IOC Report
https://1drv.ms/o/c/76471f3776916fd0/EomjtsItbi9Ag0bnzrJDx08BhxVWepFoAXrJFoYeR9IZ0A?e=5%3aEFCh5b&sharingv2=true&fromShare=true&at=9

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 14:51:04 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 14:51:04 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 14:51:04 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 14:51:04 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 14:51:04 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 258
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 259
ASCII text, with very long lines (5949), with no line terminators
downloaded
Chrome Cache Entry: 260
JSON data
dropped
Chrome Cache Entry: 261
ASCII text, with very long lines (38617), with no line terminators
dropped
Chrome Cache Entry: 262
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 263
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 264
ASCII text, with very long lines (58562)
downloaded
Chrome Cache Entry: 265
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 266
ASCII text, with very long lines (14666), with no line terminators
downloaded
Chrome Cache Entry: 267
ASCII text, with very long lines (1922), with no line terminators
downloaded
Chrome Cache Entry: 268
ASCII text, with very long lines (41569), with no line terminators
dropped
Chrome Cache Entry: 269
ASCII text, with very long lines (20946), with CRLF line terminators
dropped
Chrome Cache Entry: 270
ASCII text, with very long lines (57788)
dropped
Chrome Cache Entry: 271
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 272
Web Open Font Format, TrueType, length 6784, version 3.30147
downloaded
Chrome Cache Entry: 273
ASCII text, with very long lines (20082), with no line terminators
dropped
Chrome Cache Entry: 274
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 275
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
Chrome Cache Entry: 276
ASCII text, with very long lines (627)
downloaded
Chrome Cache Entry: 277
GIF image data, version 89a, 24 x 24
downloaded
Chrome Cache Entry: 278
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 279
ASCII text, with very long lines (42915)
dropped
Chrome Cache Entry: 280
ASCII text, with very long lines (60197)
dropped
Chrome Cache Entry: 281
JSON data
downloaded
Chrome Cache Entry: 282
ASCII text, with very long lines (32011), with CRLF line terminators
downloaded
Chrome Cache Entry: 283
PNG image data, 222 x 204, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 284
ASCII text, with very long lines (47531)
downloaded
Chrome Cache Entry: 285
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 286
ASCII text, with very long lines (7694)
dropped
Chrome Cache Entry: 287
JSON data
downloaded
Chrome Cache Entry: 288
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 289
ASCII text, with very long lines (29173), with no line terminators
dropped
Chrome Cache Entry: 290
PNG image data, 102 x 102, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 291
ASCII text, with very long lines (32038)
dropped
Chrome Cache Entry: 292
Unicode text, UTF-8 text, with very long lines (56385)
downloaded
Chrome Cache Entry: 293
JSON data
downloaded
Chrome Cache Entry: 294
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 295
ASCII text, with very long lines (63604)
dropped
Chrome Cache Entry: 296
Unicode text, UTF-8 text, with very long lines (12695)
downloaded
Chrome Cache Entry: 297
Unicode text, UTF-8 text, with very long lines (28488)
downloaded
Chrome Cache Entry: 298
ASCII text, with very long lines (27024), with CRLF line terminators
downloaded
Chrome Cache Entry: 299
XML 1.0 document, ASCII text
dropped
Chrome Cache Entry: 300
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 301
PNG image data, 222 x 204, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 302
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 303
JSON data
dropped
Chrome Cache Entry: 304
ASCII text, with very long lines (7708)
dropped
Chrome Cache Entry: 305
ASCII text, with very long lines (63604)
downloaded
Chrome Cache Entry: 306
Unicode text, UTF-8 text, with very long lines (28488)
dropped
Chrome Cache Entry: 307
ASCII text, with very long lines (65437)
dropped
Chrome Cache Entry: 308
JSON data
dropped
Chrome Cache Entry: 309
ASCII text, with very long lines (30298)
dropped
Chrome Cache Entry: 310
ASCII text, with very long lines (47531)
dropped
