Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
original.eml

Overview

General Information

Sample name:original.eml
Analysis ID:1590925
MD5:96c43f66e14e2fa5782d19584b26f335
SHA1:3e56151ad9584754141986f6374fac15afe157e0
SHA256:44c374171a3dfc7380266297d4952b51e3c81980fdcf9c17b8a61278198fffca
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected landing page (webpage, office document or email)
AI detected suspicious elements in Email content
Queries the volume information (name, serial number etc) of a device
Sigma detected: Office Autorun Keys Modification
Sigma detected: Outlook Security Settings Updated - Registry
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • OUTLOOK.EXE (PID: 6840 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\original.eml" MD5: 91A5292942864110ED734005B7E005C0)
    • ai.exe (PID: 6576 cmdline: "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "A27B1353-F78E-41CB-B0F8-11E7263BE425" "F4A2E0B0-23B1-4F6F-94CF-29A684FB319C" "6840" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD)
    • OUTLOOK.EXE (PID: 5404 cmdline: "C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\KQHSMYVS\phish_alert_sp2_2.0.0.0.eml" MD5: 91A5292942864110ED734005B7E005C0)
    • Acrobat.exe (PID: 6360 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\KQHSMYVS\Worksheet BT154296 - METALUS PLAN VICTORIAVILLE.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C)
      • AcroCEF.exe (PID: 6416 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
        • AcroCEF.exe (PID: 6756 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2248 --field-trial-handle=1556,i,7561464354657488856,13588845150243518525,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
    • chrome.exe (PID: 4016 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://can01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.techlift.ca%2Fmail%2Fview%3Fmodel%3Dproject.task%26res_id%3D166767%26access_token%3Db8f79f62-9a1a-4f0f-8b02-ad8868e93ff6%26auth_signup_token%3DeTAQ1X91NMP6dRJVqneq&data=05%7C02%7Cdany.ratte%40metalus.qc.ca%7C53624b36948c4e181b5508dd34a0b22b%7C4f85cc14eaa84e0b829193aab6969f78%7C0%7C0%7C638724587237591513%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=ev37I7VoFUBfa7Lk84FtS%2BnKwDPw9NN1cCQVVWEXz7Q%3D&reserved=0 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 6928 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2148 --field-trial-handle=1868,i,14692796438039856495,12729467369949085797,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 6840, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Addins\OneNote.OutlookAddin\1
Source: Registry Key setAuthor: frack113: Data: Details: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\KQHSMYVS\, EventID: 13, EventType: SetValue, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE, ProcessId: 6840, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Outlook\Security\OutlookSecureTempFolder
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: EmailJoe Sandbox AI: Email contains prominent button: 'signer le rapport'
Source: EmailJoe Sandbox AI: Detected potential phishing email: The email contains suspicious links with access tokens and auth tokens that are common in phishing attempts. The recipient address contains 'phisher.knowbe4.com' which indicates this is likely a phishing simulation. The email attempts to get the user to click on links to 'sign a report' which is a common phishing tactic
Source: EmailClassification: Credential Stealer
Source: chrome.exeMemory has grown: Private usage: 7MB later: 31MB
Source: unknownTCP traffic detected without corresponding DNS query: 23.56.162.204
Source: unknownTCP traffic detected without corresponding DNS query: 23.56.162.204
Source: unknownTCP traffic detected without corresponding DNS query: 23.56.162.204
Source: unknownTCP traffic detected without corresponding DNS query: 23.56.162.204
Source: unknownTCP traffic detected without corresponding DNS query: 23.56.162.204
Source: unknownTCP traffic detected without corresponding DNS query: 23.56.162.204
Source: unknownTCP traffic detected without corresponding DNS query: 23.56.162.204
Source: unknownTCP traffic detected without corresponding DNS query: 23.56.162.204
Source: unknownTCP traffic detected without corresponding DNS query: 23.56.162.204
Source: unknownTCP traffic detected without corresponding DNS query: 23.56.162.204
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknownTCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknownTCP traffic detected without corresponding DNS query: 40.126.31.71
Source: global trafficHTTP traffic detected: GET /mail/view?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6&auth_signup_token=eTAQ1X91NMP6dRJVqneq HTTP/1.1Host: www.techlift.caConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6 HTTP/1.1Host: www.techlift.caConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8
Source: global trafficHTTP traffic detected: GET /en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6 HTTP/1.1Host: www.techlift.caConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA
Source: global trafficHTTP traffic detected: GET /web/assets/1282895-916948a/1/web.assets_common.min.css HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA
Source: global trafficHTTP traffic detected: GET /web/assets/1280054-689d2b2/1/web.assets_frontend.min.css HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA
Source: global trafficHTTP traffic detected: GET /web/static/lib/fontawesome/fonts/fontawesome-webfont.woff2?v=4.7.0 HTTP/1.1Host: www.techlift.caConnection: keep-aliveOrigin: http://www.techlift.caUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA
Source: global trafficHTTP traffic detected: GET /web/assets/1126508-6596fbe/1/web.assets_common_minimal.min.js HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA
Source: global trafficHTTP traffic detected: GET /web/assets/1126508-6596fbe/1/web.assets_common_minimal.min.js HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA
Source: global trafficHTTP traffic detected: GET /web/assets/1126511-81ea84f/1/web.assets_frontend_minimal.min.js HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478
Source: global trafficHTTP traffic detected: GET /web/assets/1126511-81ea84f/1/web.assets_frontend_minimal.min.js HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478
Source: global trafficHTTP traffic detected: GET /web/image/website/1/logo/Techlift?unique=6b367a2 HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York
Source: global trafficHTTP traffic detected: GET /base/static/img/country_flags/ca.png?height=25 HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York
Source: global trafficHTTP traffic detected: GET /base/static/img/country_flags/ca.png?height=25 HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York
Source: global trafficHTTP traffic detected: GET /web/image/website/1/logo/Techlift?unique=6b367a2 HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York
Source: global trafficHTTP traffic detected: GET /web/assets/1278114-5599ff5/1/web.assets_common_lazy.min.js HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/image/website/1/favicon?unique=6b367a2 HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/image/website/1/favicon?unique=6b367a2 HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/assets/1278114-5599ff5/1/web.assets_common_lazy.min.js HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/assets/1278119-68fc4ee/1/web.assets_frontend_lazy.min.js HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/assets/1278119-68fc4ee/1/web.assets_frontend_lazy.min.js HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /website_sale_hide_price/static/src/xml/website_sale_templates.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /website/translations/04e840c3ed34e2d0b9fc364b60b58ef5e7bde60f?lang=en_CA HTTP/1.1Host: www.techlift.caConnection: keep-aliveAccept: */*User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36X-Requested-With: XMLHttpRequestReferer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/webclient/locale/en_CA HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /en_CA/website/translations/04e840c3ed34e2d0b9fc364b60b58ef5e7bde60f?lang=en_CA HTTP/1.1Host: www.techlift.caConnection: keep-aliveAccept: */*User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36X-Requested-With: XMLHttpRequestReferer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /website_sale_hide_price/static/src/xml/website_sale_templates.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/webclient/locale/en_CA HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/webclient/qweb/1736865482654?bundle=web.assets_frontend HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /en_CA/website/translations/04e840c3ed34e2d0b9fc364b60b58ef5e7bde60f?lang=en_CA HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /website/translations/04e840c3ed34e2d0b9fc364b60b58ef5e7bde60f?lang=en_CA HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/webclient/qweb/1736865482654?bundle=web.assets_frontend HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /website/static/src/xml/website.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /website/static/src/xml/website.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /website/static/src/snippets/s_searchbar/000.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /e3k_techlift_website/static/src/snippets/s_searchbar/000.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /website/static/src/snippets/s_searchbar/000.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /mail/chatter_init HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /portal/static/src/xml/portal_chatter.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /e3k_techlift_website/static/src/snippets/s_searchbar/000.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /portal_rating/static/src/xml/portal_tools.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /portal/static/src/xml/portal_chatter.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /portal_rating/static/src/xml/portal_chatter.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /portal_rating/static/src/xml/portal_tools.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /portal_rating/static/src/xml/portal_chatter.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/image/mail.message/4579457/author_avatar/50x50 HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/static/img/mimetypes/pdf.svg HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.techlift.ca/web/assets/1282895-916948a/1/web.assets_common.min.cssAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/image/mail.message/4579457/author_avatar/50x50 HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/static/img/mimetypes/pdf.svg HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /en_CA/my/task/166767/worksheet?access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6 HTTP/1.1Host: www.techlift.caConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0
Source: global trafficHTTP traffic detected: GET /web/static/img/logo.png HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.techlift.ca/en_CA/my/task/166767/worksheet?access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865485.54.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865485.54.0.0
Source: global trafficHTTP traffic detected: GET /web/static/img/logo.png HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.1.1736865485.54.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.1.1736865485.54.0.0
Source: global trafficHTTP traffic detected: GET /website/translations/04e840c3ed34e2d0b9fc364b60b58ef5e7bde60f?lang=en_CA HTTP/1.1Host: www.techlift.caConnection: keep-aliveAccept: */*User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36X-Requested-With: XMLHttpRequestReferer: http://www.techlift.ca/en_CA/my/task/166767/worksheet?access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.1.1736865485.54.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.1.1736865485.54.0.0
Source: global trafficHTTP traffic detected: GET /web/webclient/qweb/1736865487448?bundle=web.assets_frontend HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767/worksheet?access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.1.1736865485.54.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.1.1736865485.54.0.0
Source: global trafficHTTP traffic detected: GET /web/webclient/qweb/1736865487448?bundle=web.assets_frontend HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.1.1736865485.54.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.1.1736865485.54.0.0
Source: global trafficHTTP traffic detected: GET /website/translations/04e840c3ed34e2d0b9fc364b60b58ef5e7bde60f?lang=en_CA HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767/worksheet?access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.1.1736865485.54.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.1.1736865485.54.0.0
Source: global trafficHTTP traffic detected: GET /portal/static/src/xml/portal_signature.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767/worksheet?access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.1.1736865485.54.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.1.1736865485.54.0.0
Source: global trafficHTTP traffic detected: GET /portal/static/src/xml/portal_signature.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.1.1736865485.54.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.1.1736865485.54.0.0
Source: global trafficHTTP traffic detected: GET /web/static/src/legacy/xml/name_and_signature.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767/worksheet?access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.1.1736865485.54.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.1.1736865485.54.0.0
Source: global trafficHTTP traffic detected: GET /e3k_invoice_sale_renting/static/src/xml/signature_form.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://www.techlift.ca/en_CA/my/task/166767/worksheet?access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.1.1736865485.54.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.1.1736865485.54.0.0
Source: global trafficHTTP traffic detected: GET /web/static/src/legacy/xml/name_and_signature.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.1.1736865485.54.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.1.1736865485.54.0.0
Source: global trafficHTTP traffic detected: GET /e3k_invoice_sale_renting/static/src/xml/signature_form.xml HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.1.1736865485.54.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.1.1736865485.54.0.0
Source: global trafficHTTP traffic detected: GET /web/sign/get_fonts/ HTTP/1.1Host: www.techlift.caConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.1.1736865485.54.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.1.1736865485.54.0.0
Source: global trafficDNS traffic detected: DNS query: x1.i.lencr.org
Source: global trafficDNS traffic detected: DNS query: can01.safelinks.protection.outlook.com
Source: global trafficDNS traffic detected: DNS query: www.techlift.ca
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: googleads.g.doubleclick.net
Source: global trafficDNS traffic detected: DNS query: analytics.google.com
Source: global trafficDNS traffic detected: DNS query: stats.g.doubleclick.net
Source: unknownHTTP traffic detected: POST /mail/chatter_init HTTP/1.1Host: www.techlift.caConnection: keep-aliveContent-Length: 194User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/jsonAccept: */*Origin: http://www.techlift.caReferer: http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: session_id=ebfba9cdbd3054b7938b1689961a96d78a6a54d8; frontend_lang=en_CA; _gcl_au=1.1.1511753366.1736865478; tz=America/New_York; _ga=GA1.1.2066110333.1736865480; _ga_NBRWDBNKYM=GS1.1.1736865479.1.0.1736865479.60.0.0; _ga_Q7QQB9B00Q=GS1.1.1736865479.1.0.1736865479.60.0.0Data Raw: 7b 22 69 64 22 3a 30 2c 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 6d 65 74 68 6f 64 22 3a 22 63 61 6c 6c 22 2c 22 70 61 72 61 6d 73 22 3a 7b 22 72 65 73 5f 6d 6f 64 65 6c 22 3a 22 70 72 6f 6a 65 63 74 2e 74 61 73 6b 22 2c 22 72 65 73 5f 69 64 22 3a 31 36 36 37 36 37 2c 22 6c 69 6d 69 74 22 3a 31 30 2c 22 6f 66 66 73 65 74 22 3a 30 2c 22 61 6c 6c 6f 77 5f 63 6f 6d 70 6f 73 65 72 22 3a 31 2c 22 74 6f 6b 65 6e 22 3a 22 62 38 66 37 39 66 36 32 2d 39 61 31 61 2d 34 66 30 66 2d 38 62 30 32 2d 61 64 38 38 36 38 65 39 33 66 66 36 22 2c 22 64 6f 6d 61 69 6e 22 3a 5b 5d 7d 7d Data Ascii: {"id":0,"jsonrpc":"2.0","method":"call","params":{"res_model":"project.task","res_id":166767,"limit":10,"offset":0,"allow_composer":1,"token":"b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6","domain":[]}}
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: classification engineClassification label: mal48.winEML@38/104@21/172
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmp
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile created: C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20250114T0936380105-6840.etl
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile read: C:\Users\desktop.ini
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\Desktop\original.eml"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "A27B1353-F78E-41CB-B0F8-11E7263BE425" "F4A2E0B0-23B1-4F6F-94CF-29A684FB319C" "6840" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\KQHSMYVS\phish_alert_sp2_2.0.0.0.eml"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\KQHSMYVS\Worksheet BT154296 - METALUS PLAN VICTORIAVILLE.pdf"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2248 --field-trial-handle=1556,i,7561464354657488856,13588845150243518525,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding C4FE118CEFABFA3C5C4CEEB8CA8AB112
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe "C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe" "A27B1353-F78E-41CB-B0F8-11E7263BE425" "F4A2E0B0-23B1-4F6F-94CF-29A684FB319C" "6840" "C:\Program Files (x86)\Microsoft Office\Root\Office16\OUTLOOK.EXE" "WordCombinedFloatieLreOnline.onnx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE "C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE" /eml "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\KQHSMYVS\phish_alert_sp2_2.0.0.0.eml"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\KQHSMYVS\Worksheet BT154296 - METALUS PLAN VICTORIAVILLE.pdf"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2248 --field-trial-handle=1556,i,7561464354657488856,13588845150243518525,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://can01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.techlift.ca%2Fmail%2Fview%3Fmodel%3Dproject.task%26res_id%3D166767%26access_token%3Db8f79f62-9a1a-4f0f-8b02-ad8868e93ff6%26auth_signup_token%3DeTAQ1X91NMP6dRJVqneq&data=05%7C02%7Cdany.ratte%40metalus.qc.ca%7C53624b36948c4e181b5508dd34a0b22b%7C4f85cc14eaa84e0b829193aab6969f78%7C0%7C0%7C638724587237591513%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=ev37I7VoFUBfa7Lk84FtS%2BnKwDPw9NN1cCQVVWEXz7Q%3D&reserved=0
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2148 --field-trial-handle=1868,i,14692796438039856495,12729467369949085797,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://can01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.techlift.ca%2Fmail%2Fview%3Fmodel%3Dproject.task%26res_id%3D166767%26access_token%3Db8f79f62-9a1a-4f0f-8b02-ad8868e93ff6%26auth_signup_token%3DeTAQ1X91NMP6dRJVqneq&data=05%7C02%7Cdany.ratte%40metalus.qc.ca%7C53624b36948c4e181b5508dd34a0b22b%7C4f85cc14eaa84e0b829193aab6969f78%7C0%7C0%7C638724587237591513%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=ev37I7VoFUBfa7Lk84FtS%2BnKwDPw9NN1cCQVVWEXz7Q%3D&reserved=0
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2148 --field-trial-handle=1868,i,14692796438039856495,12729467369949085797,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: apphelp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: c2r64.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeSection loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\CLSID\{4E3A7680-B77A-11D0-9DA5-00C04FD65685}\InprocServer32
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEWindow found: window name: SysTabControl32
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEFile Volume queried: C:\Windows\SysWOW64 FullSizeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEProcess information queried: ProcessInformation
Source: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exeQueries volume information: C:\Program Files (x86)\Microsoft Office\root\Office16\AI\WordCombinedFloatieLreOnline.onnx VolumeInformation
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation21
Browser Extensions
1
Process Injection
1
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Registry Run Keys / Startup Folder
1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
DLL Side-Loading
1
DLL Side-Loading
1
DLL Side-Loading
Security Account Manager14
System Information Discovery
SMB/Windows Admin SharesData from Network Shared Drive3
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
Extra Window Memory Injection
1
Extra Window Memory Injection
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture4
Application Layer Protocol
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://www.techlift.ca/web/image/website/1/logo/Techlift?unique=6b367a20%Avira URL Cloudsafe
http://www.techlift.ca/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff60%Avira URL Cloudsafe
http://www.techlift.ca/web/assets/1126511-81ea84f/1/web.assets_frontend_minimal.min.js0%Avira URL Cloudsafe
http://www.techlift.ca/website_sale_hide_price/static/src/xml/website_sale_templates.xml0%Avira URL Cloudsafe
http://www.techlift.ca/web/static/lib/fontawesome/fonts/fontawesome-webfont.woff2?v=4.7.00%Avira URL Cloudsafe
http://www.techlift.ca/mail/view?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6&auth_signup_token=eTAQ1X91NMP6dRJVqneq0%Avira URL Cloudsafe
http://www.techlift.ca/website/translations/04e840c3ed34e2d0b9fc364b60b58ef5e7bde60f?lang=en_CA0%Avira URL Cloudsafe
http://www.techlift.ca/web/assets/1278119-68fc4ee/1/web.assets_frontend_lazy.min.js0%Avira URL Cloudsafe
http://www.techlift.ca/en_CA/website/translations/04e840c3ed34e2d0b9fc364b60b58ef5e7bde60f?lang=en_CA0%Avira URL Cloudsafe
http://www.techlift.ca/web/assets/1278114-5599ff5/1/web.assets_common_lazy.min.js0%Avira URL Cloudsafe
http://www.techlift.ca/web/image/website/1/favicon?unique=6b367a20%Avira URL Cloudsafe
http://www.techlift.ca/web/assets/1280054-689d2b2/1/web.assets_frontend.min.css0%Avira URL Cloudsafe
http://www.techlift.ca/web/assets/1282895-916948a/1/web.assets_common.min.css0%Avira URL Cloudsafe
http://www.techlift.ca/base/static/img/country_flags/ca.png?height=250%Avira URL Cloudsafe
http://www.techlift.ca/web/webclient/qweb/1736865482654?bundle=web.assets_frontend0%Avira URL Cloudsafe
http://www.techlift.ca/web/webclient/locale/en_CA0%Avira URL Cloudsafe
http://www.techlift.ca/web/assets/1126508-6596fbe/1/web.assets_common_minimal.min.js0%Avira URL Cloudsafe
http://www.techlift.ca/portal_rating/static/src/xml/portal_tools.xml0%Avira URL Cloudsafe
http://www.techlift.ca/website/static/src/xml/website.xml0%Avira URL Cloudsafe
http://www.techlift.ca/e3k_techlift_website/static/src/snippets/s_searchbar/000.xml0%Avira URL Cloudsafe
http://www.techlift.ca/web/sign/get_fonts/0%Avira URL Cloudsafe
http://www.techlift.ca/portal/static/src/xml/portal_signature.xml0%Avira URL Cloudsafe
http://www.techlift.ca/web/static/src/legacy/xml/name_and_signature.xml0%Avira URL Cloudsafe
http://www.techlift.ca/web/static/img/mimetypes/pdf.svg0%Avira URL Cloudsafe
http://www.techlift.ca/web/image/mail.message/4579457/author_avatar/50x500%Avira URL Cloudsafe
http://www.techlift.ca/mail/chatter_init0%Avira URL Cloudsafe
http://www.techlift.ca/e3k_invoice_sale_renting/static/src/xml/signature_form.xml0%Avira URL Cloudsafe
http://www.techlift.ca/portal_rating/static/src/xml/portal_chatter.xml0%Avira URL Cloudsafe
http://www.techlift.ca/web/static/img/logo.png0%Avira URL Cloudsafe
http://www.techlift.ca/website/static/src/snippets/s_searchbar/000.xml0%Avira URL Cloudsafe
http://www.techlift.ca/portal/static/src/xml/portal_chatter.xml0%Avira URL Cloudsafe
http://www.techlift.ca/web/webclient/qweb/1736865487448?bundle=web.assets_frontend0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
can01.safelinks.eop-tm2.outlook.com
104.47.75.220
truefalse
    unknown
    bg.microsoft.map.fastly.net
    199.232.214.172
    truefalse
      high
      analytics-alv.google.com
      216.239.38.181
      truefalse
        high
        googleads.g.doubleclick.net
        142.250.185.98
        truefalse
          high
          edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
          217.20.57.34
          truefalse
            high
            techlift.odoo.com
            35.224.169.167
            truefalse
              unknown
              www.google.com
              142.250.186.164
              truefalse
                high
                stats.g.doubleclick.net
                173.194.76.157
                truefalse
                  high
                  can01.safelinks.protection.outlook.com
                  unknown
                  unknownfalse
                    high
                    www.techlift.ca
                    unknown
                    unknownfalse
                      unknown
                      x1.i.lencr.org
                      unknown
                      unknownfalse
                        high
                        analytics.google.com
                        unknown
                        unknownfalse
                          high
                          NameMaliciousAntivirus DetectionReputation
                          http://www.techlift.ca/web/assets/1126511-81ea84f/1/web.assets_frontend_minimal.min.jsfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.techlift.ca/e3k_techlift_website/static/src/snippets/s_searchbar/000.xmlfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.techlift.ca/web/assets/1278119-68fc4ee/1/web.assets_frontend_lazy.min.jsfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://www.techlift.ca/web/image/website/1/logo/Techlift?unique=6b367a2false
                          • Avira URL Cloud: safe
                          unknown
                          http://www.techlift.ca/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6false
                          • Avira URL Cloud: safe
                          unknown
                          http://www.techlift.ca/en_CA/my/task/166767/worksheet?access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6false
                            unknown
                            http://www.techlift.ca/web/static/lib/fontawesome/fonts/fontawesome-webfont.woff2?v=4.7.0false
                            • Avira URL Cloud: safe
                            unknown
                            http://www.techlift.ca/portal_rating/static/src/xml/portal_tools.xmlfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://www.techlift.ca/website_sale_hide_price/static/src/xml/website_sale_templates.xmlfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://www.techlift.ca/web/assets/1280054-689d2b2/1/web.assets_frontend.min.cssfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://www.techlift.ca/website/static/src/xml/website.xmlfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6false
                              unknown
                              http://www.techlift.ca/web/image/website/1/favicon?unique=6b367a2false
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/web/sign/get_fonts/false
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/web/webclient/qweb/1736865482654?bundle=web.assets_frontendfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/e3k_invoice_sale_renting/static/src/xml/signature_form.xmlfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/web/webclient/locale/en_CAfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/web/static/src/legacy/xml/name_and_signature.xmlfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/portal/static/src/xml/portal_signature.xmlfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/web/static/img/mimetypes/pdf.svgfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/mail/chatter_initfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/web/image/mail.message/4579457/author_avatar/50x50false
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/web/static/img/logo.pngfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/website/translations/04e840c3ed34e2d0b9fc364b60b58ef5e7bde60f?lang=en_CAfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/en_CA/website/translations/04e840c3ed34e2d0b9fc364b60b58ef5e7bde60f?lang=en_CAfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/mail/view?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6&auth_signup_token=eTAQ1X91NMP6dRJVqneqfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/portal_rating/static/src/xml/portal_chatter.xmlfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/web/assets/1278114-5599ff5/1/web.assets_common_lazy.min.jsfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/base/static/img/country_flags/ca.png?height=25false
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/web/assets/1282895-916948a/1/web.assets_common.min.cssfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/website/static/src/snippets/s_searchbar/000.xmlfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/portal/static/src/xml/portal_chatter.xmlfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/web/webclient/qweb/1736865487448?bundle=web.assets_frontendfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.techlift.ca/web/assets/1126508-6596fbe/1/web.assets_common_minimal.min.jsfalse
                              • Avira URL Cloud: safe
                              unknown
                              • No. of IPs < 25%
                              • 25% < No. of IPs < 50%
                              • 50% < No. of IPs < 75%
                              • 75% < No. of IPs
                              IPDomainCountryFlagASNASN NameMalicious
                              173.194.76.157
                              stats.g.doubleclick.netUnited States
                              15169GOOGLEUSfalse
                              52.109.89.119
                              unknownUnited States
                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                              216.239.38.181
                              analytics-alv.google.comUnited States
                              15169GOOGLEUSfalse
                              216.58.206.36
                              unknownUnited States
                              15169GOOGLEUSfalse
                              142.250.185.202
                              unknownUnited States
                              15169GOOGLEUSfalse
                              23.56.162.204
                              unknownUnited States
                              16625AKAMAI-ASUSfalse
                              23.209.209.135
                              unknownUnited States
                              23693TELKOMSEL-ASN-IDPTTelekomunikasiSelularIDfalse
                              52.109.32.97
                              unknownUnited States
                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                              199.232.214.172
                              bg.microsoft.map.fastly.netUnited States
                              54113FASTLYUSfalse
                              142.250.184.227
                              unknownUnited States
                              15169GOOGLEUSfalse
                              172.64.41.3
                              unknownUnited States
                              13335CLOUDFLARENETUSfalse
                              52.113.194.132
                              unknownUnited States
                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                              54.224.241.105
                              unknownUnited States
                              14618AMAZON-AESUSfalse
                              1.1.1.1
                              unknownAustralia
                              13335CLOUDFLARENETUSfalse
                              172.217.18.8
                              unknownUnited States
                              15169GOOGLEUSfalse
                              74.125.133.84
                              unknownUnited States
                              15169GOOGLEUSfalse
                              142.250.184.194
                              unknownUnited States
                              15169GOOGLEUSfalse
                              2.23.240.205
                              unknownEuropean Union
                              8781QA-ISPQAfalse
                              142.250.185.136
                              unknownUnited States
                              15169GOOGLEUSfalse
                              239.255.255.250
                              unknownReserved
                              unknownunknownfalse
                              142.250.185.195
                              unknownUnited States
                              15169GOOGLEUSfalse
                              104.47.75.220
                              can01.safelinks.eop-tm2.outlook.comUnited States
                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                              35.224.169.167
                              techlift.odoo.comUnited States
                              15169GOOGLEUSfalse
                              142.250.186.164
                              www.google.comUnited States
                              15169GOOGLEUSfalse
                              142.250.184.238
                              unknownUnited States
                              15169GOOGLEUSfalse
                              142.250.185.74
                              unknownUnited States
                              15169GOOGLEUSfalse
                              20.42.73.31
                              unknownUnited States
                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                              172.217.18.100
                              unknownUnited States
                              15169GOOGLEUSfalse
                              142.250.185.98
                              googleads.g.doubleclick.netUnited States
                              15169GOOGLEUSfalse
                              IP
                              192.168.2.16
                              Joe Sandbox version:42.0.0 Malachite
                              Analysis ID:1590925
                              Start date and time:2025-01-14 15:35:26 +01:00
                              Joe Sandbox product:CloudBasic
                              Overall analysis duration:
                              Hypervisor based Inspection enabled:false
                              Report type:full
                              Cookbook file name:defaultwindowsinteractivecookbook.jbs
                              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                              Number of analysed new started processes analysed:22
                              Number of new started drivers analysed:0
                              Number of existing processes analysed:0
                              Number of existing drivers analysed:0
                              Number of injected processes analysed:0
                              Technologies:
                              • EGA enabled
                              Analysis Mode:stream
                              Analysis stop reason:Timeout
                              Sample name:original.eml
                              Detection:MAL
                              Classification:mal48.winEML@38/104@21/172
                              Cookbook Comments:
                              • Found application associated with file extension: .eml
                              • Exclude process from analysis (whitelisted): dllhost.exe
                              • Excluded IPs from analysis (whitelisted): 2.23.242.162
                              • Excluded domains from analysis (whitelisted): fs.microsoft.com, e16604.g.akamaiedge.net, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net
                              • Not all processes where analyzed, report is missing behavior information
                              • Report size getting too big, too many NtQueryAttributesFile calls found.
