Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://artsofbristy.com/?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==

Overview

General Information

Sample URL:https://artsofbristy.com/?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==
Analysis ID:1574805

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected suspicious Javascript
Javascript uses Clearbit API to dynamically determine company logos
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6996 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6324 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=1876,i,5777755985416115551,16577458776573209128,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 2648 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://artsofbristy.com/?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: 0.1.id.script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: https://artsofbristy.com/nextpage.html?data=ZGdyaW... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to a suspicious domain. The script also enforces a modal that cannot be closed, which is a highly suspicious behavior. Overall, the script demonstrates malicious intent and poses a significant security risk.
Source: https://artsofbristy.com/?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==HTTP Parser: const pms = new urlsearchparams(window.location.search); const data = pms.get('data'); if (data) { try { if (!/^[a-za-z0-9+/=]+$/.test(data)) { throw new error('invalid data format'); } const email = atob(data); if (!/^[^\s@]+@[^\s@]+\.[^\s@]+$/.test(email)) { throw new error('invalid email format'); } const domain = email.split('@')[1]; const companyname = domain.split('.')[0]; const displayname = companyname.charat(0).touppercase() + companyname.slice(1); // update both dashboard and modal images const profileimg = document.getelementbyid('dashboard-img'); const modalimg = document.getelementbyid('modal-img'); const fallbackimage = 'https://via.placeholder.com/100'; const logourl = `https://logo.clearbit.com/${domain}`; [prof...
Source: https://artsofbristy.com/nextpage.html?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==HTTP Parser: const pms = new urlsearchparams(window.location.search); const data = pms.get('data'); if (data) { try { if (!/^[a-za-z0-9+/=]+$/.test(data)) { throw new error('invalid data format'); } const email = atob(data); if (!/^[^\s@]+@[^\s@]+\.[^\s@]+$/.test(email)) { throw new error('invalid email format'); } const domain = email.split('@')[1]; const companyname = domain.split('.')[0]; const displayname = companyname.charat(0).touppercase() + companyname.slice(1); // update both dashboard and modal images const profileimg = document.getelementbyid('dashboard-img'); const modalimg = document.getelementbyid('modal-img'); const fallbackimage = 'https://via.placeholder.com/100'; const logourl = `https://logo.clearbit.com/${domain}`; [prof...
Source: https://artsofbristy.com/?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==HTTP Parser: No favicon
Source: https://artsofbristy.com/nextpage.html?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==HTTP Parser: No favicon
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: global trafficDNS traffic detected: DNS query: artsofbristy.com
Source: global trafficDNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: logo.clearbit.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: classification engineClassification label: mal48.phis.win@17/14@10/137
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=1876,i,5777755985416115551,16577458776573209128,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://artsofbristy.com/?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ=="
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=1876,i,5777755985416115551,16577458776573209128,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
3
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Registry Run Keys / Startup Folder
1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://artsofbristy.com/?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
d26p066pn2w0s0.cloudfront.net
13.227.8.64
truefalse
    unknown
    artsofbristy.com
    103.243.175.186
    truetrue
      unknown
      cdnjs.cloudflare.com
      104.17.25.14
      truefalse
        high
        www.google.com
        172.217.19.164
        truefalse
          high
          logo.clearbit.com
          unknown
          unknownfalse
            high