Chrome Cache Entry: 311
ASCII text, with very long lines (616)
downloaded
Chrome Cache Entry: 312
ASCII text, with very long lines (41569), with no line terminators
downloaded
Chrome Cache Entry: 313
Unicode text, UTF-8 text, with very long lines (65526), with no line terminators
downloaded
Chrome Cache Entry: 314
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 315
ASCII text, with very long lines (35936), with CRLF line terminators
downloaded
Chrome Cache Entry: 316
JSON data
dropped
Chrome Cache Entry: 317
Unicode text, UTF-8 text, with very long lines (65340), with no line terminators
dropped
Chrome Cache Entry: 318
XML 1.0 document, ASCII text
downloaded
Chrome Cache Entry: 319
ASCII text, with very long lines (59425)
dropped
Chrome Cache Entry: 320
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
downloaded
Chrome Cache Entry: 321
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 322
ASCII text, with very long lines (3527), with no line terminators
downloaded
Chrome Cache Entry: 323
ASCII text, with very long lines (627)
dropped
Chrome Cache Entry: 324
ASCII text, with very long lines (8369), with no line terminators
dropped
Chrome Cache Entry: 325
PNG image data, 171 x 213, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 326
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 327
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
dropped
Chrome Cache Entry: 328
ASCII text, with very long lines (22548), with no line terminators
dropped
Chrome Cache Entry: 329
ASCII text, with very long lines (64817)
downloaded
Chrome Cache Entry: 330
ASCII text, with very long lines (1922), with no line terminators
dropped
Chrome Cache Entry: 331
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 332
PNG image data, 150 x 54, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 333
ASCII text, with very long lines (30249)
dropped
Chrome Cache Entry: 334
ASCII text, with very long lines (61584), with CRLF line terminators
dropped
Chrome Cache Entry: 335
Unicode text, UTF-8 (with BOM) text, with very long lines (18992), with CRLF line terminators
downloaded
Chrome Cache Entry: 336
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 337
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 338
Unicode text, UTF-8 text, with very long lines (58392)
downloaded
Chrome Cache Entry: 339
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 340
ASCII text, with very long lines (672)
dropped
Chrome Cache Entry: 341
Unicode text, UTF-8 text, with very long lines (65308), with no line terminators
downloaded
Chrome Cache Entry: 342
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 343
JSON data
dropped
Chrome Cache Entry: 344
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 345
ASCII text, with very long lines (2224), with no line terminators
downloaded
Chrome Cache Entry: 346
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 347
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 348
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
dropped
Chrome Cache Entry: 349
ASCII text, with very long lines (64817)
dropped
Chrome Cache Entry: 350
ASCII text, with very long lines (65394)
dropped
Chrome Cache Entry: 351
ASCII text, with very long lines (65443)
downloaded
Chrome Cache Entry: 352
JSON data
dropped
Chrome Cache Entry: 353
PNG image data, 171 x 213, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 354
TrueType Font data, 15 tables, 1st "OS/2"
downloaded
Chrome Cache Entry: 355
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 356
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 357
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 358
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 359
JSON data
dropped
Chrome Cache Entry: 360
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 361
JSON data
dropped
Chrome Cache Entry: 362
ASCII text, with very long lines (35936), with CRLF line terminators
dropped
Chrome Cache Entry: 363
Unicode text, UTF-8 (with BOM) text, with very long lines (18992), with CRLF line terminators
dropped
Chrome Cache Entry: 364
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 365
ASCII text, with very long lines (38617), with no line terminators
downloaded
Chrome Cache Entry: 366
ASCII text, with very long lines (24306), with CRLF line terminators
dropped
Chrome Cache Entry: 367
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 368
PNG image data, 452 x 444, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 369
ASCII text, with very long lines (11252)
dropped
Chrome Cache Entry: 370
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 371
MS Windows cursor resource - 1 icon, 32x32, hotspot @16x16
dropped
Chrome Cache Entry: 372
ASCII text, with very long lines (30497), with no line terminators
dropped
Chrome Cache Entry: 373
Unicode text, UTF-8 text, with very long lines (65526), with no line terminators
dropped
Chrome Cache Entry: 374
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
dropped
Chrome Cache Entry: 375
ASCII text, with very long lines (59425)
downloaded
Chrome Cache Entry: 376
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
Chrome Cache Entry: 377
ASCII text, with very long lines (32038)
downloaded
Chrome Cache Entry: 378
ASCII text, with very long lines (1917), with no line terminators
downloaded
Chrome Cache Entry: 379
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 380
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 381
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 382
Unicode text, UTF-8 text, with very long lines (65340), with no line terminators
downloaded
Chrome Cache Entry: 383
PNG image data, 102 x 102, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 384
ASCII text, with very long lines (11652), with no line terminators
downloaded
Chrome Cache Entry: 385
ASCII text, with very long lines (58562)
dropped
Chrome Cache Entry: 386
Unicode text, UTF-8 text, with very long lines (56385)
dropped
Chrome Cache Entry: 387
ASCII text, with very long lines (64762), with CRLF line terminators
downloaded
Chrome Cache Entry: 388
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 389
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 390
ASCII text, with very long lines (3527), with no line terminators
dropped
Chrome Cache Entry: 391
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 392
ASCII text, with very long lines (11652), with no line terminators
dropped
Chrome Cache Entry: 393
ASCII text, with very long lines (1917), with no line terminators
dropped
Chrome Cache Entry: 394
PNG image data, 82 x 258, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 395
JSON data
downloaded
Chrome Cache Entry: 396
ASCII text, with very long lines (1837)
downloaded
Chrome Cache Entry: 397
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 398
JSON data
downloaded
Chrome Cache Entry: 399
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 400
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 401
JSON data
downloaded
Chrome Cache Entry: 402
JSON data
dropped
Chrome Cache Entry: 403
ASCII text, with very long lines (61584), with CRLF line terminators
downloaded
Chrome Cache Entry: 404
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
dropped
Chrome Cache Entry: 405
Web Open Font Format, TrueType, length 3052, version 4.-22282
downloaded
Chrome Cache Entry: 406
ASCII text, with very long lines (4615)
dropped
Chrome Cache Entry: 407
ASCII text, with very long lines (65443)
dropped
Chrome Cache Entry: 408
Web Open Font Format, TrueType, length 151924, version 0.0
downloaded
Chrome Cache Entry: 409
ASCII text, with very long lines (672)
downloaded
Chrome Cache Entry: 410
PNG image data, 82 x 258, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 411
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 412
JSON data
downloaded
Chrome Cache Entry: 413
ASCII text, with very long lines (1837)
dropped
Chrome Cache Entry: 414
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 415
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 416
ASCII text, with very long lines (42915)
downloaded
Chrome Cache Entry: 417
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 418
ASCII text, with very long lines (64762), with CRLF line terminators
dropped
Chrome Cache Entry: 419
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 420
JSON data
downloaded
Chrome Cache Entry: 421
JSON data
dropped
Chrome Cache Entry: 422
JSON data
dropped
Chrome Cache Entry: 423
ASCII text, with very long lines (20116), with no line terminators
downloaded
Chrome Cache Entry: 424
JSON data
dropped
Chrome Cache Entry: 425
PNG image data, 150 x 54, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 426
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 427
PNG image data, 452 x 444, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 428
ASCII text, with very long lines (2936)
downloaded
Chrome Cache Entry: 429
ASCII text, with very long lines (33654)
downloaded
Chrome Cache Entry: 430
JSON data
downloaded
Chrome Cache Entry: 431
ASCII text, with very long lines (20082), with no line terminators
downloaded
Chrome Cache Entry: 432
ASCII text, with very long lines (29173), with no line terminators
downloaded
Chrome Cache Entry: 433
JSON data
downloaded
Chrome Cache Entry: 434
JSON data
dropped
Chrome Cache Entry: 435
JSON data
dropped
Chrome Cache Entry: 436
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 437
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 438
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 439
GIF image data, version 89a, 24 x 24
dropped
Chrome Cache Entry: 440
ASCII text, with very long lines (11252)
downloaded
Chrome Cache Entry: 441
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
downloaded
Chrome Cache Entry: 442
Unicode text, UTF-8 text, with very long lines (58392)
dropped
Chrome Cache Entry: 443
ASCII text, with very long lines (20946), with CRLF line terminators
downloaded
Chrome Cache Entry: 444
ASCII text, with very long lines (24306), with CRLF line terminators
downloaded
Chrome Cache Entry: 445
ASCII text, with very long lines (2936)
dropped
Chrome Cache Entry: 446
PNG image data, 59 x 10, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 447
ASCII text, with very long lines (33654)
dropped
Chrome Cache Entry: 448
ASCII text, with very long lines (14666), with no line terminators
dropped
Chrome Cache Entry: 449
ASCII text, with very long lines (65457)
downloaded
Chrome Cache Entry: 450
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 451
PNG image data, 59 x 10, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 452
ASCII text, with very long lines (65437)
downloaded
Chrome Cache Entry: 453
ASCII text, with very long lines (11667), with no line terminators
dropped
Chrome Cache Entry: 454
JSON data
downloaded
Chrome Cache Entry: 455
ASCII text, with very long lines (8369), with no line terminators
downloaded
Chrome Cache Entry: 456
ASCII text, with very long lines (22010)
dropped
Chrome Cache Entry: 457
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 458
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
downloaded
Chrome Cache Entry: 459
ASCII text, with very long lines (60197)
downloaded
Chrome Cache Entry: 460
ASCII text, with very long lines (616)
dropped
Chrome Cache Entry: 461
ASCII text, with very long lines (14762)
dropped
Chrome Cache Entry: 462
JSON data
dropped
Chrome Cache Entry: 463
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 464
ASCII text, with very long lines (11667), with no line terminators
downloaded
Chrome Cache Entry: 465
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 466
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 467
Unicode text, UTF-8 text, with very long lines (12695)
dropped
Chrome Cache Entry: 468
ASCII text, with very long lines (22010)
downloaded
Chrome Cache Entry: 469
Unicode text, UTF-8 text, with very long lines (1592)
dropped
Chrome Cache Entry: 470
ASCII text, with very long lines (30298)
downloaded
Chrome Cache Entry: 471
Unicode text, UTF-8 text, with very long lines (1592)
downloaded
Chrome Cache Entry: 472
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 473
ASCII text, with very long lines (20116), with no line terminators
dropped
Chrome Cache Entry: 474
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 475
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 476
ASCII text, with very long lines (7694)
downloaded
Chrome Cache Entry: 477
ASCII text, with very long lines (30663)
downloaded
Chrome Cache Entry: 478
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 479
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 480
Unicode text, UTF-8 text, with very long lines (65308), with no line terminators
dropped
Chrome Cache Entry: 481
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 482
ASCII text, with very long lines (14762)
downloaded
Chrome Cache Entry: 483
JSON data
dropped
Chrome Cache Entry: 484
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 485
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 486
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 487
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 488
ASCII text, with very long lines (57788)
downloaded
Chrome Cache Entry: 489