                              • Report size getting too big, too many NtQueryValueKey calls found.
                              • Report size getting too big, too many NtSetValueKey calls found.
                              • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                              • VT rate limit hit for: can01.safelinks.eop-tm2.outlook.com
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:ASCII text
                              Category:dropped
                              Size (bytes):287
                              Entropy (8bit):5.188867494932004
                              Encrypted:false
                              SSDEEP:
                              MD5:8FD411E05C6A9463CF26B946A38B0D61
                              SHA1:772D30E096BB6A51AABDE513FAD9DBC5E216C60F
                              SHA-256:1DAE14437BA4921F95ECACEFDA5B9F870DA80F9321C5DB7A523D5B1A358B273C
                              SHA-512:1C6078ACB52A943E65415A9F1BACF38D0FEBE1DA7E7B9642BA6D53D1DDC11FD6FC219CED2FEF97B2E4E27194815DAFC81D45D460C3920977BB5F02F1E16E70D2
                              Malicious:false
                              Reputation:unknown
                              Preview:2025/01/14-09:36:59.207 30c Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2025/01/14-09:36:59.209 30c Recovering log #3.2025/01/14-09:36:59.209 30c Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:ASCII text
                              Category:dropped
                              Size (bytes):334
                              Entropy (8bit):5.21190461716513
                              Encrypted:false
                              SSDEEP:
                              MD5:664DFF188F91CDF3FB8C9B369CEC87C0
                              SHA1:AE4D86A69B48D3A38B69D5AFA4B00253F52FB041
                              SHA-256:62C48CDCE62F1C998B8EB595A6D9932FB12AD99160F3DF26EFC242905EAA557A
                              SHA-512:53DF42BD51C9118145CA631479500EBBA534F392E613FFB1596A9E2A9D3EEBBA6358F5D6D73185586DC0CBE528EA45546BC74D4EC4AE622CC63305AC3CBC85A2
                              Malicious:false
                              Reputation:unknown
                              Preview:2025/01/14-09:36:59.095 1658 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2025/01/14-09:36:59.098 1658 Recovering log #3.2025/01/14-09:36:59.098 1658 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):403
                              Entropy (8bit):4.9699165732968
                              Encrypted:false
                              SSDEEP:
                              MD5:A93586925464029BB36C90E69C7B3DA1
                              SHA1:B9DA34D49A3E6AD56EC8016E20DEC7C0066BAE42
                              SHA-256:EABB0D72875F438B47CAEC43EAC5F82693420CD633D5500BB0BAAF5832CD7600
                              SHA-512:01FF255615D0A71A57097DB2FF6D1A662BE1640F49AF09A7D49AAA23B72E8E2F6E2268C7A4B25C0DF6B897005822E9ABBCF2C10938E799D5ED072C8513504061
                              Malicious:false
                              Reputation:unknown
                              Preview:{"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13381425431222440","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":127354},"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"supports_quic":{"address":"192.168.2.16","used_quic":true},"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):0
                              Entropy (8bit):0.0
                              Encrypted:false
                              SSDEEP:
                              MD5:A93586925464029BB36C90E69C7B3DA1
                              SHA1:B9DA34D49A3E6AD56EC8016E20DEC7C0066BAE42
                              SHA-256:EABB0D72875F438B47CAEC43EAC5F82693420CD633D5500BB0BAAF5832CD7600
                              SHA-512:01FF255615D0A71A57097DB2FF6D1A662BE1640F49AF09A7D49AAA23B72E8E2F6E2268C7A4B25C0DF6B897005822E9ABBCF2C10938E799D5ED072C8513504061
                              Malicious:false
                              Reputation:unknown
                              Preview:{"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13381425431222440","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":127354},"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"supports_quic":{"address":"192.168.2.16","used_quic":true},"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:data
                              Category:dropped
                              Size (bytes):4099
                              Entropy (8bit):5.233354969637357
                              Encrypted:false
                              SSDEEP:
                              MD5:D2545FFF03D669E9E55778BE1AAA9FB6
                              SHA1:AD7EC2E86BD135D847DE9A10AF115E97A0017DB7
                              SHA-256:45D48EB00B2B1C096EF72660961ACB22450561B836A993815B03FBA2ED379612
                              SHA-512:C76FBE68E747964AD93332B0DF9B10EF443C3A458662CC98A4F927C01BD3CE3C4F4FF7DA08901EA0FADA468BF104F836CC119A90D10D0660FCB45C97D909B533
                              Malicious:false
                              Reputation:unknown
                              Preview:*...#................version.1..namespace-e...o................next-map-id.1.Pnamespace-1d95df23_a38f_44a8_b732_4e62dd896a16-https://rna-resource.acrobat.com/.0y.S_r................next-map-id.2.Snamespace-2a884c18_b39c_4e3d_942f_252e530ca4bd-https://rna-v2-resource.acrobat.com/.16.X:r................next-map-id.3.Snamespace-2e78bfda_7188_4688_a4aa_1ff81b6e5eaa-https://rna-v2-resource.acrobat.com/.2.P.@o................next-map-id.4.Pnamespace-09c119c2_97bc_4467_8f67_f92472c9e5dc-https://rna-resource.acrobat.com/.346.+^...............Pnamespace-1d95df23_a38f_44a8_b732_4e62dd896a16-https://rna-resource.acrobat.com/....^...............Pnamespace-09c119c2_97bc_4467_8f67_f92472c9e5dc-https://rna-resource.acrobat.com/..?&a...............Snamespace-2a884c18_b39c_4e3d_942f_252e530ca4bd-https://rna-v2-resource.acrobat.com/_...a...............Snamespace-2e78bfda_7188_4688_a4aa_1ff81b6e5eaa-https://rna-v2-resource.acrobat.com/...o................next-map-id.5.Pnamespace-07af9ee9_2076_4f12_94b5_
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:ASCII text
                              Category:dropped
                              Size (bytes):322
                              Entropy (8bit):5.267148347408719
                              Encrypted:false
                              SSDEEP:
                              MD5:C457A12F7997227A48A4E3FDCF61874D
                              SHA1:9E85BA66B7E00E8F2E5C69BE62ADDDF6FF46BD91
                              SHA-256:A88D94A7CFD910BBA1F655E9391127E2E36280FE6EA73391C5E14E126BA39B56
                              SHA-512:E0666A9CBE5AA9AB03F51BBAD8C3978148DB4F216F50B602C0E6C5262BE3DA120FC7121860F492BF2D3A8724C70431C15A6E9C6E5BA39C628C717E62DD9BEF54
                              Malicious:false
                              Reputation:unknown
                              Preview:2025/01/14-09:36:59.274 1658 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2025/01/14-09:36:59.277 1658 Recovering log #3.2025/01/14-09:36:59.279 1658 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:PC bitmap, Windows 3.x format, 117 x -152 x 32, cbSize 71190, bits offset 54
                              Category:dropped
                              Size (bytes):71190
                              Entropy (8bit):2.3404177371019603
                              Encrypted:false
                              SSDEEP:
                              MD5:3784A93EB5381519B8B956E0B5F3957A
                              SHA1:DC6D776F8B1BC8921C88C3D0B40E455085976FE7
                              SHA-256:B968D94AECCE07FD61BF4007366E956B0737867F2A7B4E8B6F43B5C889D05ED4
                              SHA-512:E51D4A385A65179B9564B68AA7F2BBB88BDBAC246122C1D07B4FABD7386B068D034BDCADD83CDB017015A446BCCDFB77009546F4A240260421B188C49BFF5880
                              Malicious:false
                              Reputation:unknown
                              Preview:BM........6...(...u...h..... ...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 2, database pages 14, cookie 0x5, schema 4, UTF-8, version-valid-for 2
                              Category:dropped
                              Size (bytes):57344
                              Entropy (8bit):3.291927920232006
                              Encrypted:false
                              SSDEEP:
                              MD5:A4D5FECEFE05F21D6F81ACF4D9A788CF
                              SHA1:1A9AC236C80F2A2809F7DE374072E2FCCA5A775C
                              SHA-256:83BE4623D80FFB402FBDEC4125671DF532845A3828A1B378D99BD243A4FD8FF2
                              SHA-512:FF106C6B9E1EA4B1F3E3AB01FAEA21BA24A885E63DDF0C36EB0A8C3C89A9430FE676039C076C50D7C46DC4E809F6A7E35A4BFED64D9033FEBD6121AC547AA5E9
                              Malicious:false
                              Reputation:unknown
                              Preview:SQLite format 3......@ ..........................................................................c.......1........T...U.1.D............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:SQLite Rollback Journal
                              Category:dropped
                              Size (bytes):16928
                              Entropy (8bit):1.21288622268763
                              Encrypted:false
                              SSDEEP:
                              MD5:4EEF4E040611769DDADE2C8A66AC37F3
                              SHA1:C9772D2DA90FF4CE7792F9418A2651346B4E5E9F
                              SHA-256:2152C8D05A5398C3FBB10AA2880C792EFD047E47CF952DA614D28681294EAE90
                              SHA-512:1B9667F31342607C68D5AE26741BBC19412518E2FDD146A9A67993D7921D6918034058762D1FF5E01BCB8D29DA569A3B553D8596DCA8E073B02C234508049B30
                              Malicious:false
                              Reputation:unknown
                              Preview:.... .c.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:Certificate, Version=3
                              Category:dropped
                              Size (bytes):1391
                              Entropy (8bit):7.705940075877404
                              Encrypted:false
                              SSDEEP:
                              MD5:0CD2F9E0DA1773E9ED864DA5E370E74E
                              SHA1:CABD2A79A1076A31F21D253635CB039D4329A5E8
                              SHA-256:96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6
                              SHA-512:3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910
                              Malicious:false
                              Reputation:unknown
                              Preview:0..k0..S............@.YDc.c...0...*.H........0O1.0...U....US1)0'..U... Internet Security Research Group1.0...U....ISRG Root X10...150604110438Z..350604110438Z0O1.0...U....US1)0'..U... Internet Security Research Group1.0...U....ISRG Root X10.."0...*.H.............0..........$s..7.+W(.....8..n<.W.x.u...jn..O(..h.lD...c...k....1.!~.3<.H..y.....!.K...qiJffl.~<p..)"......K...~....G.|.H#S.8.O.o...IW..t../.8.{.p!.u.0<.....c...O..K~.....w...{J.L.%.p..)..S$........J.?..aQ.....cq...o[...\4ylv.;.by.../&.....................6....7..6u...r......I.....*.A..v........5/(.l....dwnG7..Y^h..r...A)>Y>.&.$...Z.L@.F....:Qn.;.}r...xY.>Qx....../..>{J.Ks......P.|C.t..t.....0.[q6....00\H..;..}`...).........A.......|.;F.H*..v.v..j.=...8.d..+..(.....B.".'].y...p..N..:..'Qn..d.3CO......B0@0...U...........0...U.......0....0...U......y.Y.{....s.....X..n0...*.H.............U.X....P.....i ')..au\.n...i/..VK..s.Y.!.~.Lq...`.9....!V..P.Y...Y.............b.E.f..|o..;.....'...}~.."......
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 71954 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
                              Category:dropped
                              Size (bytes):71954
                              Entropy (8bit):7.996617769952133
                              Encrypted:true
                              SSDEEP:
                              MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
                              SHA1:1723BE06719828DDA65AD804298D0431F6AFF976
                              SHA-256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
                              SHA-512:BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B
                              Malicious:false
                              Reputation:unknown
                              Preview:MSCF............,...................I..................XaK .authroot.stl.[.i..6..CK..<Tk......4.cl!Kg..E..*Y.f_..".$mR"$.J.E.KB."..rKv.."{.g....3.W.....c..9.s...=....y6#..x..........D......\(.#.s.!.A.......cd.c........+^.ov...n.....3BL..0.......BPUR&.X..02.q...R...J.....w.....b.vy>....-.&..(..oe."."...J9...0U.6J..|U..S.....M.F8g...=.......p...........l.?3.J.x.G.Ep..$g..tj......)v]9(:.)W.8.Op.1Q..:.nPd........7.7..M].V F..g.....12..!7(...B.......h.RZ.......l.<.....6..Z^.`p?... .p.Gp.#.'.X..........|!.8.....".m.49r?.I...g...8.v.....a``.g.R4.i...J8q....NFW,E.6Y....!.o5%.Y.....R..<..S9....r....WO...(.....F..Q=*....-..7d..O(....-..+k.........K..........{Q....Z..j._.E...QZ.~.\.^......N.9.k..O.}dD.b1r...[}/....T..E..G..c.|.c.&>?..^t. ..;..X.d.E.0G....[Q.*,*......#.Dp..L.o|#syc.J............}G-.ou6.=52..XWi=...m.....^u......c..fc?&pR7S5....I...j.G........j.j..Tc.El.....B.pQ.,Bp....j...9g.. >..s..m#.Nb.o_u.M.V...........\#...v..Mo\sF..s....Y...
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:data
                              Category:dropped
                              Size (bytes):192
                              Entropy (8bit):2.756901573172974
                              Encrypted:false
                              SSDEEP:
                              MD5:34E60EA098A96654B59504674ABA7F73
                              SHA1:29DD032C0395E6A7F0205B5375C598B409CDCDE8
                              SHA-256:0D71A7CCF9375DB52896D9892077EA83ACC397F7EB41F2A9200DE237C2E653D2
                              SHA-512:16127F150D20CF60E3DFB7F3B78D4E0F410AD2F243070402A2D25B9F200BF798CB67DE63AAFD2179630EB6BB02D6D4C583B3D413FFFBD7AE2240AEF2ADDCCAD6
                              Malicious:false
                              Reputation:unknown
                              Preview:p...... ........K...f..(....................................................... ..........W....IX..............o...h.t.t.p.:././.x.1...i...l.e.n.c.r...o.r.g./...".6.4.c.d.6.6.5.4.-.5.6.f."...
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:data
                              Category:modified
                              Size (bytes):328
                              Entropy (8bit):3.2478978672539016
                              Encrypted:false
                              SSDEEP:
                              MD5:0352D8314CD8007E9EBBB8FC62215A5B
                              SHA1:611989A4579E6170BC698B7DD11A790417372281
                              SHA-256:E5470849044B24DD9CE3A7E0A0E3827A31A29CFBAB156552A1C4C5B8254DEAB4
                              SHA-512:758A8FB3A10AB8D06D7442DD0AAF814E47AED148649F73FCC6ADA9FE46577601E8C1B46F44AA30962D21931330B2C749E4EEAE46F8A8EE23CECDA39FFE142DA9
                              Malicious:false
                              Reputation:unknown
                              Preview:p...... ............f..(....................................................... ........G..@.......&......X........h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".a.7.2.8.2.e.b.4.0.b.1.d.a.1.:.0."...
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):295
                              Entropy (8bit):5.360444744536055
                              Encrypted:false
                              SSDEEP:
                              MD5:CEDE111B2A83CBB9F4D84DCFF9275186
                              SHA1:45C2AA4FF0F348B7014AECE9B118C1A6BAA59A51
                              SHA-256:43A3E121A7D156CB0DE39FF45455FF3A3EB42C861160A9BD2D2DF2F08199AF47
                              SHA-512:B74D212B1520B81CEDA40A8C3132CE499D7864CDA3BD8ED727AACC9A5CB49017A784A8CCE9A9C03AFE0FF241E63720A9EC50AFC5D385D2FF49B65BA1865535BA
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"ACROBAT_READER_MASTER_SURFACEID","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):294
                              Entropy (8bit):5.310136967991502
                              Encrypted:false
                              SSDEEP:
                              MD5:092C18FEF662CBD3A5EEE27D70A8E4DE
                              SHA1:563DB647394DD234BDA1DE464C0C287A741762CA
                              SHA-256:B39227C9A15448C4CB8377165F92EAF3A493B0D34EFB7E095F4BFDB70328C7D1
                              SHA-512:861839915DD1B24F3A3B39D00CE036F767A57B936921A2F140478FF894D066AA0B2DFCC582F0D1F7684A3D47ADF956F25E8E342A53AB1B7D060943D7656A4F8C
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_FirstMile_Home_View_Surface","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):294
                              Entropy (8bit):5.28839646334931
                              Encrypted:false
                              SSDEEP:
                              MD5:3803582C25DEBDD73FB16197F4C847F6
                              SHA1:663A148110D9F347FE9D87C8E2039F76567F9093
                              SHA-256:2FD00533748FD82C9BD7136D365ECEEC8C9981972D76C2426C46732B274F518F
                              SHA-512:7484B212FA5953C20C12A666BD61FA73E26575659E64B385FADBF49B191346F84C6270584B8AFD69AB76B511729AAC98710D034DE6B52E19D3DA405684B31685
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_FirstMile_Right_Sec_Surface","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):285
                              Entropy (8bit):5.3487225247935015
                              Encrypted:false
                              SSDEEP:
                              MD5:B980F922A9AE3A9E16B1292CB209458A
                              SHA1:EE057E18B70E1E5CB1D7F27C4D07959B4706AB41
                              SHA-256:29ECCCC9DB67B5329A11899BF129203F085254989CD7430EA69D86C9FCF16670
                              SHA-512:03EE8853B5204C27C140ED367804397187E7A8BB7CD2E7F4F6265E5DF86E2F003E875AD707E9D4EBDF685E91A246871F739F9B9866930F046A32498ECB191AA1
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_READER_LAUNCH_CARD","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):1123
                              Entropy (8bit):5.693152053187803
                              Encrypted:false
                              SSDEEP:
                              MD5:011CF041D58AC6B35D74290BF11CADFE
                              SHA1:728B131216AE6D0E8B9FA06428836AB3935F87B6
                              SHA-256:E31A1CDE277735BB483DE109CB1D0C066040CA89891B835886C3197568A92775
                              SHA-512:19421760F41285990DF585E6FF551D117E70CEE9FF12FDEBF794381745E8479B66549F1D5CE41BB0853AE78DF860E884F4D0DB89EE989752439E07F3332956A3
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_Reader_Convert_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Convert_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"93365_289436ActionBlock_1","campaignId":93365,"containerId":"1","controlGroupId":"","treatmentId":"d5bba1ae-6009-4d23-8886-fd4a474b8ac9","variationId":"289436"},"containerId":1,"containerLabel":"JSON for DC_Reader_Convert_LHP_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IkZyZWUgdHJpYWwiLCJjbGljayI6Im9wZW5Ub29sIiwidG9vbF9pZCI6IkNvbnZlcnRQREZSZHJSSFBBcHAifSwidWkiOnsidGl0bGVfc3R5bGluZyI6eyJmb250X3NpemUiOiIxNHB4IiwiZm9udF9zdHlsZSI6IjAifSwiZGVzY3JpcHRpb25fc3R5bGluZyI6eyJmb250X3NpemUiOiIxMnB4IiwiZm9udF9zdHlsZSI6Ii0xIn0sInRpdGxlIjpudWxsLCJkZXNjcmlwdGlvbiI6IkV4cG9ydCBQREZzIHRvIE1pY3Jvc29mdCBXb3JkIGFuZCBFeGNlbC4ifSwidGNh
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):289
                              Entropy (8bit):5.299713850775975
                              Encrypted:false
                              SSDEEP:
                              MD5:B3899B8856E0536E03169DA6A82B53B8
                              SHA1:83B06F73ADE658510A60F3ECA010D53B8CCE5827
                              SHA-256:AE635BE39446DC123FBE008AEE209F4E824FB7A339ABD905D63F79591586878B
                              SHA-512:A54EB38E831016376A0F5D0F148DD305EC478EFDFC54C1A5452BF457603F42FA485B758A31B37769D2E73449B869470053B2F93ACC814DD1E7C20C8B55CB2BEB
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_Reader_Disc_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):292
                              Entropy (8bit):5.302659842203466
                              Encrypted:false
                              SSDEEP:
                              MD5:640EB0E09443A0E7BB870465DCFDB853
                              SHA1:8AC6056F1012C89E1C010C8048BA8B2AC7ED6E8B
                              SHA-256:0064DB6C864AE1A93C55D066FA7434F1AD831E12343C23B6319FC1C5317CE945
                              SHA-512:4BA3EF504053B605D753D65EFF1E5BC04AA8306E211400AAC7A2F03FA4EAB78BF3495A43FF1254819FC798C6FAF40DE7918F575197942421DBA7F2CD9FD2EC87
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_Reader_Disc_LHP_Retention","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):289
                              Entropy (8bit):5.3112834470550245
                              Encrypted:false
                              SSDEEP:
                              MD5:49BE2F6B489C207B8AE3B578BC580CD1
                              SHA1:76F3FABDABC79C43BF2ED259720047289F824D2E
                              SHA-256:22C88E0C6D3F368FC313C5E8CED97FF818B74C6F1D67E779BC988531CC73A0FD
                              SHA-512:F64570004EF621891FC34DBDBF10C0C3ADAAC080558339ACB67F835A0BFBE8E0FABBCD8113DFD23F41FF401A628AE616302948E8F28D7B8FE1EA3C12AD9EEA11
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_Reader_Edit_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):295
                              Entropy (8bit):5.325526654692105
                              Encrypted:false
                              SSDEEP:
                              MD5:486A7060A2FBAA8882E4701E4A7F1F09
                              SHA1:7F8BB2EC5A3F2A7AC18BD072BF231C73191A1461
                              SHA-256:A9F505F25B5D985A94E0FF6A719158263AFDE0D225F03D6ECDF071440291A342
                              SHA-512:A45A95E944CF18FCD06A307B3FA8DF1FF6C272890E8D30DC6CAD622E049BBBA5EB5228341416D7A23B07EC9BAEA11BED3B3E31696E8C4AE49961C1C9DBE04070
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_Reader_Home_LHP_Trial_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):289
                              Entropy (8bit):5.306298349724066
                              Encrypted:false
                              SSDEEP:
                              MD5:DE77726EE294E92F77536165181F66FB
                              SHA1:929126DEDDA609811491A3C3FBEE4268FCFF78A4
                              SHA-256:57A5C74048E728C89A5F3BDA73E78659FFF4CE915CF63FB1A3D69F2E374AA11E
                              SHA-512:EE19EE06090B2895658741890A1C54FBF25D91A4A62656C3BE8840D527E82EFB5C7C218D5616C07A7D44920678C25DC2AF21821A3C450716A17BBA9280A91FEA
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_Reader_More_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):284
                              Entropy (8bit):5.292459608985744
                              Encrypted:false
                              SSDEEP:
                              MD5:3BD75DC39E80999A4C3EA8237AFACAEC
                              SHA1:2D7E5E0DD19C21B56E534000F4EFA45AA3BF90F2
                              SHA-256:4206335E2D2A8FFECF8A476F5984C0BAE1C96764280B9981751ECC7886FB43E8
                              SHA-512:80A72E4A67CE6D52333D4D9A193B608CA05A7BF529511FB52E7C9089DB288E0AA4E9D4A3FC1E810A4E3580E459E0DE5FE21A7ED84EFA05EC636369E3D431F5E6
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_Reader_RHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):291
                              Entropy (8bit):5.28980215977096
                              Encrypted:false
                              SSDEEP:
                              MD5:19DFBAAA7952C3398DB7F46B34733F28
                              SHA1:57B6C4DA9938A7417A96CBE9E64DAEDE238BDFBA
                              SHA-256:7642AB5F80602671BAAA1914C56A65E86F4D48254C57C95B1D0323C4FD6F4EC7
                              SHA-512:1DD27BB2DEA25E77ADE80041FA2AFBBA7F8C3A45715D179E7CE5B89F201CB78B3FDD3C6796941A254A4977ECC99371D02E2B230D78DC33DF241C20B91D51A16F
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_Reader_RHP_Intent_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):287
                              Entropy (8bit):5.293270658650349
                              Encrypted:false
                              SSDEEP:
                              MD5:2F3876DB63346D6D105F2348B0AAA5FA
                              SHA1:33EE4E0E5D5AF19ACCC51B49FB9160A3CBF2D579
                              SHA-256:5B0836434BD29336038EDA5A8B773453EA24531C883DBBF5995A4F595B4AAA02
                              SHA-512:4022E137F454135AA59E7AC760CB1A076CEF78E0B66194B6A53283EFCB96F78332B9F5D98BE0990A2AE8ED202284A06B05E8E2E0D2B5ED418B1E10E84CD10F97
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_Reader_RHP_Retention","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):1090
                              Entropy (8bit):5.667619335815281
                              Encrypted:false
                              SSDEEP:
                              MD5:418F1F54418F13ED480FA4AA160D6838
                              SHA1:59B3F1DDA9B7A755E1CF1645466F2EB34D1D3CD7
                              SHA-256:C34C82AD9C681503F7608680AC9C852682488AE8D164B80DD26B40407DE10F79
                              SHA-512:F6AA8B61640CA479A025B23E05658563595A175E80EC72F2B81C219BAC621CFF8FFAA661B02E94F88851E93D597579D1BACC413357C110AB85D736E7A34985A5
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_Reader_Sign_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Sign_LHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"93365_289436ActionBlock_0","campaignId":93365,"containerId":"1","controlGroupId":"","treatmentId":"266234d2-130d-426e-8466-c7a061db101f","variationId":"289436"},"containerId":1,"containerLabel":"JSON for DC_Reader_Sign_LHP_Banner","content":{"data":"eyJjdGEiOnsidGV4dCI6IkZyZWUgdHJpYWwiLCJjbGljayI6Im9wZW5Ub29sIiwidG9vbF9pZCI6IlVwZ3JhZGVSSFBSZHJBcHAifSwidWkiOnsidGl0bGVfc3R5bGluZyI6eyJmb250X3NpemUiOiIxNHB4IiwiZm9udF9zdHlsZSI6IjAifSwiZGVzY3JpcHRpb25fc3R5bGluZyI6eyJmb250X3NpemUiOiIxMnB4IiwiZm9udF9zdHlsZSI6Ii0xIn0sInRpdGxlIjpudWxsLCJkZXNjcmlwdGlvbiI6IkVhc2lseSBmaWxsIGFuZCBzaWduIFBERnMuIn0sInRjYXRJZCI6bnVsbH0=","dataType":"app
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):286
                              Entropy (8bit):5.270923126018789
                              Encrypted:false
                              SSDEEP:
                              MD5:7449B2CA4BD70CEE0C9CF7418D742A69
                              SHA1:413ED6DDAD310384F0894CB2603BA2967B0D0056
                              SHA-256:3DA4AECEFE5C336BA3DF96A77BE508FAB9884F3C954147F54DD6D4A1638CF3CE
                              SHA-512:F58A8144E34BB4548409432461F62FA7EED4CCB184427F56517C2D3DC68C4CFF207D03DD81A2A968DD4D5813F3274927D5297382F6CCA007EB9F8B2B2C15FF78
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"DC_Reader_Upsell_Cards","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):282
                              Entropy (8bit):5.2759528892398455
                              Encrypted:false
                              SSDEEP:
                              MD5:6073685B0A6995A61F679D8BA8C9CC56
                              SHA1:AD23A5CE93DF71612C8604DB4CB5E76ABC7E4EC0
                              SHA-256:D708E3A9571C6744EB16BEB73816DD614F59C24E6FF87F76B6B090D88D45669F
                              SHA-512:718E0FDD64832F9FD1F71DB3674D062083F7A4E6513CBE00638AFA972E0C3DDB4AC256221CCA848C2C804710C01FAE06F437CD9184A9CD838F437B95198AE23A
                              Malicious:false
                              Reputation:unknown
                              Preview:{"analyticsData":{"responseGUID":"90a0844e-71c1-428f-9c63-34564795a026","sophiaUUID":"5E8BF9F5-1E3B-447C-A619-6054B1C06D0A"},"encodingScheme":true,"expirationDTS":1737041779560,"statusCode":200,"surfaceID":"Edit_InApp_Aug2020","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:data
                              Category:dropped
                              Size (bytes):4
                              Entropy (8bit):0.8112781244591328
                              Encrypted:false
                              SSDEEP:
                              MD5:DC84B0D741E5BEAE8070013ADDCC8C28
                              SHA1:802F4A6A20CBF157AAF6C4E07E4301578D5936A2
                              SHA-256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
                              SHA-512:65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71
                              Malicious:false
                              Reputation:unknown
                              Preview:....
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:JSON data
                              Category:dropped
                              Size (bytes):2814
                              Entropy (8bit):5.136622864569504
                              Encrypted:false
                              SSDEEP:
                              MD5:A76FB65BE9BCB8B4377A043346516DED
                              SHA1:FB4CB726070A1660C4B84303196E2C56227F15A6
                              SHA-256:FCD7DA792E19DE056E3ECD4F9F53F14AE7F68C19A0A6D438C789912A5B2D3CF3
                              SHA-512:86EA4386E293FC67E3A9293530E1FE92EDC1ABF172FE6B1400BA249F4D3F602C851BF76F37390A825DC081D1CD9846C5A1B23776773E4EEF30A23926756726D2
                              Malicious:false
                              Reputation:unknown
                              Preview:{"all":[{"id":"DC_Reader_Disc_LHP_Banner","info":{"dg":"ef9c124b5300ece5b0e34e776e463e4d","sid":"DC_Reader_Disc_LHP_Banner"},"mimeType":"file","size":289,"ts":1736865424000},{"id":"DC_Reader_Sign_LHP_Banner","info":{"dg":"826b02663197377cebbc6de25044e1b6","sid":"DC_Reader_Sign_LHP_Banner"},"mimeType":"file","size":1090,"ts":1736865424000},{"id":"DC_Reader_Convert_LHP_Banner","info":{"dg":"2edfd6e44b062a78e00af1f39742ebbe","sid":"DC_Reader_Convert_LHP_Banner"},"mimeType":"file","size":1123,"ts":1736865424000},{"id":"DC_Reader_Home_LHP_Trial_Banner","info":{"dg":"37249b78ae4d1cf197f4d166d70a3983","sid":"DC_Reader_Home_LHP_Trial_Banner"},"mimeType":"file","size":295,"ts":1736865424000},{"id":"DC_Reader_Disc_LHP_Retention","info":{"dg":"d1d1b81b13dbe9655cbacb32975aeedd","sid":"DC_Reader_Disc_LHP_Retention"},"mimeType":"file","size":292,"ts":1736865424000},{"id":"DC_Reader_More_LHP_Banner","info":{"dg":"a44fdf9e776d64a2d1880beca8ab706a","sid":"DC_Reader_More_LHP_Banner"},"mimeType":"file","
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 19, database pages 3, cookie 0x2, schema 4, UTF-8, version-valid-for 19
                              Category:dropped
                              Size (bytes):12288
                              Entropy (8bit):0.9884020261887027
                              Encrypted:false
                              SSDEEP:
                              MD5:A8FB99CBA64EAF7AD57EF0FDDFBCB5CA
                              SHA1:A7B3F8C1FEC673D5E5444C5568E50BA38117AD18
                              SHA-256:8A17AD2102123D5E79187A14D473E0D2E402322AA7E1DE4969D383BC133458A2
                              SHA-512:CA4870A0EB5D53C24FF50F77310A18AA22999422F30E393383121576249B72EED5E905E4CDC6FDE44498F9E85EAD1A33F49ACECE2C5915EA31E510FF50917724
                              Malicious:false
                              Reputation:unknown
                              Preview:SQLite format 3......@ ..........................................................................c.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:SQLite Rollback Journal
                              Category:dropped
                              Size (bytes):8720
                              Entropy (8bit):1.344446999809957
                              Encrypted:false
                              SSDEEP:
                              MD5:F24A96DDC00BB2AFCF40630421AC6F65
                              SHA1:A351ADC9DE3AD895817422DD8086F561AEBF0200
                              SHA-256:C060E311BE4A771EA60E8B08653BA2425803638FEEA2009BA00B833AD9500DD8
                              SHA-512:95A3D49602D0922D3D5C282B896EB097D4333B84EC473C0E4E70749FBC395ADE47713D46F448FC5644C9E2F1D03BA8E39C28FF13B47D3873B2942C923919FDFA
                              Malicious:false
                              Reputation:unknown
                              Preview:.... .c...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................j...#..#.#.#.#.#.#.#.#.7.7........................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:data
                              Category:dropped
                              Size (bytes):66726
                              Entropy (8bit):5.392739213842091
                              Encrypted:false
                              SSDEEP:
                              MD5:47FC6A5550AEB3281860DBD797E9A14C
                              SHA1:62AEFAA0AA942E91A4B2E2D14361FA438325DB47
                              SHA-256:630F955B1F4609EECB56D6886098506C6799CCEDBB35F37E55F368B4F11975BC
                              SHA-512:209AF4A1B2325B61A35AE1F293F4006865E8FD2BA1BBC015E0C5235F6AEB660C24187998AF1DDA9FFE5CC35656A98C077B4BFCD0C61DFAF69330D8D776AA65DF
                              Malicious:false
                              Reputation:unknown
                              Preview:4.397.90.FID.2:o:..........:F:AgencyFB-Reg.P:Agency FB.L:$.........................."F:Agency FB.#.96.FID.2:o:..........:F:AgencyFB-Bold.P:Agency FB Bold.L:%.........................."F:Agency FB.#.84.FID.2:o:..........:F:Algerian.P:Algerian.L:$..........................RF:Algerian.#.95.FID.2:o:..........:F:ArialNarrow.P:Arial Narrow.L:$.........................."F:Arial Narrow.#.109.FID.2:o:..........:F:ArialNarrow-Italic.P:Arial Narrow Italic.L:$.........................."F:Arial Narrow.#.105.FID.2:o:..........:F:ArialNarrow-Bold.P:Arial Narrow Bold.L:%.........................."F:Arial Narrow.#.118.FID.2:o:..........:F:ArialNarrow-BoldItalic.P:Arial Narrow Bold Italic.L:%.........................."F:Arial Narrow.#.77.FID.2:o:..........:F:ArialMT.P:Arial.L:$.........................."F:Arial.#.91.FID.2:o:..........:F:Arial-ItalicMT.P:Arial Italic.L:$.........................."F:Arial.#.87.FID.2:o:..........:F:Arial-BoldMT.P:Arial Bold.L:$.........................."F:Arial.#.100.FID.2
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                              Category:dropped
                              Size (bytes):246
                              Entropy (8bit):3.5390718303530573
                              Encrypted:false
                              SSDEEP:
                              MD5:AB02F743A8D2ED867EA2C57B76DF38A9
                              SHA1:8A064EC70CD3E5E990F8F7A8E12CE6F17B007C77
                              SHA-256:15FC24CDA6980D162187EF6BFF6015C077FD23905D46CB25017BD4729ADF52A1
                              SHA-512:4F642F3B8BD4AC6517208E4304C1E149CB172C2ED46A34655A3ECDCD028696740C0E9674521AE2D7597F0147FDBF75CC9222E376B22F305FAE404222D8DEDFD6
                              Malicious:false
                              Reputation:unknown
                              Preview:..E.r.r.o.r. .2.7.1.1...T.h.e. .s.p.e.c.i.f.i.e.d. .F.e.a.t.u.r.e. .n.a.m.e. .(.'.A.R.M.'.). .n.o.t. .f.o.u.n.d. .i.n. .F.e.a.t.u.r.e. .t.a.b.l.e.......=.=.=. .L.o.g.g.i.n.g. .s.t.o.p.p.e.d.:. .1.4./.0.1./.2.0.2.5. . .0.9.:.3.7.:.0.6. .=.=.=.....
                              Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                              File Type:data
                              Category:modified
                              Size (bytes):118784
                              Entropy (8bit):4.513100762077878
                              Encrypted:false
                              SSDEEP:
                              MD5:DE2BF2669C5B915B67B2833517C021A3
                              SHA1:8E92C740530B3B4F2BECD116F3FFC0C0D813CC6E
                              SHA-256:3E3255F07DE16D3FABFA25059BF530EEF6AFC1FB66D815AB6AEA2A23FFBF2F47
                              SHA-512:A0392746768C6F9A8B26F8FE8249548581D433AFB6615BA39CF3F22FBCE021BAD4953A0392C770596EAC056EE7148659F6F9D03D01BB34FC4E09F67756527B32
                              Malicious:false
                              Reputation:unknown
                              Preview:............................................................................`...........7....f..................eJ..............Zb..2...................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1...........................................................`.>.Y..........7....f..........v.2._.O.U.T.L.O.O.K.:.1.a.b.8.:.d.8.1.e.8.4.9.6.f.2.3.f.4.e.a.c.8.6.8.0.6.6.3.7.9.b.2.7.b.f.e.3...C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.O.u.t.l.o.o.k. .L.o.g.g.i.n.g.\.O.U.T.L.O.O.K._.1.6._.0._.1.6.8.2.7._.2.0.1.3.0.-.2.0.2.5.0.1.1.4.T.0.9.3.6.3.8.0.1.0.5.-.6.8.4.0...e.t.l.......P.P..........a...f..........................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                              File Type:data
                              Category:dropped
                              Size (bytes):16384
                              Entropy (8bit):3.553687546821918
                              Encrypted:false
                              SSDEEP:
                              MD5:BC37E667118384CD4A1348E7B8C0D5A8
                              SHA1:058FC38AC696AC426AB4AF72E6CFA5978F3ABD19
                              SHA-256:6AD45E23E3599011C7AF0D5B76667CCF99B820F96DE5C89CBE3A7C50200069DB
                              SHA-512:967DE7A385D79422A97B999A4FE1FCD4529DDFBA5D9AA7D472542EC158DEB3C0BE339FE171C1E9C4EC5BA4F3B75888B73E63F56C23DEC739A60F8A74CC139716
                              Malicious:false
                              Reputation:unknown
                              Preview:............................................................................`.............2..f..................eJ........<..f..Zb..2...................................,...@.t.z.r.e.s...d.l.l.,.-.1.1.2.......................................................@.t.z.r.e.s...d.l.l.,.-.1.1.1...........................................................`.>.Y............2..f..........v.2._.O.U.T.L.O.O.K.:.1.5.1.c.:.e.d.5.f.7.a.d.1.5.3.0.6.4.2.e.b.9.c.5.f.8.3.e.8.1.6.9.6.4.9.4.2...C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.O.u.t.l.o.o.k. .L.o.g.g.i.n.g.\.O.U.T.L.O.O.K._.1.6._.0._.1.6.8.2.7._.2.0.1.3.0.-.2.0.2.5.0.1.1.4.T.0.9.3.6.5.0.0.1.6.3.-.5.4.0.4...e.t.l.......P.P..........Y5..f..........................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:ASCII text, with very long lines (393)
                              Category:dropped
                              Size (bytes):16525
                              Entropy (8bit):5.353642815103214
                              Encrypted:false
                              SSDEEP:
                              MD5:91F06491552FC977E9E8AF47786EE7C1
                              SHA1:8FEB27904897FFCC2BE1A985D479D7F75F11CEFC
                              SHA-256:06582F9F48220653B0CB355A53A9B145DA049C536D00095C57FCB3E941BA90BB
                              SHA-512:A63E6E0D25B88EBB6602885AB8E91167D37267B24516A11F7492F48876D3DDCAE44FFC386E146F3CF6EB4FA6AF251602143F254687B17FCFE6F00783095C5082
                              Malicious:false
                              Reputation:unknown
                              Preview:SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:072+0200 ThreadID=6404 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:072+0200 ThreadID=6404 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:072+0200 ThreadID=6404 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:073+0200 ThreadID=6404 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1".SessionID=ec4bacf2-5410-40d4-850b-5ac338f864f3.1696585143072 Timestamp=2023-10-06T11:39:03:073+0200 ThreadID=6404 Component=ngl-lib_NglAppLib Description="SetConfig:
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                              File Type:ASCII text, with CRLF line terminators
                              Category:dropped
                              Size (bytes):29752
                              Entropy (8bit):5.420386620749323
                              Encrypted:false
                              SSDEEP:
                              MD5:11B193961799E7F6A1AAE0C185E0F375
                              SHA1:94CC79055225F4B88A42A1AB1D1F4FD332A57A6C
                              SHA-256:EE3BCA5DA4B086F8D76F881EB538A018154A5BFDDFEA06F422CB004B4678FD51
                              SHA-512:87A6EDE6DCCEBE67CD5244D8C57E38C914FEF6B87C595D3E07EFDD3096FC213986669E9AF139A91C48D023E5EA9F1F5C6C88582E4A5CFAD93AF863C323674B4A
                              Malicious:false
                              Reputation:unknown
                              Preview:06-10-2023 10:08:42:.---2---..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : ***************************************..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : ***************************************..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : ******** Starting new session ********..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : Starting NGL..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : Setting synchronous launch...06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 ::::: Configuring as AcrobatReader1..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : NGLAppVersion 23.6.20320.6..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : NGLAppMode NGL_INIT..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : AcroCEFPath, NGLCEFWorkflowModulePath - C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1 C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow..06-10-2023 10:08:42:.AcroNGL Integ ADC-4240758 : isNGLExternalBrowserDisabled - No..06-10-2023 10:08:42:.Closing File..06-10-
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 299538
                              Category:dropped
                              Size (bytes):758601
                              Entropy (8bit):7.98639316555857
                              Encrypted:false
                              SSDEEP:
                              MD5:59EE5E2FB56A099CAA8EDFD7AF821ED6
                              SHA1:F5DC4F876768D57B69EC894ADE0A66E813BFED92
                              SHA-256:E100AAAA4FB2B3D78E3B6475C3B48BE189C5A39F73CFC2D22423F2CE928D3E75
                              SHA-512:77A45C89F6019F92576D88AE67B59F9D6D36BA6FDC020419DAB55DBD8492BA97B3DAC18278EB0210F90758B3D643EA8DCF8EC2BD1481930A59B8BB515E7440FE
                              Malicious:false
                              Reputation:unknown
                              Preview:...........].s..R/c..D@..\......3Z.....E.,...d{.k.~..H3....-......A...<>n.......X..Dp..d......f.{...9&F..........R.UW-..^..zC.kjOUUMm...nW...Z.7.J.R.....=*.R........4..(WCMQ..u]]R...R......5.*..N)].....!.-.d]M....7.......i..rmP...6A.Z .=..~..$C-..}..Mo.T......:._'.S....r.9....6.....r....#...<U@.Iiu..X].T x.j....x...:q.....j]P3......[.5]|..7;.5....^..7(.E..@..s...2..}..j....*...t.5J...6Rf..%P{2T^$Y.V.O9.W...4...\ .5............Q.&j....h.+.u......W...4f]..s..(...:....`.<W_...z*Bs|tF5 NI4.zD..5...u...!........M.0.K%F....,.c.....>R6..i..Am.y.~5..S....M...^......F.&..V...Z.......i....b....V..,.UH"...W...5}A.....KUT..=6jZ.....B...Z...Y(..u...=....x,2..."._Cf.....b...z7..... r..#.r..L9....2...R,..J?&..p..~.....3.=z...w..m..U..%._#<....r.....B.z..G..D.:4m.Z.&.N......</..Dz+.......vn.....;Qhk....!dw...A......3..a..K...).Q.`t[..)].6.%@....v.g.%E>;Z...uz.L..6Ct..O.Eo.O.e..........J.J$...:....K..)......F.....ZWE...z..5..g.io...l2[.,m9X..f......5|:bj[.._R{gi...^
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1311022
                              Category:dropped
                              Size (bytes):386528
                              Entropy (8bit):7.9736851559892425
                              Encrypted:false
                              SSDEEP:
                              MD5:5C48B0AD2FEF800949466AE872E1F1E2
                              SHA1:337D617AE142815EDDACB48484628C1F16692A2F
                              SHA-256:F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE
                              SHA-512:44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324
                              Malicious:false
                              Reputation:unknown
                              Preview:...........]s[G. Z...{....;...J$%K&..%.[..k...S....$,.`. )Z..m........a.......o..7.VfV...S..HY}Ba.<.NUVVV~W.].;qG4..b,N..#1.=1.#1..o.Fb.........IC.....Z...g_~.OO.l..g.uO...bY.,[..o.s.D<..W....w....?$4..+..%.[.?..h.w<.T.9.vM.!..h0......}..H..$[...lq,....>..K.)=..s.{.g.O...S9".....Q...#...+..)>=.....|6......<4W.'.U.j$....+..=9...l.....S..<.\.k.'....{.1<.?..<..uk.v;.7n.!...g....."P..4.U........c.KC..w._G..u..g./.g....{'^.-|..h#.g.\.PO.|...]x..Kf4..s..............+.Y.....@.K....zI..X......6e?[..u.g"{..h.vKbM<.?i6{%.q)i...v..<P8P3.......CW.fwd...{:@h...;........5..@.C.j.....a.. U.5...].$.L..wW....z...v.......".M.?c.......o..}.a.9..A..%V..o.d....'..|m.WC.....|.....e.[W.p.8...rm....^..x'......5!...|......z..#......X_..Gl..c..R..`...*.s-1f..]x......f...g...k........g....... ).3.B..{"4...!r....v+As...Zn.]K{.8[..M.r.Y..........+%...]...J}f]~}_..K....;.Z.[..V.&..g...>...{F..{I..@~.^.|P..G.R>....U..../HY...(.z.<.~.9OW.Sxo.Y
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 33081
                              Category:dropped
                              Size (bytes):1407294
                              Entropy (8bit):7.97605879016224
                              Encrypted:false
                              SSDEEP:
                              MD5:1D64D25345DD73F100517644279994E6
                              SHA1:DE807F82098D469302955DCBE1A963CD6E887737
                              SHA-256:0A05C4CE0C4D8527D79A3C9CEE2A8B73475F53E18544622E4656C598BC814DFC
                              SHA-512:C0A37437F84B4895A7566E278046CFD50558AD84120CA0BD2EAD2259CA7A30BD67F0BDC4C043D73257773C607259A64B6F6AE4987C8B43BB47241F3C78EB9416
                              Malicious:false
                              Reputation:unknown
                              Preview:...........[.s.8..}.....!#..gw.n.`uNl.f6.3....d%EK.D["...#.......!)...r.$.G.......Z..u.._>.~....^e..<..u..........._D.r.Z..M.:...$.I..N.....\`.B.wj...:...E|.P..$ni.{.....T.^~<m-..J....RQk..*..f.....q.......V.rC.M.b.DiL\.....wq.*...$&j....O.........~.U.+..So.]..n..#OJ..p./..-......<...5..WB.O....i....<./T.P.L.;.....h.ik..D*T...<...j..o..fz~..~."...w&.fB...4..@[.g.......Y.>/M.".....-..N.{.2.....\....h..ER..._..(.-..o97..[.t:..>..W*..0.....u...?.%...1u..fg..`.Z.....m ~.GKG.q{.vU.nr..W.%.W..#z..l.T......1.....}.6......D.O...:....PX.......*..R.....j.WD).M..9.Fw...W.-a..z.l\..u*.^....*L..^.`.T...l.^.B.DMc.d....i...o.|M.uF|.nQ.L.E,.b!..NG.....<...J......g.o....;&5..'a.M...l..1.V.iB2.T._I....".+.W.yA ._.......<.O......O$."C....n!H.L`..q.....5..~./.._t.......A....S..3........Q[..+..e..P;...O...x~<B........'.)...n.$e.m.:...m.....&..Y.".H.s....5.9..A5)....s&.k0,.g4.V.K.,*.e....5...X.}6.P....y\.s|..Si..BB..y...~.....D^g...*7'T-.5*.!K.$\...2.