            NameMaliciousAntivirus DetectionReputation
            https://artsofbristy.com/?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==true
              unknown
              https://artsofbristy.com/nextpage.html?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==true
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                172.217.19.206
                unknownUnited States
                15169GOOGLEUSfalse
                1.1.1.1
                unknownAustralia
                13335CLOUDFLARENETUSfalse
                172.217.17.78
                unknownUnited States
                15169GOOGLEUSfalse
                172.217.17.35
                unknownUnited States
                15169GOOGLEUSfalse
                172.217.19.164
                www.google.comUnited States
                15169GOOGLEUSfalse
                103.243.175.186
                artsofbristy.comSingapore
                59210PHOENIXNAP-AS-SG1PhoenixNAPSGtrue
                64.233.164.84
                unknownUnited States
                15169GOOGLEUSfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                13.227.8.64
                d26p066pn2w0s0.cloudfront.netUnited States
                16509AMAZON-02USfalse
                172.217.21.42
                unknownUnited States
                15169GOOGLEUSfalse
                142.250.181.99
                unknownUnited States
                15169GOOGLEUSfalse
                172.217.17.42
                unknownUnited States
                15169GOOGLEUSfalse
                104.17.25.14
                cdnjs.cloudflare.comUnited States
                13335CLOUDFLARENETUSfalse
                IP
                192.168.2.16
                192.168.2.4
                Joe Sandbox version:41.0.0 Charoite
                Analysis ID:1574805
                Start date and time:2024-12-13 16:28:50 +01:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:defaultwindowsinteractivecookbook.jbs
                Sample URL:https://artsofbristy.com/?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:13
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • EGA enabled
                Analysis Mode:stream
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal48.phis.win@17/14@10/137
                • Exclude process from analysis (whitelisted): svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.181.99, 64.233.164.84, 172.217.17.78, 172.217.17.46, 172.217.21.42, 142.250.181.42, 142.250.181.138, 172.217.17.74, 216.58.208.234, 172.217.19.202, 172.217.19.10, 172.217.19.234, 142.250.181.10, 172.217.17.42, 142.250.181.106, 142.250.181.74, 199.232.214.172
                • Excluded domains from analysis (whitelisted): clients2.google.com, accounts.google.com, redirector.gvt1.com, content-autofill.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com
                • Not all processes where analyzed, report is missing behavior information
                • VT rate limit hit for: https://artsofbristy.com/?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Dec 13 14:29:22 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2673
                Entropy (8bit):3.986819232954173
                Encrypted:false
                SSDEEP:
                MD5:3888E712F7EAC4B1CA97D294413520D5
                SHA1:FF2A81EE25B0468B969C5A32BD9C441F4A769EA4
                SHA-256:1D24228FD1F0D756C1D8F07052AF09C31923BB81F006FA95661C2EED94901792
                SHA-512:7DEE1980D17E2AE6C278B4D7F8FD07654C199D5D13302606A1B26AD01D923822E249CA1CAA1AFC9E422579314DF93BE819D16282EDC23DDA499A6A4104FD94DF
                Malicious:false
                Reputation:unknown
                Preview:L..................F.@.. ...$+.,......&.sM..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Y.{....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y.{....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y.{....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y.{..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.{...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............c;%.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Dec 13 14:29:22 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2675
                Entropy (8bit):4.0051544090099105
                Encrypted:false
                SSDEEP:
                MD5:BFA93880850EDBFF3A4C53D0A8B37873
                SHA1:68E2E077BA446B8965850F40E876EB18C31A36EE
                SHA-256:2A666BB838D1D327150DA7FE1ADDB56A8F66E7027E72FA8AD10D70D4EE4AE3D8
                SHA-512:B2A96F4F0EF1DC8A357DF6C5393E29801FD17A70CF096BFE43DD59FE8A26A72102735155F93679D59C5AC2C069058711F50F8FDE6ACBB23AA8F66364E5B03B22
                Malicious:false
                Reputation:unknown
                Preview:L..................F.@.. ...$+.,.....O..sM..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Y.{....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y.{....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y.{....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y.{..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.{...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............c;%.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2689
                Entropy (8bit):4.011949878608345
                Encrypted:false
                SSDEEP:
                MD5:7952931362E9652759E720333913E1BA
                SHA1:E10794F293D129C85B3FCF67435F3E1E18186464
                SHA-256:4EC240FAA43518D9EA60D6A5458D4C0FC67440396082BF1ABFC07DCEA3265E09
                SHA-512:BDE41FAAF9F46BA758EE4678A34366A1CB7A73D70CCFF0081FCC2C2C9B10FCC3225AAA658295F3892CC095281296B4CEC3331DB64BBE5A0BC933AE98A6F8F977
                Malicious:false
                Reputation:unknown
                Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Y.{....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y.{....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y.{....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y.{..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............c;%.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Dec 13 14:29:22 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2677
                Entropy (8bit):4.001117229592252
                Encrypted:false
                SSDEEP:
                MD5:D52BCCAADA56E26F07D48A5B2A42C069
                SHA1:65FAE34F04DBE28045EDD1316E714DB69C405AFB
                SHA-256:6F5C7C0863A183A384AC58E7FF0234F010B6FC4D145DA4EBF83DE41D1A8F0C5C
                SHA-512:0778E2292C93D27E5987285C1082A45568061BD141BFB1D65E295FFB1A95DAE38ECDF8EFB40641B25B6AE2703D60106AB583893ED5A21A190811CE25C99E2228
                Malicious:false
                Reputation:unknown
                Preview:L..................F.@.. ...$+.,....A5..sM..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Y.{....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y.{....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y.{....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y.{..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.{...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............c;%.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Dec 13 14:29:22 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2677
                Entropy (8bit):3.9914335823345977
                Encrypted:false
                SSDEEP:
                MD5:0CE9636ECA422C22C8645D6B583F8524
                SHA1:31AA8FAD90DEA32301F62BB34420803F9D8DDE38
                SHA-256:D317454A8410F2D6DECCAB210273BBB03A1630711ED916370AEF85527E7CF652
                SHA-512:8BE94CD228E7552282EA7B6650527253BA1A5D286D1B6054649323B2631F2CDB48C9BEC96D8C74B0ECD8545A44D0B10CDDAF6947F17EC02352199BBD6EC245FB
                Malicious:false
                Reputation:unknown
                Preview:L..................F.@.. ...$+.,.....-!.sM..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Y.{....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y.{....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y.{....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y.{..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.{...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............c;%.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Dec 13 14:29:22 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2679
                Entropy (8bit):4.002170934173046
                Encrypted:false
                SSDEEP:
                MD5:F22B6CA33EF0E14C93654777A2B4D637
                SHA1:2B3B18692DDFF471E6D35BEA3EDB3EB5C14126A1
                SHA-256:F12773508D680EE2D361834D9ED18FC960382F2EAD7D2379B0C426C741155807
                SHA-512:65C822D101C5FE09B76C675E3B7765F7A3E00E82DADEE1F3D4F81612488BF747384B560EAC8F925E78A9D2E0F3A8EFBF5AF7C4891A8DAE2CA496A45BC9233DBE
                Malicious:false
                Reputation:unknown
                Preview:L..................F.@.. ...$+.,........sM..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Y.{....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Y.{....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Y.{....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Y.{..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Y.{...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............c;%.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with no line terminators
                Category:downloaded
                Size (bytes):16
                Entropy (8bit):3.875
                Encrypted:false
                SSDEEP:
                MD5:46DF3E5E2D15256CA16616EBFDA5427F
                SHA1:BE8F9B307E458075DA0D43585A05F1D451469182
                SHA-256:AF3248D0B278571EFF9A22F8ED1CEB54B70D202B44FD70ECA4CA13A5771CECC3
                SHA-512:88FBCC0A92317A0BADE7D4B72C023A16792F3728443075BF4B1767C8A55258836B54D56B24EABE36AE4EF240F796B58B8F1EA10C7E3C146BDE89882FC9ADE302
                Malicious:false
                Reputation:unknown
                URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAnCWJqv_ImU9hIFDZFhlU4=?alt=proto
                Preview:CgkKBw2RYZVOGgA=
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, Unicode text, UTF-8 text, with very long lines (593), with CRLF line terminators
                Category:downloaded
                Size (bytes):25812
                Entropy (8bit):4.497102583042215
                Encrypted:false
                SSDEEP:
                MD5:F716BB052AC522F40C89139B1D7A8AE6
                SHA1:7E7C8D5EA73BD92C7BCCCCEA470A3EFF4F85CA91
                SHA-256:B1171BF701781E307966FB79E529E03DD193ABD1D2ED3AB58B24D4B16F42A078
                SHA-512:0F71482B5337004423AB0AEDA35151F0BD8D17534997E87AD897B608DE59216F076D62B635A5C9DB35ADB9FA6E3EF91B07E7C7AE79E8B58466F12105F41B4DF2
                Malicious:false
                Reputation:unknown
                URL:https://artsofbristy.com/?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==
                Preview:<!DOCTYPE html>..<html lang="en">..<head>.. <meta charset="UTF-8">.. <meta name="viewport" content="width=device-width, initial-scale=1.0">.. <title>0neDrive</title>.. <style>.. body {.. margin: 0;.. font-family: 'Segoe UI', sans-serif;.. background-color: #f5f5f5;.. }.... .header {.. display: flex;.. align-items: center;.. justify-content: space-between;.. padding: 8px 16px;.. background-color: white;.. border-bottom: 1px solid #e5e5e5;.. }.... .left-header {.. display: flex;.. align-items: center;.. gap: 16px;.. }.... .menu-icon {.. cursor: pointer;.. padding: 8px;.. }.... .search-container {.. flex-grow: 1;.. max-width: 600px;.. margin: 0 20px;.. }.... .search-box {.. width: 100%;.. padding
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PNG image data, 128 x 128, 8-bit/color RGB, non-interlaced
                Category:dropped
                Size (bytes):27782
                Entropy (8bit):7.990075943726779
                Encrypted:true
                SSDEEP:
                MD5:A91E9D2DA3845653A2D62E3A4DF81E54
                SHA1:548E246865653108CD61AA019C0AD9F47C1F234A
                SHA-256:301909D1D8797B5CA6D80DF7DCAFA384DA19BAE724B9D0FA978D25107FFB0882
                SHA-512:D5AD57591031F0EEFD650936D720EEFD83833582CB4022CD81A180CCCF871CD9D7A0F92A6997D8533F23DB06A7F1B1BC245F65D69FB7AE6CA1A6DE39D842A070
                Malicious:false
                Reputation:unknown
                Preview:.PNG........IHDR.............L\....lMIDATx.....E.?^oU.I;....a.,9)..Q..9#.Y1.3{..9.Y.$.((9#K.a.e.l......OU...<.w..........7T..9G....#..!.9........@~...0.1p.4..n.....5.B...........~..RJP....d!@.+%%G.JK.3........}.8.s....&Fj..........o.9..a.....<..b....#..s.c...[6...`..]....-9..CwDr..j.qx..$.l.._3....P#b......];w......g..@.B..]0..._.e.......i./..^.a._7.......8...T..T."....r.1.R..p.....90G.....<\.B%.hBM......k..!....6l.......a^.."..F..E......eu~ .JD:.f..r.r.1..j..Q....0...HX.......v......`...9.?.j{..W.K..C..v...."143n(...Wi..zt.y.....\0Ru8m....6c.3.<._......1F.8_.v.../.8.sw....+..!:3%..}..+..c..o...u.F+7^.c.`.....4.Y.$...m.w_6.).o|bi}.......n..(.;...5........>.R..[....zsO.=.+f...O...EF833..@<.P).........&_..o?.........$c...BX....5...F%.y...-Xsl....^|..s....3..3"...0...8.......f.@.....w]_7..s..z..0...e._.`..T..1...Y.^|r....u.K~.......K...vGf..[....##b).._t..U..8~..G......S......]V..3.....qu...>Y.....F_.Y...A..=X......9!2:...(.....q`..*}!B
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with very long lines (52276)
                Category:downloaded
                Size (bytes):102641
                Entropy (8bit):4.781784574734628
                Encrypted:false
                SSDEEP:
                MD5:9402848C3D4BBC710C764326F8B887C9
                SHA1:B6E555166EB1381392E00ADCDE9BF8863F16FF01
                SHA-256:C22CFB6520A7FDBB738632834019ACF47C78B1279462C0EB4CB83BAE83ECB5A7
                SHA-512:0D33903BD456087DE9A46A9C59A100D41219382EB1C5A97012CC3D73641078021FB65F957A0A2F96779ED5CF505F84DCB6758C9F5DD36727BE822326F1ED8BC0
                Malicious:false
                Reputation:unknown
                URL:https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.5.1/css/all.min.css
                Preview:/*!. * Font Awesome Free 6.5.1 by @fontawesome - https://fontawesome.com. * License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License). * Copyright 2023 Fonticons, Inc.. */..fa{font-family:var(--fa-style-family,"Font Awesome 6 Free");font-weight:var(--fa-style,900)}.fa,.fa-brands,.fa-classic,.fa-regular,.fa-sharp,.fa-solid,.fab,.far,.fas{-moz-osx-font-smoothing:grayscale;-webkit-font-smoothing:antialiased;display:var(--fa-display,inline-block);font-style:normal;font-variant:normal;line-height:1;text-rendering:auto}.fa-classic,.fa-regular,.fa-solid,.far,.fas{font-family:"Font Awesome 6 Free"}.fa-brands,.fab{font-family:"Font Awesome 6 Brands"}.fa-1x{font-size:1em}.fa-2x{font-size:2em}.fa-3x{font-size:3em}.fa-4x{font-size:4em}.fa-5x{font-size:5em}.fa-6x{font-size:6em}.fa-7x{font-size:7em}.fa-8x{font-size:8em}.fa-9x{font-size:9em}.fa-10x{font-size:10em}.fa-2xs{font-size:.625em;line-height:.1em;vertical-align:.225em}.fa-xs{font-size:.75em;line-
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with no line terminators
                Category:downloaded
                Size (bytes):28
                Entropy (8bit):4.182005814760213
                Encrypted:false
                SSDEEP:
                MD5:E8494723C0CA6800579C8C3501BE0FBB
                SHA1:FDE4484D6E826CD353E350D4D7970502956B5ED1
                SHA-256:4ED23D10BB33528BC772C619439C79CA9F71F569B3C56AB4A6842BE5B29A0169
                SHA-512:07CC9B61AF4E387585EC46F71F2692E796580A944C8BAC694AD129B6B821AA0004DE5CB1FDEA6170231683CA3253B0F705BBCF0B72E5158C1FE412D8E0310313
                Malicious:false
                Reputation:unknown
                URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwmXi-wK3H1gjRIFDTcwqTASBQ2RYZVO?alt=proto
                Preview:ChIKBw03MKkwGgAKBw2RYZVOGgA=
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:Web Open Font Format (Version 2), TrueType, length 156496, version 773.768
                Category:downloaded
                Size (bytes):156496
                Entropy (8bit):7.996570522285877
                Encrypted:true
                SSDEEP:
                MD5:6C4EEE562650E53CEE32496BDFBE534B
                SHA1:1AAE708E3B94EE981B452A918D28ED037FBB5E18
                SHA-256:9FC85F3A4544AB0D570C7F8F9BBB88DB8D92C359B2707580EA8B07C75673EAE2
                SHA-512:EBCB5A2E2A908228F77ECD03B45491778CAD73DDC39FA3A6334B129AAF9FA36C16C0307AEAAD74D77F616B5B34AAC52D91E9F4816945253DC9A826DDD71F4D12
                Malicious:false
                Reputation:unknown
                URL:https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.5.1/webfonts/fa-solid-900.woff2
                Preview:wOF2......cP..........c..........................6.$. .`..<...... .@..m. %.......V'.......).=<E..........%........~.....W.......................S`0...0-.q.=^.../?.zn.Do,.pF..B..8Tr....5..n...Q.>...t:...Q...S....t..eV.....).`.Igb"......"ZI2}.,........#..."1.3.....j.V.....J.......$F..>:(|E..$...U.r.j.vOM.......^....T..$...w*.Dx`.lZ?a..D.`.r.A.UL........ x.]....|....V.D.T..8..R.X%.[.x.>..Z.r....g.?....UCuu.4VI.m.j..1.*K.NX.xn...,..8.Y...b...@.#..kw...%..HK..'...LOH..`.Y`v3fg.............(...(.)R.AERTX.V.LA.GQ.O..-...|o:...).%...{D.Z]=..'....0..6`..X`v..Cr.....)9A..,.^<%:@V..Pp.Lg8S...'.9..N..'......Q....r..^w....fr....;;..V....`.P...HB......!.C\....8...w.>].....|..,s...^./....z.........%...:I'.hw...t.6.......o.f.X.^.....k.....s.....fZ....z.(..%...v.JjI...d.............R`....z.{.=.,Q>.r>.L>d.d..4..!....]n]..K.A.UAD.k.p....Dwy..D......."@..>F!..&@..U........g.F..V.FcT..b4.........=l...~.#.....Y....{.....n............P...R.d.X...{..y.....k.?..2...