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 490
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 491
ASCII text, with very long lines (41116)
dropped
Chrome Cache Entry: 492
JSON data
downloaded
Chrome Cache Entry: 493
JSON data
downloaded
Chrome Cache Entry: 494
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 495
ASCII text, with very long lines (65394)
downloaded
Chrome Cache Entry: 496
ASCII text, with very long lines (22548), with no line terminators
downloaded
Chrome Cache Entry: 497
ASCII text, with very long lines (41116)
downloaded
Chrome Cache Entry: 498
ASCII text, with very long lines (30497), with no line terminators
downloaded
Chrome Cache Entry: 499
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
dropped
Chrome Cache Entry: 500
MS Windows cursor resource - 1 icon, 32x32, hotspot @16x16
downloaded
Chrome Cache Entry: 501
ASCII text, with very long lines (65451)
dropped
Chrome Cache Entry: 502
ASCII text, with very long lines (2224), with no line terminators
dropped
Chrome Cache Entry: 503
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
downloaded
Chrome Cache Entry: 504
ASCII text, with very long lines (4615)
downloaded
Chrome Cache Entry: 505
ASCII text, with very long lines (65457)
dropped
Chrome Cache Entry: 506
JSON data
dropped
Chrome Cache Entry: 507
HTML document, ASCII text, with very long lines (337), with CRLF line terminators
downloaded
Chrome Cache Entry: 508
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 509
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 510
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 511
ASCII text, with very long lines (32011), with CRLF line terminators
dropped
Chrome Cache Entry: 512
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 513
ASCII text, with very long lines (5949), with no line terminators
dropped
Chrome Cache Entry: 514
ASCII text, with very long lines (7708)
downloaded
There are 254 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2208 --field-trial-handle=1952,i,1742604777212346186,10490191622210278842,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://1drv.ms/o/c/76471f3776916fd0/EomjtsItbi9Ag0bnzrJDx08BhxVWepFoAXrJFoYeR9IZ0A?e=5%3aEFCh5b&sharingv2=true&fromShare=true&at=9"

URLs

Name
IP
Malicious
https://1drv.ms/o/c/76471f3776916fd0/EomjtsItbi9Ag0bnzrJDx08BhxVWepFoAXrJFoYeR9IZ0A?e=5%3aEFCh5b&sharingv2=true&fromShare=true&at=9
malicious
https://1drv.ms/o/c/76471f3776916fd0/EomjtsItbi9Ag0bnzrJDx08BhxVWepFoAXrJFoYeR9IZ0A?e=5%3aEFCh5b&sharingv2=true&fromShare=true&at=9
13.107.42.12
malicious
https://roaming.officeapps.partner.office365.cn/rs/v1/settings
unknown
https://www.onenote.com/officeaddins/meetings?ui=fil-PH&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=az-Latn-AZ&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=hy-AM&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=is-IS&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=mi-NZ&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=kok-IN&temporaryLocalization=true
unknown
http://www.opensource.org/licenses/mit-license.php
unknown
https://www.onenote.com/officeaddins/meetings?ui=ky-KG&temporaryLocalization=true
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/8d7b21457ba24766/1729785106325/6f3139b1deeb106748e9957d1db230b01f4dc8bcedcbab15d8aaf2da7189cf4a/xaqRYNrtNwA4T8_
104.18.95.41
https://www.onenote.com/officeaddins/meetings?ui=sk-SK&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ca-ES-valencia&temporaryLocalization=true
unknown
https://fa000000128.resources.office.net:3000/index.html
unknown
https://www.onenote.com/officeaddins/meetings?ui=ka-GE&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=tk-TM&temporaryLocalization=true
unknown
https://a.nel.cloudflare.com/report/v4?s=wu3hal5hOBDQe6aLEqIpAkaDR2DQzj61MaIF7cfFy7TvjA%2BYkshXv0iIfVWr2HGSNqHP6i8FzrorjhmxDholbjA16fhRXG92uhaGMrViN3YqWPOU6nCmZ5WcbdWmLw%3D%3D
35.190.80.1
https://augloop.office.com/v2;394866fc-eedb-4f01-8536-3ff84b16be2a;liveprofilecard.access;https://sh
unknown
https://js.monitor.azure.com/scripts/c/ms.shared.analytics.mectrl-3.gbl.min.js
13.107.253.45
https://www.onenote.com/officeaddins/meetings?ui=et-EE&temporaryLocalization=true
unknown
https://cdn.fluidpreview.office.net/fluid/prod
unknown
https://my.microsoftpersonalcontent.com
unknown