                              Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                              File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 5111142
                              Category:dropped
                              Size (bytes):1419751
                              Entropy (8bit):7.976496077007677
                              Encrypted:false
                              SSDEEP:
                              MD5:BE0B75D7B096B44CBB2A7F9140209151
                              SHA1:FCE18CAA51DF1C9E5FA036FF1D1267212A48AAC2
                              SHA-256:A571984DB01CF39DA8A828152CDEC864004CB56158C4BF6DFC2888A32A54B0E9
                              SHA-512:7090CCAE1C6724F611C54A96D28016FB17E64FA8C9E71EB0A0C8E9034750565068FA279BD2F8FB02A17DC3FC89763D531EEFF4777836E9FDF018ED6BE184E5F3
                              Malicious:false
                              Reputation:unknown
                              Preview:...........}.s.H....W`E.........M9h...q..p......%..!q.p....~..2......DlWtW!)?_.|....?..?.s.w1.i..G...h6.]..y...p..m.b..N..rr..F..Xc...l.4.."..Q.... hL.p......s...x6..:.....x.~.6.Q..~......~b7..k.l......Yc.G[....hY3...C..n..|.'6......i4f...,.."...O.b...x..,..jgc..bTn....,u.F..0......V.K,u..p....X.wAap...+.G..v....i.z...E.Rj8.a.r..<@.q.'...!.4..]...|..3...-.2...`...4..i...w......$0D.....i./a......Z.]..e.mj..c}.?.....o......c...W..+....c...W...?8...n.......U..7..O........@....'...^.z..=.m....o.o<..~....... ...C{......w.m.h.-Q...6.(..uk/w!...Z..n.....p.U........T^w..[....1l...../i......0..1U|}../xS}.q..B|.......h>....S....g...A.s6.=.&....~.\.......-N.p...._.xex.....}.r..q$..<.S;l=. ..P..55;....[.}.T......d.p..vd'vl.].DN..o...................D...].......I}.t...D`?..n.A.zT..:@.`S5.K..,R....h...XzT....F..Xt...R...+N.....ee...P...F+C.....dq...r..5..aP.zY....c.f/..Pn...:f.>.Z..s.+.......7...O.C.#..6.....=.K.5{.%6,..Z.....DqZ.4....g-%.p..n...\
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jan 14 13:37:55 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                              Category:dropped
                              Size (bytes):2673
                              Entropy (8bit):3.9796931204021773
                              Encrypted:false
                              SSDEEP:
                              MD5:3C41A4FF18242941D0FA15703724C5BE
                              SHA1:E5E73528577B1A69B0E6DF70018704B23EE60DE0
                              SHA-256:5AEDC85B60E7943462D7DE1907EC3ACCB6672F3C93AEF906A019930D7F182B0E
                              SHA-512:2696CDF61A452FF14F31A63B556A27FEB5F80058DB356B617CF0E055407743C9A0ED98970B191DE080C7AE9B593A1A63CDFB5CC32669E28F636366B151E7C1B8
                              Malicious:false
                              Reputation:unknown
                              Preview:L..................F.@.. ...$+.,.....5).f..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Z.t....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Z.t....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Z.t....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Z.t..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Z.t...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........RV-......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jan 14 13:37:55 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                              Category:dropped
                              Size (bytes):2675
                              Entropy (8bit):3.996103440733677
                              Encrypted:false
                              SSDEEP:
                              MD5:E020CDD7498849CED1B94ACDD3C2E507
                              SHA1:ED0CEA66F00D3C0280BF9B65ACBF0EDF898B5F15
                              SHA-256:4DE5E76802D17CC26A102914F95ACA536025FD66220B85E392D838A2C4AFB8A7
                              SHA-512:D639863AC61F6BC5297A5DF642867ADC4FEDA5CE90E6C4826B850A106F54A4188736F983DADDA6B62B678A910014B0BE7FEFA4914B3F72BB1909024524DFA01C
                              Malicious:false
                              Reputation:unknown
                              Preview:L..................F.@.. ...$+.,....P...f..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Z.t....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Z.t....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Z.t....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Z.t..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Z.t...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........RV-......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                              Category:dropped
                              Size (bytes):2689
                              Entropy (8bit):4.005870319348876
                              Encrypted:false
                              SSDEEP:
                              MD5:51A36150AF6BFD8253E6578FE0E467CD
                              SHA1:69E338AAC5D5696DE7E19AF4F8641C5E1724E5EA
                              SHA-256:DE15F3A260507E7DD076EB8BFC1126D60E617C3337906DC49857D0B9C4FA9D98
                              SHA-512:6039CA7B42BA2F835E1BB68871C28FECCFEB29783EF25AA01B4FCB2688E9050E876828A476BA1FC749744BDE910E97A8278F776D2F9D84D4310B1CD5C05BBC02
                              Malicious:false
                              Reputation:unknown
                              Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Z.t....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Z.t....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Z.t....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Z.t..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........RV-......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jan 14 13:37:55 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                              Category:dropped
                              Size (bytes):2677
                              Entropy (8bit):3.9942672723846604
                              Encrypted:false
                              SSDEEP:
                              MD5:65E9525B0644A691250EBA1127AFEF28
                              SHA1:9FBEB9F6C08B515EB0FCB15E9558368397852B19
                              SHA-256:CA011E88B029543859342889A9BEDCE378E318845B40049802552EC07185504D
                              SHA-512:D881E6C0224683C4FEA1C2E0C8293FDA70DD5EF192128F5FE9463CE3FADD375610E2BBDB5550E7268A87E7F25F4457B6D98A834D9BA790F49D53B34C70CBF71A
                              Malicious:false
                              Reputation:unknown
                              Preview:L..................F.@.. ...$+.,........f..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Z.t....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Z.t....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Z.t....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Z.t..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Z.t...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........RV-......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jan 14 13:37:55 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                              Category:dropped
                              Size (bytes):2677
                              Entropy (8bit):3.98588685600956
                              Encrypted:false
                              SSDEEP:
                              MD5:EB2F617E1922A0ED7ABF7E2EA4FDB9D2
                              SHA1:5716463E947071F819768F97BB7C5F68E98D50C0
                              SHA-256:5D55D2C18085955AA17222CDABF5F0EF75B03997EC0AADB1BE00AB18EA16B6F9
                              SHA-512:A80F3AAE13A0B7021A889F141A553202D591CD377505CE3305BC10932B84EDEDD1A4D15D2D16E890D5E41862788D04905086D969232E4216A5820E1942504B8A
                              Malicious:false
                              Reputation:unknown
                              Preview:L..................F.@.. ...$+.,....[.".f..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Z.t....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Z.t....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Z.t....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Z.t..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Z.t...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........RV-......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jan 14 13:37:55 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                              Category:dropped
                              Size (bytes):2679
                              Entropy (8bit):3.994402922013063
                              Encrypted:false
                              SSDEEP:
                              MD5:3B2E75CEA427D2EF2BF192B8ADD234F2
                              SHA1:FF732F46390C2C093D385F2677890AD40E2FA572
                              SHA-256:AA5DA6AC721D8C5FF8963E4AD09C174D80704A444A5D31905FB785F166B138B1
                              SHA-512:2767957CB637A9FA7552531B1288116E97BCC223E23928D0927A8D444F5D1A12FC267A36823CCD5B6D574C9E00D717E052E97A4802CB7A00D0D42BAC14D1A0C0
                              Malicious:false
                              Reputation:unknown
                              Preview:L..................F.@.. ...$+.,.....%..f..N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.Z.t....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.Z.t....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.Z.t....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.Z.t..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.Z.t...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........RV-......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                              Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                              File Type:Microsoft Outlook email folder (>=2003)
                              Category:dropped
                              Size (bytes):2302976
                              Entropy (8bit):1.6778741447261982
                              Encrypted:false
                              SSDEEP:
                              MD5:3F6508787099EB1149CADBF5F68EC8BF
                              SHA1:82941A24A35C61307CC9EBCCC7EA6DB8A4A0EC29
                              SHA-256:8AD6382D8E3FF9392CF6EA1E1894C2C4E9E9403FC304E4797B7A5254AF6AE6A9
                              SHA-512:B7F9B95DCE2B89C3A8B307586617DE22B82CB33632C83A0F8957C902E8CA4C16A31AA80A7B82EAE9934526FFB96139E6CD2027562F382996FD3DCC942E0F7180
                              Malicious:true
                              Reputation:unknown
                              Preview:!BDND.X.SM......\...I...................c................@...........@...@...................................@...........................................................................$#......D.......v...................................................................................................................................................................................................................................................................................................................................8w........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
                              File Type:data
                              Category:dropped
                              Size (bytes):393216
                              Entropy (8bit):6.472615504848319
                              Encrypted:false
                              SSDEEP:
                              MD5:DF6D6BC0A32330940AFD2DF528D85C0C
                              SHA1:B375A3E2BB10190C6F13866F3B64796C2C1EE9CA
                              SHA-256:08B8FEE293221D8E7F7D2DBC706779A029CF3BEE73EEA868A98016BCB4784798
                              SHA-512:99925F8ED3E53B7F872F0DA434165F66A82E96E73038413E028141D998BED619931C082CAAA1158FCCE2C71DAE622FF9EE877F151301550625D540C563B5E959
                              Malicious:true
                              Reputation:unknown
                              Preview:JHAa0....................f.......$............#.....?...........................................................~.......................................................................................................................................................................................................................................................................................................................................................................................................................................................$......O..$0....................f.......B............#........................................*................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:Unicode text, UTF-8 text, with very long lines (14620)
                              Category:dropped
                              Size (bytes):427449
                              Entropy (8bit):5.644803133009802
                              Encrypted:false
                              SSDEEP:
                              MD5:DA659EDA8F6B1531BCC671866590ABC0
                              SHA1:3B8BC42FEB5D3BAA3EC559836062A32CD111965E
                              SHA-256:3A287A39E31BA11C693C68E06D4986B6B5A2C5ABB0D8C0B750504FBACEA42E35
                              SHA-512:E84C10352AC67038A63D2A69C87D1345CBDC26646F4D032CF2495A4508C0D48AA9A04D300E103249CC344C57F8E72B54D41A37060A33F6D1B5ECB1452FE1E01B
                              Malicious:false
                              Reputation:unknown
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"2",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_ga_send","priority":16,"vtp_value":true,"tag_id":107},{"function":"__ogt_referral_exclusion","priority":16,"vtp_includeConditions":["list","heliforklift\\.ca"],"tag_id":109},{"function":"__ogt_session_timeout","priority":16,"vtp_sessionMinutes":30,"vtp_sessionHours":0,"tag_id":110},{"function":"__ogt_1p_data_v2","priority":16,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CS
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 25670
                              Category:dropped
                              Size (bytes):7579
                              Entropy (8bit):7.974047556858248
                              Encrypted:false
                              SSDEEP:
                              MD5:D1D6D600F1B68D5A905DF6706ED9CAD1
                              SHA1:7726A606E293CB7395D992CF92733A2852555671
                              SHA-256:5D84610F9E3685DB0505DADC0F9741462E8EA4F5FFF24CAAB307A4B9A262EA6A
                              SHA-512:24BF3C522CF9068381F8CEB42F5E3CEC74F708B585D4D3C92F67C6C5FE0503D9E4DF20F30101B2245C8A513D112E8CC91C5D089B056E52FA021F386DCB1C36AF
                              Malicious:false
                              Reputation:unknown
                              Preview:...........\{s.Hr..?......%/.+...\e..].]..+.H.". ..@.:.?G>P.X~.=3..([.&......._..3....C/...4SY'.v.U.._v.[...I......o.S.....j.ziz.Z..,.uVq.%q..#U\..T.JA.?P.^.u..Uk......U..`.R....L...:...s3. ...o.3..;7..~...u...zK?.m..T-........ni.gW.....aV...h......g....$..M..,.......O..my../?].x.T..61D.....<.3?)..<dY.../.H..g..;/..Y'.:.0X..j-0...%..w..g.FU..!..hW^...V...G..~....9?V..%.S0..@[A....b..{].K......P8K.3.E.m.....L.'..y......Z..%~.Y.P_.......!...}/.T...W..4`...C.obH.U..&"+.E..{..........6.......?.Z.I..i..u...f$.3}O|...N..]C.O....]g?.l..]p5...T1g.8zA$.......K.^..9..xI....C.+/Z.4C.]z.D...Om.....,B..0..u.+.... ../../t]<.....ei8..l..(1.....l.+...^y.|..tAF.o.^.n..?..U..............z.....K..(..X/...p...%...O....~.E..;/.@..Z.P....]....B..GY.R.8.H_].N.1...G...m|.:'s....;k.E.6&I...O...}7...'F.A..........z-.....=..1:../.....`.....?Y.Y'_..%....a../dq...Y-=..cH. .j{..-1`. .......y....ZE.....c..N.....R'...YId,).e'EYf).....p.A....HO.....r..$..@..'(...
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 2156793
                              Category:dropped
                              Size (bytes):851077
                              Entropy (8bit):7.99948611448095
                              Encrypted:true
                              SSDEEP:
                              MD5:550A9C8C178B90F8B800F2D1B974686E
                              SHA1:392707C5271AF5B71AD362B2DAC842F97B8B5954
                              SHA-256:85B96E7D2EC0082B4CCE974758AC1A7FCDAD3FA192B9647C99E5DFB041004146
                              SHA-512:57F474507BB51ECEA0F79E34460E14DA4B9A1DB21921D2B3DCCE704598DD70674FA3780E11ED910F1605883A1EBBECEC0B821EC9CABBA8471A29E301B7680662
                              Malicious:false
                              Reputation:unknown
                              Preview:...........iw.G...]..R.. . )..*R..JKY]...V.@.../IH ..@S2!....o..~.}_.g.....s...%...E..;=S.............yc....Eq.>.v....~.p.|.-...H~6_MV..qoPtWz..C...+.Tmv&.b:98........Oo++..oT...G..pP.].......ikz.l.k4.~...'..Z,.<....q..7..t.....O....W.....4.y..4...r.$......bM~7&..Q..JBc:|>...'-o..)....... F.x.6.......c.d".......y...N..]y........j...r.....*G.%4{0..[...I.AL....].....!.......Am\L....o#.f....."..b..j.,.<..wF...b.w..1....h8.Nn.Z....MEZ..g..y...WW5.i.k..................T.....=....g_.*...7.T....w...xp..B.5...i.f..O....SA..[...^we.i.........Z..y....'...:.bes.h....N...]&..N._u.4....w..o.....CP....l.,.V..$.....4..;W.[.|.......y...lH..s..........-M.$)M.g.m /.....L'5V..8J.Aq......,.g.f..X..[r>.&.M.h............$(U?h.u.m.......o".<..6...cH.".x.0.G.%d..0M...."Ze...w2(..B1.6..~6..p..SL\.P...LO[..MM`....;..J..H9...c.#.hks[....L.....|.9..hK....m9.U-Uk.%.....6.{w..=..zR...'.7....m..".8k.6$.....e....!.L...a8u...t...L."..O]...5D.8..i.Xo..C\.[!G.z\L.....;..S.9.iQ
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:Unicode text, UTF-8 text, with very long lines (14620)
                              Category:dropped
                              Size (bytes):427440
                              Entropy (8bit):5.644779443085709
                              Encrypted:false
                              SSDEEP:
                              MD5:2F820BF5BA8F3F5C96B5CE8CD1690535
                              SHA1:8185FF0B4274E9AC5397406DA2C9FC620CE55CAC
                              SHA-256:999CC6152868086841BA4A5EC3E17701987A40CA44EFB3B7E14E209601803ED9
                              SHA-512:088753A3B0FCA60F6213A508989D1F0094CC6B84500504C2BC4993D5D2AD3211E4383EE3A193D648A1F0CD65512BB57B21B41DCAE5A469CB0F3A913CCAD479AD
                              Malicious:false
                              Reputation:unknown
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"2",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_ga_send","priority":16,"vtp_value":true,"tag_id":107},{"function":"__ogt_referral_exclusion","priority":16,"vtp_includeConditions":["list","heliforklift\\.ca"],"tag_id":109},{"function":"__ogt_session_timeout","priority":16,"vtp_sessionMinutes":30,"vtp_sessionHours":0,"tag_id":110},{"function":"__ogt_1p_data_v2","priority":16,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CS
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 1016068
                              Category:downloaded
                              Size (bytes):306891
                              Entropy (8bit):7.998389586941649
                              Encrypted:true
                              SSDEEP:
                              MD5:B62060AE2B544609E55034DC634690E1
                              SHA1:9BB25FD350EA3E34703B747AF6870B90AC74723F
                              SHA-256:C740BD9DEB9BCD0ADF90C726498EBF933A552C575B976BAC3F1961891038DB8E
                              SHA-512:1F05C78ED2636951DE921C0FA44EB1F18FE7AD6CD8B907A55A307129ACE1C590F792C37DE50B836A2465AA9E87F7B47FDEC20CA8637119C48CBD209A41E16A2E
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/web/assets/1278119-68fc4ee/1/web.assets_frontend_lazy.min.js
                              Preview:............r.I........Z`..I..F.`..I.iW..!g..@\..4E.@4....!..F8..G......../.~.}....n..v..gcGD.GVVVVVVVV.....}L...l4X.........{^....I:..&.w..p......~.....t.Mf.dx2..v...Wk...?.1.n.t>..F..~....y..y....t4..i.k'..iv.Ng.4o.....,.@.j.f....u.wF.pbk.N...vF++.+....`:..e....w|Z+....i..8.V.^_...y.V.d.....T.M....Q..?..u..i......[.......f..{.....2....?x...i..>........M".,{C.Jd..w..X..f.......]^...&.3...D...4...Z..N...,...WY...|..{..s.;.l^Y.G..T.:....E.;.j-...k........y.0......2...i#k^..I...APpW...v.p...W....N..PPx..h\.......jd..:.'Vw.3A.m.P^..hv/..,.+n.+E...!k~M.HO...W..D....n...#".~}}O...6.z2}........^*..`.>]R+....<.^^=....e.._...A.<....I.81...M.i.b.7..lp.H.....7.m..O..,.D...$...b2b...wK..I!..".i.W.j..l......~.b........F..k.P.7...{.H.w..P.Zo...S.?...I.1..`!$.-r...b..q4....?({..)...B....+S%......*K+..J.....DE.7a....az\o..vW7..>N..2..I.4tX.~'...,.*{../"..%:!...i.sR....Z...?.$`..0..;Y......N.."...X0o.fg..c.0<.$~>.b.s.kP..i.C.....Y-.....5j....j.u...$
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:PNG image data, 180 x 79, 8-bit colormap, non-interlaced
                              Category:downloaded
                              Size (bytes):4798
                              Entropy (8bit):7.764392139121034
                              Encrypted:false
                              SSDEEP:
                              MD5:0DCA18187C9C002522A6DE8BB166C121
                              SHA1:6E0543EFE50AC2BC0062B2AA14225E0F2C3A2AB0
                              SHA-256:786ECC496082CBA365686DC8E445A38DD78EAB818C15DA50E8A17EA99C83679A
                              SHA-512:13482E95AC7D99A0C11BBAE54A9B4BE90443E4F644247C1014A2712167D48756C1F4B49BD6E0488685E5191B63D11F1DC877558C77EE43A1E8D78669CBD3BD59
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/web/static/img/logo.png
                              Preview:.PNG........IHDR.......O.....uF......gAMA......a.....sRGB.........PLTE..........I...........{........I....UUW.U.....I.....I..............UU.......J................................I.....I.....................................................I.....I..I..............I.....I..I..........................I........I..@..H......................................I..K..I..I.................H.....I.....I........J.............................H...........I...........I........I..I......................................H.................H..I.....I..I..J..I..J..H.....H..G.....r..I.....I..I..I........H..H.....I.....I..H.....D..I.................G..I.....H..I..I..H..I..H..I.....H..I..I..I..J.....H..f..I..I..I..J..J..J..I..J..J...........I..D.....I..........................K..J..L..L........I..J..L..K..M..M..M.....N..J..K..M...........................P?....tRNS....................5......11..I...\...e..Sja..EC..............v.....%.,..h......w..*..x.@...s..qL.'.....m.>P.N.}6...*g8.....P.;]....Y...z=3.A7^).
