Windows Analysis Report
https://girlsincpinellas.sharepoint.com/:b:/s/GirlsIncofPinellas/EXa1VrXO6yVMqBgR838NynIBu_L7dOZdbKMLEwI-2F0hPQ?e=4%3ayt0MH1&at=9

Overview

General Information

Sample URL: https://girlsincpinellas.sharepoint.com/:b:/s/GirlsIncofPinellas/EXa1VrXO6yVMqBgR838NynIBu_L7dOZdbKMLEwI-2F0hPQ?e=4%3ayt0MH1&at=9
Analysis ID: 1564517
Infos:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Source: https://girlsincpinellas.sharepoint.com/:b:/s/GirlsIncofPinellas/EXa1VrXO6yVMqBgR838NynIBu_L7dOZdbKMLEwI-2F0hPQ?e=4%3ayt0MH1&at=9 HTTP Parser: No favicon
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\scoped_dir568_836259673 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\chrome_BITS_568_494098623 Jump to behavior
Source: unknown HTTPS traffic detected: 96.7.232.109:443 -> 192.168.11.20:49723 version: TLS 1.2
Source: unknown HTTPS traffic detected: 96.7.232.109:443 -> 192.168.11.20:49724 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.43.51.137:443 -> 192.168.11.20:49725 version: TLS 1.2
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 68.142.107.129
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.42.73.31
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.42.73.31
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.151.67
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.151.67
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.151.67
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.151.67
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.151.67
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.151.67
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 96.7.232.109
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 23.43.51.137
Source: unknown TCP traffic detected without corresponding DNS query: 23.43.51.137
Source: global traffic HTTP traffic detected: GET /:b:/s/GirlsIncofPinellas/EXa1VrXO6yVMqBgR838NynIBu_L7dOZdbKMLEwI-2F0hPQ?e=4%3ayt0MH1&at=9 HTTP/1.1Host: girlsincpinellas.sharepoint.comConnection: keep-alivesec-ch-ua: "Chromium";v="128", "Not;A=Brand";v="24", "Google Chrome";v="128"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: girlsincpinellas.sharepoint.comConnection: keep-alivesec-ch-ua: "Chromium";v="128", "Not;A=Brand";v="24", "Google Chrome";v="128"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://girlsincpinellas.sharepoint.com/:b:/s/GirlsIncofPinellas/EXa1VrXO6yVMqBgR838NynIBu_L7dOZdbKMLEwI-2F0hPQ?e=4%3ayt0MH1&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /client/config?cc=GB&setlang=en-US HTTP/1.1X-Search-CortanaAvailableCapabilities: NoneX-Search-SafeSearch: ModerateAccept-Encoding: gzip, deflateX-Device-MachineId: {9A18632D-0E0D-4CA4-9A0A-9577C1FFEAFA}X-UserAgeClass: UnknownX-BM-Market: GBX-BM-DateFormat: dd/MM/yyyyX-Device-OSSKU: 48X-BM-DTZ: -300X-DeviceID: 0100A45C090094CAX-BM-WindowsFlights: RS:B4BC,FX:117B9872,FX:119E26AD,FX:11A8C293,FX:11A8C2FE,FX:11C0E96C,FX:11CC111C,FX:11D5BFCD,FX:11DF5B12,FX:11DF5B75,FX:11F1992A,FX:11F4161E,FX:11F41B68,FX:11FB0F2F,FX:1201B330,FX:1202B7FC,FX:120BB68E,FX:121A20E1,FX:121BF15F,FX:121E5EC8,FX:122B3A5C,FX:122D8E86,FX:123031A3,FX:1231B88B,FX:123371B1,FX:1233C945,FX:123D7C31,FX:1240013C,FX:1240931B,FX:1246E4A3,FX:1248306D,FX:124B38D0,FX:1250080B,FX:125A7FDA,FX:1264FA75,FX:126DBC22,FX:127159BE,FX:12769734,FX:127C935B,FX:127DC03A,FX:127FC878,FX:1283FFE8,FX:12840617,FX:128979F9,FX:128EBD7E,FX:129135BB,FX:129E053F,FX:12A74DB5,FX:12AB734D,FX:12B8450E,FX:12BD6E73,FX:12C3331B,FX:12C7D66E,FX:12CDE644,FX:12D1574C,FX:12D281C4,FX:12E8312D,FX:12EC0B54,FX:12F0AC91,FX:12FF5D3C,FX:13143E2F,FX:13214552,FX:13283A3B,FX:133A07C7,FX:133BFFE3,FX:13404069,FX:134128A5,FX:1342B470X-Search-TimeZone: Bias=300; StandardBias=0; TimeZoneKeyName=Eastern Standard TimeX-BM-Theme: 000000;0078d7X-Agent-DeviceId: 0100A45C090094CAX-Search-RPSToken: t%3DEwDoAkR8BAAUcvamItSE/vUHpyZRp3BeyOJPQDsAAQr1X%2Bx7sTT%2Byny3Lfhdm2SHmK5f%2BbgVc/lwj6x%2Ba/mcXpKCKCS5XXXMnJ6laKwAiplZNhIDIs/4wrZLWUdKo9mQMNfpiKPE5FESPDQgltfqu6ZhByXPO5G6XknTWCFCSLzoALUe2cWsilvMg13X6S2fogp5h3zSNNqTZGICAndtyK2azdjg8nr/uBcC91aZmxXywp1dbOzOe6GXFDy6UUtMt7Q5cYuhHOKJ1G199/S1TKo2Y1VKfXz3EBgAeHl5%2Bx63OSXIrYApooVFSBtpezlocTUyfNmnMweMuFYCYMDHNQeG6k7QGr/X7pHyRKtGxeKhVzifoQkGEZfE8BLoOQUQZgAAEGCMzOZrx0Ge1NKBoudvCTOwAXmMIexb%2B/HKbeCxGuFzLSjo3NoVEioPRPz6dqeI%2BPzQLWYCWM2BKUSvZ1nEC9XnULuOZtJ%2Bb5Gu0OpUBEQUPlPYU15X%2B00um7bRwv3ecDQpgWq3jwWO/TG0kNvjc8BUR8OHf67fCsCACvCQfRIWAAmov%2BvsaBEDk9xJjha8xvmfa6ALQGEbuC1inp1htLIxC41Ye%2B%2BH3UAXFs2MGx2m0gTsrKWbkl8U37o7KSGapLSTyrS8YNO1xmaTBOdBqi5LtqNw5WI4fWxaYpA9j2LGCWIq9kCJtSV4yebxk3K0Dfcn/gb0fMkqmKiwoqfkPnqz1pa%2B1aULaFAKxLAUMvGraYXQmSgcIMwNVXG5nqsWnl7/74O%2BbJGXLruM3Ib582wCYk50dg1srY8q0gT6fngr3MdmflISARhG3GB7DdNpqH8pdmI3GIRbSke9DKgMlmQlJ26uF69hXGR/IdPpZRUWpGO1PSB/ZDmX3dAz%2BAB%2B3gUbz76Q2S1ldiLuYc6vlQ2n0m3Quk3YX779AuDXy5XyN3EdPdZJlcDczsAWp0l4t4riKgohCDXKKqeJdP97Ima4ztkB%26p%3DX-BM-CBT: 1732795947User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; Cortana 1.14.2.19041; 10.0.0.0.19042.1165) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19042X-Device-isOptin: falseAccept-language: en-US, enX-Device-Touch: falseX-Device-ClientSession: A50D0F83856D4CD09B575AA3D5E6368AX-Search-AppId: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUIHost: www.bing.comConnection: Keep-AliveCookie: SRCHUID=V=2&GUID=0051B20720A34FFCA45E0D908944BC77&dmnchg=1; SRCHD=AF=NOFORM; SRCHUSR=DOB=20241118; SRCHHPGUSR=IPMH=d7475077&IPMID=1732774233764&SRCH
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: girlsincpinellas.sharepoint.com
Source: global traffic TCP traffic: 192.168.11.20:50674 -> 239.255.255.250:1900
Source: global traffic TCP traffic: 192.168.11.20:50674 -> 239.255.255.250:1900
Source: global traffic TCP traffic: 192.168.11.20:50674 -> 239.255.255.250:1900
Source: global traffic TCP traffic: 192.168.11.20:50674 -> 239.255.255.250:1900