https://www.onenote.com/officeaddins/meetings?ui=mt-MT&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=sr-Latn-RS&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ne-NP&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ru-RU&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=sl-SI&temporaryLocalization=true
unknown
https://forms.office.com
unknown
https://www.onenote.com/officeaddins/meetings?ui=bn-BD&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=vi-VN&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=af-ZA&temporaryLocalization=true
unknown
https://whiteboard.microsoft.scloud
unknown
https://augloop-int.officeppe.com/v2
unknown
https://aka.ms/Officeaddins
unknown
https://www.onenote.com/officeaddins/meetings?ui=mn-MN&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ro-RO&temporaryLocalization=true
unknown
https://consent.config.office.com/consentcheckin/v1.0/consents
unknown
https://www.onenote.com/officeaddins/meetings?ui=cs-CZ&temporaryLocalization=true
unknown
https://fa000000096.resources.office.net
unknown
https://www.onenote.com/officeaddins/meetings?ui=pl-PL&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=prs-AF&temporaryLocalization=true
unknown
https://whiteboard.office.com/root/index.fluid.js
unknown
https://www.onenote.com/officeaddins/meetings?ui=sv-SE&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=uk-UA&temporaryLocalization=true
unknown
https://support.office.com/article/7afcb4f3-4aa2-443a-9b08-125a5d692576
unknown
https://support.office.com/article/ec43ed03-eb3c-4a10-8d9d-e9e5433c9ed2
unknown
https://www.onenote.com/officeaddins/meetings?ui=ar-SA&temporaryLocalization=true
unknown
https://roaming.osi.office.de/rs/v1/settings
unknown
https://www.onenote.com/officeaddins/meetings?ui=he-IL&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=nso-ZA&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=mk-MK&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=zu-ZA&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=lt-LT&temporaryLocalization=true
unknown
https://reactjs.org/link/react-polyfills
unknown
https://www.onenote.com/officeaddins/meetings?ui=sq-AL&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=pt-PT&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/learningtools/?et=
13.107.253.45
https://www.onenote.com/officeaddins/meetings?ui=tg-Cyrl-TJ&temporaryLocalization=true
unknown
https://mann.ru.com/9?ai=xd
https://cdn.fluidpreview.office.net/fluid/gcc
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/8d7b21457ba24766/1729785106325/9N0aiT9M7lwIIf7
104.18.95.41
https://www.onenote.com/officeaddins/meetings?ui=nb-NO&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=zh-TW&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=tr-TR&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=fr-FR&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=wo-SN&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=de-DE&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=kn-IN&temporaryLocalization=true
unknown
https://fa000000096.resources.office.net/f7024bdc-7caf-4ca8-807d-2908f09640d6/1.0.2210.23001/en-us_w
unknown
https://www.onenote.com/officeaddins/mathassistant
unknown
https://googleweblight.com/
https://forms.officeppe.com
unknown
https://common.online.office.com/suite/RemoteUls.ashx?usid=d0fa52e3-0f3d-e35c-d61d-a94526612b29&officeserverversion=
52.108.8.12
https://www.onenote.com/officeaddins/meetings?ui=bn-IN&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=fi-FI&temporaryLocalization=true
unknown
https://localcdn.centro-dev.com:5555/floodgate.bundle.js.map
unknown
https://www.onenote.com/officeaddins/meetings?ui=ms-MY&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=te-IN&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ml-IN&temporaryLocalization=true
unknown
http://hammerjs.github.io/
unknown
https://whiteboard.office365.us
unknown
https://www.onenote.com/officeaddins/meetings?ui=id-ID&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ca-ES&temporaryLocalization=true
unknown
https://edog.onenote.com
unknown
https://whiteboard.eaglex.ic.gov
unknown
https://onedrive.live.com/personal/76471f3776916fd0/_layouts/15/Doc.aspx?sourcedoc=%7Bc2b6a389-6e2d-402f-8346-e7ceb243c74f%7D&action=default&fromShare=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&slrid=64165da1-90a4-6000-a17a-a7453b5ea7e9&originalPath=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_cnRpbWU9d3B6TnEwUDAzRWc&CID=e20b8c70-5808-4803-b162-15b8d742ff39&_SRM=0:G:36