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (4665), with no line terminators
                              Category:dropped
                              Size (bytes):4665
                              Entropy (8bit):5.827669931000862
                              Encrypted:false
                              SSDEEP:
                              MD5:B4CBF28FE57D0FB0E62F9349155608B2
                              SHA1:26F2E4523A634EC6B0F5CD5EFCD3E16755467A43
                              SHA-256:AC10A4ED8E6F91E812943101D9EC029B3A3333BA9570C01E59EE6EB349206361
                              SHA-512:60D791CA6434A8A42F9C032B6D828A159597AC9B772507596202E215986E18C94E50E5820A8F60A2FEB790417EF7057655BC355DD80FCA62707D897A83E52B40
                              Malicious:false
                              Reputation:unknown
                              Preview:(function(){var s = {};(function(){var h=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};function k(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");} var m=k(this),n=typeof Symbol==="function"&&typeof Symbol("x")==="symbol",q={},t={};function u(a,b,c){if(!c||a!=null){c=t[b];if(c==null)return a[b];c=a[c];return c!==void 0?c:a[b]}} function v(a,b,c){if(b)a:{var d=a.split(".");a=d.length===1;var e=d[0],g;!a&&e in q?g=q:g=m;for(e=0;e<d.length-1;e++){var f=d[e];if(!(f in g))break a;g=g[f]}d=d[d.length-1];c=n&&c==="es6"?g[d]:null;b=b(c);b!=null&&(a?h(q,d,{configurable:!0,writable:!0,value:b}):b!==c&&(t[d]===void 0&&(a=Math.random()*1E9>>>0,t[d]=n?m.Symbol(d):"$jscp$"+a+"$"+d),h(g,t[d],{co
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:MS Windows icon resource - 7 icons, 16x16 with PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
                              Category:downloaded
                              Size (bytes):17635
                              Entropy (8bit):7.9459992917167455
                              Encrypted:false
                              SSDEEP:
                              MD5:43064A5957CC2C9795A539954A8372FA
                              SHA1:97819DC8E7C4308AA282A11C9CC8FCD3F20C7F38
                              SHA-256:3B7F55439345FEAF20AE1ECF4A9BD618D4DBE252534993225A61D6C67685CA12
                              SHA-512:F4DBAF3D2ED9CBC2BC9A6A014E4D80DF5AECD474DE7B957A773531845D5631A0D7FA4600484EC3AE522EB1E9C24FBAB05BB7786267E3FAAD879103F17C8AF6B1
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/web/image/website/1/favicon?unique=6b367a2
                              Preview:............ .....v......... .....(... .... .........00.... .........@@.... ............... .....c......... .....5&...PNG........IHDR................a...yIDATx...N.Q...s..w!.$.l..&.m.d.^....f1....-.1.....Kx....B.@L ~ .,.3...qc.&&.....s..EC...?...U..j..(.........................=..O9.p;.'...WFE..Hk.uv. .\.M......P..a..........mlV.W]]...8..`..k.........\.|'.....]..A?..,,....V9.[.P&....'.OA.f..;L&.v..d7C..N|.w.{.N.g.x08...OC.zeL.}s..l.BV{|.(....^.t..'...F.;i,...].A...s.....[@p*..j..v......y........6..........C..K....IEND.B`..PNG........IHDR..............w=.....IDATx...KTQ..?..7..(C..4p..#...1..lUSD....-..+Z...N.j."s.m...ZX..8..21....bf...........s..v.i..0L......9.@....=.......O^l :_$..d...H=.Z4^....J.~.._..s=c.....u...........b..q.@.&Q...T.~s...(`N...+B........\o...c.,~..w.o'.%.}.}..-..F*Z...0p..a....Wt.C...TZ.D.o.M....T..5..'.Eu....?....%B&.|.@3.l........1F...n...&......&&+..1p..g...0&A..!t...=........B......0.P.K.9a.,..f^.?..|56e.d$.Ed..7...Y..V.
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
                              Category:downloaded
                              Size (bytes):48236
                              Entropy (8bit):7.994912604882335
                              Encrypted:true
                              SSDEEP:
                              MD5:015C126A3520C9A8F6A27979D0266E96
                              SHA1:2ACF956561D44434A6D84204670CF849D3215D5F
                              SHA-256:3C4D6A1421C7DDB7E404521FE8C4CD5BE5AF446D7689CD880BE26612EAAD3CFA
                              SHA-512:02A20F2788BB1C3B2C7D3142C664CDEC306B6BA5366E57E33C008EDB3EB78638B98DC03CDF932A9DC440DED7827956F99117E7A3A4D55ACADD29B006032D9C5C
                              Malicious:false
                              Reputation:unknown
                              URL:https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTS-muw.woff2
                              Preview:wOF2.......l......D...............................O..B..h?HVAR.x.`?STAT.$'...0+...|.../V........+..2.0..6.6.$..`. ..~......[B4q.....t..P.M_.z...1..R.S*...u.#..R....fR.1.N.v.N.P...;.2........!Z......Qs...5f.G.K.an2&....2...*......C.H.t..N!.....nh.<(.vN.....j.._.L.P.t..Ai.%.............._I.i,..o,C.].H.X9.....a.=N....k.....n.L..k.f.u..{...:.}^\[..~5...Z`...........`!...%4..,...K0..&.a/....P....S....m.Z......u...D.j.F...f.0`I.`.`.h#..)(FQ.F!o$........S.).MV8%Rh...r...x...T]$.=......Y...!.3.&U..."....Q....{.l/0..d..4iJ/..}...3....i[Z..NG.WD...>.[U..Q.h..@m.=..S...1C2...d...<..v.?.q.f..n...OUz.....&Z......Z."..N.....n...9.B..C..W....}...W..6Zs.i.+Z........jB.n..x.8M.....q..@I....-.%..,C,..K..#.2...4)/.v_..x.<....t.....%[.4?.=j.V..jj''..W.u..q....I.L.=......E...\.M.7{.>......W........C.`...,9$......\..o........y...4A..m.P.,X..=?.:................wF`..+.P..........M!.4.......l.>M..t.ff5r..^..Z.g...!fA,hIIQ...e.R>B.AH.VuX..>..\.=.ky...1>C....>C.c.;...6D.
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (17021)
                              Category:dropped
                              Size (bytes):408845
                              Entropy (8bit):5.650371905757697
                              Encrypted:false
                              SSDEEP:
                              MD5:6AF196E08C718B63F45AB75DA465C3BA
                              SHA1:0E0F278AE7E984ABFDA478DAB8A5826B18EF2B38
                              SHA-256:554DC5A55220C75AEADEEA15FE1F136A291A4A1B565EC642DB9DA76524267921
                              SHA-512:1245E435482BE23585E7CB2EEEFF1B08755AC19520377EA581847050124160D107BC1A06F5844F440AFB066DF0142561401238DA46EDCAC25E3A40536AD4D35E
                              Malicious:false
                              Reputation:unknown
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_1p_data_v2","priority":14,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":false,"vtp_postalCodeType":"CSS_SELECTOR","vtp_emailValue":"","vtp_firstNameValue":"","vtp_streetValue":"","vtp_lastNameType":"CSS_SELECTOR","vtp_autoAddressEnabled":false,"vtp_regionValue":"","vtp_countryValue":"",
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:Unicode text, UTF-8 text, with very long lines (14620)
                              Category:downloaded
                              Size (bytes):427466
                              Entropy (8bit):5.644905775568932
                              Encrypted:false
                              SSDEEP:
                              MD5:D6AD724041CCF19B6D4B881A816DCC79
                              SHA1:F5FCF44152C76D77AD1EC64B5CF16F7AB51FA206
                              SHA-256:DA0718D9ECD266B06F150E6DF2DC0A059C26D31993F76EF208E55CCD4F6EFBDA
                              SHA-512:25B3CDA48AF609DA332A6A8FCFCBF1D9858D1215A492B969B106D8B9B11AA63135F9D329E6DBBA02A5D87CE9FE70D06DDF6BF0EB02D0F67E1598FA895B7D78F1
                              Malicious:false
                              Reputation:unknown
                              URL:https://www.googletagmanager.com/gtag/js?id=G-Q7QQB9B00Q&l=dataLayer&cx=c&gtm=45be51d0v9105953142za200
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"2",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_ga_send","priority":16,"vtp_value":true,"tag_id":107},{"function":"__ogt_referral_exclusion","priority":16,"vtp_includeConditions":["list","heliforklift\\.ca"],"tag_id":109},{"function":"__ogt_session_timeout","priority":16,"vtp_sessionMinutes":30,"vtp_sessionHours":0,"tag_id":110},{"function":"__ogt_1p_data_v2","priority":16,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CS
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:Unicode text, UTF-8 text, with very long lines (14620)
                              Category:dropped
                              Size (bytes):427466
                              Entropy (8bit):5.6448839239094495
                              Encrypted:false
                              SSDEEP:
                              MD5:ABE287842BD0FF1A33E39B35B406D4DB
                              SHA1:0599722C48B3BE8D5034FF4DF11ECFC5D39B0E7A
                              SHA-256:55F690713B3F74BC8D19795E4F8FC270FBEF438807F93C071CDB72D06DDBABB4
                              SHA-512:8B952EBED3F75BB97A9C9284FB9873CEE22332576A05E03F11F7D44F37190C862DAD19937A0ED7AC4830D90CBD8D9684D86A5DC9F93410ED4A72504C0C7668CC
                              Malicious:false
                              Reputation:unknown
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"2",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_ga_send","priority":16,"vtp_value":true,"tag_id":107},{"function":"__ogt_referral_exclusion","priority":16,"vtp_includeConditions":["list","heliforklift\\.ca"],"tag_id":109},{"function":"__ogt_session_timeout","priority":16,"vtp_sessionMinutes":30,"vtp_sessionHours":0,"tag_id":110},{"function":"__ogt_1p_data_v2","priority":16,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CS
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:PNG image data, 207 x 50, 8-bit/color RGBA, non-interlaced
                              Category:dropped
                              Size (bytes):5119
                              Entropy (8bit):7.9355710305729765
                              Encrypted:false
                              SSDEEP:
                              MD5:30DC7ABAF799EE72C7877E3FFAFEDB1F
                              SHA1:FB6999F776300DCE95105330A54D0427B57301BC
                              SHA-256:287B8D845CC68250AAE39929582858A6E70CB253158208078394269CB70A39CB
                              SHA-512:B2387A6222353FB65A968E3CDB14FB12C9AFECB792C4334CCFFFC2254F55DA7E0AEEB0A7D66BC306D17BD39B9E4273E06EF0E834CD14C10509A3D854E06EDA08
                              Malicious:false
                              Reputation:unknown
                              Preview:.PNG........IHDR.......2.............sRGB.........IDATx^...mGY..W..J.M.%A..JD,.I..R.........$..B(&t........4..4.].@h.P@A!4c. ..e..f.u..g....?..9.V..g..=_..o...E.s#..............?..lI'^.s.)e.........B....#.u.9.N........NZ.f..v..I....&.x.#"....Y....k$.o{..y.@<.....oV..'..I......).m?$".0...wq..n..........E;".(....ZoC<.v.=..o....'.qI.~.=..o.........M|'".V....t....6.!.5..N...m"....\.{w..c....S.M....8....E.^I..h7].n....'.._.p7.F...1"..h.t.OJ.....9..D.>.....S..{.Y%B-..$..[.m.........l....#b..~W..l.&".S.{...m..*..<I.7....._..^....;..siLC..r..rD.v......1f...98"~..SE..pZ8..G...}8.%......@...a/.<y.G.....@W...}'.....V.+.dIO..`D_...`I/.2.|_..E.k*..P..!..ft..^...#...q....|.u..?.Kq........9......3.t.|.....O..=......q.V..~[&...t...GD.......\0.?N...h...UI..0.7x...m............|D.~.......F....G..#..[..z3b.-.<N........K.c.%c<L.IYeC.....'..4.....x`.s".......q.B..I................}#..P..'"^.............2.5l9..p.7E...5`a... ..#.I.....i.>Q...o..._..v..
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 38602
                              Category:downloaded
                              Size (bytes):9670
                              Entropy (8bit):7.982334172849447
                              Encrypted:false
                              SSDEEP:
                              MD5:554B3FC761E34FBCDAAD750DDEAED338
                              SHA1:49074BF06A16AEC0EFE2D2896573DBC0D1439816
                              SHA-256:F2FBC237EB359CFFA15C7EF1131D3DB0F39316A09CE9D4B1747BAF2403B8EC36
                              SHA-512:C1A19BB4A2AC3BBEFD048322D8EED8D0FF10A2B664F9F03BCD3908B8B585E28CD61E36028BC2EEDEE7BA61C41AFA98B36A8D1CAA727DD04496485EF31FD3DB91
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/en_CA/my/task/166767/worksheet?access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6
                              Preview:...........}.v....<E5}&.V.^%..Iul....om...d8 ...A..@.l...3Op.y.....79Or....(\HQ..t...l.@]vU..........?.z,f..?..P.}.)|;..jn`]<...Nlk.b/q-...Z.....+..u...E..W....~..;=<P.B..............o.=}r)..<..?.y,..x....o;N{lG.....q....?sm'.5.y.&....(v..2.X.ZcS.Y.,,..K.jP.g.....A.x#..q.$n.F.>....=...@.....O9 ..".....s...q...k.C..^....m........N..h...E....S._D......N.....Z..6.%.Yy..?..x.I,~...x.{....".i.!~bS..7...=k4V.U=Q...v.......u#..w.V.{.=i..@n..7..&....7.hCM}...1.`..{.'C~..2...t..Q.{b.7.cbH....K.c..r>......+..Ik.-...;..F..|..[..{.;....6..0..jb...A.V*..z../@.. .}*6?.....8.Q..A..X.(..0.^0......H....1^.8...4..>..tn....[..w.m.5.....q..k...j...l0.~........8.N....v#1(?..'..?...e0N.0.......N}..g.@...$3>..Q..{.....].Gv.....W.1_.o.w{&.{..3........s..........?..~...E..ao...X.(.;K{.I.@.O.....C...9.:....Wv$&...<.].....=}..........\.oQv....*.B..?...s.......o.....o.r..h...a@....a^.....7...R_...."t...`...I...o.'..4|<..p.c^..=.D{...{.\>........F.._.i...6D
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:Web Open Font Format (Version 2), TrueType, length 77160, version 4.459
                              Category:downloaded
                              Size (bytes):77160
                              Entropy (8bit):7.996509451516447
                              Encrypted:true
                              SSDEEP:
                              MD5:AF7AE505A9EED503F8B8E6982036873E
                              SHA1:D6F48CBA7D076FB6F2FD6BA993A75B9DC1ECBF0C
                              SHA-256:2ADEFCBC041E7D18FCF2D417879DC5A09997AA64D675B7A3C4B6CE33DA13F3FE
                              SHA-512:838FEFDBC14901F41EDF995A78FDAC55764CD4912CCB734B8BEA4909194582904D8F2AFDF2B6C428667912CE4D65681A1044D045D1BC6DE2B14113F0315FC892
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/web/static/lib/fontawesome/fonts/fontawesome-webfont.woff2?v=4.7.0
                              Preview:wOF2......-h..........-.........................?FFTM.. .`..r.....(..X.6.$..p..... .....u[R.rGa...*...'.=.:..&..=r.*.......].t..E.n.......1F...@....|....f.m.`.$..@d[BQ.$([U<+(..@P.5..`....>.P..;.(..1..l..h...)..Yy..Ji......|%..^..G..3..n........D..p\Yr .L.P.....t.)......6R.^"S.L~.YR.CXR...4...F.y\[..7n..|.s.q..M..%K......,.....L.t.'....M.,..c..+b....O.s.^.$...z...m...h&gb...v.....'..6.:....s.m.b.1.m0"....*V.....c.$,0ATPT.1.....<..;...`..'.H.?.s.:..ND.....I..$..T..[..b4........,....bl6...IL.i}.&.4.m,'....#....Rw..bu..,K......v....m_-...\H....HH.......?...m..9P...)9.J..$.....8......~.;.r..n.=$.....Nddn.!'....;...8..'.N...!.-..J.........X.=.,......"`:....... {......K!'...-FH....#$~.Z_.......N5VU8F....%.P..........Cp..$.Q.......r.....k.k...3...:R.%....2{.....h%.)8..........ILK.6v.#......,;.6..N.2.hv...........OO..t#....xT..Bf....q^.#....?{.5b.I..%-WZ..b.A...^.1..n5.....NQ.Y'.........S.....!t" .`b3..%....35....fv;....l..9.:jgf?gr..p.x. ..|.. $. e.
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (5268)
                              Category:downloaded
                              Size (bytes):274192
                              Entropy (8bit):5.562363538760156
                              Encrypted:false
                              SSDEEP:
                              MD5:66FE243CA8726878220F2EAB148614FE
                              SHA1:C9FEF410A74E53CDDE787FC9C9E127490AA067EB
                              SHA-256:ECB41A8E804A97AD43AABD965890C27DEF98723EB782389E34463192883FA123
                              SHA-512:45C54554F06FD4A70B9E6A27C28D4B108DEC1707F0214098C45BBB7292AA3B025C2D4F9C74FC091E027AB8D9934D09127D57D8B178DBFC3254BED7FDC72F1980
                              Malicious:false
                              Reputation:unknown
                              URL:https://www.googletagmanager.com/gtag/js?id=AW-652382924
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"}],. "tags":[{"function":"__ogt_1p_data_v2","priority":3,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":true,"vtp_postalCodeType":"CSS_SELECTOR","vtp_emailValue":"","vtp_firstNameValue":"","vtp_streetValue":"","vtp_lastNameType":"CSS_SELECTOR","vtp_isEnabled":true,"vtp_autoAddressEnabled":true,"vtp_regionValue":"","vtp_countryValue":"","vtp_isAutoCollectPiiEnabledFlag":false,"tag_id":4},{"function":"__ccd
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (4524), with no line terminators
                              Category:dropped
                              Size (bytes):4524
                              Entropy (8bit):5.815854714295377
                              Encrypted:false
                              SSDEEP:
                              MD5:5D5200F59F21F357EB576191C8DF5561
                              SHA1:15A7EBEF1A33F7BF1D786ADE01A52D4CFCF58F37
                              SHA-256:1D234383C06342C5ED2C347AD38CE50F7A16A821F0A1990C1219F0B80E59193D
                              SHA-512:B979C99BE6CD270151C3567E04C306BA8723C3BA17168A8EDC9981E9AFC5AA7F53089C30AD81FAB5A55B50DB5500F4B8FDF11C5736026D703C75F606415F4250
                              Malicious:false
                              Reputation:unknown
                              Preview:(function(){var s = {};(function(){var h=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};function k(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");} var m=k(this),n=typeof Symbol==="function"&&typeof Symbol("x")==="symbol",q={},t={};function u(a,b,c){if(!c||a!=null){c=t[b];if(c==null)return a[b];c=a[c];return c!==void 0?c:a[b]}} function v(a,b,c){if(b)a:{var d=a.split(".");a=d.length===1;var e=d[0],g;!a&&e in q?g=q:g=m;for(e=0;e<d.length-1;e++){var f=d[e];if(!(f in g))break a;g=g[f]}d=d[d.length-1];c=n&&c==="es6"?g[d]:null;b=b(c);b!=null&&(a?h(q,d,{configurable:!0,writable:!0,value:b}):b!==c&&(t[d]===void 0&&(a=Math.random()*1E9>>>0,t[d]=n?m.Symbol(d):"$jscp$"+a+"$"+d),h(g,t[d],{co
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 6048
                              Category:downloaded
                              Size (bytes):1685
                              Entropy (8bit):7.889402704019235
                              Encrypted:false
                              SSDEEP:
                              MD5:D4250A891290D72C955E88131351A712
                              SHA1:3F651BCB7EA1EDAC681AF7D17EEF33CED81A09AE
                              SHA-256:1D2F23132446AA11D46DCFFDEC4550A555545094BFA77BAFC81FEA22C7218CD2
                              SHA-512:FA8B9F4318362124CF66AAB2D5BAF6BE5A79501F9578BB1B1F28CD8B4DC59A2D054997C511605CC8C812EDFD9F2FD593775E2E66F94FC50099F906CF981BE075
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/portal_rating/static/src/xml/portal_chatter.xml
                              Preview:...........XM..6.....%@e7.......m........$.f".*I..H..;Cqd}x.,...=X+...y.8...]U.4V.:.....@..T.M..........Z9Y5.p.*.."../l#r.F..V.[.]_....%...n~.w.('...6FW.h.D.NC.Z...pN..+..#...$I0..%......f/nt.h\;..W.a..n.9..wN.)"|..IV)XU.4g.-.<....J.....o.BnD[.u%..[.....^Xg......O...q..^-.5...$.4d.t-.T....V...r.j..s.8.Y8Y..z........:s.$T..(.'..#o.....0...'...N$"' ..o>LC.h..m.J.ukJ...G...P.......j./.e./.......\..K.M.P.g.d.8Lb.$z........d..;.-..."a.~..`.d+].1C.Y..([.q..x...."5z....,|C...:....h....<..A......A...k.~..&...7q@...G.Ct._K(;..@.7.Q.e...C..@...=..S...5g..X.J..N......T.......Z.....D.2P...=U..I..|..Q.....rQ....iE.\..v.w.....L...6+.E...Qa.8G..F.A.:PC.@..YB......6.....!l@.....-TA....39$..}.o..........!..8v^|c.....nJ.1.>.ro..n...T...8ls.O...}[.Y....u~R.(A3aR.........r.Lq...Yr....`q...N....)Vj_.....9....F.7}...2.....s..a?.5......73.Kam...~:.3\;.=.Lb....N..J...@.....U.5............d..(.G........".*...V....=<JS.v.E.....&...|......1........n..STT..F.F$,J.4%..7(7&
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (5268)
                              Category:dropped
                              Size (bytes):274176
                              Entropy (8bit):5.562238955079305
                              Encrypted:false
                              SSDEEP:
                              MD5:54609EECACB08E53231FE4485E84EAD2
                              SHA1:B28C00FBB3D28D034F93118A3FFBC28BEC10C396
                              SHA-256:DF8A4130354CB98F80FB9FBEE1BEBF723689C556CCB6A7C2771A6FCA4664EA4F
                              SHA-512:8D9BCFAE3404CC391E70847EEC10FA473CA33197296011C63E612DA0345272A016D1A8B1A6E6B592D0A22E2122DC2CB666F2F76D660544E46451E52B901F9443
                              Malicious:false
                              Reputation:unknown
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"}],. "tags":[{"function":"__ogt_1p_data_v2","priority":3,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":true,"vtp_postalCodeType":"CSS_SELECTOR","vtp_emailValue":"","vtp_firstNameValue":"","vtp_streetValue":"","vtp_lastNameType":"CSS_SELECTOR","vtp_isEnabled":true,"vtp_autoAddressEnabled":true,"vtp_regionValue":"","vtp_countryValue":"","vtp_isAutoCollectPiiEnabledFlag":false,"tag_id":4},{"function":"__ccd
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with no line terminators
                              Category:downloaded
                              Size (bytes):16
                              Entropy (8bit):3.75
                              Encrypted:false
                              SSDEEP:
                              MD5:BCE442D3D579E92EF0F38FC6DF2EC79B
                              SHA1:330033083823FE496110493FC29EE379C6A77447
                              SHA-256:E07A46D6EA3A298335A56522CF17A9CBB8965482DCB0662EA96899BED67631EF
                              SHA-512:E2E0CB25A487930435668E90D8F76709CDF54CA919FF276B913B46661BF0B6965BB05560EEB04F6F69A76E7F50BE1A81146CE19D57355EEE97B0827C376935C3
                              Malicious:false
                              Reputation:unknown
                              URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAmuX6-zkbkKJhIFDcZosPw=?alt=proto
                              Preview:CgkKBw3GaLD8GgA=
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (2562)
                              Category:dropped
                              Size (bytes):207484
                              Entropy (8bit):5.537632220900244
                              Encrypted:false
                              SSDEEP:
                              MD5:51A1BB2FDB9F5D803FF65073EB1513BF
                              SHA1:6386C712F3C1DD44FB1E3D5DFE0C52C210FE1807
                              SHA-256:50D00EBBB20AF8B3A25960D1A3639B0B348CD464073C4CBD20E99AFA410A7CE2
                              SHA-512:980B838E9997CD1CFA0CC31E1CF5C92018A17ED0C9714DCFB474D51EAB4845AC70A936B2BC0688DDB063779CC58445E17DE1A53BFC9B038A459405DFC23C3F64
                              Malicious:false
                              Reputation:unknown
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__u","vtp_component":"URL","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__u","vtp_component":"HOST","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__u","vtp_component":"PATH","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__f","vtp_component":"URL"},{"function":"__e"}],. "tags":[],. "predicates":[],. "rules":[].},."runtime":[ [50,"__e",[46,"a"],[36,[13,[41,"$0"],[3,"$0",["require","internal.getEventData"]],["$0","event"]]]]. ,[50,"__f",[46,"a"],[52,"b",["require","copyFromDataLayer"]],[52,"c",["require","getReferrerUrl"]],[52,"d",["require","makeString"]],[52,"e",["require","parseUrl"]],[52,"f",[15,"__module_legacyUrls"]],[52,"g",[30,["b","gtm.referrer",1],["c"]]],[22,[28,[15,"g"]],[46,[36,["d",[15,"g"]]]]],[38,[17,[15,"a"],"
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 5164
                              Category:downloaded
                              Size (bytes):1575
                              Entropy (8bit):7.881913433779521
                              Encrypted:false
                              SSDEEP:
                              MD5:CFA5060A844610EDC288F608D3A1AE14
                              SHA1:2351D84BD87142E61D5F19FFCDCF857E7A9EB0BA
                              SHA-256:280E4453CC3B1C930F2CE09632354D90F36E0A09B3DED5DF59142F25AAE0B025
                              SHA-512:9A822EC8956EA18F54AD63D3BAC17B78E1CF5FEB9E3A108637EEBAE1E4ED47EF04E72ABAFE86D6558B4A0A2974E8169E5470A1C3005A5B07155FA18AD2C69B1C
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/website/static/src/xml/website.xml
                              Preview:...........X..6.}.`.h..DV.i.4...Z.....}.....6..TEj/(.....XgF.M..@k...9.....P..S....NY..../#.&..2.E.......~y.z(+-=8..E.?E.w.q..a.U58.. Z^...^....W.a.yU...:...A.V#M....H.Z:..J[H-l.!...K..L$.\)S.."...N.>)q.y...V....>$..`B...[...C......5..U...W^.f.9..t.j...&....%.4.:<.......+4d..3d...H..K4.+........+..G.[..W.....&l.#..Tfx..-.'...}m.....%.Gkb....Fb.z.6..6.r{......./p/.......tV.e...p.........V...R!J..F..'MX...A........L.~...z.<b..3^...8.<<..A...$......F...G.....h..e.rZ.~...2..`.9..w..J....Y....#.h.......}u...I....Y.......~.Z..XIO!.....qU.R..<..P.A..c..d.M...d....q.h.(.@...49.b;...F.'C.Zy.q.....syu.<.P..6.+p.s.O....Q...s....'......M. .Bj-.2_.&....ii.o...q.4...`w....4..._....s.f.r.#....]....;.a..7..P.....C=..`Z...\.}?R....J..ZV.......4>..f.H.u...z...+:.x.&[D...O.C.. -2.=..J'<Uh)B...Te.v.c...N......AG.?.Tb.$.odY.5+W..........]..X)..XD.......].,['.[.3dp.K....oX..\...r.#F<.E.K.=...Z.!..C...i`..-.L.j.U6'.!...O...1../.....Y.).n;.wQ._8#..Q..._D.6
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:PNG image data, 250 x 125, 8-bit/color RGBA, non-interlaced
                              Category:downloaded
                              Size (bytes):2819
                              Entropy (8bit):7.851441305371096
                              Encrypted:false
                              SSDEEP:
                              MD5:E9D91562DE782832220A92B29C6609B6
                              SHA1:6BE00CAB4372C2C66EB2ED1F3AFC00995CDCBCC2
                              SHA-256:DC4A36A31941A836EAD97BEB5A8E34FC0E7505465712C3513174A4F73FF06A8E
                              SHA-512:1883F2088FD2F199660FB19818B1F6A924A8222FA81AD5C7E5B29804638934DE8100E9FAF343A0A056A05C056F863B0EED8A1E3E0FB0960EE9B6EC5A4704873A
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/base/static/img/country_flags/ca.png?height=25
                              Preview:.PNG........IHDR.......}......Y~]....bKGD..............IDATx...]l.........P>L....CMM%.F#b-...xa4.b..I..Z..1...`0..1...AA....B>..b..&$.*R.V...v.../....v............=...twv.M3..:jl.v.R]....x.m.U(...."J=..H..:...t".0.D.`.4...i.A'...N....H...nn..i.A.M{..H+... .ML..+./...y..r.>|E.Ik+0<,..V....t]....p...}...]......~....H....._...{..}..y.....f`zz......y...u...tt.~..C.!Oc.n.v ...x0(.1.^v..p.....;&.g1.^e.2.m...e..$.........s.d..$..ff.;..].%.a..`|.......[......o....6...R..x....t7.....`.:..W.....NM.;v$........J...IM>_.m.m.t.x.Ay[......o.!.S"}..p.Z..\.&..ixX.,*..ff.&r...-.C5=...........?/.mo.v.4.......s.?/m..H..W.1....n...s..>.PnV...W^I.&r$....C...`.'.DQ1.n.j..d..*B.,.....t7q.1..j.y1.n.p9......&N...j.y1.n.p9......&k..YY.....U].%.Aw.....Du.RC./.p...m....5PB.t......!K..Nh......@SSb.8.j.Dkhj.}%e.t....ZZ.....)-.......K..jk.}<~<u5..t......z..3.m|>..0u5..0.1..o@h_I..]..)..IY.......o[....}...S ?.<y..-(...d..F..!^.}7...r..........A..}....75%....a.sJ........\ /.x.