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundCache-Control: privateContent-Length: 18Content-Type: text/plain; charset=utf-8P3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"X-NetworkStatistics: 0,2102272,0,47,333489,0,1128071,7X-SharePointHealthScore: 3SPRequestGuid: c34d68a1-602b-6000-f52f-b7a3f050a11frequest-id: c34d68a1-602b-6000-f52f-b7a3f050a11fMS-CV: oWhNwytgAGD1L7ej8FChHw.0Strict-Transport-Security: max-age=31536000X-AspNet-Version: 4.0.30319SPRequestDuration: 61SPIisLatency: 5X-Powered-By: ASP.NETMicrosoftSharePointTeamServices: 16.0.0.25430X-Content-Type-Options: nosniffX-MS-InvokeApp: 1; RequireReadOnlyX-Cache: CONFIG_NOCACHEX-MSEdge-Ref: Ref A: 5DE84EB52BB94D4AADD44D8D5D68958A Ref B: LAX311000113029 Ref C: 2024-11-28T12:11:54ZDate: Thu, 28 Nov 2024 12:11:54 GMTConnection: close
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundP3P: CP="ALL IND DSP COR ADM CONo CUR CUSo IVAo IVDo PSA PSD TAI TELo OUR SAMo CNT COM INT NAV ONL PHY PRE PUR UNI"X-NetworkStatistics: 0,1051136,17,9,2609987,0,1051136,7SPRequestDuration: 23SPIisLatency: 1X-Powered-By: ASP.NETMicrosoftSharePointTeamServices: 16.0.0.25430X-Content-Type-Options: nosniffX-MS-InvokeApp: 1; RequireReadOnlyX-Cache: CONFIG_NOCACHEX-MSEdge-Ref: Ref A: 24AA463F82BB4BDAAE37D92C9DE921F4 Ref B: LAXEDGE1611 Ref C: 2024-11-28T12:11:55ZDate: Thu, 28 Nov 2024 12:11:54 GMTConnection: closeContent-Length: 0
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49686
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49683
Source: unknown Network traffic detected: HTTP traffic on port 49697 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49686 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49697
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49675
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49673
Source: unknown Network traffic detected: HTTP traffic on port 49694 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49694
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49683 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown HTTPS traffic detected: 96.7.232.109:443 -> 192.168.11.20:49723 version: TLS 1.2
Source: unknown HTTPS traffic detected: 96.7.232.109:443 -> 192.168.11.20:49724 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.43.51.137:443 -> 192.168.11.20:49725 version: TLS 1.2
Source: classification engine Classification label: clean0.win@16/2@4/4
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\scoped_dir568_836259673 Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-subproc-heap-profiling --field-trial-handle=2232,i,9846390632335110549,12838943418161714383,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20240909-180142.416000 --mojo-platform-channel-handle=2248 /prefetch:3
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://girlsincpinellas.sharepoint.com/:b:/s/GirlsIncofPinellas/EXa1VrXO6yVMqBgR838NynIBu_L7dOZdbKMLEwI-2F0hPQ?e=4%3ayt0MH1&at=9"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-subproc-heap-profiling --field-trial-handle=2232,i,9846390632335110549,12838943418161714383,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20240909-180142.416000 --mojo-platform-channel-handle=2248 /prefetch:3 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\scoped_dir568_836259673 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\chrome_BITS_568_494098623 Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs