Windows
Analysis Report
https://forms.office.com/e/DXEauFZHZH
Overview
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 60% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 7028 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6364 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2192 --fi eld-trial- handle=197 2,i,162086 7940274382 6994,93678 4943334901 894,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 3680 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://forms .office.co m/e/DXEauF ZHZH" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Window detected: |
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 142.250.184.228 | true | false | unknown | |
forms.office.com | unknown | unknown | false | unknown | |
c.office.com | unknown | unknown | false | unknown | |
cdn.forms.office.net | unknown | unknown | false | unknown | |
lists.office.com | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
13.69.116.104 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
1.1.1.1 | unknown | Australia | 13335 | CLOUDFLARENETUS | false | |
2.21.22.168 | unknown | European Union | 20940 | AKAMAI-ASN1EU | false | |
52.111.243.107 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
13.107.21.237 | unknown | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
74.125.133.84 | unknown | United States | 15169 | GOOGLEUS | false | |
13.107.6.194 | unknown | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
142.250.185.138 | unknown | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.185.131 | unknown | United States | 15169 | GOOGLEUS | false | |
13.74.129.1 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
142.250.184.206 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.184.228 | www.google.com | United States | 15169 | GOOGLEUS | false | |
13.69.239.72 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1541913 |
Start date and time: | 2024-10-25 10:10:34 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://forms.office.com/e/DXEauFZHZH |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | stream |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@16/31@18/79 |
- Exclude process from analysis (whitelisted): svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.131, 74.125.133.84, 142.250.184.206, 13.107.6.194, 34.104.35.123, 2.21.22.168, 2.21.22.185
- Excluded domains from analysis (whitelisted): a1894.dscms.akamai.net, b-0039.b-msedge.net, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, cdn.forms.office.net.edgesuite.net, clientservices.googleapis.com, clients.l.google.com, forms.office.com.b-0039.b-msedge.net
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://forms.office.com/e/DXEauFZHZH
Input | Output |
---|---|
URL: https://forms.office.com/pages/responsepage.aspx?id=LpxU6C4NYEWVkTGGdV_Fh7Vl0TyGg49KpN60kKRUvmJUNThGNkNLMklDNDhIVFMxRjMwT0E5SFNTViQlQCN0PWcu&route=shorturl Model: claude-3-haiku-20240307 | ```json { "contains_trigger_text": true, "trigger_text": "Start now", "prominent_button_name": "Start now", "text_input_field_labels": "unknown", "pdf_icon_visible": false, "has_visible_captcha": false, "has_urgent_text": false, "has_visible_qrcode": false } |