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (4665), with no line terminators
                              Category:downloaded
                              Size (bytes):4665
                              Entropy (8bit):5.831478542748506
                              Encrypted:false
                              SSDEEP:
                              MD5:288814208969787288A106BF6CD26104
                              SHA1:0E4846A8BB1748D108A8F259381DD6797D848F97
                              SHA-256:C76AC1FCF4CC9A0A0A46AE66BB066A2C36299EC27F9147A9A2860AB84F2B9D04
                              SHA-512:F9AB23221520C4BBE1885123A613CD5CB6CE5CF995A3D186994091FF15C855F8F35F5DC458CE15203FD87CB7CCF5FDC49409C9F40DD7D75AE2DD2AFF4127F21A
                              Malicious:false
                              Reputation:unknown
                              URL:https://googleads.g.doubleclick.net/pagead/viewthroughconversion/652382924/?random=1736865485355&cv=11&fst=1736865485355&bg=ffffff&guid=ON&async=1&gtm=45be51d0v9105953142za200&gcd=13l3l3l3l1l1&dma=0&tag_exp=101925629~102067555~102067808~102081485~102123607~102198178&u_w=1280&u_h=1024&url=http%3A%2F%2Fwww.techlift.ca%2Fen_CA%2Fmy%2Ftask%2F166767%2Fworksheet%3Faccess_token%3Db8f79f62-9a1a-4f0f-8b02-ad8868e93ff6&ref=http%3A%2F%2Fwww.techlift.ca%2Fen_CA%2Fmy%2Ftask%2F166767%3Fmodel%3Dproject.task%26res_id%3D166767%26access_token%3Db8f79f62-9a1a-4f0f-8b02-ad8868e93ff6&hn=www.googleadservices.com&frm=0&tiba=My%20Worksheets%20%7C%20Techlift&npa=0&pscdl=noapi&auid=1511753366.1736865478&fdr=QA&data=event%3Dgtag.config&rfmt=3&fmt=4
                              Preview:(function(){var s = {};(function(){var h=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};function k(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");} var m=k(this),n=typeof Symbol==="function"&&typeof Symbol("x")==="symbol",q={},t={};function u(a,b,c){if(!c||a!=null){c=t[b];if(c==null)return a[b];c=a[c];return c!==void 0?c:a[b]}} function v(a,b,c){if(b)a:{var d=a.split(".");a=d.length===1;var e=d[0],g;!a&&e in q?g=q:g=m;for(e=0;e<d.length-1;e++){var f=d[e];if(!(f in g))break a;g=g[f]}d=d[d.length-1];c=n&&c==="es6"?g[d]:null;b=b(c);b!=null&&(a?h(q,d,{configurable:!0,writable:!0,value:b}):b!==c&&(t[d]===void 0&&(a=Math.random()*1E9>>>0,t[d]=n?m.Symbol(d):"$jscp$"+a+"$"+d),h(g,t[d],{co
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (17021)
                              Category:dropped
                              Size (bytes):408842
                              Entropy (8bit):5.650424177995092
                              Encrypted:false
                              SSDEEP:
                              MD5:D5CCC3887FC25B841D2818F0C550CF60
                              SHA1:88774035A9C0717004D28057B461E4FAF90F7CE6
                              SHA-256:639C0200C86CF9C759F4927FDBEFCD99AC61E290834A738E16943F54897D2706
                              SHA-512:5758F5A1597753E49A2CFEB070D38751A9103A2B0C954452B50F5C4926301CADA52CC6B1DFABF8877B558CF1D861DD2BE5A1AFEB6616DC0A8633B2640CFACAC4
                              Malicious:false
                              Reputation:unknown
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_1p_data_v2","priority":14,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":false,"vtp_postalCodeType":"CSS_SELECTOR","vtp_emailValue":"","vtp_firstNameValue":"","vtp_streetValue":"","vtp_lastNameType":"CSS_SELECTOR","vtp_autoAddressEnabled":false,"vtp_regionValue":"","vtp_countryValue":"",
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 5788
                              Category:dropped
                              Size (bytes):1894
                              Entropy (8bit):7.90598778708296
                              Encrypted:false
                              SSDEEP:
                              MD5:38489A501C457065840D0A6929023D6C
                              SHA1:9C33061EFEE6B34E7B531239A563ED130759B6D1
                              SHA-256:356E179147777CE88D06FF3656F9A5C936911B0B7E2712C7ABD0BA9731819E44
                              SHA-512:AE3D5BE8993E372247D2D843262B1EA25C126DEE5369EB39FF5F2F2729683DEDC9591B89CDD07EAA5224F5422225B1A966B4AFFA22C60F5BC88D3359FD7B7A52
                              Malicious:false
                              Reputation:unknown
                              Preview:...........X...6..=..D..w{+{....k;.h.._@......%.RC.>..........j.....r.vmQ.......7.....2z.\./..:3y.....7..L..L..WJx..I.....n%29MVV:i.2.=yB.L..i...o..QkF..8..7..ZZ8&_Jz..K.....?4.j..o..M)u.q.6...h....q,I.Q.l..Z.J,."/....ZH.eQi..;.l...}9.3...i.C...L..0.Fyv[.b)....sR.jY.=/..).......K........F...t."....u.on.f..v%.z.{...QU..a.A.....<@R.D.Vx.5.JaE......;.W...nJ...Be.%.8<0Hgd..n*'...(....)u?.`S ....X..ah.#....`0A.).6M6r1.y..z9....L...'..h.M.....i...0..][$.4..=.`.N.;W....[....yw.G.s{..'.7L..@6....N.>u..cJ.).>...lL.Ug..b.G....../.it3.......,..H.O;.Qlv...H=.9.0......c2.f.a.....b.. . ..ib.Um-.ty..U...I..A.,Pf"...hcl.eT.:.'8...V...4....-5.-+.3zF#..}..r..X.].i;.L6.....w../.#..F4.N.....~....>....9Tq.#....tu...,.{...8?M...(?...../t.RmW....`p.u........_.....P..[.0m....?.w.2.....N(L".:+..&u..J&.;....e|..|o..7.}...KV./Q.Q.8..Bq...CE.v.|.lp...(.x.rv.Wk.pn..9\.^..m.I..-.iV!...7\GB%.R......5..wt.`...*.j......p.K_.Wy2.......(.....4...W[H..i.qYU........1`.a.j..j....
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 442
                              Category:downloaded
                              Size (bytes):289
                              Entropy (8bit):7.188742336728925
                              Encrypted:false
                              SSDEEP:
                              MD5:B607EFB0476ED7370D9BBB457071EA16
                              SHA1:EEC6DAB8ED6903D0D66DCC04930F70861DD58210
                              SHA-256:A6E28119827FD5666D1D062F146C3F7D9C0FCBBB2C0B48D6EF213F45E7FE2327
                              SHA-512:D1F14E7AAA724C78FC744023D9187DAF323C3B597E14CA00B2095C326325DAFEA72B44A1C211FC07D010112D934928AEFD63DA0EB5338CBDD8AE54BA7CB0687C
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/website_sale_hide_price/static/src/xml/website_sale_templates.xml
                              Preview:..........mQ=O.0...+.....6$.Tb`F..P...Qb......'JA.n...}...S....w.....io.;....A...VY.h.F1b.e.JJz.i..L...#.AG8..P.sb.....A....oz.T..T[c.......$.%N.gJ1b.-c.U.|.OPA..*.g.}r...2J5..|...R.;....r=Zs....d..8...ER.]r.sj...O.....{:.O.K9............,].....&.DL..n>.o..k..6S.............
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (2562)
                              Category:downloaded
                              Size (bytes):207483
                              Entropy (8bit):5.537530993862335
                              Encrypted:false
                              SSDEEP:
                              MD5:BE2B00D56F050FDBF64F0FC03E45E3EE
                              SHA1:AB7B1E475E724550F8EC20B8322673F164F00B19
                              SHA-256:42F932BB4C896F4D7F96B35B2FB6B4BDD1D856AF2256199EEDC115663FD2B6D7
                              SHA-512:8A86870EC71ED16AE75610855462EE3376E205F0B2C012B470A3965272681566F87D56BF729FE9E04401E1B34077770D768A686EBDDB60A05E597C500E1A08B2
                              Malicious:false
                              Reputation:unknown
                              URL:https://www.googletagmanager.com/gtm.js?id=GTM-T5BWKR8
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__u","vtp_component":"URL","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__u","vtp_component":"HOST","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__u","vtp_component":"PATH","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__f","vtp_component":"URL"},{"function":"__e"}],. "tags":[],. "predicates":[],. "rules":[].},."runtime":[ [50,"__e",[46,"a"],[36,[13,[41,"$0"],[3,"$0",["require","internal.getEventData"]],["$0","event"]]]]. ,[50,"__f",[46,"a"],[52,"b",["require","copyFromDataLayer"]],[52,"c",["require","getReferrerUrl"]],[52,"d",["require","makeString"]],[52,"e",["require","parseUrl"]],[52,"f",[15,"__module_legacyUrls"]],[52,"g",[30,["b","gtm.referrer",1],["c"]]],[22,[28,[15,"g"]],[46,[36,["d",[15,"g"]]]]],[38,[17,[15,"a"],"
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (1572)
                              Category:downloaded
                              Size (bytes):36171
                              Entropy (8bit):5.345618653817642
                              Encrypted:false
                              SSDEEP:
                              MD5:32E0116AFC6049A232076B1CAD87550F
                              SHA1:4AE0622C65805DEEB6BA96CCA5EB14A7403EC559
                              SHA-256:5054D8D8F1849AD858FFBC7913BED1A80DDF3712FE200482BE874A7E39BC10D8
                              SHA-512:940EBDE0CB5BDE2D3187B9755BC236ED0124164E5A0B794B2089107AC53ACD8968A9BB2F74DCF29F765F89F220B3A83F0DFE956C0D5983BB74A6EC00C7FF605D
                              Malicious:false
                              Reputation:unknown
                              URL:"https://fonts.googleapis.com/css?family=Open+Sans:300,300i,400,400i,700,700i&display=swap"
                              Preview:/* cyrillic-ext */.@font-face {. font-family: 'Open Sans';. font-style: italic;. font-weight: 300;. font-stretch: 100%;. font-display: swap;. src: url(https://fonts.gstatic.com/s/opensans/v40/memtYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWqWtE6F15M.woff2) format('woff2');. unicode-range: U+0460-052F, U+1C80-1C8A, U+20B4, U+2DE0-2DFF, U+A640-A69F, U+FE2E-FE2F;.}./* cyrillic */.@font-face {. font-family: 'Open Sans';. font-style: italic;. font-weight: 300;. font-stretch: 100%;. font-display: swap;. src: url(https://fonts.gstatic.com/s/opensans/v40/memtYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWqWvU6F15M.woff2) format('woff2');. unicode-range: U+0301, U+0400-045F, U+0490-0491, U+04B0-04B1, U+2116;.}./* greek-ext */.@font-face {. font-family: 'Open Sans';. font-style: italic;. font-weight: 300;. font-stretch: 100%;. font-display: swap;. src: url(https://fonts.gstatic.com/s/opensans/v40/memtYaGs126MiZpBA-UFUIcVXSCEkx2cmqvXlWqWtU6F15M.woff2) format('woff2');. unicode-range: U+1F00-1FFF;.}
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 3770
                              Category:downloaded
                              Size (bytes):1159
                              Entropy (8bit):7.810218654131982
                              Encrypted:false
                              SSDEEP:
                              MD5:71C8AC6BE7E69844E08A63E67C8F3C89
                              SHA1:1128E74034F4CE79280E663EE119DDF18732B942
                              SHA-256:8287A52CEF2E9C9105B92D7E61B697E469AE625703CAF5FE8BC455F68D24C4FC
                              SHA-512:8D1B8B6A7547F1691485DD3AA51FF1C87C1C08F5D59EA87F04C7DF9DA5CAC361F09C55355777D8BF3EA81E73659E07173646C296CFDC2FDF3AB0F4C0342F0C05
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/e3k_invoice_sale_renting/static/src/xml/signature_form.xml
                              Preview:...........W.n.6.}.WL...h...Y.(R.(.&..<.E!p%..E.$.......w].......y...hy}.H.rc.V9.8;'.U.+.69....}K..N..7.d.[.UN.;..}i[V..[n..\...,.8.X./v|uf.F...`.*..s..?.Jl........q..=6Fw-..ih..7..I..r..... `....,.a..(....B..+2..v..pwV.F.R...3.A.J.H..ug..'8]...1N.a.=,.a..Q{DE.....S..8..m~G...u. ".V......q.....8~...D`....-...iW.........4.<'..G..g..dB..;ax.0^.i.2.y.D.+.f.t.u..b"s.@.......1U.....>.........@......e..@.WA*.G..IH2v...(R..;.L....6...ZV..../v..H I...zEi...6...;.EUq...%...=.x.:.5Ws(...f..`..W.*+m..kXu.v.q4z..ZV...k....JW..`u...2.,...>...V.`r,6.Wk....t........}R`c',."W....6..Y......%V...r#...K.;....5g..b1Ga._..s....}.d...L...!.N+.5.6...2.{.C.V......?..).K....no.N......<..ep..+..........@...-..jX....h.F.......xn.A.w{..?......Y......(..-.O...-..70T.4.Z.I..L..UZ...i.hy...T*......^ .W.%/].z..c.5....{.........t....y....e~m..fm5N.....qfK...O......@.......$>.N.'.o.Zm../..VV..gT..f4.]..9.-=.<.a.?..N....7............U88q..x.Ad~V.)>&.q.....6....
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 1517
                              Category:dropped
                              Size (bytes):574
                              Entropy (8bit):7.64476026674318
                              Encrypted:false
                              SSDEEP:
                              MD5:790739E4FA354A6CF6A69C1EBDB26B33
                              SHA1:F30040F4CB0CFB086440B6E3249EEA91E0F91AC1
                              SHA-256:EC396981C10AA43E1BF3B8E8FD31E67E8CFFFE2D9BE3A51F47D377D825424E51
                              SHA-512:CF7424104C6471480863FE6C7F0E6AE64084DF224662800CB54227389069C4B91BA77D12121162BB7D3D0F411C83921E9A38475CD9373F57C9858074EAF2BBEA
                              Malicious:false
                              Reputation:unknown
                              Preview:...........T=..0...+x.....%K.N.Z.t2d....!....W.Wd_.......G.I... ...S......}/$...Gw..|8@X..1..qP[..".U. ..j....O.#0v.b....E8.H...*....#x\<`v.!.6p......G.e.! >....B.........CL....Cp....{..8.V..R..O.-.X...[.S%L?.L.*.5...=.]....o.jZ..{.(."k...Pv..'.4.d..L...N.G.....:.|..Y...W.x-..L.(.......q....p...%J..E.|.i;.1y.F....-.G.L.<..c..{..]A.Qi.z....D..A.E.....'......d.'....y.g.'qcy.|.jL.k..@J4....p.......}../.0W.k...G.ub..a..J*.....:|..8l.F.q....}a.+.}W....C+y....Y......CC.u.12...'.D)....z.....2..X.9.$.1".q*.[.'s.,:.Lb.%S...>U..pM9.F.../.......*,....
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (17021)
                              Category:downloaded
                              Size (bytes):408862
                              Entropy (8bit):5.650459678249728
                              Encrypted:false
                              SSDEEP:
                              MD5:D28DEF4100F3234227356A9BA6053871
                              SHA1:7CD6DD868A64C58608DEB2EA96E423F8665C0C31
                              SHA-256:9C0770AC4F305E32A83951AE0568F9237B477A6D716752D1EE13B67920B7D3EF
                              SHA-512:B1DA7516FE5F1781AD5FD84012CFDFC0E72A3B68D44F324A0F4067D6F758CCCB24932B8B2EEC31F72FDB6BB588950E01519A679E420464D704574E1B3908A742
                              Malicious:false
                              Reputation:unknown
                              URL:https://www.googletagmanager.com/gtag/js?id=G-NBRWDBNKYM&l=dataLayer&cx=c&gtm=45He51d0za200
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_1p_data_v2","priority":14,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":false,"vtp_postalCodeType":"CSS_SELECTOR","vtp_emailValue":"","vtp_firstNameValue":"","vtp_streetValue":"","vtp_lastNameType":"CSS_SELECTOR","vtp_autoAddressEnabled":false,"vtp_regionValue":"","vtp_countryValue":"",
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:SVG Scalable Vector Graphics image
                              Category:dropped
                              Size (bytes):2113
                              Entropy (8bit):4.70654581047032
                              Encrypted:false
                              SSDEEP:
                              MD5:4D15968CF9252D5BA0640CA89942A200
                              SHA1:8F1C88ABB3D1A2EF3F3886CCAF54EA982B08E310
                              SHA-256:5B5AD8BA4240A3445F08C30E623495B0A4E3756CD7035CE49FCBD7B991C3030A
                              SHA-512:F18A1B33FE1E4055B85FFECDE127AB570CF244EB68E18F3EB9927B91266575B5199184FC554830E95912FDC363F210E9B17D2954ADB36DCA472F54D891EDD3A9
                              Malicious:false
                              Reputation:unknown
                              Preview:<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="38" height="38" viewBox="0 0 38 38">. <defs>. <rect id="pdf-a" width="32" height="35" x="3" y="1" rx="3"/>. <path id="pdf-b" d="M16.5580408,9.73125638 C15.6316195,8.82062898 12.9890407,9.07105151 11.6677514,9.23799987 C10.3616492,8.4412009 9.48838322,7.34085945 8.87330023,5.72449582 C9.1694513,4.50273739 9.64025557,2.64353978 9.28335556,1.47490129 C8.96442364,-0.513301867 6.41296827,-0.315999264 6.04847464,1.02717615 C5.71435549,2.24893458 6.01810018,3.94877239 6.58002785,6.11910103 C5.82066613,7.93276726 4.68921717,10.3686956 3.89188737,11.7649909 C2.37316393,12.5466128 0.322887299,13.7531941 0.019142612,15.2709064 C-0.231446755,16.4698991 1.99348308,19.4597924 5.79788528,12.9032752 C7.49885552,12.3417216 9.35169811,11.6511625 10.9919194,11.3779743 C12.4271131,12.1520075 14.1053025,12.6680297 15.2291578,12.6680297 C17.1655302,12.6680297 17.3553706,10.5280554 16.5580408,9.73125638
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (17021)
                              Category:downloaded
                              Size (bytes):408845
                              Entropy (8bit):5.650437029661594
                              Encrypted:false
                              SSDEEP:
                              MD5:39730525D4C38E5E301508EC39FCFCA9
                              SHA1:D0830A6434F82CDB3EAA5640CBEAD5B6F7EDD451
                              SHA-256:BFACF31E8EA9C9E97FA620AD3406CAA0928C1E6F675596DE4D7EE09DA39C9EDD
                              SHA-512:0B82BBCD6FE16365F51DA8559BD4689C33A45478780205C2606AEE4AB1BB29EE1C8BFAE8316E39B15C98531084F85377C0590DA3989C4883E7A2B389588F221D
                              Malicious:false
                              Reputation:unknown
                              URL:https://www.googletagmanager.com/gtag/js?id=G-NBRWDBNKYM&l=dataLayer&cx=c&gtm=45be51d0v9105953142za200
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_1p_data_v2","priority":14,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":false,"vtp_postalCodeType":"CSS_SELECTOR","vtp_emailValue":"","vtp_firstNameValue":"","vtp_streetValue":"","vtp_lastNameType":"CSS_SELECTOR","vtp_autoAddressEnabled":false,"vtp_regionValue":"","vtp_countryValue":"",
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 37x50, components 3
                              Category:downloaded
                              Size (bytes):1826
                              Entropy (8bit):7.626542601861562
                              Encrypted:false
                              SSDEEP:
                              MD5:046FF94913D9BD7D4DD2B921645E70DA
                              SHA1:C2CEBDE40B18840EE6AD555B7FAC365361832E1F
                              SHA-256:E094D8EF4CAD3941C3EA143CF18EEB4B737EE9741EC50D4E052B870B35B3FF95
                              SHA-512:3A0CB584C08399CA29F519D584619D5A4AC046245499FA4261BF763E686AA417E55E26FF52128FECB4099B0BC9966CEAD286A3C6B23324793F7A58039375129E
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/web/image/mail.message/4579457/author_avatar/50x50
                              Preview:......JFIF.............C....................................................................C.......................................................................2.%..".......................................1.............................!."1A2.Qa...#$4Br...............................+.......................!..1Qq2Aa..#34................?....E0...n8.6.}.Z.K.#:.$.#-..yg)>.# .j7.Cg..O...m.?.@....\...x?G....{.....n.ka47.}.p.aNMiI.. .}....V......N.o~...Um...e:5..Q]..Oe....Y{..V.....c...F..A.^r......m0`..w[/Q]h;.v].B..to..i...RV8.QY.?......;+qc.et.7.&.....\O...\..}3..yt.xm..a.UF.v.h..t.L....J.;......R..<...^..u..a..e..Ax..jt6.|eJ......u[[\..kZ..v.A.V......u}4. pi.XH...|c..4k..CG.d..............(..<e:..}.n.r.H........ozVj...R.nB..D5R....\..M.....rR.....O.. ..<..L.]kT...E.Q6;B.L$).rB...3...s..9..2...t.D..d.|..n..!.P\8..z.....Q_t+.V.8.......u...d....>u*...5...m.2.[$<..a...w.B.|.....ko}{^..`<.b$D.9.%;.4k...c.U ..9..p#.......t..4o/Lt.1.).}:.:Z..c.i..]..\)...!.
