Windows
Analysis Report
original.eml
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- OUTLOOK.EXE (PID: 6892 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \Root\Offi ce16\OUTLO OK.EXE" /e ml "C:\Use rs\user\De sktop\orig inal.eml" MD5: 91A5292942864110ED734005B7E005C0) - ai.exe (PID: 6276 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \root\vfs\ ProgramFil esCommonX6 4\Microsof t Shared\O ffice16\ai .exe" "342 64153-B4D4 -4F3D-9FC0 -B8DEACFF6 CDA" "5757 DC72-AC9C- 4E4D-95D8- 35547F8A0B 1F" "6892" "C:\Progr am Files ( x86)\Micro soft Offic e\Root\Off ice16\OUTL OOK.EXE" " WordCombin edFloatieL reOnline.o nnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD) - OUTLOOK.EXE (PID: 5404 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \root\Offi ce16\OUTLO OK.EXE" /e ml "C:\Use rs\user\Ap pData\Loca l\Microsof t\Windows\ INetCache\ Content.Ou tlook\NGQS 9FPJ\phish _alert_sp2 _2.0.0.0.e ml" MD5: 91A5292942864110ED734005B7E005C0) - chrome.exe (PID: 5688 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// can01.safe links.prot ection.out look.com/? url=https% 3A%2F%2Fsi emensgbs.s ervice-now .com%2Fesc &data=05%7 C02%7Csoph ie.desgagn e%40metalu s.qc.ca%7C 0c5ad14b20 594d77160c 08dd1adba7 0d%7C4f85c c14eaa84e0 b829193aab 6969f78%7C 0%7C0%7C63 8696252896 352473%7CU nknown%7CT WFpbGZsb3d 8eyJFbXB0e U1hcGkiOnR ydWUsIlYiO iIwLjAuMDA wMCIsIlAiO iJXaW4zMiI sIkFOIjoiT WFpbCIsIld UIjoyfQ%3D %3D%7C0%7C %7C%7C&sda ta=er1QvLq AgdZvbKUIP FCNfL%2F3% 2BoNewbBqC hI%2B7M9j7 %2F4%3D&re served=0 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 2464 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2164 --fi eld-trial- handle=195 2,i,112080 0828693568 3408,19181 8301994857 4756,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 3720 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// can01.safe links.prot ection.out look.com/? url=https% 3A%2F%2Fsi emensgbs.s ervice-now .com%2Fesc &data=05%7 C02%7Csoph ie.desgagn e%40metalu s.qc.ca%7C 0c5ad14b20 594d77160c 08dd1adba7 0d%7C4f85c c14eaa84e0 b829193aab 6969f78%7C 0%7C0%7C63 8696252896 352473%7CU nknown%7CT WFpbGZsb3d 8eyJFbXB0e U1hcGkiOnR ydWUsIlYiO iIwLjAuMDA wMCIsIlAiO iJXaW4zMiI sIkFOIjoiT WFpbCIsIld UIjoyfQ%3D %3D%7C0%7C %7C%7C&sda ta=er1QvLq AgdZvbKUIP FCNfL%2F3% 2BoNewbBqC hI%2B7M9j7 %2F4%3D&re served=0 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 4348 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2044 --fi eld-trial- handle=175 2,i,342094 7399555927 208,552150 8960869548 366,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: frack113: |
Click to jump to signature section
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | Classification: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: |
Source: | File created: |
Source: | File read: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: |
Source: | Key value queried: |
Source: | Window found: |
Source: | Window detected: |
Source: | Key opened: |
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: |
Source: | Key value created or modified: |
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: |
Source: | File Volume queried: |
Source: | Process information queried: |
Source: | Queries volume information: |
Source: | Key value queried: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 21 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Modify Registry | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 Registry Run Keys / Startup Folder | 1 Registry Run Keys / Startup Folder | 1 Process Injection | Security Account Manager | 13 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 DLL Side-Loading | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
can01.safelinks.eop-tm2.outlook.com | 104.47.75.156 | true | false | high | |
sni1gl.wpc.upsiloncdn.net | 152.199.21.175 | true | false | unknown | |
sni1gl.wpc.omegacdn.net | 152.199.21.175 | true | false | high | |
www.google.com | 172.217.171.196 | true | false | high | |
siemensgbs.service-now.com | 149.96.176.144 | true | true | unknown | |
s-part-0035.t-0009.t-msedge.net | 13.107.246.63 | true | false | high | |
autologon.microsoftazuread-sso.com | 40.126.53.13 | true | false | unknown | |
aadcdn.msauthimages.net | unknown | unknown | false | high | |
can01.safelinks.protection.outlook.com | unknown | unknown | false | unknown | |
identity.nel.measure.office.net | unknown | unknown | false | high | |
aadcdn.msftauth.net | unknown | unknown | false | high | |
login.microsoftonline.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
20.190.177.148 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
172.217.19.206 | unknown | United States | 15169 | GOOGLEUS | false | |
13.107.246.63 | s-part-0035.t-0009.t-msedge.net | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
40.126.53.13 | autologon.microsoftazuread-sso.com | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
149.96.176.144 | siemensgbs.service-now.com | United States | 16839 | SNCUS | true | |
52.178.17.2 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
23.218.208.109 | unknown | United States | 6453 | AS6453US | false | |
52.109.89.19 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
2.20.68.223 | unknown | European Union | 37457 | Telkom-InternetZA | false | |
172.217.17.42 | unknown | United States | 15169 | GOOGLEUS | false | |
104.47.75.156 | can01.safelinks.eop-tm2.outlook.com | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
142.250.201.35 | unknown | United States | 15169 | GOOGLEUS | false | |
20.190.147.8 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
52.113.194.132 | unknown | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
13.89.179.10 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
20.190.181.3 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
142.251.173.84 | unknown | United States | 15169 | GOOGLEUS | false | |
2.16.149.34 | unknown | European Union | 1273 | CWVodafoneGroupPLCEU | false | |
172.217.171.196 | www.google.com | United States | 15169 | GOOGLEUS | false | |
52.109.28.48 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.251.37.35 | unknown | United States | 15169 | GOOGLEUS | false | |
152.199.21.175 | sni1gl.wpc.upsiloncdn.net | United States | 15133 | EDGECASTUS | false | |
20.50.73.9 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1574052 |
Start date and time: | 2024-12-12 21:13:49 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 23 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | stream |
Analysis stop reason: | Timeout |
Sample name: | original.eml |
Detection: | MAL |
Classification: | mal48.winEML@30/93@22/167 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, backgroundTaskHost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 52.113.194.132, 23.218.208.109, 52.109.89.19, 2.20.68.223, 2.20.68.229, 52.109.28.48, 13.89.179.10
- Excluded domains from analysis (whitelisted): osiprod-uks-bronze-azsc-000.uksouth.cloudapp.azure.com, omex.cdn.office.net, odc.officeapps.live.com, slscr.update.microsoft.com, europe.odcsm1.live.com.akadns.net, weu-azsc-000.roaming.officeapps.live.com, onedscolprdcus12.centralus.cloudapp.azure.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, eur.roaming1.live.com.akadns.net, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, osiprod-weu-buff-azsc-000.westeurope.cloudapp.azure.com, login.live.com, e16604.g.akamaiedge.net, prod.fs.microsoft.com.akadns.net, a1864.dscd.akamai.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, fe3cr.delivery.mp.microsoft.com, uks-azsc-000.odc.officeapps.live.com, s-0005.s-msedge.net, ecs.office.trafficmanager.net, omex.cdn.office.net.akamaized.net, prod.odcsm1.live.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtQueryAttributesFile calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtSetValueKey calls found.
- VT rate limit hit for: original.eml
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 231348 |
Entropy (8bit): | 4.387723032944626 |
Encrypted: | false |
SSDEEP: | |
MD5: | 95BAC81373CF797AE2D22D98F7739BDB |
SHA1: | CCADA32C720926CE2ABA948CAF9C39A360AAFB77 |
SHA-256: | DA26FB1F40771F884F4F098A7FD6652F02F2DA461BD106D5C2C8538D074EA7A1 |
SHA-512: | 16C56737CD829F062DDA5396803067052A5C6DE2B6CEB97FA5D4FF387579E2F894B638E757CEABA4A089952C27086E72BDF007480EC4DD02BFDA4E24EF0D3E4A |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 521377 |
Entropy (8bit): | 4.9084889265453135 |
Encrypted: | false |
SSDEEP: | |
MD5: | C37972CBD8748E2CA6DA205839B16444 |
SHA1: | 9834B46ACF560146DD7EE9086DB6019FBAC13B4E |
SHA-256: | D4CFBB0E8B9D3E36ECE921B9B51BD37EF1D3195A9CFA1C4586AEA200EB3434A7 |
SHA-512: | 02B4D134F84122B6EE9A304D79745A003E71803C354FB01BAF986BD15E3BA57BA5EF167CC444ED67B9BA5964FF5922C50E2E92A8A09862059852ECD9CEF1A900 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\FontCache\4\PreviewFont\flat_officeFontsPreview_4_40.ttf
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 773040 |
Entropy (8bit): | 6.55939673749297 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4296A064B917926682E7EED650D4A745 |
SHA1: | 3953A6AA9100F652A6CA533C2E05895E52343718 |
SHA-256: | E04E41C74D6C78213BA1588BACEE64B42C0EDECE85224C474A714F39960D8083 |
SHA-512: | A25388DDCE58D9F06716C0F0BDF2AEFA7F68EBCA7171077533AF4A9BE99A08E3DCD8DFE1A278B7AA5DE65DA9F32501B4B0B0ECAB51F9AF0F12A3A8A75363FF2C |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntities.bin
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 322260 |
Entropy (8bit): | 4.000299760592446 |
Encrypted: | false |
SSDEEP: | |
MD5: | CC90D669144261B198DEAD45AA266572 |
SHA1: | EF164048A8BC8BD3A015CF63E78BDAC720071305 |
SHA-256: | 89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899 |
SHA-512: | 16F8A8A6DCBAEAEFB88C7CFF910BCCC71B76A723CF808B810F500E28E543112C2FAE2491D4D209569BD810490EDFF564A2B084709B02963BCAF6FDF1AEEC59AC |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntitiesUpdated.bin
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 10 |
Entropy (8bit): | 2.6464393446710157 |
Encrypted: | false |
SSDEEP: | |
MD5: | 11F7E48EAC36BDB3C907B9D15EA864B1 |
SHA1: | 2B21F23A4DA9461A5F1C59F0695DA5E59DAA4E4E |
SHA-256: | D4CFDE2D248925FA5030002EF579F151B830CA634B98C877929A9D560439B283 |
SHA-512: | 20384DA984EC4AFDAA2FF0737B278BEAF04EBD32D8E92EA651A2BFACF823607B775BBE540948C9F2820FF5CE401BA548647800B531C125E97FD8B047A5D8DB80 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 4096 |
Entropy (8bit): | 0.09216609452072291 |
Encrypted: | false |
SSDEEP: | |
MD5: | F138A66469C10D5761C6CBB36F2163C3 |
SHA1: | EEA136206474280549586923B7A4A3C6D5DB1E25 |
SHA-256: | C712D6C7A60F170A0C6C5EC768D962C58B1F59A2D417E98C7C528A037C427AB6 |
SHA-512: | 9D25F943B6137DD2981EE75D57BAF3A9E0EE27EEA2DF19591D580F02EC8520D837B8E419A8B1EB7197614A3C6D8793C56EBC848C38295ADA23C31273DAA302D9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 4616 |
Entropy (8bit): | 0.13760166725504608 |
Encrypted: | false |
SSDEEP: | |
MD5: | 1DFD88A5AF8C1F43D5861D92C1847C75 |
SHA1: | 64F9A27784BD057E6B3877325C3D63483B243C8E |
SHA-256: | 3D830D68EB76B10DDB1957DC8453E1DD66BACB1757E93A73E8C1D35B01D5AB8A |
SHA-512: | 1D999D7A91BE99AD566ADE6239F8ACFCC4F6CD7F9C5A116F149152FEE73AF2BD6543246D1149756876D4F70972299A1C93A4E1EF50A164C8A2B6732F3542500C |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 32768 |
Entropy (8bit): | 0.04495055541749482 |
Encrypted: | false |
SSDEEP: | |
MD5: | 081644696FFC04CD77AEC3E86CF36CA3 |
SHA1: | F27C6ACCF918EF70BF7C14099AC01D5B640F7B4C |
SHA-256: | A62731A3EB48D4BE2F6DD1DFBD26A1D6575FF2ED825CDFCC8D98936A07447A41 |
SHA-512: | 30F63CE15ABFB093886F43590150EB0EBAB7CB8673CF3C7BE0F6BA232A2E5E4C4EC97DF615B77A5709C5FD880FFA473F375EBDF49C475F4326F123E707430EAD |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 45352 |
Entropy (8bit): | 0.3938846966157005 |
Encrypted: | false |
SSDEEP: | |
MD5: | 009D288EFAA41C4326FCE39B1433F260 |
SHA1: | D22EB2643A579423A49FFD8F45CC22A43CEA786D |
SHA-256: | BA470911F09CC7F8AD29B3BC5FCA537BBB039299AA24009963D25E539EADA905 |
SHA-512: | F89E8414D6840747675705E6B3236A89FC4FDA81347EAE70707E9337565767DCA2E07149CBF713C59F3C046E15FB6CDC399774F15F7B69CBA8809CC6DB1BB5FC |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbres
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 2278 |
Entropy (8bit): | 3.8550621171774804 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4F64F95F9007CD6283428B3D89595FBB |
SHA1: | 23BD37879A98DEAA2FF076B36F59D71D1E9D1091 |
SHA-256: | A1FE2061D471DE82D2DDB6523337B36499542143EAF1295D48A8EDB3CC6DF966 |
SHA-512: | 96B392ADB2390494EA551E8BF2AD67DB668CC5FB7E63AD6EF7B5A0B52F81C69A20D6296CBCE467CE7C9E92F8B9E2E4AEE92DF48C83986CCA25FFC8996DABFA2C |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\5475cb191e478c39370a215b2da98a37e9dc813d.tbres
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | modified |
Size (bytes): | 2684 |
Entropy (8bit): | 3.9016432971479733 |
Encrypted: | false |
SSDEEP: | |
MD5: | A931FDABFB676389A20FDEE50A0968F8 |
SHA1: | 85F1A97E9EDB0F6C01D7FD5096ED33BBDBD98916 |
SHA-256: | 930E6E0AC55AEEF3A57741C84F3C8CB26BBF32764DA73B54ADA580498E01B9DF |
SHA-512: | FB835176DBD588C79EC68D349F94ED43220236BEF95670C56BDE16BFB630424C737A983B22C0806D3798E23DB3DFD169E76B54B20D445500BB6331C1C0D0F218 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbres
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 4542 |
Entropy (8bit): | 4.0031629995313756 |
Encrypted: | false |
SSDEEP: | |
MD5: | D886A8ED7AB2094912F87827DA3334F6 |
SHA1: | C27664081863B417CCB4CEBF11D282B8DE829335 |
SHA-256: | CC2E247E2DA45A565CCBF81EC7D4891D39E6A3395714B72C809AF3F84838765D |
SHA-512: | 76B233E291CDB689E8309D9076CE12E44FE4E70A85690A40BEC123F384A9F1CFACB4DC2ABDE6A93FF59F3771F7DDCB7F151788DC623E2E6B7D30709652519411 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\NGQS9FPJ\phish_alert_sp2_2.0.0.0 (002).eml
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 35761 |
Entropy (8bit): | 6.1089114444195625 |
Encrypted: | false |
SSDEEP: | |
MD5: | D0FAF9ABB120330913CBED868DF596F2 |
SHA1: | 4EA666621F1EE4F493C5235104C65E4F89A8D4B5 |
SHA-256: | 05211D61C8E17E51FBDD265CB5ADE46256F1B311CE71EE6E4B5E3D9A09462306 |
SHA-512: | BA1CC60CC5ADA1FAC22FE0E30B6803F6DF6DD8C2EE97039CD1AB5F3D2DEB319590F4C209CBF8E60ED0EFF0A2ED80F7997DD46DD71DB50D5E0364C3DBE24FA910 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\NGQS9FPJ\phish_alert_sp2_2.0.0.0 (002).eml:Zone.Identifier (copy)
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 0 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | D0FAF9ABB120330913CBED868DF596F2 |
SHA1: | 4EA666621F1EE4F493C5235104C65E4F89A8D4B5 |
SHA-256: | 05211D61C8E17E51FBDD265CB5ADE46256F1B311CE71EE6E4B5E3D9A09462306 |
SHA-512: | BA1CC60CC5ADA1FAC22FE0E30B6803F6DF6DD8C2EE97039CD1AB5F3D2DEB319590F4C209CBF8E60ED0EFF0A2ED80F7997DD46DD71DB50D5E0364C3DBE24FA910 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\NGQS9FPJ\phish_alert_sp2_2.0.0.0.eml:Zone.Identifier
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | |
MD5: | FBCCF14D504B7B2DBCB5A5BDA75BD93B |
SHA1: | D59FC84CDD5217C6CF74785703655F78DA6B582B |
SHA-256: | EACD09517CE90D34BA562171D15AC40D302F0E691B439F91BE1B6406E25F5913 |
SHA-512: | AA1D2B1EA3C9DE3CCADB319D4E3E3276A2F27DD1A5244FE72DE2B6F94083DDDC762480482C5C2E53F803CD9E3973DDEFC68966F974E124307B5043E654443B98 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{4BABE5D6-354F-4EDF-976C-FC5955FA1295}.tmp
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 12076 |
Entropy (8bit): | 3.8276468765056575 |
Encrypted: | false |
SSDEEP: | |
MD5: | EFE8EBBBA3B1EDB2018F146C3EA3746C |
SHA1: | 0BEE2937E62384FD8959F01D643C85E3D8532A2D |
SHA-256: | 4EDE4275A0705324E899FD61C2823F5A0784A7B9658AEAA39B9F96377DF99827 |
SHA-512: | BFC0B62AAB3B758461BD0DF2057DDBF68995FEC00C61503012117F4754E4070F7697C7C0E7A8A587300561DBAED23A963843DD1B3B4BBAB380282FBE11DB68AA |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{D22D8C51-8E44-469B-A4A1-FF31C150D038}.tmp
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | modified |
Size (bytes): | 6176 |
Entropy (8bit): | 3.455736041720719 |
Encrypted: | false |
SSDEEP: | |
MD5: | E700FCCD2DEA9759D074BB21DA266403 |
SHA1: | 9B66F612007B956C7FAFE0990355F8183EE93928 |
SHA-256: | A436DA28ACC68934705988F2279A7FBEE552F4952659903C2F2530D315AD3C21 |
SHA-512: | D48047AE276E8962FD7D8F87D47DFB9E8396123C74C6C316C85D4B35AB8376DAAB0CEE1DBA16F07302347085C4FCDF08758B09097EC7E89D6A0227A959ABD2ED |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\Diagnostics\OUTLOOK\App1734034463109813000_75897218-34E0-4F81-B08B-5ABB5C55B417.log
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 20971520 |
Entropy (8bit): | 0.012073952386077664 |
Encrypted: | false |
SSDEEP: | |
MD5: | 761944475DF0A6444B8E0FCFDF61C44F |
SHA1: | CDBEDC668D2AAA1892E0B05BF4B6C990288BA756 |
SHA-256: | 5E434C25505ED25931FFC0426F115394AD5C5345B21E1C03B20E5EE79F8FCEC9 |
SHA-512: | 4DE56DDA3D6D31532E5A600F9C56CAF898A97D956BFC38FB8B18C44FC0D56882452DC9DDEBC46C899813A9983DCFA9EA03CA6138A2B36EEF8A0333D7907831E0 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\Diagnostics\OUTLOOK\App1734034463110572400_75897218-34E0-4F81-B08B-5ABB5C55B417.log
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 20971520 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8F4E33F3DC3E414FF94E5FB6905CBA8C |
SHA1: | 9674344C90C2F0646F0B78026E127C9B86E3AD77 |
SHA-256: | CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC |
SHA-512: | 7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20241212T1514220911-6892.etl
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | modified |
Size (bytes): | 208896 |
Entropy (8bit): | 4.831669899653048 |
Encrypted: | false |
SSDEEP: | |
MD5: | AA7C62A9D195D1A2F6B4187A44392E49 |
SHA1: | CF582C480C5EBAD9921498121CE57F2D906FD963 |
SHA-256: | 4358FD118BC57B4CB6ADD281385118BCDEBA06C3320C2A2BE3CD43B89A4411A1 |
SHA-512: | 42C5D6E364B3CC7028811A586A1D18ACB93C2E4B5216EA807102AA1B3694E06A2DEC50C950BF337ADEB343013320C3D464AB98927B32142237E88AED8C38E0ED |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20241212T1514330804-5404.etl
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 3.5688472350781 |
Encrypted: | false |
SSDEEP: | |
MD5: | A6897A0BDCA56B11FE1579E0F2EF40D4 |
SHA1: | DAF803703B5F2E0FBF7D05B957AA80E6C8ED6D7A |
SHA-256: | 7B1FE309A8DC6BC5CBE04B54D89D1CC5E5FCC37892530D2B56F57EE5C7482A0E |
SHA-512: | 0CC5E6854DD3439EFF435BFAA38613BB4120BC6527F2DAE1853D21C9D67C3D64D2A352DCDD3BAA9D476089A389494C793242A12D839BB64114935F4E636C47A5 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.6698461310714667 |
Encrypted: | false |
SSDEEP: | |
MD5: | 665B04D70A0286763F24DBA7F3910573 |
SHA1: | D72744373089E890E53ED99C15A1A10EA05C4F70 |
SHA-256: | 39B08D9DC990E4809F4D3BA682F8F21F7258A28BE7134876EB0408D9E2B4F597 |
SHA-512: | C8A638B55448FF893E9AF3EE6C280F670B0E7F2C8891123483B35010DCA2F582E42B57D6976D43A9B275A929F750C6A694F2039D6A06BC190672D6A76BCB0E74 |
Malicious: | true |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9853656693440804 |
Encrypted: | false |
SSDEEP: | |
MD5: | E6DA55A618257281748DF86B8C96038E |
SHA1: | 2751E43242DEDA523D9BFEDDD7A5763C2CF131D7 |
SHA-256: | 5A1C52FA33E18CF3F2986F6F43187D109F6B2E8DD730FE9AFB685C5C83028772 |
SHA-512: | CE5BAFE94FD6D03D12D9E92853A94DB58997A7E622F8CE2C2505FF243AFA3A29C3CFDF9A815E5F356626EB22AEA32BBF1AB2CC58FA98660D6BCA22B2E0878D4D |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 4.005569735294415 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2E1AD68A19D39DA149221D699417EF21 |
SHA1: | 356865C922FA4DC4563B5965AA1BA81745666B3C |
SHA-256: | 9E48A795C2AC3E80E1C90774E8A618120B72127D485C8197A37B9CAC56CA789C |
SHA-512: | 8E0858A8DDB13EE692D089B12F54AA799B222B3AD460F213BF8023BF42913629DAD11832B0A133230A720473E7AAD09FD8ABFFAD6E6EA1D79C20EE58DEF2CD89 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.011331377149591 |
Encrypted: | false |
SSDEEP: | |
MD5: | E59C8936BF66B2343C50EF26F99DE9BE |
SHA1: | 36EED68E58E61B65446586087E752B386441DAE9 |
SHA-256: | 702D09F05BBBD938A10182DA56682CB17DA7297E928B8AF7CD914A61B27D0481 |
SHA-512: | 97ED5AA203FA664DDEF25E34B1BEEAFFC3B430854CBEE06D9671F0959EC98CD9D976197A98512003BE19ECE3789A0A74D7BB0341F5EC820256FC27A9369CED86 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 4.00060462113836 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8811C924DE0BE4B709958B05AEC3ED35 |
SHA1: | E0C6DDF6D9312C996867E11BD7BCD0BD4FB3B8C9 |
SHA-256: | B440BBB28C672EEFE1BA78FFB4454B230119206B092C280063CE54848468C24E |
SHA-512: | E7BACAA8A86E22AD89FE63F46D15709A4F142C585B3F93AFF7232DB3A1075626788F68F534953DDD157D1A78E654F2E445D6FB0EA47C81A361D8923C14DA2765 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.989898296565966 |
Encrypted: | false |
SSDEEP: | |
MD5: | 96EF0F9F8B1100B0D2235F68806FB782 |
SHA1: | E1DE114384A61D78FD7FD42DC352477CBD63C358 |
SHA-256: | 05798169FB78334F861C75D83F09C47620391C790CD2D2ADD97A64528D6054F3 |
SHA-512: | 886C48356D3AFE8325123CB41013BCA211D6AA8F00FBD9C938AC1292FCCC46280024AED418349955B247AC558CCF48A84857C7BDC2B8792C2B26B76A5664294C |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9991977715523443 |
Encrypted: | false |
SSDEEP: | |
MD5: | AA19799E849907C6BF947093C2A77A37 |
SHA1: | C0465BBC93C75CAC6A463A11ECBA23E6ECAD04E3 |
SHA-256: | 5901085DFE9FFFD332E4576E69C6C944FFC90EEC071807AB8249985797F884FF |
SHA-512: | E85FEB564826AD913EB2DB8F6522260B200E4C3BC82BBA4A4A2CAC60B42F1BE54FCB082EA392EFD6F8F9DA06E000ACAE8C3326CF6009C1EAB49F01C04A8C8F8B |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 271360 |
Entropy (8bit): | 5.23590940853306 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3D4B87D66D0F570BC0F46D5A0BB11F1A |
SHA1: | 734C48F69C8C0113959B587C475D083EA01955A5 |
SHA-256: | D3D7C3CF7A3E9F5712B37A311B521CE2D020FF511DDC30FF668E87F97AC65089 |
SHA-512: | A2DC523626AC1C0E17747A595BB867068BBE3CCEF27F8195B4C7BB2E5FAD79BD3B42BFBC97EAE5B99BCEC7D930243682EADEA1B2C360E6ACA753EEF2D787F45B |
Malicious: | true |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 262144 |
Entropy (8bit): | 4.511355247161966 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5677BBCBE305F1C573A67B9F8F1686C0 |
SHA1: | ABE0E4C4934B6949CC725082026BCFBF77D0F552 |
SHA-256: | 9E4F7A3306C6DBB76302893F370DED183A1D78D920C802D69F84F4B2EB3E27A5 |
SHA-512: | 5CA035F04A12E85EF379FB2C7F39EA696247438D8B5C77A2B837C7A0B4087FDED5E5761F795580AFF642C60BD75759FBAE38BDCEA0F59247B6010BB0A410AFD0 |
Malicious: | true |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 666 |
Entropy (8bit): | 4.8302111215072765 |
Encrypted: | false |
SSDEEP: | |
MD5: | B9C267325E4B8875068403D0E2C99B5A |
SHA1: | 0AA3BD8BE2CBA2592AA14B58F5ADBE7FA76D2838 |
SHA-256: | D2E481B8FECC063B1A66B00C75E55ACDFB15DA394EBEF58B04082FE744622DF5 |
SHA-512: | 80BA0B4928D24832D9C1702A8A1004D7725F0F91812919F8AA7B703E0B0AEA1F535B3CE8049CE7A36F0262B3CFC65A03932DFB39C4C67B41A258D413BD011EFB |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/TableCollectorCutFilter.jsdbx?c=0 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 737522 |
Entropy (8bit): | 6.002982912743529 |
Encrypted: | false |
SSDEEP: | |
MD5: | F19C90CBF2A76A9FE3825E820600BA15 |
SHA1: | 84E310245B5FE7209E7075CC71CDDF48969DB345 |
SHA-256: | 1CE20DF9B429248C55416706140A263207F1C3A5CC10F965A8D8648246056EBA |
SHA-512: | 0E23C3408C3287CA7FBB001D9C3CC7A1E231A1483D1532C3144375CD24AA65B53A434FCCF255CBBA055D4DDC0ED31DB8308A44430B5ADEB55E785CDFBA7F87D7 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/a84b49ce1b5d341047582171604bcb7b.spcssdbx?portal=70cd9f3b734b13001fdae9c54cf6a72f&theme=8d52afcb1b5ed99091e963d8624bcb29&c=1f2c8033c3125a900e7e790f0501317a |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2124087 |
Entropy (8bit): | 5.483874448028802 |
Encrypted: | false |
SSDEEP: | |
MD5: | 124883D07C8B1B69ED5613AE74CA4CA5 |
SHA1: | 0C3F2B403FCA275CAA216ECA75537398F3471844 |
SHA-256: | 2DC5EF6761541495CA7D14FEC67859660FF8C47F6ABCD04203864E80CDB9A332 |
SHA-512: | 8377DA0C239D601B6A9F17A762F5E4A6D03A7CC3D92A6081CB193869E493E76BCE41760199CF2BE9F562ADDD591EAE1B30329CDC25B1F8264D4F2A88EE406F96 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3452 |
Entropy (8bit): | 5.117912766689607 |
Encrypted: | false |
SSDEEP: | |
MD5: | CB06E9A552B197D5C0EA600B431A3407 |
SHA1: | 04E167433F2F1038C78F387F8A166BB6542C2008 |
SHA-256: | 1F4EDBD2416E15BD82E61BA1A8E5558D44C4E914536B1B07712181BF57934021 |
SHA-512: | 1B4A3919E442EE4D2F30AE29B1C70DF7274E5428BCB6B3EDD84DCB92D60A0D6BDD9FA6D9DDE8EAB341FF4C12DE00A50858BF1FC5B6135B71E9E177F5A9ED34B9 |
Malicious: | false |
Reputation: | unknown |
URL: | https://login.live.com/Me.htm?v=3 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 303360 |
Entropy (8bit): | 5.197165220732047 |
Encrypted: | false |
SSDEEP: | |
MD5: | 1885094A6793A574761657F9456CD2BE |
SHA1: | 69E210B6796DC0BD1B2342D023F805AB1D0AF4BE |
SHA-256: | 094A9270746FFDAE4E348DB6D76AD8807C47987B70542AAA2C4BEA4E4D046DB4 |
SHA-512: | E3227170893404647FF37D8410F533E26034A8A675B6DC9DF15494106336AF2073318B7BC180DA124E31473233EABF6A6B462D14FE71445E57AD39A91508DF34 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 61052 |
Entropy (8bit): | 7.996159932827634 |
Encrypted: | true |
SSDEEP: | |
MD5: | C1E82BF71ADD622AD0F3BF8572F634FC |
SHA1: | 6CA863D4CAB96669202548D301693B3F5F80B0D5 |
SHA-256: | BA48AF15D297DB450DC4870242482145ADDB2D18375A4871C490429E2DC5464A |
SHA-512: | 820A7F8A0C8EA33A8FE1E90CDC35F45DC1E143E836B0D8EA047E1E312F8CAEC72CDEE4E7DB54760A4D749CD0ACFE103A27E39A9A56EB2D704E448A67B0D0C079 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1612 |
Entropy (8bit): | 5.259159894747691 |
Encrypted: | false |
SSDEEP: | |
MD5: | EB65C0BF0919B953C6EE9B5A363E1486 |
SHA1: | 3487D905242CA5DB1919029781B8287F5236D082 |
SHA-256: | 099E473D06E4DDA8EC48B77F5576611A5EF895FAC1114CEFFCD483E59CA95949 |
SHA-512: | F26CF56587ED7779035B521128D914C6A90209DD79AC52E87D729E0396DEAFF7EA54C69509480D7CACC11A21B4B1F032FEDD1C47F3FDAA715C7A8D9710F6975C |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/angular.do?sysparm_type=get_partial&name=sn_banner.xml |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 103695 |
Entropy (8bit): | 5.34473680950684 |
Encrypted: | false |
SSDEEP: | |
MD5: | A8250E5D356599CA3F666C0070A884C7 |
SHA1: | 92173B7CE034B71F7030EB9329AA9AE44D1135BF |
SHA-256: | E5BD8B5F7D4E0A05ADEE08D9250451EE3D17A8492196A43C6AD8F8576044B157 |
SHA-512: | 45CF7834526C3049AF41DA338B2472658EF966FF4130B45EC0DB2F032DE393C2F3479B3A2283992D5BD95E29938F3CBB082AB333A7D2B63577AF5536DA7125B3 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/uxasset/externals/@servicenow/ui-renderer-react/index.jsdbx?sysparm_use_cache_buster=true&uxpcb=1734013114774 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 310623 |
Entropy (8bit): | 5.418303971924681 |
Encrypted: | false |
SSDEEP: | |
MD5: | CAA0480DACEA2712D51E1A1C87907C89 |
SHA1: | 84AA421403266551DADC77ED8514CD011A6F166C |
SHA-256: | 753F8F11BD894AB52F0A1CDB5EC6C1E25D03F9F63AAA90BA5D1BD17EC361B8E7 |
SHA-512: | 7AAD8C9A31211ACAEC3A39BA2FE38525FF214C01E77BB0A31A23C3717D55E1E705B489A52CB6B21F48C5675D713CC2E42C5F7635AF50BA14B140BD4F2623D810 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/scripts/js_includes_sp_libs_min.jsx?v=11-19-2024_1208&lp=Sat_Dec_07_07_03_14_PST_2024&c=27_632 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 258673 |
Entropy (8bit): | 5.184064656663596 |
Encrypted: | false |
SSDEEP: | |
MD5: | EC96102579BBCE54B66EEA14A1A44127 |
SHA1: | D34FDA2A6CDFD1A15314E0AA9B00BD9ADF3529C9 |
SHA-256: | 0F58C83C460E06BDF5B969D662FE9414F7C0EF1532191D1A8C9EA576CAFE4252 |
SHA-512: | B66C343EDB2EB30478B5A358FC775918CBF47A785411F6F9C1614827D64B07252688B64351BE89992EBED48C9C5BD207CE73FCF46A49290DBC634078EEC41809 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/styles/scss/sp-bootstrap-rem.scss?portal_id=70cd9f3b734b13001fdae9c54cf6a72f&theme_id=8d52afcb1b5ed99091e963d8624bcb29&v=7984307bc3de9a900e7e790f05013185&uxf_theme_id=null&uxf_theme_variant_id=null&is_rtl=false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 116343 |
Entropy (8bit): | 7.997640489040715 |
Encrypted: | true |
SSDEEP: | |
MD5: | 3063B0DA40B45B46602FCE99AC53D315 |
SHA1: | 57883FF854B80AD2A76479A0273BE9218B4DA553 |
SHA-256: | C60FB365DF08D31F36EDA468941C309AE3A917ED784A30495800F05E5F98B66B |
SHA-512: | 3EAF55117A825B588972F6AE324F6173EF4F2A309BAB69A9A6CC43C8F9A4EE25C2FA86752C8912542CC353727DC54A034B369D4A4451F0C3B20206C16FA9FE98 |
Malicious: | false |
Reputation: | unknown |
URL: | https://aadcdn.msauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_27cef08ca792f8e8b149.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 376 |
Entropy (8bit): | 4.870326236766533 |
Encrypted: | false |
SSDEEP: | |
MD5: | C1248FA927BE2B21A80086C4E98D29FE |
SHA1: | 06433DC83A1A9F3103333DE0D092FC113CD2D80C |
SHA-256: | 35A86319D80B941DF7DB498279450D00C7AAFF7F890B8C0779A8536A2A51EBEF |
SHA-512: | 83E0C668E1F71BFFA7E22B00DB99B40B8033519B4FB8402E5D0ECF692B64D3C702AE19FD68FC1461068BB674CB6E4F493A3AF01A352E41CFC59509990A4BF3D2 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 92314 |
Entropy (8bit): | 5.459000182228848 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0DFE36DC4B9B5F7267E0913F8521CF13 |
SHA1: | E0B2F0BAA3D60EE6BF5607EE39C84664ACE90DEC |
SHA-256: | A7846E347BA6040DEC5CEBA744396B4501EC05B199C07B7BEDDBADA41FF40227 |
SHA-512: | DC84303EFC60A663B52BAF79B38EB6D524D1458846C828E6DF5A997518F6A4AE8A3AA633C2BD484628F51B5BC1258D0F82DAAE5712BF769FBC1FFB240E980363 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/uxasset/externals/amb-client-js/index.jsdbx?sysparm_use_cache_buster=true&uxpcb=1734013114774 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 38712 |
Entropy (8bit): | 4.912519157798346 |
Encrypted: | false |
SSDEEP: | |
MD5: | 762E68D878E1A981F56D6E028F987E27 |
SHA1: | B1E3AE98753DD884E4C8B138025A43D1A408697E |
SHA-256: | A5571EC0464A9B9D36C6B145E41FD4CE6427C9FA4EA20E659229191584086AAC |
SHA-512: | 36109C1FA263C3EC4B50E87A63C34616C207D8C6F22EAC461CF747093BFB14D0BAADB679A0738E7CB3A1AE5BD47FBD4744023C8C66894341E7D645316D880F12 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/styles/css_includes_$sp_later.css?v=7984307bc3de9a900e7e790f05013185 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 25320 |
Entropy (8bit): | 7.992717825046205 |
Encrypted: | true |
SSDEEP: | |
MD5: | 344EE6EAAD74DF6B72DEC90B1B888AAB |
SHA1: | 490E2D92C7F8F3934C14E6C467D8409194BB2C9A |
SHA-256: | A3CF4861C7D0C966F0ED6564F6AAD6B28CBD3421A9CA4F60E2246848D249F196 |
SHA-512: | 2A9A9162D610376512A8FAE2CF9EB7E5146CC44C8EBDE7A12E9A3985DA1718C62AE517C25B00DE7C0269EFAB61B4850A0BECFBF04382A25730DBE9CF59825A62 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/styles/polarisberg/fonts/lato/lato-v17-latin-ext_latin-regular.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 77160 |
Entropy (8bit): | 7.996509451516447 |
Encrypted: | true |
SSDEEP: | |
MD5: | AF7AE505A9EED503F8B8E6982036873E |
SHA1: | D6F48CBA7D076FB6F2FD6BA993A75B9DC1ECBF0C |
SHA-256: | 2ADEFCBC041E7D18FCF2D417879DC5A09997AA64D675B7A3C4B6CE33DA13F3FE |
SHA-512: | 838FEFDBC14901F41EDF995A78FDAC55764CD4912CCB734B8BEA4909194582904D8F2AFDF2B6C428667912CE4D65681A1044D045D1BC6DE2B14113F0315FC892 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/scripts/icon-fonts/font-awesome/fonts/fontawesome-webfont.woff2?v=4.7.0 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 72 |
Entropy (8bit): | 4.241202481433726 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9E576E34B18E986347909C29AE6A82C6 |
SHA1: | 532C767978DC2B55854B3CA2D2DF5B4DB221C934 |
SHA-256: | 88BDF5AF090328963973990DE427779F9C4DF3B8E1F5BADC3D972BAC3087006D |
SHA-512: | 5EF6DCFFD93434D45760888BF4B95FF134D53F34DA9DC904AD3C5EBEDC58409073483F531FEA4233869ED3EC75F38B022A70B2E179A5D3A13BDB10AB5C46B124 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1296 |
Entropy (8bit): | 4.9479893750336945 |
Encrypted: | false |
SSDEEP: | |
MD5: | 6A4E2DC5D5406655B316EE1C591175CF |
SHA1: | 6D238647AD70F6816662A9ED9C25B776F1578176 |
SHA-256: | 4C5EB2D3F0FA094CFB7ADB5528F52ABC9B7111FDC884CEAF61D25C5566F0370B |
SHA-512: | 2417FC45EFDC6FBB86A6D2EAE212CC908C097C10B66F2B7DFF73192157929F6D708B7C7BD5C5AE77277EBF0C0D29EE35417124811A553B7F6C4A0A1E047D95A0 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 122515 |
Entropy (8bit): | 7.997419459076181 |
Encrypted: | true |
SSDEEP: | |
MD5: | AC9A6ED508328361A4C9530325A94076 |
SHA1: | ADC81FAE51EB66A220539EEEDECEB96CFF390BBB |
SHA-256: | BA93F4A83BB77D32AF9AFB9B014BFD13FD497E3D8F15AF016C782ABD1D34037B |
SHA-512: | 066D92389A7EFB3A80FCFC86696EE6AE008259570F73814303A9ACC1690F881DF2034A16D5C7970BA703648CA79C2E7CBAA2CAD98C28879ADD44AB06620305B4 |
Malicious: | false |
Reputation: | unknown |
URL: | https://aadcdn.msauth.net/shared/1.0/content/js/ConvergedLogin_PCore_kAx9qZOSH4g90FNHstHMCA2.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 18692 |
Entropy (8bit): | 5.055262935903728 |
Encrypted: | false |
SSDEEP: | |
MD5: | 92DA024D492B48BE21891E8EEA374020 |
SHA1: | 6CF4CA1E363C759589ABE00FE2F7766FD46DFEEC |
SHA-256: | A3633C3B21E417D7F3C241A5A9F35CACC784C6400F3A631FE833EA57603597B2 |
SHA-512: | 6D6241791D622E09D279AD1AECBD0ABEFC63B818EDEB3D4BCA16F1AAE3DD90DA25BEF29A307639B4CA2875BDED9812EB864AB519349ED56D1FB364F133355D0D |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/legacy_date_time_choices_processor.do?lang=en |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16463 |
Entropy (8bit): | 4.687617147837003 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4768C17196B853779CE5EF589EA2B60A |
SHA1: | DE3551EA6668DF5000219AD0487CBB74598A277B |
SHA-256: | 06BCAAC81283157BEEC648B2FA7667CFB201C486CE74741529D9BE74C6CDE332 |
SHA-512: | 59ECFBFC3DAB00E47C9A8D09408AA3936C40E7D49270B97A3BEE1399E6348F71DC23932523FB7889AB16EF6560EF3C4A04F59760CDCDBAEF25F0D02FA443BA54 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/styles/retina_icons/retina_icons.css?v=11-19-2024_1208 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 21518 |
Entropy (8bit): | 5.406406599485588 |
Encrypted: | false |
SSDEEP: | |
MD5: | EB2CEEE1048DFCC0E5F0D5A746173FA1 |
SHA1: | 0DB7C469F7BFA5EFD03063845BE08C4C21637AA9 |
SHA-256: | 1617976607BD6B3E355D5883B558A9D3CE61E14CC0BC2D956552466FE6971E4B |
SHA-512: | 809026B9EA88DEA83B51FC0442EFBC5B3660405A639436F997F02285761F8D94CBE89DB043370596E0BC5E07D809B541D5515BC3B063E844E924E0A28B31855E |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3168 |
Entropy (8bit): | 7.9103431269175735 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9BBF95ECB779B96A05F5CE82E9CAD47F |
SHA1: | F4D1A6516FF78028C9909FF474FE63AB7AC2D11A |
SHA-256: | 2BAB94B6548FE079E724FBE340BE0916FC16C2D29524ABA956492F5B65B667B3 |
SHA-512: | 8DBA189EB43CD5F6C22F3B866ECA321B610FAF2308C531B42B5A86FDDAAA7040E2A6805F110D2B078C185EE0B9A16711E7492EF129C1C060314806283E6E1218 |
Malicious: | false |
Reputation: | unknown |
URL: | https://aadcdn.msauthimages.net/c1c6b6c8-ynmmni9vieierh5atlddxa2loq3ihganl084p3vc9m4/logintenantbranding/0/bannerlogo?ts=637374934307906358 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 11995 |
Entropy (8bit): | 5.304578777673101 |
Encrypted: | false |
SSDEEP: | |
MD5: | F5CBEF1FA3E8DCF48ED100F5AF84F288 |
SHA1: | A6F39A7A42F46206E448DF550B54AE71426FFE7D |
SHA-256: | 3E6C37C70422FA9871C095DE2E672F61A742EAE4B976DBC1C96ED431F5B11AEB |
SHA-512: | 05C1DB8688A72177D78DEBE356630E0ECB162221F83594D085D6E439095B884E799DE69CBF3C67357D92F73CFB761E7B39783C22787B307596256588B1458DB2 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/uxasset/externals/@servicenow/ui-analytics-bundle/bundled-assets.jsdbx?sysparm_use_cache_buster=true&uxpcb=1734013114774 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1337 |
Entropy (8bit): | 5.2586053598886195 |
Encrypted: | false |
SSDEEP: | |
MD5: | A02FC46B55D2F8517397074D6A56B6DC |
SHA1: | 42E8C7D56935339447B6591B20FB6F73C82A26AF |
SHA-256: | 0121FB52F232F75482C936C366AB565BDC8C9F3A194B7C0D6DC21F888F264A75 |
SHA-512: | 13B3D78B980BE0DD52F606561161A1C5C09C973ECCFD6C9BE14CAC722A8D67D336099BEBF773F16A9CDF6F22866E984F5898F09ED5C30EAA50E0DF9EDDEA615C |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2694 |
Entropy (8bit): | 5.1307085617324475 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9A3D034FE09E511A4F61B80B965383DE |
SHA1: | A45EB6C66B900D4FC88F2F1619F1E49A274899E0 |
SHA-256: | 6180805B29832044A2FDDC24E4407B972E29C369F361F6F1FABAAA6F364F66D7 |
SHA-512: | 678EF33358CACBBE5F01792E8E03A7A3B91B5BD4F6CAB88123D6FEC60BD4A9C1D4B3F849E26F39CF0F4786BB8F8907CE2B9409B21B4CC2B8F83A8A72C0B322FD |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/scripts/ui_page_footer.jsx?v=11-19-2024_1208 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 72821 |
Entropy (8bit): | 5.092095451421716 |
Encrypted: | false |
SSDEEP: | |
MD5: | CCA5D557516541F5C7C273ABBE942C34 |
SHA1: | 81C1F77DC17B1F6B46ABAE3B59506843A784EFB2 |
SHA-256: | D2833068740AD54A90AB691A43889DD3B2CC6DB9AF4994C900AEFCAE653D5055 |
SHA-512: | 67CB0D4875EC2E824913DD51CB42D4BDA07730248E8CB7A16BDEB369E1C6559A22231382067F3FBA18ED336B07DAC0D7396038B7EEFAC928EC87D4E6D608EAC0 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/scripts/doctype/js_includes_legacy.jsx?v=11-19-2024_1208&lp=Sat_Dec_07_07_03_14_PST_2024&c=27_632 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9141 |
Entropy (8bit): | 5.1653389683863375 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5A2C8842BB544E97B74E8059D9DC62BD |
SHA1: | 78B1BFF2410E86D0ECA1C05BC3D8F74DE8404DA4 |
SHA-256: | 3D737C33266D736EB4784D5A4EC9EDDE0117FE9DBAA51D2714EA5B9C4C184453 |
SHA-512: | A423F88F70D6B0928247B0415014DE95C4E257DE141F7C849C8F2B404555F1C40B330BBA62B54F4A78631A84CBADC6D3E7971F6DC827A4A6E38BF3DDB759DCAC |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 288922 |
Entropy (8bit): | 7.989911896006276 |
Encrypted: | false |
SSDEEP: | |
MD5: | E4015B415F50E8A1B8635BD855682F12 |
SHA1: | 2E3369AACF302E997563ED5B5B9461139505C711 |
SHA-256: | E5AE180750A3F36A8C386FE14F3757D7CE5A6E21D60AD97EBE710EC75994C8E3 |
SHA-512: | 3BE675C3DA9829C77961A189FA3865639873A657FC772057D8A5A9431E844879B86EE7D23502F8C9EDD682213EA9E2921A4AA00B3E4FB4FDB304DCA08E3A070D |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 49911 |
Entropy (8bit): | 7.994516776763163 |
Encrypted: | true |
SSDEEP: | |
MD5: | 9B96CC09F9E89D0334BA2FBC22B5197A |
SHA1: | B5FE69F39E9F61FEF88DF794F02DC4F4086E2592 |
SHA-256: | E6331018533143C411BAE25326AB52FCED541C48674551AEA78E750855BDCD1D |
SHA-512: | 2BDD71A34A7D6172AD4B7B6CF077A891D6266C148000EEF8345E2343E6C21ED8783B2EA328EF3BF7176462A3CA575D2D6D4B55A07138CFD1B02900C95F61077D |
Malicious: | false |
Reputation: | unknown |
URL: | https://aadcdn.msauth.net/shared/1.0/content/js/BssoInterrupt_Core_zKox_QMcTIVut7mG_Z9Eew2.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1075 |
Entropy (8bit): | 5.1845520409273655 |
Encrypted: | false |
SSDEEP: | |
MD5: | 16B1882C373F0EB3DB6C495D8DB7C60A |
SHA1: | 04B49E678129A15E3FD8E0DFBF813FA177FC53D9 |
SHA-256: | 0C0165F4FBF9DD81E8E22D5CFEB2E504D8E595906390459F8983AFB7DCA540D2 |
SHA-512: | 1EBD97F453FEE88EC3D9978B41DFBE77B8EC59E2A28B69D7A2D4EF7530FD40521DE31E39E6061E7677AE14670D2C5B6A8346A60CA1397138D5CC77B83A856156 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/app_com.jsdbx?c=21 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1367 |
Entropy (8bit): | 5.128623006020269 |
Encrypted: | false |
SSDEEP: | |
MD5: | 799C4BAF87B32D402A35B36E0F4B9DAB |
SHA1: | F49507F7E77BFD1D1D1B24AE1C1FC3D8EEF8E5BE |
SHA-256: | FED3B2FAB073B450BE8937EFA4D2D0981FAB662D9B8081F3CBCEE346E956F71D |
SHA-512: | 414CDDCEED956561EEC8F667E923F942BAE30654A7B67246FAF714FD667697C3BD63E60AF353E9561A148931370240880CD41AB7EDB1909A9BF2E2CB9900DADB |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/scripts/polaris_theme_refresh_observer.jsx?v=11-19-2024_1208 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5525 |
Entropy (8bit): | 7.961202222662501 |
Encrypted: | false |
SSDEEP: | |
MD5: | 28CE5BF8BACB96D1C2CFA0092145C6EE |
SHA1: | 303A4629C4467AF2C551EC9E6353464C8C25827D |
SHA-256: | 6B89EEC14865DB53FE20FB3C70B0853362E21669DACE19C06172F673B2EDC5CD |
SHA-512: | 6A10794F105EF5C6F7F7DC2C89152A8342E6D9D8D9490783863ED2737FFD5982E916F72E0A9ECB944AB9815FA70BD20C7256A91E2A62D971F80C23822B809A02 |
Malicious: | false |
Reputation: | unknown |
URL: | https://aadcdn.msauth.net/shared/1.0/content/js/asyncchunk/convergedlogin_pfetchsessionsprogress_1cd84c14a6b01fcd8515.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 36 |
Entropy (8bit): | 4.503258334775644 |
Encrypted: | false |
SSDEEP: | |
MD5: | 06B313E93DD76909460FBFC0CD98CB6B |
SHA1: | C4F9B2BBD840A4328F85F54873C434336A193888 |
SHA-256: | B4532478707B495D0BB1C21C314AEF959DD1A5E0F66E52DAD5FC332C8B697CBA |
SHA-512: | EFD7E8195D9C126883C71FED3EFEDE55916848B784F8434ED2677DF5004436F7EDE9F80277CB4675C4DEB8F243B2705A3806B412FAA8842E039E9DC467C11645 |
Malicious: | false |
Reputation: | unknown |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwmCAmly1gHbXRIFDdFbUVISBQ1Xevf9?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 18028 |
Entropy (8bit): | 7.988319422898098 |
Encrypted: | false |
SSDEEP: | |
MD5: | 448C34A56D699C29117ADC64C43AFFEB |
SHA1: | CA35B697D99CAE4D1B60F2D60FCD37771987EB07 |
SHA-256: | FE185D11A49676890D47BB783312A0CDA5A44C4039214094E7957B4C040EF11C |
SHA-512: | 3811804F56EC3C82F0BEF35DE0A9250E546A1E357FB59E2784F610D638FEC355A27B480E3F796243C0E3D3743BE3EADDA8F9064C2B5B49577E16B7E40EFCDB83 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/styles/fonts/glyphicons-halflings-regular.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 270 |
Entropy (8bit): | 4.632626320716766 |
Encrypted: | false |
SSDEEP: | |
MD5: | C961337E276E7BF10C98A2F1D5381158 |
SHA1: | 7CC63798DC697B0584DE16D93F486FF89BA08E57 |
SHA-256: | F9D6711D0A28AAC9FCA0DF564629141FE239B82B605D463ABF9DB96B1E8E29F3 |
SHA-512: | D6BEA8F15138F20F39F19E8539E0DBD09CD25B8D12FC6B67B12C3383DAE9C43DC4E664FFA84D4F4656FD606694BD1D1B9F344280644AC3741AAE9949F9BCBF71 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/gbsAngularReplaceFilter.jsdbx?c=1 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 45160 |
Entropy (8bit): | 7.992042896065771 |
Encrypted: | true |
SSDEEP: | |
MD5: | 390B5B48631D2E5BB35CA6D8233D88D4 |
SHA1: | 3EB127AAC566ED7C451219E9BE75B59F7E14ABCD |
SHA-256: | BA85E2E3BC928A967EBEA99D4E3B7E2D4BA0EAF49BC3550FB52D2EE912DE5A71 |
SHA-512: | 747BCE14A6C4273C9A765AD59F18F7A462EF93D9CF4774CEE5E7B5E26E266AF9450FB7CAFF61D06D1B7010AAFAF6BFCA69EF3FA2235E9390410DB671D57E05D7 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/styles/now_icons/now-icons.woff?1b83226fe70623e32efcda1aaf0a6462 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 621 |
Entropy (8bit): | 7.673946009263606 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4761405717E938D7E7400BB15715DB1E |
SHA1: | 76FED7C229D353A27DB3257F5927C1EAF0AB8DE9 |
SHA-256: | F7ED91A1DAB5BB2802A7A3B3890DF4777588CCBE04903260FBA83E6E64C90DDF |
SHA-512: | E8DAC6F81EB4EBA2722E9F34DAF9B99548E5C40CCA93791FBEDA3DEBD8D6E401975FC1A75986C0E7262AFA1B9D1475E1008A89B92C8A7BEC84D8A917F221B4A2 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 139456 |
Entropy (8bit): | 5.298480196002961 |
Encrypted: | false |
SSDEEP: | |
MD5: | 39EA7A7715DE51ED15F989623E9C9298 |
SHA1: | B6168FFA9095EB1E52C5E309E9F5ACEB49052EA2 |
SHA-256: | B14C33D1F9205FFE093C2341FA58CB72B5DC64E2844322B2D67AE321AE05A677 |
SHA-512: | 97A2D50BB7064CD12B53B990C7957A1ADD479E242D674596D56D9245AF00CB24297051EC4FC94ACE8513D624978E3CB6D750B64D23979B09AA2C03FB356F76BF |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/styles/css_includes_doctype_polaris.cssx?v=11-19-2024_1208&c=1f2c8033c3125a900e7e790f0501317a&theme=Polaris |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 47087 |
Entropy (8bit): | 5.144337240038449 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5F84773D1E55578D10949109142D32E9 |
SHA1: | 13FBEE46E02D3AFE649E24F78F25A72CBC72BA32 |
SHA-256: | 14DC50C0B62F97C266B688BA43CB7BE7681078169C48E490467A9308B4E16D59 |
SHA-512: | A95E3833E8206355E4D382EC4439AD28BA867D37A7D388530F1B5E9E3D9F23D9117E446F08D1CCC2DE7D8A7598C65B1936C2159B31D92E784D1E9D06A3624462 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/scripts/thirdparty/dom_purify/purify.jsx?v=11-19-2024_1208&sysparm_substitute=false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3620 |
Entropy (8bit): | 6.867828878374734 |
Encrypted: | false |
SSDEEP: | |
MD5: | B540A8E518037192E32C4FE58BF2DBAB |
SHA1: | 3047C1DB97B86F6981E0AD2F96AF40CDF43511AF |
SHA-256: | 8737D721808655F37B333F08A90185699E7E8B9BDAAA15CDB63C8448B426F95D |
SHA-512: | E3612D9E6809EC192F6E2D035290B730871C269A267115E4A5515CADB7E6E14E3DD4290A35ABAA8D14CF1FA3924DC76E11926AC341E0F6F372E9FC5434B546E5 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35170 |
Entropy (8bit): | 7.993096534744333 |
Encrypted: | true |
SSDEEP: | |
MD5: | 171A4DD9400708B88724B57D62B24A6A |
SHA1: | 9C6F1303B8F02FCE18D20EC9CADA11D38D0C4B37 |
SHA-256: | EA00750636C11DBD4FA3ACB1B3CDCBAE3EFA43F6B6C3753444B6D6A242AE9336 |
SHA-512: | 5B13B63912B34E3EEEDD8DA5953B869A83DF82FFD2A8D737AA81DC984F1811800A534F340C48041DA803C25B6B8F5605EA8D003B6A09A1874408F95A710F5126 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 17174 |
Entropy (8bit): | 2.9129715116732746 |
Encrypted: | false |
SSDEEP: | |
MD5: | 12E3DAC858061D088023B2BD48E2FA96 |
SHA1: | E08CE1A144ECEAE0C3C2EA7A9D6FBC5658F24CE5 |
SHA-256: | 90CDAF487716184E4034000935C605D1633926D348116D198F355A98B8C6CD21 |
SHA-512: | C5030C55A855E7A9E20E22F4C70BF1E0F3C558A9B7D501CFAB6992AC2656AE5E41B050CCAC541EFA55F9603E0D349B247EB4912EE169D44044271789C719CD01 |
Malicious: | false |
Reputation: | unknown |
URL: | https://aadcdn.msauth.net/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16345 |
Entropy (8bit): | 7.98960525258912 |
Encrypted: | false |
SSDEEP: | |
MD5: | 187B9EBA41FDF66B2C8F7EB645D2BC17 |
SHA1: | B1C034F7F5F754F271D094FB417B9A820C1F712C |
SHA-256: | CA0FBF8421A0CF4CCDA7310B2AE74CBD92214901EC2D0F273EA3B07F12CF96EA |
SHA-512: | 0D7FB682D24E97C9E3FC04AA87CCB8EC508CA0CF197DA0617EFFD981BC8B5E3600824FDD08F1F31F59D276B5BF53229D00805D984E01D512FD968610C5FE9609 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 216087 |
Entropy (8bit): | 5.205195754201935 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8BEC8A10BC03D8B90F0AA271A5970838 |
SHA1: | 452F9E7499B13D22F24DB74783AEB6AC8B1F3EC3 |
SHA-256: | 6440EE267F63E7491450D50889C97441F8E7F826C16F55B6EEC07EB339D33DC0 |
SHA-512: | 441F41AAD2B1EB73413FCFFA41F90096A98D0BB06B171023577F7C2D038CA1372680AB354EB4BC26061DBD3274B5F3B4C7F1D5F560E29C4DFA48F73C269F3766 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/scripts/js_includes_list_edit_doctype.jsx?v=11-19-2024_1208&lp=Sat_Dec_07_07_03_14_PST_2024&c=27_632 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 603776 |
Entropy (8bit): | 5.110563373227547 |
Encrypted: | false |
SSDEEP: | |
MD5: | 90E628F63BF6AE97B005E255809583AA |
SHA1: | 9C7BE0825437940B49462D1AD42341FA4A75C9F8 |
SHA-256: | 8CCE77E110B257173D657E611D15F94303025197712B329DA59624FE3F86E93F |
SHA-512: | A85CFFE1E827FB0AAC1AFCAA7C71D95B666B33521EAF61C3C41BA959688202E12C27766DC4194903E0B49A4D47A6A30E4D6CB96A0C61F3E4C3DC67696EBA5BA3 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/styles/polarisberg/css_includes_polarisberg.cssx?v=11-19-2024_1208&c=1f2c8033c3125a900e7e790f0501317a&theme=Polaris |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1408 |
Entropy (8bit): | 4.888815376336492 |
Encrypted: | false |
SSDEEP: | |
MD5: | D9DB5FF70240541175C8853C363459AE |
SHA1: | B611C779602DBFE130C0450171CEB70EA7DCAA20 |
SHA-256: | 1C7C259141B903C0B2F76CD49515CEE7CB34ECEA8A59C08DD2A7304DA457A871 |
SHA-512: | 84A54F6BF6FA6DF00E7FB1B7F68A4CE522D6884121C8E6F393E1C87378B546B9B672E242D2D2679E6EE3423DC25CA21C1EAD51AD502681D28470401C54E0078E |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/styles/fonts/source-sans-pro/source-sans-pro-latin.css?v=7984307bc3de9a900e7e790f05013185 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 20410 |
Entropy (8bit): | 7.980582012022051 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3BA4D76A17ADD0A6C34EE696F28C8541 |
SHA1: | 5E8A4B8334539A7EAB798A7799F6E232016CB263 |
SHA-256: | 17D6FF63DD857A72F37292B5906B40DC087EA27D7B1DEFCFA6DD1BA82AEA0B59 |
SHA-512: | 8DA16A9759BB68A6B408F9F274B882ABB3EE7BA19F888448E495B721094BDB2CE5664E9A26BAE306A00491235EB94C143E53F618CCD6D50307C3C7F2EF1B4455 |
Malicious: | false |
Reputation: | unknown |
URL: | https://aadcdn.msauth.net/ests/2.1/content/cdnbundles/converged.v2.login.min_81imvbluez-v5hbzpkxfcg2.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2672 |
Entropy (8bit): | 6.640973516071413 |
Encrypted: | false |
SSDEEP: | |
MD5: | 166DE53471265253AB3A456DEFE6DA23 |
SHA1: | 17C6DF4D7CCF1FA2C9EFD716FBAE0FC2C71C8D6D |
SHA-256: | A46201581A7C7C667FD42787CD1E9ADF2F6BF809EFB7596E61A03E8DBA9ADA13 |
SHA-512: | 80978C1D262BC225A8BA1758DF546E27B5BE8D84CBCF7E6044910E5E05E04AFFEFEC3C0DA0818145EB8A917E1A8D90F4BAC833B64A1F6DE97AD3D5FC80A02308 |
Malicious: | false |
Reputation: | unknown |
URL: | https://aadcdn.msauth.net/shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 828 |
Entropy (8bit): | 4.855857619456706 |
Encrypted: | false |
SSDEEP: | |
MD5: | C18F89F8041FD2A409A9AE6DBCA6AC8E |
SHA1: | 19ECCA5678D087D5F271FAEAF3354704C9EBED98 |
SHA-256: | 8D742426FF9C3AB9E8B31CE4DB9ABF46E770723AE47D552E87DD1C476A9B0495 |
SHA-512: | E51D1C4B3AC5F4C24AF57BAE92E66B385DDE45D759EF5273160D546A1369CA05132CCC3910C6DC3E817E108ACCF7DF58812144BB78619F5A3950DDAD8770EFAE |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/uxasset/externals/@servicenow/now-icon/icons/magnifyingGlass.jsdbx?sysparm_use_cache_buster=true&uxpcb=1734013114774 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 7590 |
Entropy (8bit): | 5.290708939812461 |
Encrypted: | false |
SSDEEP: | |
MD5: | EC13DE119F711F3D7BB04EB08C809A36 |
SHA1: | 2CB38B23350F44CF20CE6B7E62D8083828511AEF |
SHA-256: | A3BC7FC614D398FAA526F1753EB2D70AF7314BDB6DDBC12258484F1D10DDC1D3 |
SHA-512: | 523E9D0FC9AFECC8C54DCF82E53EB5C792334E4B534748F54AFBDDE9AFE26FF4D3DE2537CFAC3BF91F652CF59C5E58977D057F5C778471F188FB252A271131A4 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/app_com.modelUtil.jsdbx?c=20 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 219139 |
Entropy (8bit): | 4.781282471710643 |
Encrypted: | false |
SSDEEP: | |
MD5: | 27B27C9599F474D6D399BEF485354E0D |
SHA1: | B90E8E5307EA10585BD59C1B96FF4CD4AB9462E5 |
SHA-256: | 9E5D5A7F9A0183C75E219525B516083E1551A3557AEA1E868F28E84DFA35E5C2 |
SHA-512: | 1F955D81811A6DAE015EFB6BA9E4E9680E9777D02F73A570F26ABFB76FA02A6A5C7AADCDED1633926FF0C89DA56EA93B087A1037D8AF04E76E4367E4FD043B3B |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/polarisberg_theme_variables.do?c=falseluNJVUCf9GyDXPEqQk04K1WfS2M%3D |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 275655 |
Entropy (8bit): | 5.5260844785098 |
Encrypted: | false |
SSDEEP: | |
MD5: | 65A7CEFF4A196F981D653104BDC897AE |
SHA1: | DC30BB9E10D3E5FD9B174AEAFFB539D28805908A |
SHA-256: | 89222CCAFD52F96F057B3372AF81A7BBA3E8B8DEF5D5015B9D53577A4FC36DDB |
SHA-512: | C7DFFAAAF40B5B04E57695E09A51E7E182F913F4B02E70A10E2CF069568C0E6A01AF41E75EE6F598183FC69475222200E5020EAA97A89F11CE54F6E364815BD4 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/uxasset/externals/@servicenow/ui-mega/index.jsdbx?sysparm_use_cache_buster=true&uxpcb=1734013114774 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 130976 |
Entropy (8bit): | 4.8971596944524105 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9099432A2FC1BAC88E50CD68F83E2459 |
SHA1: | BC37792041F7F903F960B8F6A81EF22F37B371AB |
SHA-256: | 61C60DB313006AA9F05E95653BDC1338045F2EE6FE72E28596C99D8580C17D1B |
SHA-512: | C920B56173DDB746BD5F17E9FDA8A75AC5351F8FC94238B92A1B70C4FB0094EFE85DC4DD735C604724AC186C42C9150170FC7FAB67D0FF557D01B6ADA3D50099 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 48403 |
Entropy (8bit): | 5.1277711605161524 |
Encrypted: | false |
SSDEEP: | |
MD5: | 48C2F0555FAD4B0C1CD2D6C199C54E13 |
SHA1: | 5DEF9E1CF6F6B85719BC16C922821FA4A7BC31A1 |
SHA-256: | CEC72FFA8D5568A5A8A8B97B0B7957D7472AEAFE23D85343A62077A86227661C |
SHA-512: | 701C98B6580B905772E15A95266092CFBCA6D8EDE1A2BD8F7DDB732990B05CEFEF778823230EB9985EB8D0B72CAEFE139FB5010E4325327B81C39527A99DA4C9 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/styles/css_includes_$sp.css?v=7984307bc3de9a900e7e790f05013185 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4294296 |
Entropy (8bit): | 5.512322250230403 |
Encrypted: | false |
SSDEEP: | |
MD5: | 004F0C9F089FD57B42E0E259C1B595BB |
SHA1: | FC8F0E323AEDAD303686869A8F3111491D177D29 |
SHA-256: | DFF052CEE132DDE2FDFD5A6100EA89F9AB88C2CD93477F3341AFD1CEC86EC30F |
SHA-512: | D26A740D199D3A1C8EEA8C5FD664AF1A6B73E677E5E61C74097945BA9CFA199AD4930B5AA78CDE022BBBB9DBF96093A47641F574A98BDA99218325C0C14CEA2C |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/uxasset/externals/ais-sn-components/index.jsdbx?sysparm_use_cache_buster=true&uxpcb=1734013114774 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 37755 |
Entropy (8bit): | 5.405244808756547 |
Encrypted: | false |
SSDEEP: | |
MD5: | 26FC7FEFC7D7A9578D318EEC75A58E96 |
SHA1: | 02BFDAD2A39820493621459172D6B342115949BC |
SHA-256: | 4485432A04332B11E38BDC4DB18F8BFAEAEEB2589F2E66DCED3D2C424A948A3D |
SHA-512: | FBA36D09E37CAC382109C5FD69876837D7AE00621120C2A032BEC985D236600A3460647CBBAE9CE9159336EF2F9960184777878FD722C531B278671009AC053E |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/scripts/app.guided_tours/js_guided_tours_includes.jsx?v=11-19-2024_1208 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 6870 |
Entropy (8bit): | 5.070081230453467 |
Encrypted: | false |
SSDEEP: | |
MD5: | E43982103F98555EE5D96AD16CF9C8FF |
SHA1: | 28E3424353D7AED580751D7240849B09C57FF0B1 |
SHA-256: | C3A408DBE2C6E6B40AF0681C60AED6CDD17405EC60A4F688AB7CEA3B7A47875D |
SHA-512: | 0C90CC024F197B4CB9AFA31848CB91FA6081A7751F91D61FC842E38D5DEEE2F90A9CE53A3F346A4C2F7D4597B73100248785E2D4AB324AAB1A01BC6F37DBF285 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/app_com.cxs.contextual_search.jsdbx?c=56 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1879753 |
Entropy (8bit): | 5.381603640926299 |
Encrypted: | false |
SSDEEP: | |
MD5: | 675EA644DF479D9CC4C5B22BE42B3792 |
SHA1: | 6D0E18AE584836D26668F8B7EDB6CEFF0715707D |
SHA-256: | B4E4CE08E5546B0668D3760812C5A9A4493D70BBB939D305D4F4B2C78FA356C4 |
SHA-512: | A95F5829EA6308F1233134C59DE509F1D71DCE48EAB80DB758600FC5CCDE6B0C61A05536AB4F5F3F242AEEC3A7E6886A1B365223D327CFD079D03737901F7C0B |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/scripts/doctype/js_includes_doctype.jsx?v=11-19-2024_1208&lp=Sat_Dec_07_07_03_14_PST_2024&c=27_632 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1247 |
Entropy (8bit): | 5.240389408231503 |
Encrypted: | false |
SSDEEP: | |
MD5: | D56D316B559D3BF5940A0210F9B84A67 |
SHA1: | FCF6DB25CF8C8103077839A6CF4FEF3D8EC15733 |
SHA-256: | EBB585B6BB4E5CFB9F6B07296734766B85A00536323B532988EA3201AA5565C3 |
SHA-512: | E366C2358110FEB8F890888B14510C6B73FE060E1A91457A11CC13F5382B833433386BDCCCC25FA2B0DF7070DEA01B66274CFC8A00F858F3271B21A067604B75 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/scripts/doctype/xperf_timing.jsx?v=11-19-2024_1208 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 447 |
Entropy (8bit): | 5.234132357918461 |
Encrypted: | false |
SSDEEP: | |
MD5: | B8AAB8FB85B50B64DAF8E995A9B1682B |
SHA1: | 40A8E1ECA0412D4EFBE8F6884185D698C10BA3F4 |
SHA-256: | 1714D869C0C08026BF364CEE5F3D8509523A066F79CD2413F4237112C5229B0D |
SHA-512: | 25F4F5CCCC46238A7152B4E2DBE8CE650F8ADB7EF213883E1DF2C5E6DCF20999014137A203A41A7F62970410FCB4A283B4219404AB9E890D453198526295EDF7 |
Malicious: | false |
Reputation: | unknown |
URL: | https://siemensgbs.service-now.com/scripts/doctype/history_across_tabs.jsx?v=11-19-2024_1208 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2 |
Entropy (8bit): | 1.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | 99914B932BD37A50B983C5E7C90AE93B |
SHA1: | BF21A9E8FBC5A3846FB05B4FA0859E0917B2202F |
SHA-256: | 44136FA355B3678A1146AD16F7E8649E94FB4FC21FE77E8310C060F61CAAFF8A |
SHA-512: | 27C74670ADB75075FAD058D5CEAF7B20C4E7786C83BAE8A32F626F9782AF34C9A33C2046EF60FD2A7878D378E29FEC851806BBD9A67878F3A9F1CDA4830763FD |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 921 |
Entropy (8bit): | 7.080074795492917 |
Encrypted: | false |
SSDEEP: | |
MD5: | C5C6520D27337C89AA59693E97468CEF |
SHA1: | 405A412787A4A06C3B416E1EF4A4F4DAB5AF252F |
SHA-256: | 525785E069D430274D2717D13BE70ECD7DFF1C3F51102905C873382EE39F54AC |
SHA-512: | 4A9C4AFAEE87F2B8B00F50239DEABF277276A0DAA4E4F72771D86196E2D42E3AAA5374E3355B8162E4907017973DAA6CC18E60C5F3C40E1E79799975A12EE2D4 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 166676 |
Entropy (8bit): | 5.2987337592708545 |
Encrypted: | false |
SSDEEP: | |
MD5: | D3133251DB75F3A589DE92863A06F11E |
SHA1: | E32499045A85E602EB44972A6C544830677865BB |
SHA-256: | BB3B9668FA15FF89D469F193DEFC95B2496E8FCBE672C39A2D15E84B07E7CCF5 |
SHA-512: | 763F9CCC4524CC953D6DC2B8425E6813C8FF6C8AD83FC453D5DC22BA22E3C29C1809DB5822011E8645A4F01574B2A9A2EF7749C0BDB415DD0897F6C746009780 |
Malicious: | false |
Reputation: | unknown |
Preview: |
File type: | |
Entropy (8bit): | 6.098095080621487 |
TrID: |
|
File name: | original.eml |
File size: | 92'233 bytes |
MD5: | d735cf00abcdb1a41cdabca2af5b7a8b |
SHA1: | fd930d8da61ed148ac6cc0ea73f7b12b51d693a8 |
SHA256: | dfe64ac81ac436611e7b2cfb62a64950ff73cc013a8b93c453bc0d4940ae8073 |
SHA512: | 1f45e1fe52e45105d3d6e960de59b1d0ce533a71e7cbf402199718fcd6d8f175b4cc9f9e683b20b580f884f33e69c60aac8de4439d15fcaae572f67b1ab6e695 |
SSDEEP: | 1536:PK4dQWIyLoBNAclrlnba6aSxJ5SJvd1Ug7+g4tUaT74ZqYf+c/okrR7aQAYlxYiL:y4FEjZ37AvdKVg4tUlf+cAkrRWAPUAnn |
TLSH: | CD93BFFB0AC07DE80AB459A5F14DB740B660254BF272818835DDE487FEC5A7236312DE |
File Content Preview: | Return-Path: <sophie.desgagne@metalus.qc.ca>..Received: from YT5PR01CU002.outbound.protection.outlook.com (mail-canadacentralazon11021073.outbound.protection.outlook.com [40.107.192.73]).. by inbound-smtp.us-east-1.amazonaws.com with SMTP id aictqpn0tvir0 |
Subject: | [Phish Alert] CS3677598 - AK:D35:MDV-1283710:METALUS INC |
From: | Sophie Desgagne <sophie.desgagne@metalus.qc.ca> |
To: | "c9025caf-ebfb-4a55-8a88-3cf1915dac7c@ca.phisher.knowbe4.com" <c9025caf-ebfb-4a55-8a88-3cf1915dac7c@ca.phisher.knowbe4.com> |
Cc: | |
BCC: | |
Date: | Thu, 12 Dec 2024 18:56:49 +0000 |
Communications: |
|
Attachments: |
|
Key | Value |
---|---|
Return-Path | <sophie.desgagne@metalus.qc.ca> |
Received | from YQBPR0101MB9936.CANPRD01.PROD.OUTLOOK.COM ([fe80::248e:9c4e:76d5:c2db]) by YQBPR0101MB9936.CANPRD01.PROD.OUTLOOK.COM ([fe80::248e:9c4e:76d5:c2db%7]) with mapi id 15.20.8251.008; Thu, 12 Dec 2024 18:56:49 +0000 |
Received-SPF | pass (spfCheck: domain of metalus.qc.ca designates 40.107.192.73 as permitted sender) client-ip=40.107.192.73; envelope-from=sophie.desgagne@metalus.qc.ca; helo=YT5PR01CU002.outbound.protection.outlook.com; |
Authentication-Results | amazonses.com; spf=pass (spfCheck: domain of metalus.qc.ca designates 40.107.192.73 as permitted sender) client-ip=40.107.192.73; envelope-from=sophie.desgagne@metalus.qc.ca; helo=YT5PR01CU002.outbound.protection.outlook.com; dkim=pass header.i=@metalusinc.onmicrosoft.com; dmarc=pass header.from=metalus.qc.ca; |
X-SES-RECEIPT | AEFBQUFBQUFBQUFGNXgyWGYvcDd6bUZKaHdoZXppRCtIcHA4bjNMeEJqYk9KTXBielE0d0dwY1JXZFdVVjNpMDlEbm1sYWh0YzZmdVRUd0VFZ3dGci94MXc3OER6b2Y2aE5wMG4wVnZ2eFFIUERSQTh5R3pudERwK2drZ2ROdVd6MU1KYWM1SXZmMm8zSnVYVHhseFZlbjRkZDVwRWtXRStWVU5ITU9hS1JNbW12U3NQZTI3UEFZZEpFc21paTdwRmJ6R2VLWFFTSFgra3JOUGU3WmNQdmtRd1dkY3VoK2NKUFZhbysyYTBGVDdkYXFIN1FEZDRTMXlDbWFrUmVzbWM4aFhJUXpzMHVXeWRPdWJJOVIzcjh0aE4waStuOU5rY1lWSjJwWVJwWFZ1TVJMWUdXRWJhRXhzeCtsSHZWaFlYKzZqNW1BM0NtcjQ9 |
X-SES-DKIM-SIGNATURE | a=rsa-sha256; q=dns/txt; b=NMOIjen74kywDROdLsVCsJcNs5FM2m74AZGc4491Nc6ebUPD9IypXvvcoW8mfF2O3SI+OaFSzyhg1MKwrSyo7gYx48pCyMoVCXFUOFcEWaKSaLQ2f7XirgoWxwh1T/WC1EeI2H8EOqUfVbvW7ELrTFZFXHgvx9jqlNMFVgIbeoc=; c=relaxed/simple; s=ug7nbtf4gccmlpwj322ax3p6ow6yfsug; d=amazonses.com; t=1734029813; v=1; bh=v4q4JMxOuMYVdUDBvhkROYdyCrzWz3VOUo+Qy0PEPN4=; h=From:To:Cc:Bcc:Subject:Date:Message-ID:MIME-Version:Content-Type:X-SES-RECEIPT; |
ARC-Seal | i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=k7yRQOHBMA/6wAP2i9rQhvEP7nxlHS5de0eoP6LBADUrFLKwYIS2pDo1IP7ypYYPZPs8OI9/v5ix1FZwrtcBBXISR9hWEAvGTcP/JUxjdzeopsompAyKxAudReU+K2AoEIFFz7vBceQxy3SMwZwPRbqW4FDaI4SIRkwjzChejjfoGF/riXa0IK2DLxa2FdNt49WcIUQcIofh2jxxhdmV8P9Rrg8KB2CY6q8o4vsyUtvbKWUVkf7M6PEtZ4V6r3SvpqT0771Enx3HIgtf9b1+Az5JAKjMznQa9GTFF1BfbeU4P8+x5CTrCo2n03mmEyrbEWC1Ni7PuOhAMDBXDPwYeQ== |
ARC-Message-Signature | i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=w4PO8+8eQ5zZptEp6FZ8gdaYH3Yvnphz/xopWxuMY6g=; b=JqygnJqBnZ/xMOTXnSINJTld5aPlpOInLxkpAxv859GMkIks01uQdvVuRr8iNNYgYj2GTNpvASmQ94h39ANeTtHfwmhp2dsqga+gZGhpcH7b9fmQPYwEgL6NHEcSEXdhZrJfRVF9kdEQYDYzUtnTHgAqQAmqagB+aHg5GaLXvajT2zA7mRPL4OLzYduFYvtkHlCD8iGYtCjzx+aovFFOFJq1isl/NWwrMewCgKJdg9FROs1xvt2Igu4UDnXQ4/CioTp8EZDSM5QCCVhqLDwXz0fK3rxp6YQXxKUWXsnx4Msa96PYciZ5ueWFzsrE3+nMS9ueF0oJ0vgWWwXgt5uhAw== |
ARC-Authentication-Results | i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=metalus.qc.ca; dmarc=pass action=none header.from=metalus.qc.ca; dkim=pass header.d=metalus.qc.ca; arc=none |
DKIM-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=metalusinc.onmicrosoft.com; s=selector1-metalusinc-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=w4PO8+8eQ5zZptEp6FZ8gdaYH3Yvnphz/xopWxuMY6g=; b=rAJ7EhZgGLZyqElpmZCfQZVHdLyWR+dqOKEpMS2Nv9CCmGq/rJu0yEGzoVpXoVpxzbo27nuNBIrQqEQSdOex91+P2u7yGDdVmMcuw8JURf+eQJ56gaaX4s4qz5zX8/KgChFqheBG0HNxNW9qG1xmQ3ChDd3lqe7XqFXDgxlBAY8= |
From | Sophie Desgagne <sophie.desgagne@metalus.qc.ca> |
To | "c9025caf-ebfb-4a55-8a88-3cf1915dac7c@ca.phisher.knowbe4.com" <c9025caf-ebfb-4a55-8a88-3cf1915dac7c@ca.phisher.knowbe4.com> |
Subject | [Phish Alert] CS3677598 - AK:D35:MDV-1283710:METALUS INC |
Thread-Topic | [Phish Alert] CS3677598 - AK:D35:MDV-1283710:METALUS INC |
Thread-Index | AQHbTMSG2RyIhjwLvUSIz+bn9ffulLLi9anl |
Date | Thu, 12 Dec 2024 18:56:49 +0000 |
Message-ID | <YQBPR0101MB993640DD8230C2960AF26C38A33F2@YQBPR0101MB9936.CANPRD01.PROD.OUTLOOK.COM> |
References | <86106704.31328.1734028482811@app128015.dus201.service-now.com> |
In-Reply-To | <86106704.31328.1734028482811@app128015.dus201.service-now.com> |
Accept-Language | fr-FR, en-US |
Content-Language | en-US |
X-MS-Has-Attach | yes |
X-MS-TNEF-Correlator | |
authentication-results | dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=metalus.qc.ca; |
x-ms-publictraffictype | |
x-ms-traffictypediagnostic | YQBPR0101MB9936:EE_|YQXPR01MB5836:EE_ |
x-ms-office365-filtering-correlation-id | ff993687-aa58-418c-794b-08dd1adebc11 |
x-ms-exchange-atpmessageproperties | SA |
x-ms-exchange-senderadcheck | 1 |
x-ms-exchange-antispam-relay | 0 |
x-microsoft-antispam | BCL:0;ARA:13230040|69100299015|376014|1800799024|366016|8096899003|38070700018; |
x-microsoft-antispam-message-info | ATHiOCrX7MwCrXSdyI3yMP6EQwV1vX0cy46O2UXj5U52N+LVEH0RV94W9EfNDBORgKNpV4UIeEuB5KLtHcjvUYNhmyr4a3/8huU4WsvrZX1VXwGrIDIHVaN6PONJGUpgSYUr6J8RTU03l1q2thUqNqE9XkcDfxCniUvLfhRNrw9hlpnget8MqjV6Rn1Mt4NbN7eIqkId5zLWNFlSEVGPoPezi3+Yrs1cq2+ipb9gf8+N+TVBS9JH/7UzbvfWDbp0zarBcVAoueRbFb42DUEe4ZIQ7Q4upDt6oxEDcWYXQ7rsLDpBHqb8TkUsjbbvgCEELzjxl1/967jONexd7tRv8EV3c32VbcYbDnHl277gk48jRapR/YVte8f5IAfolWIvT08pn1vYX6aXw4pjx9DTUBoIqJyiA38GUqLfwAIL3m+VJqq0PMCCA6HN3bML4yBeoMg3oyJG6ljL4qaTqbVALCRxaAcaKDjl2NtWQCja211hDAeU3DtSzA9V6vkWrMDqz5Fd2x/Hp/dInz9BVeU3Z7Il2/Rl4TWtF4zwYHI/N9y6cHCmiy0YTyIIOMLcRVMX5W9UCZle6aASUHysDpUVLAKH6IQhVKVRV+wWy40wL1H2QGZrjRrlOy4D2jEpFrwYgC3pxTH/pE8NZ+eLKEh1Ri/UZBDpMgB2DP3zf8aQV/Z9yXIRX0QuvrG5rfm3FRrDIWeQLD9mj+UZo+kGd7U9+67aejmKAcd6Fvbb+j8RmU9nFCZZu7mdOl326W+ukxsrezNpxWY32YOzKtNTU8Tf/BVp/a5t1Aaa/dd95jj0x7mfEVb2bCl3MfGsWmFpkGLsVFZYEcEcPuWM9Qx3m5Q8pNcRuFDsIPvGZjzVY8qg19BBzQOBDOVQJr1aAhwtLNgjhyyw3m/n4Z6pE2/Bvclg+RnexXyAv8u07vBCKtjZYYp5v2OoJe5/4gFmR+it9RYB8ZPRB5A00Jy9QPWJVBispP9E7gfhP6zjEoecpQTxiY81rbq+MvgHf97EAAxJi7/F08aeyco4VEZ+X1NsbGbbgBr6zqKIn2OHiwZHbATwjhZ9Yhs0koyid4yTjikyAAq3t2sWV/mFBxhk2Nd+SSNFe7gnv6DtyKymZPx2WWxK8gbaD25MNShuT5IxLFIBiNq29T6GfysJoov0JA/p0JmtrnRBASSiiVhue4Jvt81TSpnXw9ZZuMcVXhlTw747499xDeJiyF/V5JNdH/aXigWuswGYitbqYUex5tbwkK/oe02UovfRqXakZ84NkYrjINaGSv95RCS7ci0DEjOqMGS4ybxFfFx2LWFubF9QJiLmgms= |
x-forefront-antispam-report | CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:YQBPR0101MB9936.CANPRD01.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(69100299015)(376014)(1800799024)(366016)(8096899003)(38070700018);DIR:OUT;SFP:1102; |
x-ms-exchange-antispam-messagedata-chunkcount | 1 |
x-ms-exchange-antispam-messagedata-0 | BhF/PZt8mujNJEWx44R6pfZ7PTcl+PrS/xTa11m75WGsMLmmidHyOqNhSbKnSV66+j0/Zm4MhofozXeS3a63LBAQRPfrbz2r9dCyzElugzY/QH/4Z+UNWtu/5mBcysS/HyJpUHFRij3/fpbofdhkIe08szMarIU3gmS1JgPEogA9U+mB+ruiUBVfcBIrF6Xx7hSY1rWbvCkB0ydKNRF6KPTpZQFyuFKuloCFkvy2YOn+PQlTwNEvnipBlUymBHZ9unsoXoUaK4cZPEdXT9TSR0QFplIfvA8+jRP5+NSmUdugtyOM4ZvK+0Yce8jKU8r6NS2PRs/XlHWxfXrl8SSkfH26/5PJKPLUiIc4CtdosRaobgUXvoAqr1K0qSwUudaqQt6ksoPkw4ZGgF0KtiGj3o+wZFhKFVqglE7UaBOx3jV51+qL/LQEjdi3Z2M98OE4JlJB5Q9T97VVr41zLWow2FcnK3E9ECzyWQv9HoxGfKHFsdBPGtN97K8bhOxPac0z0usLfSX42BW924cDL9fpm5B4/ijMJ30F26BzftnuZNxErEQg/9nHtfDkx4WlW08JQlkk+dZLmMpgT+SU/Mw9RFRnpAnNsKwmLyqfNJotLY50Gj/ZzrUDFVbYJMG5cTcvPtnddXEmVvAGdXyJfgVbnuwiUdKpGnkW/LGDHVLbYjiG0fcyaWdQUa8Ec21+wYqF8j52EhX9r7ZGKMNKFKl8hL6JUk5lRclpl168hAFajVEPFfC4A9ZymsGZw9zB2bkVO0mEZgfqlGoBlshX7J3oQKq7X7YAJj8SoZ0YVIu6W7wFY/UKjqPUpZLZ1sHyekfQe0gjtBtWozcB7FGESq2pLHDYPXiGtUYbEKvsA9+lCiKO80/Y/8uYb4NZg3FMgrT9NCl3gH/ITOrMd+20mo2TmVzKhEfbCimjh3RpUkRU9eT03SItAK5mIgJCoeh4wsS6KzSoykxY64dzPWUf1+dwesS/Dk7r84ty4yGvKKxfgwNdJ+AcjsV/3LlWUkmaEa1MIDyCUna90V3ecVS4X5b2cShtxW+XLzVk70Whe+RobtojreUdljdYlnyOYaz6GVDf/CpExjcSd4jeo1ZSYtGYr8IGlm/9YFjWlvzVzZEAiP/ttzn0/AHW9xekht9/MXzYGKEKFVT4iK0mnttAuqWZ0G5hi9S9icK+TuNL0ZE8uTvbQ2/s5lhWA1EStdsxf1+WQCnQcOvTA+7y618nwRMAXIgyeMlIb1CHBt/OsVxEaTNBkMMu0974tyuXBAEmSc2WW0AnAZNhMCxXCgxx38TN7IBJUx2gHR6vwJBRrd6S0ztkh9yZmPVXDw8uSEDO8L9s8ZzegZBWkS3ryssqu4ckFnwBEdoxUa8NMFki51FZbmfjACDorrd19q/hPqeZGIbrvAgOg6X9wu+jgKJ7Zat37lksKu1OkFRCH6IRzfk3kfM3GaEdD82eG3Lb+dAVC6YH/3v8m+dSYVqOeQiwQrE+tlu/7EnoBxIcP4npduNsftq5k4gDhbwcvzDCJGdbn3njlO4Q+MiMRkBxPWfrQMkgnZGKM5zxbJMJ6oT47wgWDIhQUp/EctfVDj8ocXvV9DLN+pdWfTe4jI4jw6oA4FAnmQ== |
Content-Type | multipart/mixed; boundary="_006_YQBPR0101MB993640DD8230C2960AF26C38A33F2YQBPR0101MB9936_" |
MIME-Version | 1.0 |
X-OriginatorOrg | metalus.qc.ca |
X-MS-Exchange-CrossTenant-AuthAs | Internal |
X-MS-Exchange-CrossTenant-AuthSource | YQBPR0101MB9936.CANPRD01.PROD.OUTLOOK.COM |
X-MS-Exchange-CrossTenant-Network-Message-Id | ff993687-aa58-418c-794b-08dd1adebc11 |
X-MS-Exchange-CrossTenant-originalarrivaltime | 12 Dec 2024 18:56:49.6592 (UTC) |
X-MS-Exchange-CrossTenant-fromentityheader | Hosted |
X-MS-Exchange-CrossTenant-id | 4f85cc14-eaa8-4e0b-8291-93aab6969f78 |
X-MS-Exchange-CrossTenant-mailboxtype | HOSTED |
X-MS-Exchange-CrossTenant-userprincipalname | A93iu/rpHyQorslUzj2EUTiyuFRAl3YGU+PTGp9JayfE/58MnP6GG65+nbOK2syjKdE8f90HdZ9NcYuJt3xmOPoiDP9eGY8CnraQAe7i8XU= |
X-MS-Exchange-Transport-CrossTenantHeadersStamped | YQXPR01MB5836 |
Icon Hash: | 46070c0a8e0c67d6 |