URL: https://forms.office.com/pages/responsepage.aspx?id=LpxU6C4NYEWVkTGGdV_Fh7Vl0TyGg49KpN60kKRUvmJUNThGNkNLMklDNDhIVFMxRjMwT0E5SFNTViQlQCN0PWcu&route=shorturl Model: claude-3-haiku-20240307 | ```json { "contains_trigger_text": true, "trigger_text": "Employer - Placement Completion Form LTU", "prominent_button_name": "Start now", "text_input_field_labels": "unknown", "pdf_icon_visible": false, "has_visible_captcha": false, "has_urgent_text": false, "has_visible_qrcode": false } |
URL: https://forms.office.com/pages/responsepage.aspx?id=LpxU6C4NYEWVkTGGdV_Fh7Vl0TyGg49KpN60kKRUvmJUNThGNkNLMklDNDhIVFMxRjMwT0E5SFNTViQlQCN0PWcu&route=shorturl Model: claude-3-haiku-20240307 | ```json { "brands": [ "Employer - Placement Completion Form LTU" ] } |
URL: https://forms.office.com/pages/responsepage.aspx?id=LpxU6C4NYEWVkTGGdV_Fh7Vl0TyGg49KpN60kKRUvmJUNThGNkNLMklDNDhIVFMxRjMwT0E5SFNTViQlQCN0PWcu&route=shorturl Model: claude-3-haiku-20240307 | ```json { "brands": [ "Microsoft 365" ] } |
URL: https://forms.office.com/pages/responsepage.aspx?id=LpxU6C4NYEWVkTGGdV_Fh7Vl0TyGg49KpN60kKRUvmJUNThGNkNLMklDNDhIVFMxRjMwT0E5SFNTViQlQCN0PWcu&route=shorturl Model: claude-3-haiku-20240307 | ```json { "contains_trigger_text": false, "trigger_text": "unknown", "prominent_button_name": "unknown", "text_input_field_labels": [ "Student's Full Name", "Location", "Estimated Start Date", "Actual End Date", "Total Placement Hours Completed" ], "pdf_icon_visible": false, "has_visible_captcha": false, "has_urgent_text": false, "has_visible_qrcode": false } |
URL: https://forms.office.com/pages/responsepage.aspx?id=LpxU6C4NYEWVkTGGdV_Fh7Vl0TyGg49KpN60kKRUvmJUNThGNkNLMklDNDhIVFMxRjMwT0E5SFNTViQlQCN0PWcu&route=shorturl Model: claude-3-haiku-20240307 | ```json { "brands": [ "LTU" ] } |
URL: https://forms.office.com/pages/responsepage.aspx?id=LpxU6C4NYEWVkTGGdV_Fh7Vl0TyGg49KpN60kKRUvmJUNThGNkNLMklDNDhIVFMxRjMwT0E5SFNTViQlQCN0PWcu&route=shorturl Model: claude-3-haiku-20240307 | ```json { "contains_trigger_text": true, "trigger_text": "To view secured document, click here", "prominent_button_name": "unknown", "text_input_field_labels": [ "Student's Full Name", "Location", "Estimated Start Date", "Actual End Date", "Total Placement Hours Completed" ], "pdf_icon_visible": false, "has_visible_captcha": false, "has_urgent_text": false, "has_visible_qrcode": false } |
URL: https://forms.office.com/pages/responsepage.aspx?id=LpxU6C4NYEWVkTGGdV_Fh7Vl0TyGg49KpN60kKRUvmJUNThGNkNLMklDNDhIVFMxRjMwT0E5SFNTViQlQCN0PWcu&route=shorturl Model: claude-3-haiku-20240307 | ```json { "brands": [ "LTU" ] } |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9736694650411843 |
Encrypted: | false |
SSDEEP: | |
MD5: | F6B023B2BF184AF4FC17243C774D4167 |
SHA1: | A679397786CC7BDA68C7AB5F01A121FAFC33F9B6 |
SHA-256: | 671F573A5A7FDD638FEC953D7F5921DCD14A74922460ECA0BC734DFFB0EA97E8 |
SHA-512: | 71B441867AD5AFB713743078369A2001DB49F12E3D2F6DB94A72D2400A9F0D99A04A55ACF9A7A84D776CA165860E7E6D4BE6E22870F95D42C6B2B2DB010A6C88 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.989664149999851 |
Encrypted: | false |
SSDEEP: | |
MD5: | 38B7C9D00B17D6AD9B99044A96238010 |
SHA1: | 3427A17AB78928F93432F821B572C0CDA2E61DB1 |
SHA-256: | B0EF53F7C92319D88C2F2232BDF8C37E2AD6F2BF2411D24692FA6701E09AA78D |
SHA-512: | 5C3086DA1169B143E4B039E34AD4A455C574BC85B9E56F97A1DB57705E8625635B0CD6566932D360DFB68BCA42104B014AC4B77CEFF94916D8BEDBD3F7D94135 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 3.9993052679646937 |
Encrypted: | false |
SSDEEP: | |
MD5: | EAF48C1766BF82CB9222A07C4F0BB997 |
SHA1: | 1B9B0EDD53B399D9D6673E52CF40EF252F710B4D |
SHA-256: | 87DC211805EF7D9C76A62F77FA9FC1E3057626B0292E61A67715CD9E8253D892 |
SHA-512: | AA8725872126BD34BC7FBF238D315EB5F101877E411B17D819275DBA1D6E99CFC64C03717502370379A9F2E7B0510DF319C67470DF1D47D78D463B8F16C3ED1F |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.988076793736384 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5E3A76F4A2A57FD80BAA1AE3998A4327 |
SHA1: | E30EC14F7772EBEEB36E90C887C0A3A606EFB42A |
SHA-256: | F9E6CA5118EF33F409334D0D8E019659A4B23BF5600FFF2878AF7069599FF374 |
SHA-512: | AD93D2B992E187B94D91D966D8162CA5DA7CEC06C8324E06C48A5A27CBF217F1EC5EB88B6D3BD3A7566E275767C057F35F9CA4990F788C635516276AFEE666EA |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9764800653445223 |
Encrypted: | false |
SSDEEP: | |
MD5: | EB42A36E5AFBA1E1BAB1BAD08AD22027 |
SHA1: | 2040DF69E0613CFF0F3C84EF2A6EB3F1814D9EC0 |
SHA-256: | 75850625FC76EF9B3A4E1C8108FF0088435FE56F312C6A0A17A09D60D2382656 |
SHA-512: | 38824E3020EDE9315FA85E7857E38645F424E3B2F1C99706B8711E90DD75613A6B2C7FAB02B94963799567C70B31D8BB02A2A96608C3113BBA800C3431E3BF51 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.986595573974258 |
Encrypted: | false |
SSDEEP: | |
MD5: | A9105F0C73564F4F909688A0DE975316 |
SHA1: | 695DBD831AA089E7135563C853822C504E7412FE |
SHA-256: | 5C4FCD581CF52A26A8330E7ECB22D792B68BE01CF170E2F0C314965B3AECFD6F |
SHA-512: | 9DA2890D4026C9C1FFCE02FDD30E284410AF746CA25A0E7665F5EF412C773ADC64532A2D99ED0848BFE6395E8AA9110CDC6B9E36F7395D7FE4334E8DDC335686 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 91093 |
Entropy (8bit): | 5.314440469403905 |
Encrypted: | false |
SSDEEP: | |
MD5: | C22370F1D6095C0349E47D38C76A7E22 |
SHA1: | FB2EBFA59ED1403E3112DDA37250AA5C20AC14BF |
SHA-256: | F2989F5E4C60FC8C4F192321376EE85D09F5B35685816031C61420D1A6D50DDA |
SHA-512: | D3F79EC8978FAFA2C789D136C93CD3A303217477C4F8DC44051857509CCADB893D518CE0D3A83CD448D586FD3AA3B827A560DF9519C81C07272F66D25104881E |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 430465 |
Entropy (8bit): | 5.663044436315742 |
Encrypted: | false |
SSDEEP: | |
MD5: | A390E10AD764FF24246B7B1325BBE8E6 |
SHA1: | 5C6B437BAC767BF792807A2D347DE03D23D5CFE9 |
SHA-256: | F9EC4B44827E1211E5DA1DDCE231052F2488904C48DE5B6A05E5D8CA96764509 |
SHA-512: | B5774C7A99770EEEFBE2824A0BCE0634C8B2F94AAEB609D4E7BFCB8F09B4B3C0CFE014384B0C88F26DB6A781F594770C9D11DA04CDF7BFCA90AD3988382EE692 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 64 |
Entropy (8bit): | 4.29778038497242 |
Encrypted: | false |
SSDEEP: | |
MD5: | FCF3FEB4B2AE9F612ABF9D6BEFF77E1C |
SHA1: | 9CC10A8DE1C67807DC11DB357A009336B8B69417 |
SHA-256: | AAA53B431E925D6783A28B3EC05897DEB1D72B8383CAC308FAC7FB3629550CE8 |
SHA-512: | 5D3E1C75B1D6C6C3DFD62AA1FD7AE93F5C422B61E202CB767601E92BEEDDFC454B90A026733B944B3359D5D8C92CF41D98B2160105CFE5F2225258C76D3398D4 |
Malicious: | false |
Reputation: | unknown |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISLAlpIpyQVMvpAhIFDZFhlU4SBQ2RYZVOEgUN8oa8-xIFDUBhihYSBQ2RYZVO?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 44745 |
Entropy (8bit): | 5.357853275003685 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0055D5757DB41BAD929E5C8B9B726180 |
SHA1: | FBA7C3D94C0FE43AF69BDCFC5186539E1DDE2EFF |
SHA-256: | 37D099733E4901725976E46366372584C0BB88EA5B32D288BAB5F996736725C4 |
SHA-512: | 674270C68411956F88AC9675948229D129FC00125F80DF3A37DC0004D0F89ADD5C07C09648D51A32F1179DA24567E6D74ABFE2BB58BAE51D200E06C097CC806C |
Malicious: | false |
Reputation: | unknown |
URL: | https://cdn.forms.office.net/forms/scripts/dists/dll-dompurify.min.11aa374.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1152 |
Entropy (8bit): | 5.363646055902644 |
Encrypted: | false |
SSDEEP: | |
MD5: | 19F88A9690395484D35F200B1BD999A9 |
SHA1: | 43033D885678C2E3BDCB23070E018E8BDFB55A7F |
SHA-256: | 600C36C9E419E1410A833B42D3257CFC535395253A8DD9F63D6A6AB1ADEB366C |
SHA-512: | 46DE4DC998602E551ED1E7D5F276DCFA3DCDDF340A6863E2A64E0684500490916AD9430127EC4BD6B3DB1B5E55B31E4B64C498642D055EF7C7DA571961798CEB |
Malicious: | false |
Reputation: | unknown |
URL: | https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.sw.9c1bfed.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 490620 |
Entropy (8bit): | 5.47717424089769 |
Encrypted: | false |
SSDEEP: | |
MD5: | B8B7DA7613290C36E59A1519C79667F1 |
SHA1: | E76EE66610B05488FE9CE04CB2CD18C4E7B84556 |
SHA-256: | CF56316FAE47E55B86235AE87FE6C58D3955292FF0830FAF5C57E58714F82916 |
SHA-512: | 7CBF27EBBC4A44A250BD14F2EC4D8D364691650417AC535508B06E034F5C3BB9EEC90DBADB17EFABB29757F437A581EF1EA53519B629F66C925D223E422139C0 |
Malicious: | false |
Reputation: | unknown |
URL: | https://cdn.forms.office.net/forms/scripts/dists/light-response-page.min.c6fbf67.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 72 |
Entropy (8bit): | 4.241202481433726 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9E576E34B18E986347909C29AE6A82C6 |
SHA1: | 532C767978DC2B55854B3CA2D2DF5B4DB221C934 |
SHA-256: | 88BDF5AF090328963973990DE427779F9C4DF3B8E1F5BADC3D972BAC3087006D |
SHA-512: | 5EF6DCFFD93434D45760888BF4B95FF134D53F34DA9DC904AD3C5EBEDC58409073483F531FEA4233869ED3EC75F38B022A70B2E179A5D3A13BDB10AB5C46B124 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 176122 |
Entropy (8bit): | 5.332897534481064 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0403F233BF93504715F3AABE0ADA2E6D |
SHA1: | 197ED5FD6CAF05064320D723AB96E833B66FCD91 |
SHA-256: | 28CEFA7AAB4CF389A65BED523E7FC95F191892589BBA1A8AEAF2D64382742A99 |
SHA-512: | 00FF2A8AE02AD38A96868FC4F4E7EEB073CC0D9D8B1D03DC6D7246250EF9D4F35D8224E1303900E07C9E75B1187505F93310E69A71C8132849B626897EDC8B54 |
Malicious: | false |
Reputation: | unknown |
URL: | https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.fluent.435ff9c.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 32551 |
Entropy (8bit): | 5.528130807927231 |
Encrypted: | false |
SSDEEP: | |
MD5: | 63F1E8204E8D1285BD9F9381D726CB6E |
SHA1: | 69CE73B8CD37D50D473063E390AF7AE5835F00B3 |
SHA-256: | 44D94C65118236B49CEADA980FC1E1BE9CB3B90EBC343DB335EB39D80DBC7070 |
SHA-512: | 379D80ECB37F39F0C88C70C5EE0A0741204839CCA9B388CB9213D0BE7E9AFF69AC785941081F1A481646B08635209CB1BCFD4C7640F0E395DF5474892E0C2F13 |
Malicious: | false |
Reputation: | unknown |
URL: | https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.lrp_saveresponse.130cef2.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 35075 |
Entropy (8bit): | 4.78247542504543 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2260CFACC25DE59539D0B1D7A50F9270 |
SHA1: | 84FECAFAFF77917530F170A1D3EBF70A51A9B7D1 |
SHA-256: | 9F00DFD9D0844DEA7FED92119F0E4149C4D6334169704CE875B14C1AC84E6629 |
SHA-512: | 4A7733F93FF56172E4D861A84F3059F2B9C4266989399D3F6D29F16D3B24BF382CA5C0D21E062D9923F487A2A5C870C124041A961134BF35A35ECDFAD3B45939 |
Malicious: | false |
Reputation: | unknown |
URL: | https://cdn.forms.office.net/forms/scripts/dists/ls-response.en-us.3508566c2.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7886 |
Entropy (8bit): | 3.973130033666625 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9425D8E9313A692BB3F022E8055FAB82 |
SHA1: | EDDCF3EA767D4C3042D01AC88594D7E795D8615C |
SHA-256: | F2A1ABCF12EBD0F329E5B66B811B0BD76C8E954CB283CE3B61E72FBF459EF6F1 |
SHA-512: | 93B3EB3C4CE385D80D4A8F6902355BBD156AC1AA20B8869AF05C8E714E90E74C5630BB8DE34D5B8FC9F876AC44BE314F3A2A08B3163295ADADBC6DD7B8D23561 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 142689 |
Entropy (8bit): | 5.441155007456589 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2F518F9978C5E6287299A5EB1CC2FD62 |
SHA1: | 7F0EF0B66D62F779A5F22AE14539F39451E47E2E |
SHA-256: | 931239A6873EDE7C93FE6C3CB436E0B0598AE87967EFB850F50E8165B13E00CA |
SHA-512: | 43BA6EAA8AA4320C2BC448B64194F25D2D7251DC206069D5843072E0D028ADAAA18EC2AD0CF2A1BADB80A3F34223ABE8C47AF05A90AAC9924A652B79497BE794 |
Malicious: | false |
Reputation: | unknown |
URL: | https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.utel.5faea0a.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 7914 |
Entropy (8bit): | 4.4735908000780045 |
Encrypted: | false |
SSDEEP: | |
MD5: | 56F9CD8A07135E776326431C8560F8F2 |
SHA1: | FCFF27C475A9FB014661B045B59C8BB4799A0392 |
SHA-256: | 0E1D105D6EE902B7279AEFD9E8AF21AB3E5D0CF058332A2A0E53A351524C75E6 |
SHA-512: | E75E2B65828CDE51CA880AEE30A74A3EE04B25B0FC0D2AF5B4BB675B62B592CF12D284771A0CE0A8174295F93C4D9007DA5C407C65229456EC0F1A18A6C8EE28 |
Malicious: | false |
Reputation: | unknown |
URL: | https://forms.office.com/offline.aspx |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 586163 |
Entropy (8bit): | 7.916279613062356 |
Encrypted: | false |
SSDEEP: | |
MD5: | 7C0CD0C7F3BA7B4C66254738C36B7BBF |
SHA1: | 21AB8368CDFF683ABD54722E7F89D454D6C9E52A |
SHA-256: | 0DB7FF2869748C19D0B51FDC9AFE1E2D657BC213299503E51103E99FA3DD5EC6 |
SHA-512: | 0066B913BD46D7B9D568343DE352D854C6E3515567DBC4093FDA6F01271106B17283EFBB542DDC23148362A3CE45B7F66C79F2910593D139D24FED9F44C34089 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1779 |
Entropy (8bit): | 7.589819392147309 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4150A5D4F2B0284A9E62D247929DD2AA |
SHA1: | 97CA2D9ECE8F0855B2A93E6BFDFC4883685C51CB |
SHA-256: | F058653DCBA7E8B00D4BDB9409E06817F098AB18125CE5A5821520F04030D176 |
SHA-512: | D034378E76D58A899047B4639115102CC8F89AEF3F300DDAF0C0B3EAE40C8381040D1656109632E9095ED3F399218F196087D070C099FD89B9605DFBC34FB585 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1964 |
Entropy (8bit): | 7.600533581971006 |
Encrypted: | false |
SSDEEP: | |
MD5: | FC6A627A2D1D410B051C01928180D30F |
SHA1: | C7ED08502C1AD2DA413B56BFDFF63873ADF7F7A3 |
SHA-256: | 7F77C691D669FC94853C14F76DE8C2665411C899C168E4655A4215D296DE8C3B |
SHA-512: | C45343430A32AADD3A2F6CD0373CC46396C67088B1495BBC43EB1001D06906D19F29BF8296F13483E7B00F921276C8444D33A0CBAD0BDDE01BE3C76EBE80D594 |
Malicious: | false |
Reputation: | unknown |
URL: | https://cdn.forms.office.net/forms/fonts/light/fluent-hybrid-icons-d54cb751.woff |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 15555 |
Entropy (8bit): | 5.474159441310109 |
Encrypted: | false |
SSDEEP: | |
MD5: | 96BE9765C5BB18D235A596311D3AB49C |
SHA1: | 120C8C52C3DEE7EE612B868D0E4EDCEC4FC3B1D0 |
SHA-256: | 52C294C0743F5261072EB6D021B1B082BA7C32B670C5F6DE9A024AB081BA26B1 |
SHA-512: | 521BF812522620572482C27F1EFCFBBF0C894A43DB0EB275E5FCACF7BE7395584A662D8836034B0797975E010E8886A2F6B5F20829D66E6EF553CA6AF516698A |
Malicious: | false |
Reputation: | unknown |
URL: | https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.lrp_post.boot.158f1c1.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 72660 |
Entropy (8bit): | 5.493868010643272 |
Encrypted: | false |
SSDEEP: | |
MD5: | BCA1B5F8EF4BC5A1A5B636DC93D6AC9C |
SHA1: | 0D9F418CDC8846A380922AFD1D1F34AA2073766B |
SHA-256: | C81802671B32B4603E56C7CD9DE8F30853F058548274164009886BD91EBA7DFE |
SHA-512: | D500DC6CDD9F5DD56CD338322CD4E9990F06C3737C75902CEB93CEB19738E93C78A04CAB761A6AF3DF701CFE1C13A6A97B73619752AF23B2078BB8DDFCC6EB79 |
Malicious: | false |
Reputation: | unknown |
URL: | https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.lrp_cover.83edd23.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 43793 |
Entropy (8bit): | 5.335551923543378 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2A327A21024EF1A4D476123537F319D9 |
SHA1: | 93E7E1C9E913AC41A0BEE9FA1A0592DED87B8B7B |
SHA-256: | D18E0BDCC5A7806BBA87DEF2C456D7D7625CD5849FD5D4CD58D1D5A0D2C366EB |
SHA-512: | 5C2EC62F4E4A338F0443930961A1BBD136C4A5E663E5C608E6A3C0EADEC042E6B4BEB8C6D605F7241E13CF02240BD260EB0562ED685BE8A0F3216857CBCBEF9D |
Malicious: | false |
Reputation: | unknown |
URL: | https://forms.office.com/sw.js?ring=Business |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5895 |
Entropy (8bit): | 7.720248605671278 |
Encrypted: | false |
SSDEEP: | |
MD5: | 311274C8C9C66E894F5AFA51FACD72CD |
SHA1: | 386D1FA0B2924DF2C21545CF2FF1DDE2CD985D33 |
SHA-256: | BC3C029408DAB6B5CB676B990B2E21BDD474E4B2E45DAF87E70210539390BF49 |
SHA-512: | 2117BC16AC878BCC307CEA0DEFA0638800715330E83E9C8C1CAD7398BBF207E9432391B851E004308FB75C20C2D6F587D015FA3FB13F8630FE3E0C7E194979FC |
Malicious: | false |
Reputation: | unknown |
URL: | https://cdn.forms.office.net/forms/images/microsoft365logo_v1.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 30478 |
Entropy (8bit): | 5.266966360988241 |
Encrypted: | false |
SSDEEP: | |
MD5: | 69B95B3AFE6F44CA43B688ED03EFDFF7 |
SHA1: | E15361771FB4D2BE2CA96436D891D96A03BB4BDF |
SHA-256: | E041BC08192240C9560B58CA4178550E0D22FC5F882B183276B1761B747E4DF0 |
SHA-512: | F3FF1452D0AC823B0F857503B35BBF66DCC4F245BBC933C0FA0C5C01621DBC3DE751D84D44B004E654BFCBD93D046F96FD597BEB15E85945F0E2711BCAE94E07 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 64 |
Entropy (8bit): | 3.8231924110430975 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0E9FBFDA77F4452938698CF7E752CFD4 |
SHA1: | 4E9AFF61BEF645F6F662CDB89ABBEA8E0F427D20 |
SHA-256: | 07F2E3BD43F9B4B93604997F27B4DB436A41556E642C4EC71E45238F62475268 |
SHA-512: | 15C3000E41390507E0155D9F1020190E3FCCCEC168B5146182615B49AE6CB6ED6901514181B7F428A39003154D3166EF4A62EFC7A9D11EFC8BBBE3179945795B |
Malicious: | false |
Reputation: | unknown |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISLAlZqBFnZrNR3RIFDZFhlU4SBQ2RYZVOEgUNkWGVThIFDZFhlU4SBQ2RYZVO?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 104982 |
Entropy (8bit): | 5.422733015057277 |
Encrypted: | false |
SSDEEP: | |
MD5: | E337ACC9EC83A4B62A94AFC9CE2E76E0 |
SHA1: | 3FD4FA35FE2230F77A79AC5044747CC3D05CC559 |
SHA-256: | 83C522ED4CD6B8241DD3E05E066F58FAA5256E1862D0A33BDE42322B39B848F4 |
SHA-512: | 133EEE9DDA8DA523B545FC21870594B2F44F8EDB7DC6C6120C8B22B216AABAB9010DB87E8E08315B650BF638C9A52CF590B5DC285FFB326160AA158D9D7DF9E9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 530 |
Entropy (8bit): | 4.860983185588505 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4D945878F36DCBBF35C41B5BB6E5513E |
SHA1: | 786EDE7740452B1C38B1FFA47C28F4E70140EC5F |
SHA-256: | 19DADB739E9886DBDDC79E9E916B753AC53A2C8C1A9560EF14AF28B400C234E0 |
SHA-512: | 37E16ACE0F5DF65065C150FB05E7968A5B3AA828F66EFDEF29DD78EF4C2D4B29D0C4F81502CDA069F1EFB0B0329FA69BC309579D74A447E2B7FE9E27AC9CCD99 |
Malicious: | false |
Reputation: | unknown |
URL: | https://forms.office.com/pwa/en-us/app.webmanifest |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 110658 |
Entropy (8bit): | 5.424597933748236 |
Encrypted: | false |
SSDEEP: | |
MD5: | 7A1CBAE1C97AD1A1E67F351FAF0F81A4 |
SHA1: | 6F024274F89AFC9319DFE7AD9D0F23A48E279DB1 |
SHA-256: | 32859A35E0C0F3BC47CCAF2A01830BF7A8C41702C026D0B74FF7E50BC7E6CD51 |
SHA-512: | 7D15A261B69A80E70BE9628839EF9C904AF335347603EA2A299E64F5E3D13EA6C13B0B1D6213EF08188D1140C40AADDAB7AA9E04C9A5D2E26DB3A4217368802D |
Malicious: | false |
Reputation: | unknown |
Preview: |