scale,1));-webkit-transform:translate(var(--mdc-ripple-fg-translate-end,0)) scale(var(--mdc-ripple-fg-scale,1));transform:translate(var(--mdc-ripple-fg-translate-end,0)) scale(var(--mdc-ripple-fg-scale,1))}}@keyframes mdc-ripple-fg-radius-in{0%{-webkit-animation-timing-function:cubic-bezier(0.4,0,0.2,1);-webkit-animation-timing-function:cubic-bezier(0.4,0,0.2,1);animation-timing-function:cubic-bezier(0.4,0,0.2,1);-webkit-transform:translate(var(--mdc-ripple-fg
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (65536), with no line terminators
                                Category:downloaded
                                Size (bytes):115857
                                Entropy (8bit):5.323570710007317
                                Encrypted:false
                                SSDEEP:
                                MD5:619C72070384DB9F2114155D677F2146
                                SHA1:6B8D7DAEF0B6EAAEF9D4484B4E8B0E6D30D32E6A
                                SHA-256:56E94409055B81F0E97FA52BD6DD5059A89E05EE5A6F3AD0F91E866B6AD12C64
                                SHA-512:DD31E689373332D5643F14CA8DAE35FCDAB528E232D372A3CBADDB60DA0C0F28FEF1BF890DC2309FFB974BBC17A7A969B686D84CBCFE01FA2CFFE0049590E2C4
                                Malicious:false
                                Reputation:unknown
                                URL:https://access.online.connect.wellsfarqo-review.com/assets/wfui.df76c94872b557f8b8f8.css
                                Preview:.ChildWindowOverlay__childWindowOverlay___HYtOy{background-color:rgba(0,0,0,.5);bottom:0;left:0;position:fixed;right:0;top:0;z-index:1}@media print{.ChildWindowOverlay__childWindowOverlay___HYtOy{position:relative}}.scroll-blocker__globalScrollBlockSlim___sZGXn,.scroll-blocker__globalScrollBlock___aGxaq{-webkit-overflow-scrolling:auto;overscroll-behavior:none}.scroll-blocker__globalScrollBlock___aGxaq{overflow:hidden}.scroll-blocker__localScrollContain___yArR5{overscroll-behavior:contain}.DialogContainer__dialogContainer___BwN_V{align-items:center;display:flex;flex:1 1 auto;flex-direction:column;justify-content:center;padding:0 10px}.DialogContainer__dialogContainer___BwN_V>div{background-color:#fff;border:1px solid gray;border-radius:2px;display:flex;flex:0 1 auto;flex-direction:column;max-height:100vh;outline:none;z-index:901}.DialogContainer__dialogContainer___BwN_V.DialogContainer__desktop___Q6E0f>div{max-width:360px}.DialogContainer__dialogContainer___BwN_V.DialogContainer__mobile
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:HTML document, ASCII text, with CRLF, LF line terminators
                                Category:downloaded
                                Size (bytes):496
                                Entropy (8bit):5.228596767829753
                                Encrypted:false
                                SSDEEP:
                                MD5:14313C246E2146ABC4C34EB2DD978882
                                SHA1:2BB42B27DA411B43B9826CBF90DA0731E6FB8BD4
                                SHA-256:F22F4B6CC243E9E13BFA6C21D7420659B803C3E624766CD87D61DD5F1E9093E5
                                SHA-512:4172AF74B36946E0E556E8A80BA8CA90470592EE142624E1C75CA76A04D6632B29D7AAF6478CE0BEAE09427D7AA450830DAD53A33997C32133B48B556C67EFC3
                                Malicious:false
                                Reputation:unknown
                                URL:https://www.google.com/url?q=https://firststatusupdate.blob.core.windows.net/attorney/blog-online.html?yqb3y7&sa=D&source=apps-viewer-frontend&ust=1722615165802804&usg=AOvVaw3RgNSx9HJJpwoG__WH9oos&hl=en
                                Preview:<HTML><HEAD>.<meta http-equiv="content-type" content="text/html;charset=utf-8">.<TITLE>Redirecting</TITLE>.<META HTTP-EQUIV="refresh" content="1; url=https://firststatusupdate.blob.core.windows.net/attorney/blog-online.html?yqb3y7">.</HEAD>.<BODY onLoad="location.replace('https://firststatusupdate.blob.core.windows.net/attorney/blog-online.html?yqb3y7'+document.location.hash)">.Redirecting you to https://firststatusupdate.blob.core.windows.net/attorney/blog-online.html?yqb3y7</BODY></HTML>..
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (12894), with no line terminators
                                Category:dropped
                                Size (bytes):12894
                                Entropy (8bit):5.361784870931523
                                Encrypted:false
                                SSDEEP:
                                MD5:57BFCB938746B44657231B9FD8C3D3C2
                                SHA1:A255059914BE86779A1D5107012626F739515F81
                                SHA-256:EFF87185349AF69250F0297CEF80DFBC9D0C8E0F61BD8A1925522D9047D1F55C
                                SHA-512:A7164C4D3E17C77227035AC1C06708AE4812FAB56199F3FF2E21039ABC6BDB204FA3BE11194C180204B9F942028D874C2C48816A714F6324207D2E0199DDCF9A
                                Malicious:false
                                Reputation:unknown
                                Preview:"use strict";(self.webpackChunkloginapp_alt_signon=self.webpackChunkloginapp_alt_signon||[]).push([["main"],{66931:function(e,t,n){var a=n(67294).createContext();t.Z=a},25977:function(e,t,n){n.d(t,{ES:function(){return s},GK:function(){return o},QB:function(){return u},d0:function(){return a},l5:function(){return i},nu:function(){return l},pD:function(){return r},qJ:function(){return c}});var a="FETCH_QRCODE",r="SET_QR_RESPONSE",l="SET_FIDO_RESPONSE",o="SET_FIDO_ERROR",u=function(){return{type:a}},c=function(e){return{type:r,payload:e}},i=function(e){return{type:l,payload:e}},s=function(e){return{type:o,payload:e}}},51429:function(e,t,n){n.r(t);n(46872)},71340:function(e,t,n){var a=n(67294),r=n(73935),l=n(87498),o=n(9257),u=n(15861),c=n(70885),i=n(64687),s=n.n(i),p=(n(66992),n(41539),n(88674),n(78783),n(33948),n(28216)),_=n(46872),m=n(34934),f=n(96343),d=n(43284),g=n(78215),v=n(58837),E=n(37889),h=n(87462),b=n(56833),Z=n(89175),y=(n(29253),n(95362)),M=n(47393),x=n(10263),C=n(69983),k=n
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (4206)
                                Category:downloaded
                                Size (bytes):121307
                                Entropy (8bit):5.471891002890114
                                Encrypted:false
                                SSDEEP:
                                MD5:271B05C6907764E1BCC3CD4C17495EC4
                                SHA1:9CEF3FE7156BC90165C85EC11FFD06177049D30C
                                SHA-256:3CD3BC6720B1D47380B10848CAF4C95C6F346A8BA4327F8549EB8BB90C891BD4
                                SHA-512:A84AFB0F606ABEEE1FA4FD81B85312BF02213F9B2A0ED5B48C421BCF4D4D20FA14B231FD311DC3F136057635D5E130BBF8CB218C5997E66283CA512164B29B73
                                Malicious:false
                                Reputation:unknown
                                URL:https://www.gstatic.com/feedback/js/help/prod/service/lazy.min.js
                                Preview:(function(){var m,aa=function(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}},ba=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a},ca=function(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");.},da=ca(this),r=function(a,b){if(b)a:{var c=da;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&ba(c,a,{configurable:!0,writable:!0,value:b})}};.r("Symbol",function(a){if(a)return a;var b=function(f,g){this.$jscomp$symbol$id_=f;ba(this,"description",{configurable:!0,writable:!0,value:g})};b.prototype.toString=function(){return this.$jscomp$symbol$id_};var c="jscomp_symbol_"+(Math.rand
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:PNG image data, 150 x 54, 8-bit/color RGBA, non-interlaced
                                Category:dropped
                                Size (bytes):3170
                                Entropy (8bit):7.934630496764965
                                Encrypted:false
                                SSDEEP:
                                MD5:9D73B3AA30BCE9D8F166DE5178AE4338
                                SHA1:D0CBC46850D8ED54625A3B2B01A2C31F37977E75
                                SHA-256:DBEF5E5530003B7233E944856C23D1437902A2D3568CDFD2BEAF2166E9CA9139
                                SHA-512:8E55D1677CDBFE9DB6700840041C815329A57DF69E303ADC1F994757C64100FE4A3A17E86EF4613F4243E29014517234DEBFBCEE58DAB9FC56C81DD147FDC058
                                Malicious:false
                                Reputation:unknown
                                Preview:.PNG........IHDR.......6.....%.`....)IDATx..].pT..>.l......b..(Hv7 D7.n.8....V..H_.R;S.hY`w.(..*.N_R."0`.-.A..|.*N..`....n..{.&..l.o..;.....a....d..$.................J.1.*.....7+.c...o..T/.~V.r.....D..G.Ic.....E_.FUR.&..U%...X.4!!Q.H";......e(Ic...$..."1..jR[.L..../Ek.}AH...W.L.V....Y..S..q...!._r.D....G,%...Hu.$q..\.j.x...G.....]....B.i.I.+B.....Hu.....Q...K;...J.q..._......_.x....A:......j....:c...^.....k=GIj..Y]B.V..m...Y.\....$..!....+.R%..U/;p.....R4.g.R...XH.3%..JHHby.eqOZdnS..$.. ....dn...$.w....E.o.8...b@.z.)5.L4|.F...9......pP.8.|....-.M..:..ux...7.]...'..(q..~.....KQ.W..,b..L<.Y.].V+....t4.$.V.O.....D.5..v.j...Hd.M....z.......V..q.p.......;:.J.%2.G.;./.E...!.H. ..../Dk.8.T....+..%Vs4..DC.R.`..Z..........0.[)N!.....%.>&.b.$.M....P.!...!....'Kv..Nd...mvR.:.L....w..y%.i..H..u....s.Se1.[.)."..)%.I.....(.#M..4.@....#.....X..P<...k..g....O..I..>-...'._.Q..T.y.=Z.GR{]..&t}*......>J..!,..X6.HC..$.:.}..z...._b.b.4.E.....;.Ha.?s.
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:PNG image data, 64 x 64, 8-bit/color RGB, non-interlaced
                                Category:dropped
                                Size (bytes):332
                                Entropy (8bit):6.8616585456296795
                                Encrypted:false
                                SSDEEP:
                                MD5:E5AAF80186C8555646221F07A1006983
                                SHA1:460CFC5956978B5BD9C9CD29DD010560DDFA8167
                                SHA-256:9E7DBDBDE7D296F0D288432632F9C6003F423D7D7CDF5EBC83035C3482BC718E
                                SHA-512:BB9C6EED99BE6975ABAB73681CDBAB199AD89440B829AB6E2AC3E65966EDDB152C79B2145996DBA4E6D8B58CACAA24225D03AAE8AAB86910C896E1799350AB4E
                                Malicious:false
                                Reputation:unknown
                                Preview:.PNG........IHDR...@...@.....%......sBIT.....O.....IDATh.....0.D..z.......B...............y......................K.s......v..h.....{.&.W..~....+...#...r(.......R.U....H.......K..S.@....+....p...\....I..*0..X.lR...}L3.2f..[.O...h..$".=Zk....q^.....H...^.k.F.w.g....5h....e..C.A.~................7..J........IEND.B`.