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 26780
                              Category:downloaded
                              Size (bytes):9195
                              Entropy (8bit):7.975337422870926
                              Encrypted:false
                              SSDEEP:
                              MD5:C81F3886FB05216E7D34948BB0AC092B
                              SHA1:2CCC17D38B9206D942CAD89BA73E29C095D815AF
                              SHA-256:86828E4C3C0B91F489AFE4263F5464719638E4B3170B40C553EB05376795650B
                              SHA-512:6CBD58ACBECE02FC2B502EE18A9700B0F4B541CAA56BF9924B290979C6556DA958B3497399A89CACB4CEBC65710EB341D047991FBA2B4FE1E552BEC2A54EA754
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/web/assets/1126508-6596fbe/1/web.assets_common_minimal.min.js
                              Preview:...........\{w..u...b]..(Hv.==.bU.-o..+..{ZY.!..`.....UJ.....@Rv.4g#..s.....=..]'g{e.W.do...%...WE>O.....g7..l.~*;..<.i'.:g.l:K:=@..L.r<...<...,..^....|.M.4..Y~...........J..N..*/.2..^~.).T..m....,.B....{....4...:I..8[...1....y..........N6.9...]P]...E..[.I......l.....xa..._~...a.)j_GER-....{.....v....oo.. ......IK...g....,Z...O.".....?J....j{..F4.Gw.L.N. ..t..."S.BX.. Kv.N.......!L....Fw...e....Y.E...%)..o....M.EY....eBrQ......".C..B.,.|...E...E.HN..id.#...4...w.'D%.%....x^Y..\i..g....b.....j..zwW..t.m"p#.5@.....xJ..]..<..P...u.....4.6..._-}...0&.N..U6j...]..e.... y....m6Z............i......|.@.!...{^|..*.Y...f..*..|5...H:'.s<)...0.uR..E..2.d..Ts..OB.>.|......-P......5...X.IR.>.'..B.t_N..h.[..u.%T?..q.\.I..H.k3..6...XZ%..TM..Yr...s[..d.i>Y...'E.W.{.x..`..`.....,'.q.....*.V."...(L..).D..;;...}.6.th....F..q:.m....3$.y...\ D..5X)..iO0...r......I/..n.....K.'.+..e=b..8.&.H.x...8..@...X....GX.Q.K(Ba.2.{...:.^Z......dm...QmXt2.......}
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:HTML document, Unicode text, UTF-8 text, with very long lines (418)
                              Category:dropped
                              Size (bytes):25723
                              Entropy (8bit):4.696132463022503
                              Encrypted:false
                              SSDEEP:
                              MD5:D2CDA605662B216D8920F346E8715245
                              SHA1:CEC8F4F1A312D4BE2A9214BA98348E33E7D56CB7
                              SHA-256:9FF95C524A3A1DEFEDEF695CD55F0D051B9681AAA9D7B53DFB11554FB0D22751
                              SHA-512:2326395D83A1520C2B24856F6B11F3EDA422395599558D0E81DEEFE0EE385C72BF54F724C198E574DAF9B659218B8FB0589DBC779FB5753271B384B3D12D2400
                              Malicious:false
                              Reputation:unknown
                              Preview:<!DOCTYPE html>. <html lang="en-CA" data-website-id="1" data-main-object="ir.ui.view(234,)" data-oe-company-name="TECHLIFT (SI.GE SOCIAL)" data-add2cart-redirect="1">. <head>. <meta charset="utf-8"/>. <meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1"/>. <meta name="viewport" content="width=device-width, initial-scale=1"/>. <meta name="generator" content="Odoo"/>. <meta property="og:type" content="website"/>. <meta property="og:title" content="400 | Techlift"/>. <meta property="og:site_name" content="Techlift"/>. <meta property="og:url" content="http://www.techlift.ca/mail/chatter_init"/>. <meta property="og:image" content="http://www.techlift.ca/web/image/website/1/social_default_image?unique=6b367a2"/>. <meta name="twitter:card" content="summary_large_image"/>. <me
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 2015
                              Category:dropped
                              Size (bytes):928
                              Entropy (8bit):7.78374145371394
                              Encrypted:false
                              SSDEEP:
                              MD5:8709B1FCCB89EC16F3A57B8D7068C747
                              SHA1:922A08D8FCC8BB6754D05DC721DCDE3DB4708F81
                              SHA-256:D508DF761A4398CD7966D7C57703446FBBE35D8006666B02C80C14AACE0B2059
                              SHA-512:588FCC9227BCE1D076BAB24F4291C7AC68F4696BD5A60D07C38B85C5F6162D98A0FD0A85C4778FF14704529937B5D41B8D2A8F12D73D6F8E2C33FA16566E7162
                              Malicious:false
                              Reputation:unknown
                              Preview:..........uUMo.8...WL..$.c5..A.......l.(..@I..T"]~$....w..j...yo...a...Nv\..V...PJ.mvV1.H.eH...|....5$..`.Ka..y....YSK.3.........UES..6f.gY.kLm.i)..^..dQt.l.().$.V......F.>....L..r...^*.....bY........w.....B.........#O..Q...c.{....$.N3.:q..,.....!<0e].z.#..:wAiNp(t(|...!1u.'.,....V.9h....2..............n?...Q<.k..aj.[..2a....^(..d....j.|...........j......*........o....S.o...y.N....+..3D...@Q.1..0...I9G.S.G.U.w%.p.1.t...>..J..um.3....3V....Di..Q..s..Q.$^.^6.j\YtEOtD?tC.S.V...~#U.hm\..n].I..u.\.~..X.F.L..._.:_.....iA../.O.(/...N....U.5.Pi.>.Di..v.$8..Y..L6k.;...a=A*..0GJ'........@J..lN.Z...}..p..S%..J..~..+......:....e.U....._7...z....9`G...=F".3.l'..54.-...q.W.WG...FX..'l...$t......q........C~.C.Z.l\`....d.o.t.!.7e..m=...0..1....K+U...~F;.A._.t1y.H.y....M.f...&F..9$......K.,pDz......."..fo.2..?...z..rS7./R..c..8a.%...5.Kn....w.z...`E..q9.].8v..S.kH....)0P....C.....B`.....
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with no line terminators
                              Category:downloaded
                              Size (bytes):28
                              Entropy (8bit):4.208966082694624
                              Encrypted:false
                              SSDEEP:
                              MD5:7C7A1894EE54EEA7BF3E9C709B2F8069
                              SHA1:46EA7D3D76197C0EB97606D608C94637CFF8AF92
                              SHA-256:471BA83A382AEAF294AEA8045C9C3C66FF2B69B8302BC39EBCED2192E3EC284E
                              SHA-512:4D8BB5EE86E9575718A423C125BEA9C24A7EFD1949FBE1008FFBEF1675AA6BB85B15A6F05BDC6DFB898DA00D6351C656556CA5BDED4810874E0740BFA385F092
                              Malicious:false
                              Reputation:unknown
                              URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwnjhjVd9KALzhIFDaQqhI4SBQ1e0O9l?alt=proto
                              Preview:ChIKBw2kKoSOGgAKBw1e0O9lGgA=
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 462830
                              Category:downloaded
                              Size (bytes):340481
                              Entropy (8bit):7.994454902700553
                              Encrypted:true
                              SSDEEP:
                              MD5:2A4504381C5379C7D5F6EFAF227827C8
                              SHA1:57F8C2ADF131980F10ED337A742EEF1024E583BD
                              SHA-256:7EAE3496D623FD0C0CDB7CDC518B4DC3EEEF3FA6E88D2EFA04929538C316ECD6
                              SHA-512:81FE7DB8DBF0191B30301E9CE14A7398FFA370048ECF3E0F38E27E8A4C95D6BFE385B0500C1C0909682A4968FADE86D57967F71ADD7247F3D248B6D5D87EDB25
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6
                              Preview:.............H.&......2.)L..'....I..x..@..7..}..QU..M.A..V......YGw.......LMMM.O....u...N[.c...tn.>._;..Z.?......\y*.5sr...?.@n.....".5....'.X8..Q~.....?..E......O....?...|.N...y....3..o.,...Wt..4.J..I/]#...}..E.!......f+if.!En>Q.z.......H......I...-u.........B',...-.G.N# .y......s..4.x.t.....gG3.._~.8..;...i......,#4R%...6z....>....|.F........S^..-....._qeUw.J.u..9...;f.;;lE.K.....]....I..?.zeY~.o.}...~.....@v.!..9..$;.b=..+#..{.....{H/.4X./.a*......c.:Ia|&U..(...(.y.....B..rV...._|%..k...o^..h..s......|.[.|'.:.....)a.:..>t..0?.h.(......TO.....vj...>ZY.JC.......FY....?<..LK.8.(Y.jp.....H..E.......$-..h.......--=...Q...?..w..E..Fx..*.......j.R.i................N;..?.....q...p......rm.}.c'4..D.......u...Xp.G...........N...........*.........3...r%.O.Yy..V#...y.../$~.....@...&......_~.......6a|.2.Q}P.5h.......?....Zj..o.........=..?~.....u.....g..u..0.K+..z..7.C..*..u....l~...&..t..f..G.........[6......i.....}....?~7;....HZ.o/
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 3659
                              Category:downloaded
                              Size (bytes):1209
                              Entropy (8bit):7.834273690580407
                              Encrypted:false
                              SSDEEP:
                              MD5:CE3E1DF1114A5DD303A3C29DE5C07067
                              SHA1:1E62B06F189F90CCD68F46B569577050757A108E
                              SHA-256:93B7061ED0B0D99F30DA8E3EB74242E58A618942E1EBC480560D72472B0A8426
                              SHA-512:CC79BAC4BE6F97A1D7C8FFD293FD2850922FE09552AD7C72DABD3B7197102F2E68C946B50117858320FA23D0640077CA852D287EED84C9FBBE4341A70433F074
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/website/static/src/snippets/s_searchbar/000.xml
                              Preview:...........Wm..4....b..! ..Nh/..t q.....*r..1.7..]..g....|.R..y{...4.=..<..e]....*.Q.u&..:......vs..Q6.7B......j..b.4Jh..E....^1....4....:..0.$..ch5..`X.KT.D.d.cm....c.....\.u.....}.JQ...z.{v.Z.o:..4+..`....8x.....F/.Q.L......w.3.....\.....K.ZC.M...D..A.(..G..+[..J.l....JUm.....i.(..l.k.s <..Z@X..|....`.K.3.m.b..ZAhQ.:]...`...p.`!.#.:.!W..{.x.#.b.c...&@h.....r...;..f.(..W.....k!..`..8.@..8....q....<..A......WW.TX..1..d.a.:q...'pR_..]...o.O=.uU)2..rW1*4.R.U...z2v.c..l..-...N.E&5...%..D.#.W$...Bu.t.......wV.E.-..\..0Lg...8.+.e..9....B.. ..e..s......\..-......-....@.c....i."n.......}...Ca'..}......{3..a.......dcphS..h.}....H.>b.f0...l.>...i....(.?.+...a?w?.f..O.?......*....{.Qw.`c.L.H....r..D...Q.p.a.7...[.H.au..z0.R....T.#k}......\.e..gH.3t8.......p.....5.n"....G>......_...a.y....c3n83\.....L..m...s...O;.u.....g..Lb.(b...O......Y....|..I..`.K...Y<...b..%..Ao..r&.....R.[....4\..x.W..V....~}.]K..t....".s..y..Q0..[2.{...W.....D}OL.....
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (4507), with no line terminators
                              Category:downloaded
                              Size (bytes):4507
                              Entropy (8bit):5.807415618279847
                              Encrypted:false
                              SSDEEP:
                              MD5:41D5E2B589E3EBF3C1E34CCC5C6794B8
                              SHA1:C3E2E001BFDA7E12C22306BDF30D52A5DD54A4A8
                              SHA-256:C51E44096FDB26F53D6A3A35EA8C3A13D6378F3134EB9D3E043FF1EC67417D73
                              SHA-512:2C35EDCFE16A4780A40B40038E96534176E27C28285CBAFC9D1D07B554B856F70F567F6A84323B5D0C9080CD3BA9B20E236215EBF877504406A029A9E2C4D8D2
                              Malicious:false
                              Reputation:unknown
                              URL:https://googleads.g.doubleclick.net/pagead/viewthroughconversion/652382924/?random=1736865477839&cv=11&fst=1736865477839&bg=ffffff&guid=ON&async=1&gtm=45be51d0v9105953142za200&gcd=13l3l3l3l1l1&dma=0&tag_exp=101925629~102067555~102067808~102081485~102123607~102198178&u_w=1280&u_h=1024&url=http%3A%2F%2Fwww.techlift.ca%2Fen_CA%2Fmy%2Ftask%2F166767%3Fmodel%3Dproject.task%26res_id%3D166767%26access_token%3Db8f79f62-9a1a-4f0f-8b02-ad8868e93ff6&hn=www.googleadservices.com&frm=0&tiba=My%20Task%20%7C%20Techlift&npa=0&pscdl=noapi&auid=1511753366.1736865478&fdr=QA&data=event%3Dgtag.config&rfmt=3&fmt=4
                              Preview:(function(){var s = {};(function(){var h=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};function k(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");} var m=k(this),n=typeof Symbol==="function"&&typeof Symbol("x")==="symbol",q={},t={};function u(a,b,c){if(!c||a!=null){c=t[b];if(c==null)return a[b];c=a[c];return c!==void 0?c:a[b]}} function v(a,b,c){if(b)a:{var d=a.split(".");a=d.length===1;var e=d[0],g;!a&&e in q?g=q:g=m;for(e=0;e<d.length-1;e++){var f=d[e];if(!(f in g))break a;g=g[f]}d=d[d.length-1];c=n&&c==="es6"?g[d]:null;b=b(c);b!=null&&(a?h(q,d,{configurable:!0,writable:!0,value:b}):b!==c&&(t[d]===void 0&&(a=Math.random()*1E9>>>0,t[d]=n?m.Symbol(d):"$jscp$"+a+"$"+d),h(g,t[d],{co
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 8664
                              Category:downloaded
                              Size (bytes):2555
                              Entropy (8bit):7.936213103186253
                              Encrypted:false
                              SSDEEP:
                              MD5:B6242AD6021EB9AA230E7FCE7116F938
                              SHA1:C848EE626FB4E4713F2EFE9DD3180FEA952EC411
                              SHA-256:FC7534B5F35A6C00E845B836E1C5A61C530451A88C05215CD38C4F7D10C7EEE8
                              SHA-512:F2969DF8A360CFB87466E937177666B5E0FC94273BDC39B31030A26D089F95405733CE24B3ED8A284202D2D3190E62C927EDCCC443584B92307CDB14C96B31F0
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/portal/static/src/xml/portal_chatter.xml
                              Preview:...........Zm..6..._...U...M..A*;.z....-..+..B.%.f......4...!E.z.MQ...#K...QB..*...L.;.....y.FVq.w^Us.....O.0|B.TP.9=*k.g...+..(.R.'.%eS(,....;$W;.<..K.5 p'..W..=.....o..H.%Y,..+.lx.0.......4...1;.AR.9/....tv....7.q.X..}.%.3..p.dl.c.}.:...<.0T.PNVNo....s.U..3.9..W..*.e..w.....p.'...}..WA.m.E;......2.J..{*U\.qV.....IR...Q..qq..J...o.*?.....(/S..K.>c...-.Z.&Qh9:.....Dkd...k...+m,.....,+...f....%...N.L.).A.....HaS^$........7.2.I.....2...o..y......0.:..DWcy...|.,..~.j.O._.......:'.".....e..F*v.,........;o{...<..-..O&jw....,...c..N.E.......U.z.n.!.A.i9l..9u...3^.7}.i\.....5K.....h!<"^.e...z.(.....CY.+.S.su....R.]]......'.k..q....H...6..Lt[RZ.>.....r.>^.&.....t.]b.C..@G...9,P.~....P......\.7.r.C.-.sS.*x...8.L.$....ik.G._..&A..epq..BF.0$..C&.....&.4f =g.[.ql..P...F.oX..QT.{.u.8......A$.|.".%.*.;|.c.....<fN.....<.q...a.1.B..e..z..R.E..n..z8.,.a:Z..Z."...S....W.....#.@..C.TY..M..A..."T.Xd[..9.a.=zP.k...F...H...Y/.C...x..[..aC.R..^g.../9|.:....G(..wi.zS?.bZ.aa
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:Web Open Font Format (Version 2), TrueType, length 48336, version 1.0
                              Category:downloaded
                              Size (bytes):48336
                              Entropy (8bit):7.995815173088384
                              Encrypted:true
                              SSDEEP:
                              MD5:BFE7AD4AA54CFF8909B2D7632073CC30
                              SHA1:7C2E625BEA4D449CA78CDE09AB59DC6C9CB4726F
                              SHA-256:47D477915FA5912616E2DC5DF8C5780F9202671678CF275472BD39F3381C0098
                              SHA-512:B083C9E0766F281A39F582404F08B3D3314C7757AC151C4CB00BD3CECEB4FA06B12D08D881A2C6BF80A066ECAD22FECE7CFF41269D2DBD2BFE38D873922A31FF
                              Malicious:false
                              Reputation:unknown
                              URL:https://fonts.gstatic.com/s/raleway/v34/1Ptug8zYS_SKggPNyC0ITw.woff2
                              Preview:wOF2...................S..........................g...l..P?HVAR...`?STAT.8'2..4....../~.....$..U..,.0..<.6.$..T. ..J.. ...[3mq..c..5.Hu..ev.5.c.L6e....<.>U..#0l..h.........F.m........."...,V...\.i....;zG-....%..Nt.j....l..m.p.`=....%...}^B).I.Q..qt.l..l...i.......9~....P.".tj.._?.P.j...B.r...'...Zh...}......M].+......k].!..E<.{.........."........m...$C.."_i.>.i@.=.#......s...........%...;."...U.....n,...DO.W.n..85.._.Bj9..nN.T.xl.U".Xq^...y.......<.2'.... .`...WCT.W........?{wI.!.B..C..B.$..Zh..0/ b.....P.(X..?..._Pi.4;`y....gi.j.Zu=.8......>...*{U..K..X.P.hN......=.....C..,............f.eE.l...e.Y...K.Xf.u.%f...k...+"V.Y"W.bD.*........~.[.~QL.z2.......V.Bd..j.D...]...X.5d........){....G~Q.x....{.{.=\.5.h...DB...H]V'.....<...sD....=D(.......^.&M.2....M(iH.8<........p\d.Wo.....@..A....U..M..K...z".%....n...k.T/a..d(..5s1..P..K..i.]l..+.......ZK7H\D.N...].kL.......^.^...K)(r.J.W..L2Y...?..`.......&.%....{?T.:P9.\%..E*....H....`....r....Q.....Rw....T..}....M
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 5741
                              Category:downloaded
                              Size (bytes):2022
                              Entropy (8bit):7.898809506409665
                              Encrypted:false
                              SSDEEP:
                              MD5:52624DE813851B3E1B37696F791CF5FC
                              SHA1:80CB58C5D4E122A0CEA7733B24975E469B8E865E
                              SHA-256:817860C490C41A8BD6586090289497EC0A714E7F9AAC329076A05207FCEBA5D2
                              SHA-512:C8EC2D05B5674B864763EF20C98F38B87E9C8FF56DBA627EF88D94E53C95F4494C877893781535E59E7D06679F985EDE27EDA0636B622BC0F4CF50435770245B
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/web/assets/1126511-81ea84f/1/web.assets_frontend_minimal.min.js
                              Preview:...........X.o...._.l.'..s}.C\...M..vo...}.R--.mf)R'RN\...;..Kr..*.(...9........w..k../.-.....o....'...N(VA.....PE\F.NV....dLk0.X.J..UQs.k&....DUJen_b...g.OW.,.W2i.....NC.M.K./....B.... ..c.-kn.i\.....o.U~...t..i.v....I...i..7u..g........#].,.;.....B.bB."..h..t.W.0.`.V....ln..,O:...y..F...:hwW .4.})D.g.......:N.+.&.......E&@..f._.H...<.c....b.[.L.Y.I....~.5.............'.Z&.Y...&G....e.@..m.#.UP....#.&A..V5..u....z.Cg.:..1.-.j._.c@...m'.O\.i..-.aF..w.m...vW..p..1...D...8......K..{e....P..7.1"...*.+h%...N......lyc.c.K..0.k.......v.B.a.Q.ze....8...l@......#?~....)U..0..N0.x..3IA.y..A.;.+u.0|,.#|>.j."CA.vPMQ..[4..*.i.%e..}..8...6.|.c..A......9.1...{.>.XM.f...............lJ<L...I.....7.7.$.C..%.I.......4.|..^BFH.Q2.....^..>..@...,XN........}......d..o...3...c...tN...20X.....aT[.).4.......a2.B..dT.v.......>.h...>.ja-..$..F.r....w...2p..!..oQ..:.R..X... ..o...^. ....<.iz._.L.C.y.S..,O7..T.I..i...;eM...t~.'......}....7+y[....T..9.p.F....
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 703616
                              Category:downloaded
                              Size (bytes):120540
                              Entropy (8bit):7.997440649645081
                              Encrypted:true
                              SSDEEP:
                              MD5:2495B9DAE793FB68BCA58182DC63225B
                              SHA1:9F89E2660C111023A85692746BFD117270376ED3
                              SHA-256:C22A643EBE9C4F959DFDF2A411CC71A2572284EA0DDC131897F35065D87E95F6
                              SHA-512:211D8F2375AEB577B3F4D3FD635367A31106B9F9B582CBBF7689D97EE5B9EE3A37EDDF66A54255863D70784F7AF3B08DA0C49EE2529FD75462943AAD1B95BAC3
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/web/assets/1280054-689d2b2/1/web.assets_frontend.min.css
                              Preview:...........ks..&....F.....E.Nz={..?M.DL.DL...7.h....E.(..}...5...R...m..............v.^...f...\.ys...n..V....bs0]..n6....v....../..OW........~...s.....c.../.~.<.._.......z.......u|....x.....[....f3....l~...`q7.<........s7o..`w~7{9......f..........^..q..T.....l.....r1y3Y....z|.f...y{.p7..Vw.....~...>..J.5....O?...[)....|.^..O`a08X..^.{X...KH...-Z.....H.p:.'..nF..z.Z........|....t.....*w.!...uz"..?L...r..f{.x3_....[m.8....W.:..B*..)uzl.(.$_......&....j......E...C......7.1.w..7......g.5...e... ..........%oW.oo.w..E...f.vs.z...Z....|.b.D.F.1.y{.......\).......S.\)d.<T{5."..g.5. IJK.k.$%hy.&.I..>.&..IRD.f..ml+.v5.l....SC+J..x=./.Q...b;o..g.k..O...l............A....J.*..`e.Q.".\t..r...P..;8.........D,.e...Y.`...i.`.. .v.!.....!..G...n.n.vq7..$...y.\l.....[.......w......F}%.*z....v.d.qd..|'bH...r'^A~NL.....Z..mgA-.X...].U... ..x.a.c.@9.k+n....k.E>>....]G.......^.i....<L.s.'.......tu..[...A..zq.R......+:...S........V.:F.2....^!y..)..