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, Unicode text, UTF-8 text, with very long lines (593), with CRLF line terminators
                Category:downloaded
                Size (bytes):22516
                Entropy (8bit):4.432998705041102
                Encrypted:false
                SSDEEP:
                MD5:5CC62A30AC627F139AAFA03ACB2DDE11
                SHA1:314CAABB521B3A35D886E9BDB042040FF15B854A
                SHA-256:EFFF9A47FB074F96152D55B87E138425DFB0FE01D18085E6F3B427A67218F821
                SHA-512:0A34FF8112E4E3D634BA83B3FC35CCC1F3D085BA2864339A423F240B16B7978133DCEB94BEFED13FAAC4E03A796AC8A0A180AF66D408BFA530A47FD23C9D6D68
                Malicious:false
                Reputation:unknown
                URL:https://artsofbristy.com/nextpage.html?data=ZGdyaW5zdGVhZEBjaXR5b2Zyb3hib3JvLmNvbQ==
                Preview:<!DOCTYPE html>..<html lang="en">..<head>.. <meta charset="UTF-8">.. <meta name="viewport" content="width=device-width, initial-scale=1.0">.. <title>0neDrive</title>.. <style>.. body {.. margin: 0;.. font-family: 'Segoe UI', sans-serif;.. background-color: #f5f5f5;.. }.... .header {.. display: flex;.. align-items: center;.. justify-content: space-between;.. padding: 8px 16px;.. background-color: white;.. border-bottom: 1px solid #e5e5e5;.. }.... .left-header {.. display: flex;.. align-items: center;.. gap: 16px;.. }.... .menu-icon {.. cursor: pointer;.. padding: 8px;.. }.... .search-container {.. flex-grow: 1;.. max-width: 600px;.. margin: 0 20px;.. }.... .search-box {.. width: 100%;.. padding
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:Web Open Font Format (Version 2), TrueType, length 25452, version 773.768
                Category:downloaded
                Size (bytes):25452
                Entropy (8bit):7.98927915276854
                Encrypted:false
                SSDEEP:
                MD5:023A4A925FA3FCE0F66B769EF6BBB264
                SHA1:2ED706340547D19C10A409EE02FB08F3D52FF670
                SHA-256:2BCCECF0BC7E96CD5CE4003ABEB3AE9EE4A3D19158C4E6EDFD2DF32D2F0D5721
                SHA-512:40F3EF2BFDE073D33A2D3CBC280FB40EA50DC2B0C3619C8D9717D665351AE219CAA5F17AE67CC87E777FF73C1275C1F3778B26E95F19459594D2F42AB95AECC1
                Malicious:false
                Reputation:unknown
                URL:https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.5.1/webfonts/fa-regular-400.woff2
                Preview:wOF2......cl..........c..........................6.$. .`..P.......*.... ...eA.....QQ.a..I=..j..o......._.....q...<..<....e...Y+Y......R...+.Bb.o...'....z..?.d.x....D.Wq%..%.....u.5H+.%..v,[..y.R.M...s.-.^....%....".......l......o...LG!..Pl.0...D..UM..F..t...:Q:..Og[c..~.D.:R......5.'..7opwvg.. .%K.V.].:.%......J9.J.....C..\.r.#.'"..>.....:/.k..A.k^w....^t.....sd../....v.J..N`.Y......O...j[.J.UVVi...k}..6.YJG?.{cA.0.....&!....e...1..~J4.I0........@.Z.:.j.%?P-Mh....RWwKj.~~._.z?.n..d.D`Ot .6..D...&... M.!2......AC......1Z9.U.X..}Z.\...b...m^c...,...LV%f....$K..ei.1f..#...'.-...?..._....5.b......eC.?....Ec....B2....\...<p....}.OB..$.6.<k(....d%~ .e.....D3...|....xI.S..^....=...Ky/..r.H...n./..S<.x.G..%n..G.v...y,..[...w.....O|......"..!....Ms.......t..d..&...w..>)Oa.:..p........^.v....a..y...5{.'.5:.6'.W..x../.%^....q.K.....u.J.n|.7...........P../..yIJ#...v= ..u...M....=..W...c...<..".U..8.W..........%..;..n........D......].%...0..*../k}.
                No static file info