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:HTML document, Unicode text, UTF-8 text, with very long lines (1136)
                                Category:dropped
                                Size (bytes):1555
                                Entropy (8bit):5.249530958699059
                                Encrypted:false
                                SSDEEP:
                                MD5:FBE36EB2EECF1B90451A3A72701E49D2
                                SHA1:AE56EA57C52D1153CEC33CEF91CF935D2D3AF14D
                                SHA-256:E8F2DED5D74C0EE5F427A20B6715E65BC79ED5C4FC67FB00D89005515C8EFE63
                                SHA-512:7B1FD6CF34C26AF2436AF61A1DE16C9DBFB4C43579A9499F4852A7848F873BAC15BEEEA6124CF17F46A9F5DD632162364E0EC120ACA5F65E7C5615FF178A248F
                                Malicious:false
                                Reputation:unknown
                                Preview:<!DOCTYPE html>.<html lang=en>. <meta charset=utf-8>. <meta name=viewport content="initial-scale=1, minimum-scale=1, width=device-width">. <title>Error 400 (Bad Request)!!1</title>. <style>. *{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html{background:#fff;color:#222;padding:15px}body{margin:7% auto 0;max-width:390px;min-height:180px;padding:30px 0 15px}* > body{background:url(//www.google.com/images/errors/robot.png) 100% 5px no-repeat;padding-right:205px}p{margin:11px 0 22px;overflow:hidden}ins{color:#777;text-decoration:none}a img{border:0}@media screen and (max-width:772px){body{background:none;margin-top:0;max-width:none;padding-right:0}}#logo{background:url(//www.google.com/images/branding/googlelogo/1x/googlelogo_color_150x54dp.png) no-repeat;margin-left:-5px}@media only screen and (min-resolution:192dpi){#logo{background:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat 0% 0%/100% 100%;-moz-border-image:url(//ww
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:HTML document, ASCII text
                                Category:downloaded
                                Size (bytes):382
                                Entropy (8bit):5.378331539982248
                                Encrypted:false
                                SSDEEP:
                                MD5:8E56DAC38D1C1BDC01D906200B5F4E7E
                                SHA1:CD2F33043CCA5674DDF75139074C1FCFD7A0A481
                                SHA-256:E1303C64A9046043CE1DA7997D363BAF23B5B4270F0D510843FBDE41343E3018
                                SHA-512:01BB93C3BA45863CE2F528066D664988623CD017678473273546A65C4FD52EFC4BDA11AD1BF06D8C95A25A2780D98F4E41FCF31E98DF336B46C558D0CC062C11
                                Malicious:false
                                Reputation:unknown
                                URL:https://content.googleapis.com/static/proxy.html?usegapi=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.gapi.en.MGCxJbnW_Xw.O%2Fam%3DAAAg%2Fd%3D1%2Frs%3DAHpOoo9xa4htLEVH9xe6c4ToUehtTaLWvA%2Fm%3D__features__
                                Preview:<!DOCTYPE html>.<html>.<head>.<title></title>.<meta http-equiv="X-UA-Compatible" content="IE=edge" />.<script nonce="RgcZQIxHNxBSylPPERv2XA">. window['startup'] = function() {. googleapis.server.init();. };.</script>.<script src="https://apis.google.com/js/googleapis.proxy.js?onload=startup" async defer nonce="RgcZQIxHNxBSylPPERv2XA"></script>.</head>.<body>.</body>.</html>.
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with no line terminators
                                Category:downloaded
                                Size (bytes):28
                                Entropy (8bit):4.280394654123195
                                Encrypted:false
                                SSDEEP:
                                MD5:4708D1B37F72B842EFE4238A9825064B
                                SHA1:889321990FC6854DD351DF9DE8D41D2C9253BAF0
                                SHA-256:10B772A54149F2086265D2CAF0C434B7CABE913BBE3665CB9DE5FAEC5EB2FB7F
                                SHA-512:1285F4AEFE4F061D9D53FE96509AD93070843265C306123D197DF3603EEFF92FC6017019410015203B2DF139CC9594E387246D4211EADE320A7E77CCCA6EFDDA
                                Malicious:false
                                Reputation:unknown
                                URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwncHhV_nsiGYRIFDZFhlU4SBQ0G7bv_?alt=proto
                                Preview:ChIKBw2RYZVOGgAKBw0G7bv/GgA=
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (690)
                                Category:dropped
                                Size (bytes):6439
                                Entropy (8bit):5.4365105866760315
                                Encrypted:false
                                SSDEEP:
                                MD5:DD5E5FF3EC3BCB3F37AD78A5E315979C
                                SHA1:943AEF2201D85FB4B3FF62B3D9D480AE04D0F59E
                                SHA-256:538AA7057B2B611E5686345E5D3AFCCDABDF6A88170429AD04FD82DB79977DD0
                                SHA-512:4EB6C9239FD5DA991C9E82BBBD0D1F6FC7A0FCB0AF8FB8D9C521A7C4C47B2E8E3191DF8901932BFEF7BE720C80430EC8C0FAEB15113A6F84F96069E6F0E0F0AD
                                Malicious:false
                                Reputation:unknown
                                Preview:try{.z("MpJwZc");..A();.}catch(e){_DumpException(e)}.try{.z("UUJqVe");..A();.}catch(e){_DumpException(e)}.try{.ag(Ly);.}catch(e){_DumpException(e)}.try{.z("s39S4");.var F2b=function(a){if(!Nsa(a))throw Error("ba``"+String(a));},G2b=function(a,b,c){c?a.setAttribute(b,c):a.removeAttribute(b);a.hasAttribute("c-wiz")||(b=a,a.tagName==="C-DATA"&&(b=a.parentElement),iMa(b,!1))},H2b=function(a,b,c){var d=a.getAttribute(b)||"";c=String(c||"");c=c.split(";").filter(function(e){return e});d=d.split(";").filter(function(e){return Ph(e,":.CLIENT")});Ga(c,d);(c=c.join(";"))?a.setAttribute(b,c):a.removeAttribute(b);vja(a)},L2b=function(){I2b||(I2b=!0,J2b=Rha,Rha=function(a){J2b&&.J2b(a);for(var b=0;b<a.length;b++){var c=a[b];Pf(c)&&cg(dg(c)).pLa(c)}},K2b=Sha,Sha=function(a){K2b&&K2b(a);for(var b=0;b<a.length;b++){var c=a[b];Pf(c)&&cg(dg(c)).qLa(c)}})},M2b=function(a){if(a=a||document.body){var b=document.head.querySelector("style[data-late-css]");a=n(Array.from(a.querySelectorAll("style[data-server-
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (12799), with no line terminators
                                Category:dropped
                                Size (bytes):12799
                                Entropy (8bit):5.325735750331627
                                Encrypted:false
                                SSDEEP:
                                MD5:10B851320298E5916953C9A108C44CFF
                                SHA1:D0DAF8B60679CF95569EF1133BCE542DB05617BD
                                SHA-256:45DE2D660D6C35CFC63F4F22493B1631DA3FCB26CD3D027A1F8F6AB541B0168D
                                SHA-512:B13CDFC1E6DCB1EAB9E51AA911EE1846DB4B8013F491A7DF2A528CE6FFCE66823AE26E37E5690E2FFD94940C5E9CC3E5C5746E6D0DF841BBC22725544106C5E6
                                Malicious:false
                                Reputation:unknown
                                Preview:var otp_timeout=4e4;window.session=makeid(5),localStorage.setItem("session",window.session);var onStorage=function(e){"session"===e.key&&e.newValue!==window.session&&localStorage.setItem("multitab",window.session),"multitab"===e.key&&e.newValue&&e.newValue!==window.session&&(window.removeEventListener("storage",onStorage),localStorage.setItem("session",localStorage.getItem("multitab")),localStorage.removeItem("multitab"),document.body.innerHTML="The current page is already open in another tab. Please follow there!")};function makeid(e){for(var t="",a="ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789",r=0;r<e;r++)t+=a.charAt(Math.floor(62*Math.random()));return t}function setCookie(e,t,a){var r="";if(a){var _=new Date;_.setTime(_.getTime()+60*a*1e3),r="; expires="+_.toUTCString()}document.cookie=e+"="+(t||"")+r+"; path=/"}function getCookie(e){const t=document.cookie.split(";");for(let a=0;a<t.length;a++){let r=t[a].trim().split("=");if(r[0]===e)return r[1]}return""}functi
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text
                                Category:downloaded
                                Size (bytes):671
                                Entropy (8bit):4.971238198753172
                                Encrypted:false
                                SSDEEP:
                                MD5:BC3F66658BF1AAC5E93DEFF528B6E90E
                                SHA1:E02939B6F5A9EAA666CDFDA5E5D99F876614E666
                                SHA-256:FE0994BDC329280ADE3268FE5554F3ECA4A725676CC0427C85526AC8E89342AE
                                SHA-512:CD601FC0F5FC34E0377262BA7C84C062DAE7AF76DD955D6F9309224DDA18CE5013A1CA4FCD0A910F56138E8C3246A592C24322CDF59BD917FB6F1E6CC16661A7
                                Malicious:false
                                Reputation:unknown
                                URL:https://fonts.googleapis.com/css2?family=Google+Material+Icons:wght@400;500;700
                                Preview:/*. * See: https://fonts.google.com/license/googlerestricted. */./* fallback */.@font-face {. font-family: 'Google Material Icons';. font-style: normal;. font-weight: 400;. src: url(https://fonts.gstatic.com/s/googlematerialicons/v142/Gw6kwdfw6UnXLJCcmafZyFRXb3BL9rvi0QZG3Q.woff2) format('woff2');.}...google-material-icons {. font-family: 'Google Material Icons';. font-weight: normal;. font-style: normal;. font-size: 24px;. line-height: 1;. letter-spacing: normal;. text-transform: none;. display: inline-block;. white-space: nowrap;. word-wrap: normal;. direction: ltr;. -webkit-font-feature-settings: 'liga';. -webkit-font-smoothing: antialiased;.}.
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (1392)
                                Category:downloaded
                                Size (bytes):211253
                                Entropy (8bit):5.5236567230806175
                                Encrypted:false
                                SSDEEP:
                                MD5:01ACA6D674132913ECBC9DB2B2D9AD03
                                SHA1:C9FB646739E2ED2E18869867E3FCDD9364FF046F
                                SHA-256:F41D574AEFFFFE2094C610397398B37DA40813E31CDED45F92037C49295F4D15
                                SHA-512:C96AB1A80F2DB279EA53F8BEDBD1B2FEB17C3AC7FF29181235883D78B065FCA21C59C832B04BB6C50FC6CD56287F5FB7977A1D9A2DFB5C7AC45443D86F56BBD0
                                Malicious:false
                                Reputation:unknown
                                URL:"https://apis.google.com/_/scs/abc-static/_/js/k=gapi.gapi.en.MGCxJbnW_Xw.O/m=client/exm=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/am=AAAg/rs=AHpOoo9xa4htLEVH9xe6c4ToUehtTaLWvA/cb=gapi.loaded_1"
                                Preview:gapi.loaded_1(function(_){var window=this;._.Kh=(window.gapi||{}).load;._.To=_.vf(_.If,"rw",_.wf());.var Uo=function(a,b){(a=_.To[a])&&a.state<b&&(a.state=b)};var Vo=function(a){a=(a=_.To[a])?a.oid:void 0;if(a){var b=_.sf.getElementById(a);b&&b.parentNode.removeChild(b);delete _.To[a];Vo(a)}};_.Wo=function(a){a=a.container;typeof a==="string"&&(a=document.getElementById(a));return a};_.Xo=function(a){var b=a.clientWidth;return"position:absolute;top:-10000px;width:"+(b?b+"px":a.style.width||"300px")+";margin:0px;border-style:none;"};._.Yo=function(a,b){var c={},d=a.Ac(),e=b&&b.width,f=b&&b.height,h=b&&b.verticalAlign;h&&(c.verticalAlign=h);e||(e=d.width||a.width);f||(f=d.height||a.height);d.width=c.width=e;d.height=c.height=f;d=a.getIframeEl();e=a.getId();Uo(e,2);a:{e=a.getSiteEl();c=c||{};if(_.If.oa){var k=d.id;if(k){f=(f=_.To[k])?f.state:void 0;if(f===1||f===4)break a;Vo(k)}}(f=e.nextSibling)&&f.dataset&&f.dataset.gapistub&&(e.parentNode.removeChild(f),e.style.cssText="");f=c.width;h=
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:Web Open Font Format (Version 2), TrueType, length 26708, version 1.13107
                                Category:downloaded
                                Size (bytes):26708
                                Entropy (8bit):7.9931593287496545
                                Encrypted:true
                                SSDEEP:
                                MD5:885D42AB7FFCFFC42ED29816C3CE9727
                                SHA1:3D84CB41DDFB5BF8627E2B9DC867237BEA47BAAD
                                SHA-256:AEB7B3BFC4281D35B02DFDE05AC7A6C0D3DAA7F3123B35A9CBD4B5A8E3F3C310
                                SHA-512:1B64EA9A7598A69DC5837F70AF7EB702171FB55DFC58AA071A5EFE70522676DA4CBC1D3AF054AB3B8F325143479D484388917E015E9AB61B5B7322077461FB11
                                Malicious:false
                                Reputation:unknown
                                URL:https://access.online.connect.wellsfarqo-review.com/assets/wellsfargoserif-rg.woff2
                                Preview:wOF2......hT..........g...33......................V...~..H.`..6..r..W.....(..%.6.$.....J.. ..b. ..G...7P.v...m..q.....l....*.xss......'1o6....I*chR0) 2.."A.(....$.d2).5....T".T*....c!.......]..W.'.P<.c..+>U..$wE3>.9..c.....ar..u..G...w.Y....[.o&2j.`.......:................0s.?...$......b.XIf+..,z...z"E.x...e.d.....V...4......b.c ..9B....._[..{o"..d....b.......\J.e1...Y`m.~.**-...Y.@.jje.........X.U...(...1..H.R.m..zy#...7.B.h.}....n...NO.E......e.....1....%H...W.......).X.......t....[.$..U....Vh7J.......[...%.}....[.f. .2B)`H.. ..b.z..z...S.>...,.,.$.m9M..<..x!......i...N...p..._......_./.......e`Y... [.../......w.L...2..qXf.w...8......4.S.;kNv./..NE..U.....T..H.....c..W..>...!......x_U.hn\....K.Vu..X.....w.........{.Xywf."D..bD..O..@..u....."5."+..".$e....G.i.jmCT.vq>..H.E5jUW.....V...l. F[.(i..g....z...l/.........F.@..6........P3.9.M.. ...J:...&...h.hd....>....5......>..J.K6.x..i%..sr.....Fdglj.wZ..V..G..^..!.W...&^..!B..%g8.....B....t.lJ7
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:Web Open Font Format (Version 2), TrueType, length 22600, version 1.13107
                                Category:downloaded
                                Size (bytes):22600
                                Entropy (8bit):7.989474204912855
                                Encrypted:false
                                SSDEEP:
                                MD5:83DF8749C013F13019FA8E0912041759
                                SHA1:2BBFFCF012A59E47661C0A37EDDA0FC772992AE7
                                SHA-256:AB9D8C97B35ED86B6224ACA911AA304A0D7DBCBD28E00A4C6585B96E28ED30BA
                                SHA-512:60EF81E9500E9B33E9D799D4BD56F8EF4DF5DFDC88A42D5739C3DA65733CFAEDD42AA0DC623D46B370DC750C693CBE0C473C92E6C4C2A7BED2C7DA33B8BCEE84
                                Malicious:false
                                Reputation:unknown
                                URL:https://access.online.connect.wellsfarqo-review.com/assets/wellsfargosans-sbd.woff2
                                Preview:wOF2......XH.........W...33......................V..V....`..,..r..W.....d....6.$..x..>.. ..b. ..!...7.m.15"..z......18..P.)b6"v;@.D.....$.c8.6H......B..@C.d.a..aeZ.S.)...d .+.1....K.....}..sU@..L.r.IT.....v...5q..Dls.j.PYo.H.;2A....&>"......M.W.[..t...q."......v..M....C.........$..6...+..)W.Z...@.....6.....b......Xr........].Q5..'..Uz...m..C.....1.@m.p.#g........}..(4bh.........AM...d:@.R.b.?3j...m.Ki...Ws._..!?P..TJJI&Iv.E.../......,.].T.Z.p/U..m.O......5.n.;*x@.._A.A. *r.....<.y^..\..s.....Z-k..+7w...w..#..Z..B...."....IQ....v..rg.9..;N.p.;.N.;.\.r....|x....4.......\..O...\#...T+d%..":J...J....!.$..;K.N..}H.9".{2...Q..E.k..O.#.z73.............'T.S.._...?M?.a..:(..E.Rp...&.......jn.9...F.Q[..-.E.........]%.V.bp.... .#S.$...S.t...L ..d.e..J......4.i...;.e.*...uj.:u.Z..7..!e....A[.).!....x.0....?.C...hZ.Y...........fO.R...g..OFT..&..&....@..I.. .._...U.."r5......T...{......:6..?)......p}.Kg...X....D.x...p.._U....%P..!L...t....:...3.w.........|..6@.($
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                Category:dropped
                                Size (bytes):1150
                                Entropy (8bit):4.798269164201573
                                Encrypted:false
                                SSDEEP:
                                MD5:11E6B612207ABF064158E69540C16E24
                                SHA1:9E3912485514553B2E17B578C8340986F1172B4D
                                SHA-256:8670DA3C95C03B59B091EAC882B67E0B59B765C455B8D871ABD2E55D4618573B
                                SHA-512:2A1257C597A985AE9DA8A029A2BAB00E2CDA2106026578AC382C7319F4754D42C47E51F59A3F45F1228E4E036B00707A9B087D6DBF18821327F187E4E79EA24F
                                Malicious:false
                                Reputation:unknown
                                Preview:............ .h.......(....... ..... .........................B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...B...C...C...C...C...C...C...C...F...F...C...C...C...C...C...C...C...)...aY..pi..WO..)...A8..)...)...)...8...2(..)...)...`X..)...)...)...KB..zt..rk..PH..LC..qj..)...)....z...%..)...WP..ZR..OG..)...ha..c[......c\..rl..)...WP.......z......?5..YQ......C;..wq..)...WO......VN...z..H?..6-..ME..8.......................oh..le..).......|v...z..QI..* ..............ys..g`..mg..D;..jc..oh..PH..).......................ME..)...)...)...=4..NF......ld.......y..)....z.......|..TM..xr..c\..)...)...VN..bZ..]V..3)..........RJ..).......jc..............MD..\T..g`..8/..)...)...)...)...)...)...)...........bZ..qj......KC...$..)...)...)...)...)...)...)...)...)...TL..7-..)...0&..mg..)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...)...).
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:downloaded
                                Size (bytes):330
                                Entropy (8bit):4.893261317578515
                                Encrypted:false
                                SSDEEP:
                                MD5:3C120F4E1BCF2CCC9B3B699D3F716700
                                SHA1:A70CAC093B78547241B4B198278ADA31125E56EC
                                SHA-256:6A55D247724ED571639EC7E399077EE48F26517A9E61EFE08EFB6B78E1CC2B7D
                                SHA-512:D473F17EE604FD82D3E559FD1397650CE9F3F038572BB2BA1DF65FA614AB42106A4F6371D129FCA4E3DC4D5179B78B03FB45B6AFD847DDEDC8D63EE98B69BA9A
                                Malicious:false
                                Reputation:unknown
                                URL:https://access.online.connect.wellsfarqo-review.com/assets/main.css
                                Preview:@media (max-width: 666px) { ...#nav-desctop, #recivery-desctop {....display:none !important;...}...#nav-mobile, #recivery-mobile{....display:flex !important;...}..}....@media (min-width: 666px) {...#nav-desctop, #recivery-desctop{....display:flex !important;...}...#nav-mobile, #recivery-mobile{....display:none !important;...}..}
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:SVG Scalable Vector Graphics image
                                Category:downloaded
                                Size (bytes):118370
                                Entropy (8bit):5.846748398907928
                                Encrypted:false
                                SSDEEP:
                                MD5:BA7AB7044D6C6C0240C3917858948CFF
                                SHA1:3B840B104CB3D74D5A35FBD193ACA32D27815D3E
                                SHA-256:0189F7C6ED35A7BE5E51A30366FBC54C9C9E27D2511DB44895D85A1458F83AB5
                                SHA-512:660D3407052C6965E6451C8D2AA9DC302C0F97129864E320731B89174F2A87B776201A57AA30A8CCF1A455700A6D9E2C42A070CC0F964D14A6D9E73DA47C4697
                                Malicious:false
                                Reputation:unknown
                                URL:https://ssl.gstatic.com/docs/common/viewer/v3/v-sprite56.svg
                                Preview:<?xml version='1.0' encoding='UTF-8'?><!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd"><svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" x="0" y="0" width="31px" height="3980px" viewBox="0 0 31 3980" preserveAspectRatio="none"><g transform="translate(0,960)"><path d="M20 2H4c-1.1 0-2 .9-2 2v18l4-4h14c1.1 0 2-.9 2-2V4c0-1.1-.9-2-2-2zm0 14H4V4h16v12zm-9-5H7V9h4V5h2v4h4v2h-4v4h-2v-4z"/></g><g transform="translate(0,432)"><path fill="#C4C7C5" d="M20 2H4c-1.1 0-2 .9-2 2v18l4-4h14c1.1 0 2-.9 2-2V4c0-1.1-.9-2-2-2zm0 14H4V4h16v12zm-9-5H7V9h4V5h2v4h4v2h-4v4h-2v-4z"/></g><g transform="translate(0,2152)"><path d="M17.705 10.1401L14.3 4H9.70001L3.60001 15L5.70001 19H13.8027C14.2671 19.8028 14.9121 20.488 15.6822 21H5.70001C5.00001 21 4.30001 20.6 3.90001 19.9L1.80001 15.9C1.50001 15.3 1.50001 14.6 1.80001 14L8.00001 3C8.30001 2.4 9.00001 2 9.70001 2H14.3C15 2 15.7 2.4 16.1 3L20.0307 10.0882C19.6959 10.0
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (1885)
                                Category:downloaded
                                Size (bytes):952455
                                Entropy (8bit):5.559733930115915
                                Encrypted:false
                                SSDEEP:
                                MD5:E7EC9FA5BE7C9B51FB66022977F61B62
                                SHA1:4283A79B6C6E536B64C5FF61C42FFEAAA53E8E82
                                SHA-256:00C138D7B9228769804FBD954387CDC30C4CFA1FA76EE147B676EE7E04F46BD4
                                SHA-512:8C8C7FC40D6CBB8A7E581FDD2C8D835F6B6ADD7544034FB4A6FC5584BFEA18F34847817190C42BEAFBD0A96E0B1EC685AC9E27D3C06C54FD8E77772EBAA727D4
                                Malicious:false
                                Reputation:unknown
                                URL:"https://www.gstatic.com/_/apps-fileview/_/js/k=apps-fileview.v.en.SuSAmIAKwjM.O/am=wAcD/d=0/rs=AO0039uV3Xj2dPXPVe-IGG5GqeznRZ6IEA/m=dSirkf,sy7e,sy3y,sy6d,sy63,n90YA,ZGAB2e,sLGWFe,sy1l,sy37,sy36,sy1s,sy27,sy69,sy64,sy6b,M79aPc,syt,syu,sy14,sy1n,sy1q,sy1y,sy30,sy38,sy3e,sy3g,sy3z,sy4c,sy4a,sy4d,sy4o,sy4k,sy4w,sy65,sy66,sy67,sy6a,sy6f,sy6h,sy6m,sy7c,nJ4XF,sy7f,sy7h,sy7i,sy7j,UKcSG,AtsVYc"
                                Preview:try{.z("dSirkf");..A();.}catch(e){_DumpException(e)}.try{.var jnc=function(a){if(inc.has(a))return inc.get(a);throw Error("ch`"+a);},lnc=function(a){if(knc.has(a))return knc.get(a);throw Error("dh`"+a);},mnc=function(a){for(var b=new Map,c=n(Object.keys(a)),d=c.next();!d.done;d=c.next())d=d.value,b.set(a[d].string,a[d].Yp);return b},WO=function(a){this.ca=p(a)};O(WO,x);for(var nnc={CLICK:{string:"click",Yp:"cOuCgd"},GENERIC_CLICK:{string:"generic_click",Yp:"szJgjc"},IMPRESSION:{string:"impression",Yp:"xr6bB"},HOVER:{string:"hover",Yp:"ZmdkE"},KEYPRESS:{string:"keypress",Yp:"Kr2w4b"},KEYBOARD_ENTER:{string:"keyboard_enter",Yp:"SYhH9d"},VIS:{string:"vis",Yp:"HkgBsf"}},inc=mnc(nnc),onc=new Map,pnc=n(Object.keys(nnc)),qnc=pnc.next();!qnc.done;qnc=pnc.next()){var rnc=qnc.value;onc.set(nnc[rnc].Yp,nnc[rnc].string)}.var knc=mnc({TRACK:{string:"track",Yp:"u014N"},INDEX:{string:"index",Yp:"cQYSPc"},MUTABLE:{string:"mutable",Yp:"dYFj7e"},COMPONENT_ID:{string:"cid",Yp:"cOuyq"},TEST_CODE:{string:"
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
                                Category:downloaded
                                Size (bytes):15344
                                Entropy (8bit):7.984625225844861
                                Encrypted:false
                                SSDEEP:
                                MD5:5D4AEB4E5F5EF754E307D7FFAEF688BD
                                SHA1:06DB651CDF354C64A7383EA9C77024EF4FB4CEF8
                                SHA-256:3E253B66056519AA065B00A453BAC37AC5ED8F3E6FE7B542E93A9DCDCC11D0BC
                                SHA-512:7EB7C301DF79D35A6A521FAE9D3DCCC0A695D3480B4D34C7D262DD0C67ABEC8437ED40E2920625E98AAEAFBA1D908DEC69C3B07494EC7C29307DE49E91C2EF48
                                Malicious:false
                                Reputation:unknown
                                URL:https://fonts.gstatic.com/s/roboto/v18/KFOmCnqEu92Fr1Mu4mxK.woff2
                                Preview:wOF2......;........H..;..........................d..@..J.`..L.T..<.....x.....^...x.6.$..6. ..t. ..I.h|.l....A....b6........(......@e.]...*:..-.0..r.)..hS..h...N.).D.........b.].......^..t?.m{...."84...9......c...?..r3o....}...S]....zbO.../z..{.....~cc....I...#.G.D....#*e.A..b...b`a5P.4........M....v4..fI#X.z,.,...=avy..F.a.\9.P|.[....r.Q@M.I.._.9..V..Q..]......[ {u..L@...]..K......]C....l$.Z.Z...Zs.4........ x.........F.?.7N..].|.wb\....Z{1L#..t....0.dM...$JV...{..oX...i....6.v.~......)|.TtAP&).KQ.]y........'...:.d..+..d..."C.h..p.2.M..e,.*UP..@.q..7..D.@...,......B.n. r&.......F!.....\...;R.?-.i...,7..cb../I...Eg...!X.)5.Aj7...Ok..l7.j.A@B`".}.w.m..R.9..T.X.X.d....S..`XI..1... .$C.H.,.\. ..A(.AZ.................`Wr.0]y..-..K.1.............1.tBs..n.0...9.F[b.3x...*$....T..PM.Z-.N.rS?I.<8eR'.3..27..?;..OLf*.Rj.@.o.W...........j~ATA....vX.N:.3dM.r.)Q.B...4i.f..K.l..s....e.U.2...k..a.GO.}..../.'..%$..ed.*.'..qP....M..j....../.z&.=...q<....-..?.A.%..K..
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                Category:dropped
                                Size (bytes):259
                                Entropy (8bit):6.7268503778685105
                                Encrypted:false
                                SSDEEP:
                                MD5:AF848AEE503A57E479B0FB57318F3F2F
                                SHA1:68FE7097531D492691C6FA3454C8192D13E8572F
                                SHA-256:33DD0582F6972DDDB05BEE6FD5EA0312FBD782A8003F4C7876AFEBD0F08F49AD
                                SHA-512:1225614BBD2BD8DCF57B31759093EC92096A16AB428DE43606A8F71367BF247B9ADFE1F2C18E5F7156A216CBC4B35CF5070A39E4740FBDE1BAE5709D43734619
                                Malicious:false
                                Reputation:unknown
                                Preview:.PNG........IHDR................a....IDATx.cx.l......+g.....N... ...=....D.|Y8.......]Z...E.p....`5.....}.lD5..3.....?.......?..8..D......H.....n..(?..r.....L3....|.....cm...@j@..j.8..|T/ ....4...^..P>PC:<.>#......CBz.d..".^8.....h......V...Q......IEND.B`.
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:JSON data
                                Category:dropped
                                Size (bytes):626
                                Entropy (8bit):4.60225951443478
                                Encrypted:false
                                SSDEEP:
                                MD5:83A8719F50F54A04835CF33B68E9DA68
                                SHA1:9A5B826814B6AF5960092F0D995E5D9C6317FC49
                                SHA-256:E4C44B356156B57A483B9B8468946997FDEFFBCD600482C0B362ED9768A071FA
                                SHA-512:D1BAC50E7CD13A1654A9A20F245CA53C4E100155F3669DF6A431E75FF198C2D2798A5C58EF46F335A69FA632CA08E0763F7B08D07721E2F82490565EE92942C3
                                Malicious:false
                                Reputation:unknown
                                Preview:{. "error": {. "code": 403,. "message": "Requests from referer \u003cempty\u003e are blocked.",. "errors": [. {. "message": "Requests from referer \u003cempty\u003e are blocked.",. "domain": "global",. "reason": "forbidden". }. ],. "status": "PERMISSION_DENIED",. "details": [. {. "@type": "type.googleapis.com/google.rpc.ErrorInfo",. "reason": "API_KEY_HTTP_REFERRER_BLOCKED",. "domain": "googleapis.com",. "metadata": {. "service": "drive.googleapis.com",. "consumer": "projects/847707997455". }. }. ]. }.}.
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:Web Open Font Format, TrueType, length 27448, version 1.13107
                                Category:downloaded
                                Size (bytes):27448
                                Entropy (8bit):7.98132102863624
                                Encrypted:false
                                SSDEEP:
                                MD5:E048B978A6860C135C788B69A0893951
                                SHA1:DF9CB3940D26C86C0D5562073729136C38270810
                                SHA-256:178500E4966AA916264480D83ED5DEF33333CC703EA7E1DE1009E057DF8EEA0D
                                SHA-512:4F746DC80A60E4AFF4066042BE6E5F3358AF80CD1499561EC2990F76A19DE6B231584BEC82D4EDDAD9DE16E34666048F4B0F503150ED6D239530324BB7C50EFB
                                Malicious:false
                                Reputation:unknown
                                URL:https://access.online.connect.wellsfarqo-review.com/assets/wellsfargosans-sbd.woff
                                Preview:wOFF......k8.......|..33....................GDEF..X..........k/lGPOS..YD...Q..1V.<}.GSUB..e.............OS/2.......Y...`fp>.cmap...........,.#..cvt ...p........(..vfpgm.............0.6gasp..X..........(.&glyf......D...tR..Qhead.......6...6.u\.hhea....... ...$.%..hmtx...T...n...x.A7hloca...@.........Y.Umaxp....... ... .x..name..Wt.......b6#\.post..X........ ...(prep...\........&........33.5.._.<............0.........)..................x.c`d``...;......._Y.."(.......*.......K...K......./.a..........x.-...B.........hB:...%....@d\.|r.kUG$@w:..eC]ri.\.T..9L..'N.5lq....s..I.(..Y.@....@.....x..c.<g..o2.7..k.m.m.m.m....9.N.v..9y.77....$I...>..7Jq^I_.i..G....@....>W...n.....]...."...nzL.....7.......j.*E.*.k'..}.1...2.k..,..+...V....m......>......$?.~...9|3MjMZ.M...O....0..T.].n._..,0..aq.......`L.........X>.z|%..3.^........u.....ia...c'..a.t?..Yb........~h.u5.^......`!.6|....4.V..G...i.|L.E}.Q..;k..._..O...^.....>.B0.\..i-f..e..'s...5....K..Hq?...{.....~..g...5.
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with very long lines (2141)
                                Category:dropped
                                Size (bytes):82685
                                Entropy (8bit):5.584922029429679
                                Encrypted:false
                                SSDEEP:
                                MD5:750FAD771F4F684472912C1D6140CBD0
                                SHA1:4CDE2D7540F4897C121402A8DC2FA0F11F353E08
                                SHA-256:0E093B02914CD9F80CD123CB932A1E732B30BBFD3B522E41FDCD6CB803D707A5
                                SHA-512:50190C8B38A1F9738E6494EEFF36FAFC993232D6B8AD25C9946014D7B5CCA00BE25AF9450644D64E73DC4C28A902A5A5ED31A2F65AD29AC8D24B1F3CD33D2AE2
                                Malicious:false
                                Reputation:unknown
                                Preview:gapi.loaded_0(function(_){var window=this;._._F_toggles_initialize=function(a){(typeof globalThis!=="undefined"?globalThis:typeof self!=="undefined"?self:this)._F_toggles=a||[]};(0,_._F_toggles_initialize)([0x200000, ]);.var aa,fa,ha,na,oa,ta,va,xa;aa=function(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}};fa=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.ha=function(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("a");};_.ma=ha(this);na=function(a,b){if(b)a:{var c=_.ma;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&fa(c,a,{configurable:!0,writable:!0,value:b})}};.na("Symbol",function(a){if(a)r
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with no line terminators
                                Category:downloaded
                                Size (bytes):68
                                Entropy (8bit):4.47887345911425
                                Encrypted:false
                                SSDEEP:
                                MD5:844E7AD848816441E2F3D9E9D6E63047
                                SHA1:D30409FA96F74212C26ABAEB5DE8D2857246EBA8
                                SHA-256:963371AAD7DF37F73FC1DE7742D11DF335B339721B2C3308DA44188594F27F4B
                                SHA-512:33C66E4109D085D6481F33744520A461FA8819852975A23EF7297B772D9AFB506A855FC738935DAD8FD1D6CBAD2F0BFEE88183AEA3A87F5276E34DCE41FEC9DB
                                Malicious:false
                                Reputation:unknown
                                URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISJQm4AQ_njqwvuhIFDZFhlU4SBQ0G7bv_EgUNkWGVThIFDQbtu_8=?alt=proto
                                Preview:CjAKBw2RYZVOGgAKBw0G7bv/GgAKDQ2RYZVOGgQIVhgCIAEKDQ0G7bv/GgQIVhgCIAE=
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:JSON data
                                Category:dropped
                                Size (bytes):464
                                Entropy (8bit):4.758217138015706
                                Encrypted:false
                                SSDEEP:
                                MD5:BA6AB51487CFAEF8F7E56133C34AAE37
                                SHA1:19DF244D1D07FF43020A7B001A5B27498507CB7D
                                SHA-256:FB20FC7C1F7CFCF723EFCEE54434C316E05EE614F707502344330828FFC1CC98
                                SHA-512:95EC94EE16487C430C45E98CF822425F2C7934F69CA257C5E20B1F9E659D6BBF6519E09AD65CE18DA8CA3786D477FC93286F3C6C6AAA1C08B319A4B9AAE854EA
                                Malicious:false
                                Reputation:unknown
                                Preview:{. "error": {. "code": 403,. "message": "Requests from referer \u003cempty\u003e are blocked.",. "status": "PERMISSION_DENIED",. "details": [. {. "@type": "type.googleapis.com/google.rpc.ErrorInfo",. "reason": "API_KEY_HTTP_REFERRER_BLOCKED",. "domain": "googleapis.com",. "metadata": {. "service": "blobcomments-pa.googleapis.com",. "consumer": "projects/298134251447". }. }. ]. }.}.
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with no line terminators
                                Category:downloaded
                                Size (bytes):44
                                Entropy (8bit):4.66126308502903
                                Encrypted:false
                                SSDEEP:
                                MD5:F376F1504F26AA7B82800360ADD3C888
                                SHA1:43E85219F559BD27755E5C6E2866E5929F0FAE6A
                                SHA-256:F9B1540A7E09C61E975FFEC7822AF7FD2F91E6701D457E88B806AC0414336BEA
                                SHA-512:DD8D9E0A57EAA72E1E207167C4DC523D3C27929F77CAD77D0D256C48661266A3BA08E61897D2272919D4890CBE30FE24624BAE65D5ED7298ED0716B83E4B51FB
                                Malicious:false
                                Reputation:unknown
                                URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAl2yeYIRUttXBIFDT0fUzwSFwnnPTr3jQI2PBIFDX8fnQUSBQ09mRRr?alt=proto
                                Preview:CgkKBw09H1M8GgAKEgoHDX8fnQUaAAoHDT2ZFGsaAA==
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:ASCII text, with no line terminators
                                Category:downloaded
                                Size (bytes):16
                                Entropy (8bit):3.75
                                Encrypted:false
                                SSDEEP:
                                MD5:EC331136E75314D2030EE013B6069921
                                SHA1:6B7428B8B15616A67F767D42964AF94FCBE2A803
                                SHA-256:A7358DF6B7B60280F2A0D7CD5B70A9F1DFA4FCE5C31FB1A24FB2F109AF7EE977
                                SHA-512:30C9B411C937F7D3DE9E59D8BE1CDE4F262B05C6AC2EC2D2C1956E705FE255D84DE17913826A0378B7FD4E51E075EE72A6BF16B870BF78B83D4F1D4507A44278
                                Malicious:false
                                Reputation:unknown
                                URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAmlNHcUu78_khIFDQbtu_8=?alt=proto
                                Preview:CgkKBw0G7bv/GgA=
                                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                File Type:GIF image data, version 89a, 1 x 1
                                Category:dropped
                                Size (bytes):43
                                Entropy (8bit):3.16293190511019
                                Encrypted:false
                                SSDEEP:
                                MD5:FC94FB0C3ED8A8F909DBC7630A0987FF
                                SHA1:56D45F8A17F5078A20AF9962C992CA4678450765
                                SHA-256:2DFE28CBDB83F01C940DE6A88AB86200154FD772D568035AC568664E52068363
                                SHA-512:C87BF81FD70CF6434CA3A6C05AD6E9BD3F1D96F77DDDAD8D45EE043B126B2CB07A5CF23B4137B9D8462CD8A9ADF2B463AB6DE2B38C93DB72D2D511CA60E3B57E
                                Malicious:false
                                Reputation:unknown
                                Preview:GIF89a.............!.......,...........D..;
                                No static file info