https://www.onenote.com/officeaddins/meetings?ui=tt-RU&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=am-ET&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=es-ES&temporaryLocalization=true
unknown
https://roaming.osi.apps.mil/rs/v1/settings
unknown
https://fa000000096.resources.office.net/f7024bdc-7caf-4ca8-807d-2908f09640d6/1.0.2401.26003/en-us_w
unknown
https://www.onenote.com/officeaddins/meetings?ui=tn-ZA&temporaryLocalization=true
unknown
https://amcdn.msftauth.net/me?partner=OneNoteOnline&version=latest&market=EN-US&wrapperId=suiteshell
13.107.246.45
https://www.onenote.com/officeaddins/meetings?ui=pt-BR&temporaryLocalization=true
unknown
https://cdn.dev.fluidpreview.office.net/fluid/dev
unknown
https://www.onenote.com/officeaddins/meetings?ui=yo-NG&temporaryLocalization=true
unknown
https://cdn.fluidpreview.office.net
unknown
https://onedrive.live.com/:o:/g/personal/76471F3776916FD0/EomjtsItbi9Ag0bnzrJDx08BhxVWepFoAXrJFoYeR9IZ0A?resid=76471F3776916FD0!sc2b6a3896e2d402f8346e7ceb243c74f&ithint=onenote&e=5%3aEFCh5b&sharingv2=true&fromShare=true&at=9&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05
13.107.137.11
https://www.onenote.com/officeaddins/meetings?ui=ja-JP&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/RemoteUls.ashx
13.107.253.45
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
s-part-0044.t-0009.fb-t-msedge.net
13.107.253.72
a.nel.cloudflare.com
35.190.80.1
s-part-0017.t-0009.t-msedge.net
13.107.246.45
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
s-part-0039.t-0009.fb-t-msedge.net
13.107.253.67
1drv.ms
13.107.42.12
dual-spov-0006.spov-msedge.net
13.107.137.11
wac-0003.wac-msedge.net
52.108.9.12
googleweblight.com
142.250.184.193
challenges.cloudflare.com
104.18.95.41
office.com
13.107.6.156
www.google.com
142.250.185.132
mann.ru.com
172.67.181.178
sni1gl.wpc.sigmacdn.net
152.199.21.175
js.monitor.azure.com
unknown
www.office.com
unknown
ajax.aspnetcdn.com
unknown
m365cdn.nel.measure.office.net
unknown
fa000000110.resources.office.net
unknown
onenoteonline.nel.measure.office.net
unknown
fa000000138.resources.office.net
unknown
onedrive.live.com
unknown
amcdn.msftauth.net
unknown
www.onenote.com
unknown
messaging.engagement.office.com
unknown
fa000000096.resources.office.net
unknown
fa000000012.resources.office.net
unknown
fa000000111.resources.office.net
unknown
fa000000128.resources.office.net
unknown
storage.live.com
unknown
common.online.office.com
unknown
login.microsoftonline.com
unknown
spoprod-a.akamaihd.net
unknown
There are 23 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.107.246.45
s-part-0017.t-0009.t-msedge.net
United States
192.168.2.4
unknown
unknown
52.108.9.12
wac-0003.wac-msedge.net
United States
35.190.80.1
a.nel.cloudflare.com
United States
142.250.185.68
unknown
United States
142.250.186.36
unknown
United States
142.250.184.193
googleweblight.com
United States
13.107.253.67
s-part-0039.t-0009.fb-t-msedge.net
United States
104.18.95.41
challenges.cloudflare.com
United States
13.107.42.12
1drv.ms
United States
13.107.253.72
s-part-0044.t-0009.fb-t-msedge.net
United States
239.255.255.250
unknown
Reserved
152.199.21.175
sni1gl.wpc.sigmacdn.net
United States
192.168.2.17
unknown
unknown
104.18.94.41
unknown
United States
172.217.18.97
unknown
United States
13.107.137.11
dual-spov-0006.spov-msedge.net
United States
13.107.253.45
s-part-0017.t-0009.fb-t-msedge.net
United States
142.250.185.132
www.google.com
United States
52.108.8.12
unknown
United States
172.67.181.178
mann.ru.com
United States
104.21.56.85
unknown
United States
There are 12 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://onedrive.live.com/personal/76471f3776916fd0/_layouts/15/Doc.aspx?sourcedoc=%7Bc2b6a389-6e2d-402f-8346-e7ceb243c74f%7D&action=default&fromShare=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&slrid=64165da1-90a4-6000-a17a-a7453b5ea7e9&originalPath=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_cnRpbWU9d3B6TnEwUDAzRWc&CID=e20b8c70-5808-4803-b162-15b8d742ff39&_SRM=0:G:36
https://onedrive.live.com/personal/76471f3776916fd0/_layouts/15/Doc.aspx?sourcedoc=%7Bc2b6a389-6e2d-402f-8346-e7ceb243c74f%7D&action=default&fromShare=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&slrid=64165da1-90a4-6000-a17a-a7453b5ea7e9&originalPath=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_cnRpbWU9d3B6TnEwUDAzRWc&CID=e20b8c70-5808-4803-b162-15b8d742ff39&_SRM=0:G:36
https://onedrive.live.com/edit.aspx?resid=76471F3776916FD0!sc2b6a3896e2d402f8346e7ceb243c74f&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&wd=target%28Quick%20Notes.one%7Ca287041b-8d97-4636-b8f2-41bad06f13a0%2FPhillip%20Valdez%20invited%20you%20to%20access%20a%20fileHere%27s%20%7C373da514-f9a0-4ae3-aa54-742cb0c19dde%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/edit.aspx?resid=76471F3776916FD0!sc2b6a3896e2d402f8346e7ceb243c74f&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&wd=target%28Quick%20Notes.one%7Ca287041b-8d97-4636-b8f2-41bad06f13a0%2FPhillip%20Valdez%20invited%20you%20to%20access%20a%20fileHere%27s%20%7C373da514-f9a0-4ae3-aa54-742cb0c19dde%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/edit.aspx?resid=76471F3776916FD0!sc2b6a3896e2d402f8346e7ceb243c74f&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&wd=target%28Quick%20Notes.one%7Ca287041b-8d97-4636-b8f2-41bad06f13a0%2FPhillip%20Valdez%20invited%20you%20to%20access%20a%20fileHere%27s%20%7C373da514-f9a0-4ae3-aa54-742cb0c19dde%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/edit.aspx?resid=76471F3776916FD0!sc2b6a3896e2d402f8346e7ceb243c74f&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&wd=target%28Quick%20Notes.one%7Ca287041b-8d97-4636-b8f2-41bad06f13a0%2FPhillip%20Valdez%20invited%20you%20to%20access%20a%20fileHere%27s%20%7C373da514-f9a0-4ae3-aa54-742cb0c19dde%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/edit.aspx?resid=76471F3776916FD0!sc2b6a3896e2d402f8346e7ceb243c74f&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&wd=target%28Quick%20Notes.one%7Ca287041b-8d97-4636-b8f2-41bad06f13a0%2FPhillip%20Valdez%20invited%20you%20to%20access%20a%20fileHere%27s%20%7C373da514-f9a0-4ae3-aa54-742cb0c19dde%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/edit.aspx?resid=76471F3776916FD0!sc2b6a3896e2d402f8346e7ceb243c74f&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&wd=target%28Quick%20Notes.one%7Ca287041b-8d97-4636-b8f2-41bad06f13a0%2FPhillip%20Valdez%20invited%20you%20to%20access%20a%20fileHere%27s%20%7C373da514-f9a0-4ae3-aa54-742cb0c19dde%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/edit.aspx?resid=76471F3776916FD0!sc2b6a3896e2d402f8346e7ceb243c74f&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&wd=target%28Quick%20Notes.one%7Ca287041b-8d97-4636-b8f2-41bad06f13a0%2FPhillip%20Valdez%20invited%20you%20to%20access%20a%20fileHere%27s%20%7C373da514-f9a0-4ae3-aa54-742cb0c19dde%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/edit.aspx?resid=76471F3776916FD0!sc2b6a3896e2d402f8346e7ceb243c74f&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&wd=target%28Quick%20Notes.one%7Ca287041b-8d97-4636-b8f2-41bad06f13a0%2FPhillip%20Valdez%20invited%20you%20to%20access%20a%20fileHere%27s%20%7C373da514-f9a0-4ae3-aa54-742cb0c19dde%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/edit.aspx?resid=76471F3776916FD0!sc2b6a3896e2d402f8346e7ceb243c74f&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&wd=target%28Quick%20Notes.one%7Ca287041b-8d97-4636-b8f2-41bad06f13a0%2FPhillip%20Valdez%20invited%20you%20to%20access%20a%20fileHere%27s%20%7C373da514-f9a0-4ae3-aa54-742cb0c19dde%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/edit.aspx?resid=76471F3776916FD0!sc2b6a3896e2d402f8346e7ceb243c74f&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&wd=target%28Quick%20Notes.one%7Ca287041b-8d97-4636-b8f2-41bad06f13a0%2FPhillip%20Valdez%20invited%20you%20to%20access%20a%20fileHere%27s%20%7C373da514-f9a0-4ae3-aa54-742cb0c19dde%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/edit.aspx?resid=76471F3776916FD0!sc2b6a3896e2d402f8346e7ceb243c74f&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy83NjQ3MWYzNzc2OTE2ZmQwL0VvbWp0c0l0Ymk5QWcwYm56ckpEeDA4Qmh4VldlcEZvQVhySkZvWWVSOUlaMEE_ZT01OkVGQ2g1YiZzaGFyaW5ndjI9dHJ1ZSZmcm9tU2hhcmU9dHJ1ZSZhdD05&wd=target%28Quick%20Notes.one%7Ca287041b-8d97-4636-b8f2-41bad06f13a0%2FPhillip%20Valdez%20invited%20you%20to%20access%20a%20fileHere%27s%20%7C373da514-f9a0-4ae3-aa54-742cb0c19dde%2F%29&wdorigin=NavigationUrl
https://mann.ru.com/9?ai=xd
https://mann.ru.com/9?ai=xd
https://mann.ru.com/9?ai=xd
https://mann.ru.com/9?ai=xd&__cf_chl_tk=iBAVvT1q0k_Ls9aZfzbK2qfH49f0zYwhU0jEUzklYIc-1729785099-1.0.1.1-8h8.Ro3xP9Pql1_Emvx.x3Z6MCdAIZ_cuji_ogYf0K8
https://googleweblight.com/i?u=google.com
https://googleweblight.com/
There are 9 hidden doms, click here to show them.