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 7503
                              Category:dropped
                              Size (bytes):1893
                              Entropy (8bit):7.900657806340236
                              Encrypted:false
                              SSDEEP:
                              MD5:757188384FC2CC2F049EC563B507F960
                              SHA1:18594A0A0CFAA25ED0380AE1056CFD8EA0630076
                              SHA-256:50D2C2788979028AA9D30E3C246105AD1CEDD5BD6CB0011E40EA7A929C8ECBE2
                              SHA-512:40A2DA24245F11CF7C18E474AD7ACA780710A9E85741CF46E842A29413210F3319A9EC78FE4C43815FF5859C05FD70627C5C83785AD7AED0E9C782607BC073E3
                              Malicious:false
                              Reputation:unknown
                              Preview:...........Ymo.6..._..@.|..E1$r.a.......!..J.-&z+I......Q.L.YNR`3.....;R...,%.\*Q.K.b..#<..X....._...._.L....d._z.....].....h..5......U.8.Q.29g.]D....i..}.p.[z.x..R.HU"E~O...E.%..!.Z.p.Hj.(.?~s..,.t...w]2...,.tvK.XV^...V.k..P`..y......tZ].......yPJ....h0T.1...........vZ......l.).?.?....W2..{..@e<...E.#.c.......q.<H..)....dU.n.X'.....K.B.X.n....Q.v ..,..O.W..*!,b........P....<&..x;..a..z..`!.}Ek.4.?. =c.2..$...y.O.U$E.9L>..\....}....W..%.A......z....\.........q....PY..2......1..1h).....}.K..d.U.Js...aL...Jv.. .`.0.Y..Q&tPhU.v.c,|V..&.;.o.m#.2=[..,....x=#%...l.JV..6.b7\AX*..E#..KHQw..B....yF&R(..fv..5..RS.mV.....f$.l].E....*.YG..Z...ou-..z..; ...O.r...~|. x..u.:.V...\_{......h...Vlv..#J.R.gXV...%y..|.:....=..V._>.SN.)...P!.....@l.t.5.....Q.....n.....3X..%.R.4.P......K?..vwh.:)i..J<............F.8.......k.i....}.........w..:}....C....h.].....iwac.R.S.M7jf;......b...'..@..N..nf.....)....j.*#.v0.F.....4../.P..."K./*...d)..fT3.[.}..
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (2562)
                              Category:dropped
                              Size (bytes):207476
                              Entropy (8bit):5.537428044758343
                              Encrypted:false
                              SSDEEP:
                              MD5:20865FB742C39E971C896F0E20055809
                              SHA1:A20F05FB2E614646275B2F41A1FF00BFFECF1F87
                              SHA-256:A96DDDD1C6C780F13891F575BD008709E96D80F42CB13D164833F9496BA27137
                              SHA-512:3329EDADE2DC2984E0AEEED87E89526E36B93B78BA9D23C9A0CD2F4295D4713CB6181B69C1A0C889B9224A72669B62955C389A88577C9CA58989077A0F7C30A3
                              Malicious:false
                              Reputation:unknown
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__u","vtp_component":"URL","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__u","vtp_component":"HOST","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__u","vtp_component":"PATH","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__f","vtp_component":"URL"},{"function":"__e"}],. "tags":[],. "predicates":[],. "rules":[].},."runtime":[ [50,"__e",[46,"a"],[36,[13,[41,"$0"],[3,"$0",["require","internal.getEventData"]],["$0","event"]]]]. ,[50,"__f",[46,"a"],[52,"b",["require","copyFromDataLayer"]],[52,"c",["require","getReferrerUrl"]],[52,"d",["require","makeString"]],[52,"e",["require","parseUrl"]],[52,"f",[15,"__module_legacyUrls"]],[52,"g",[30,["b","gtm.referrer",1],["c"]]],[22,[28,[15,"g"]],[46,[36,["d",[15,"g"]]]]],[38,[17,[15,"a"],"
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (17021)
                              Category:downloaded
                              Size (bytes):408836
                              Entropy (8bit):5.650369091990868
                              Encrypted:false
                              SSDEEP:
                              MD5:9193EDCD57CECCB183CBA2B3E1C58123
                              SHA1:98CE9DF2377F2106E1819BF5BC6CA02FDC3342B2
                              SHA-256:5D952A1D219A56B5EED697B27C3D1E5D68F7C88D0A9D354FD614D52C9DD84620
                              SHA-512:5542D631688433ECF9B1F7535EAB8D4D103EB95082AB95ECBDD59D0A5E2FAF6790C32616BF206279F70657802AFFA5B91CB4734BA68C45D6740A04A5D70569F0
                              Malicious:false
                              Reputation:unknown
                              URL:https://www.googletagmanager.com/gtag/js?id=G-NBRWDBNKYM
                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_1p_data_v2","priority":14,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":false,"vtp_postalCodeType":"CSS_SELECTOR","vtp_emailValue":"","vtp_firstNameValue":"","vtp_streetValue":"","vtp_lastNameType":"CSS_SELECTOR","vtp_autoAddressEnabled":false,"vtp_regionValue":"","vtp_countryValue":"",
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 174336
                              Category:downloaded
                              Size (bytes):32020
                              Entropy (8bit):7.9922416460661
                              Encrypted:true
                              SSDEEP:
                              MD5:1BF2EE104CE79D3A96D713BEF8E41176
                              SHA1:EB51F35531005862AAC567D807C8E6CF2FA38BC5
                              SHA-256:09EF9EB09C3023DF07A233FEA8B82D837246158E5AA1A7021DCD8616066390A4
                              SHA-512:07AD4013EAEC30E8E25394257A57531548CCE33C2DCEEF05306D5E4B1B6606B544862A011C47C84134B422BBDBB0B4ED4008FEB2C3E133A2669EFB0C1776A77C
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/web/assets/1282895-916948a/1/web.assets_common.min.css
                              Preview:...........{.#../..?En.....N..zW..z..cG....D......*...RU.T.w.?...d.......H..A..@.Wg.I...Y..6..l^..Fe..6.luV....~.].7E..z.{2..2.$.2.m..y....^VU......E.|....W.~.....T..t....C6~VX..{...|...b....?.vS....+A.y.^.......<.....l\l..9.].........:.,.UY..:w.:.c.....i.......Q0.xww.|Z...J..q.....].....F&.U.|..2.rE.$.|.V.aTn6..\..3..A9..E6.....]i....d...}e3j.x8....U.......WN.......$.nJ.w...lRl.;..,_..=(.M7.....a...N...{.)_..E..v.9._.....c............=..T......v.O.M.n.U..3..&.W.z.5's.)d.1.....H..c.<]g..J.%.e...|...58.b......A...l..=..E.....$.TI.U...g!..f.u>.i..A.....|~..[l....5..aK.kd.d....>..M.7..a.=+.t...#......P.x...{.D|...1...{.C.1...X..G.Uf..r.p?.e.....6\......~...9...'P...X..Z...xs?/......*.A3..:.c...i..i8.r8........W....&_...\..m%..I.<X..@4......{.x.N.|7."WG.T.%^h....y..wY..Mwu.M..jR>-.E..L.j5.....|.@~=.8_.aI.|_e....]r...>......u.x.....KY..D$t.....^..gM..U/...........'....48.\..K}H.....G.7o.'f......T/v...'.`F|.S...}.R..k....$..n..L
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 270
                              Category:downloaded
                              Size (bytes):200
                              Entropy (8bit):6.842337377155746
                              Encrypted:false
                              SSDEEP:
                              MD5:285A18AD3221A019DAAA32ED266D79CE
                              SHA1:E343A05998662711D216D60E7C97E0F005E4ED6A
                              SHA-256:9C45A15CC20CCA099405D1660611ADAC556108C1675C12522E9DA160540D69DB
                              SHA-512:94F1388964254808A7CDEA12FA487F15D86BA0FBA61D00277E20A11A106EB745694FDFD4C29CCA5205B1527E7C3513059CFC801DEE3DC80C6AE2C10F4A6B1CD5
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/en_CA/website/translations/04e840c3ed34e2d0b9fc364b60b58ef5e7bde60f?lang=en_CA
                              Preview:..........U....0.._....U..Bo..^<y.......d...w..z....3.3.....8.....AFi.!.E..[.2..`t..M.n.t...w$...I....J$..;nw\....I.._.~#i.>..Vy...DA..4"x.J...>'.T......~.."..d<-...t^....^e.eQ9.A-~.1f..9W......
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:HTML document, ASCII text
                              Category:dropped
                              Size (bytes):295
                              Entropy (8bit):5.2979422256799085
                              Encrypted:false
                              SSDEEP:
                              MD5:A64AC36ADB4B78FB9F3CFA8AF3605F15
                              SHA1:B746CF4C949E22F6DDEC15F3766D107D700895CE
                              SHA-256:24F234D392B45B89DE49FAED2A52FE0D2A45862D67B16E1509897D851217AB4A
                              SHA-512:6D487D98D0DADE2E4AE91BD4033EFDB56D9331E3FE4F15388F92687AB5FC10C1A58A84D7A45B6CB16460331845DC92CF241EEF0D10E2D12BBB3F905638A4BA52
                              Malicious:false
                              Reputation:unknown
                              Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">.<title>400 Bad Request</title>.<h1>Bad Request</h1>.<p>&lt;function Binary.get_fonts at 0x7f5202374dc0&gt;, /web/sign/get_fonts/: Function declared as capable of handling request of type 'json' but called with a request of type 'http'</p>.
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 5344
                              Category:downloaded
                              Size (bytes):1444
                              Entropy (8bit):7.859232652354463
                              Encrypted:false
                              SSDEEP:
                              MD5:F4DC939E1ED1B242A85165E67A3707BD
                              SHA1:0ABB6661A813CC17DEAE1668400DAC12185A479D
                              SHA-256:CF11DF2958C552618BAF06B0A2BA0F5470956003533FE68B572E8D3058F394FF
                              SHA-512:D8548BBD0150834611DE3F0C85171B20054BC7BDBE7E99965D6FC981A789F8119E412E18CB40CB359CB90525E5B7974BAE17CA9561DE41B29854384E0C18ACA1
                              Malicious:false
                              Reputation:unknown
                              URL:http://www.techlift.ca/portal_rating/static/src/xml/portal_tools.xml
                              Preview:...........X[o.6.~.`U.J..J:t.2......0`..`0h...H.A.N.6.}...LYR.......\.scv.XWd..R....*"L...b.G...1.!........5L.^.Q...8}...`y.UL3.g....'3.$...?R.Z-.5@u...P...?........pa...H...h.F.f...T..r...[.h..^.*8..IBB...ASs@...e.H...(..p.3...S.=)*.u....[jn..B.8(F.I.9T.....lQ..[..\...7n9&7$..Lpb.P.iR.%....'..I...C..pc..7...n%...&...#.f.W..D.......q.d..uE..J...$.U..y.....9Y...+.....-c....V.|..!...x...G.,+Z.'...g. K.1N....8*.*.w`.a....(d........533.5.....v..t.)@.....`....C.........]a.$.|@.v.Y...>2.|.D T.$...j.\...T..w......b../6N/.>..E.3.....c:...J...6t...Pm....O...e........&=......W/.........3Aa7.st*.E.M.{..Std..AD...>H...$..d..}D....Q.x.....*.\H....4.{....C..5.......3D7....1..._.\8....B7.C4DhP.Zq....Dg...X..*....K(.c.5tY.&...%..FhX..m:....).<.w.S.2../.pl...U.0H..rI.+d-....e.+........`......6.u,..+!B>(...f8.-..A.b..fjtI.s.L....).yefJ...g.......c..@3T4_0....T.......~.......MC/...G.`......fs..w.uKK...?.g....g4.<.....m_...X....G.b. ........i/Ij. ..m3..
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text
                              Category:downloaded
                              Size (bytes):11064
                              Entropy (8bit):5.434791713418542
                              Encrypted:false
                              SSDEEP:
                              MD5:ACDA726ED56EE5C80706788F85AE7D7D
                              SHA1:8F28B484D17E511FEB89A65D5EE28CEB3F7E6674
                              SHA-256:5C3FAE529989A89A7D6E81D3B3CF9DD28206DC877394AA6EECC281E4B4797844
                              SHA-512:106313EAB8DB9BA8135213037AE733F6E1EAB4F9FCFE86EDBB17C1F8682410BBA0E9FAD6082C8D64957DA7EA33FDB42F7C2A08C7788D2FB91F3310CAC8FFD811
                              Malicious:false
                              Reputation:unknown
                              URL:"https://fonts.googleapis.com/css?family=Raleway:300,300i,400,400i,700,700i&display=swap"
                              Preview:/* cyrillic-ext */.@font-face {. font-family: 'Raleway';. font-style: italic;. font-weight: 300;. font-display: swap;. src: url(https://fonts.gstatic.com/s/raleway/v34/1Ptsg8zYS_SKggPNyCg4QIFqPfE.woff2) format('woff2');. unicode-range: U+0460-052F, U+1C80-1C8A, U+20B4, U+2DE0-2DFF, U+A640-A69F, U+FE2E-FE2F;.}./* cyrillic */.@font-face {. font-family: 'Raleway';. font-style: italic;. font-weight: 300;. font-display: swap;. src: url(https://fonts.gstatic.com/s/raleway/v34/1Ptsg8zYS_SKggPNyCg4SYFqPfE.woff2) format('woff2');. unicode-range: U+0301, U+0400-045F, U+0490-0491, U+04B0-04B1, U+2116;.}./* vietnamese */.@font-face {. font-family: 'Raleway';. font-style: italic;. font-weight: 300;. font-display: swap;. src: url(https://fonts.gstatic.com/s/raleway/v34/1Ptsg8zYS_SKggPNyCg4QoFqPfE.woff2) format('woff2');. unicode-range: U+0102-0103, U+0110-0111, U+0128-0129, U+0168-0169, U+01A0-01A1, U+01AF-01B0, U+0300-0301, U+0303-0304, U+0308-0309, U+0323, U+0329, U+1EA0-1EF9, U+
                              File type:SMTP mail, ASCII text, with very long lines (459), with CRLF line terminators
                              Entropy (8bit):6.047194286417916
                              TrID:
                              • E-Mail message (Var. 1) (20512/2) 100.00%
                              File name:original.eml
                              File size:243'555 bytes
                              MD5:96c43f66e14e2fa5782d19584b26f335
                              SHA1:3e56151ad9584754141986f6374fac15afe157e0
                              SHA256:44c374171a3dfc7380266297d4952b51e3c81980fdcf9c17b8a61278198fffca
                              SHA512:0790b3e18b9d5de82245545286cf8bcb60ddfcd05b5299be51fbdb9414c7fc6f27a8b5dd81cc536f6ff67a62c1f4094092cf2905b40b4a4ae66658cec66295be
                              SSDEEP:6144:h4ISuDv4U4ArXuT4PVNR58c4cdX9OiZxdlyeghmUpd0gFs/Xz:h4IShAXu0Vp4AgiZxfyegP2z
                              TLSH:E534CE37938029A4CB55492BD017767E3FB41BC7CDB128FD279ABE2B978CCB29194148
                              File Content Preview:Return-Path: <dany.ratte@metalus.qc.ca>..Received: from YT3PR01CU008.outbound.protection.outlook.com (mail-canadacentralazon11020103.outbound.protection.outlook.com [52.101.189.103]).. by inbound-smtp.us-east-1.amazonaws.com with SMTP id 4ipabbfal85lj03ot
                              Subject:[Phish Alert] BT154296 Rapport
                              From:Dany Ratte <dany.ratte@metalus.qc.ca>
                              To:"c9025caf-ebfb-4a55-8a88-3cf1915dac7c@ca.phisher.knowbe4.com" <c9025caf-ebfb-4a55-8a88-3cf1915dac7c@ca.phisher.knowbe4.com>
                              Cc:
                              BCC:
                              Date:Tue, 14 Jan 2025 14:24:57 +0000
                              Communications:
                              • Vous nobtenez pas souvent de-mail partir de shamil@techlift.ca. Pourquoi cest important<https://aka.ms/LearnAboutSenderIdentification> Avertissement: Ce courriel provient d'un expditeur externe. Ne cliquez sur aucun lien et n'ouvrez pas de pice jointe, sauf si vous connaissez l'expditeur et si le contenu est fiable Votre Tche BT154296 [TECHLIFT (SIGE SOCIAL)] ________________________________ Cher METALUS PLAN VICTORIAVILLE, Voici le rapport de notre intervention sur site. Signer le rapport <http://www.techlift.ca/my/task/166767/worksheet/fsm?access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6> N'hsitez pas nous contacter si vous avez des questions. Cordialement, Voir Tche <http://www.techlift.ca/mail/view?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6&auth_signup_token=eTAQ1X91NMP6dRJVqneq> ________________________________ TECHLIFT (SIGE SOCIAL) 1 833 Techlift | web@techlift.ca<mailto:web@techlift.ca> | http://www.techlift.ca <http://www.techlift.ca/> Fourni par Odoo<https://www.odoo.com/?utm_source=db&utm_medium=email> Dany Ratte Directeur des achats 819-475-3114 #226 Victoriaville, QC [https://raw.githubusercontent.com/Metalus-Inc/signature/main/logocarteMetalusBleuWhiteSmall.png] [https://raw.githubusercontent.com/Metalus-Inc/signature/main/logofacebooksmall.png]<https://www.facebook.com/MetalusInc/> [https://raw.githubusercontent.com/Metalus-Inc/signature/main/logolinkedsmall.png] <https://ca.linkedin.com/company/m-talus> [https://raw.githubusercontent.com/Metalus-Inc/signature/main/logoinstasmall.png] <https://www.instagram.com/metalusinc/> [https://raw.githubusercontent.com/Metalus-Inc/signature/main/FR-SCEAU%20300%20PME%20-%202024.png]
                              Attachments:
                              • Worksheet BT154296 - METALUS PLAN VICTORIAVILLE.pdf
                              • phish_alert_sp2_2.0.0.0.eml
                              Key Value
                              Return-Path<dany.ratte@metalus.qc.ca>
                              Receivedfrom YT2PR01MB5902.CANPRD01.PROD.OUTLOOK.COM ([fe80::7c97:a276:a7af:a379]) by YT2PR01MB5902.CANPRD01.PROD.OUTLOOK.COM ([fe80::7c97:a276:a7af:a379%3]) with mapi id 15.20.8356.010; Tue, 14 Jan 2025 14:24:57 +0000
                              Received-SPFpass (spfCheck: domain of metalus.qc.ca designates 52.101.189.103 as permitted sender) client-ip=52.101.189.103; envelope-from=dany.ratte@metalus.qc.ca; helo=YT3PR01CU008.outbound.protection.outlook.com;
                              Authentication-Resultsamazonses.com; spf=pass (spfCheck: domain of metalus.qc.ca designates 52.101.189.103 as permitted sender) client-ip=52.101.189.103; envelope-from=dany.ratte@metalus.qc.ca; helo=YT3PR01CU008.outbound.protection.outlook.com; dkim=pass header.i=@metalusinc.onmicrosoft.com; dmarc=pass header.from=metalus.qc.ca;
                              X-SES-RECEIPTAEFBQUFBQUFBQUFHOEJJUFYzRGdUbllNKzAyd01zYktMek12RGZmK1Y4RWdUZnpzQlhZdzlWOUhhQjRzSTVubFIyOEVwMXgvUjR0aHdkbnJXYnU1S0o1RUl4emczaW5hcXpZQXdBK2d5TzBBQ0J2UWwwT1ROT0dVcWhPRVh5clErRnpicWhIYWJDdnNaQ1hnTlpYSG5XRHdLSEF3WWY2dXRjd1I4cjd0RFN6UndTWkd1M2I5V2FvUStLM2M2K252VzE5WXVieUNkRU5VSGZxemV0NGI2TkMvekZPTFhmdGFlRWsrVnN1Wkg0bTJIRzJGQkZMazBtSlpzOUVDZjlOTnZab1JRUkJjZmFMY0hjUzhpbTVtQUk2bXZUejgyck84eURQdXQwYnVpRWQ5cE1GempMdW9sMEd2eEJ2aHdQR0ZHeFVGa3g4Z3RmV3c9
                              X-SES-DKIM-SIGNATUREa=rsa-sha256; q=dns/txt; b=a/HwiU/9Q2iVkMK+VNMVQNgZ01t9vohBrpXbuQcZ9wiypqc3W6NU5ySAc4Sr2RPq1dolZUhBssVJ7p8XreRo3GL7BgoFt7MBZXtANJwe0yC1GK0JaIQVjWGOUmnIqeCNcjwgBxzB5QoAvJkn4joEmTN/w5yIeZF5eIcud+UFr4U=; c=relaxed/simple; s=ug7nbtf4gccmlpwj322ax3p6ow6yfsug; d=amazonses.com; t=1736864700; v=1; bh=t9kFyp28PrA5e3fk1kxLQvNefk4qwS57j8ftKdOH3QM=; h=From:To:Cc:Bcc:Subject:Date:Message-ID:MIME-Version:Content-Type:X-SES-RECEIPT;
                              ARC-Seali=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=El0G4FvrH760NU28wmyNovNH0lU6fLgXZlbPPwNVc/uaOuoO0FW69KI8R0hZmHD0D5KU6sBL+8f7y5hhTE5ULqCFGcFh5Zulm+1RYA14JtuAFKesV057zQBN2apxleXd9TdPTnug1XsFO9xSZwsN7cwHY0bTq9BWcRTM+9TPtSjgzhKCKtAHm/z90fOvZz0Yt80pv0nTyhxMxcGVCnNhm/il+btt3tHS6lE79tzQv4wUSmrMYVrzcijhGlPbYHRp31Qa6X76y/g7+xblHVCn2EIzmCf8ROZIZ9MjQd9lnmL5KUd7aTyEB09cHzPx/WD/wr+5q3JG+B/A8Inh7+Lj5A==
                              ARC-Message-Signaturei=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=TTvxgXKer2vt3XR3QBQ2lY0QCes2bNnZ1xyXDUZyLfw=; b=KMf9/MyQecVbmIUiF06jW3cArGeWsRNIJK4Ya8hfMpvYNPSjI4pLYXkSLhB6yzF2B+k6+eHeqN8zeSWdHRT/0Zhedyt6Ojqt8Noxo5ISfyWnEO4PywixjWE1tsujgR5qCe3iiysra8Hr1S3gIOdJ5nwRNa4Nf4TH6EOsXXJ56OTfBxpPF2vW8uE+v9nL8jjyC6lpQhfjrhROXTvw6BYMBmDBvxO6dhRoqTrrd+wAL3nR2qtwZR5B1AvBv3vzrfeztoXOdbnu97wzUXebKKMzztE/KTvTFL/E1Z01CVTQQLYFv6odgeiI9HApGnP06XsLcaKWCXXMOAJfY6sypUNuzw==
                              ARC-Authentication-Resultsi=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=metalus.qc.ca; dmarc=pass action=none header.from=metalus.qc.ca; dkim=pass header.d=metalus.qc.ca; arc=none
                              DKIM-Signaturev=1; a=rsa-sha256; c=relaxed/relaxed; d=metalusinc.onmicrosoft.com; s=selector1-metalusinc-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=TTvxgXKer2vt3XR3QBQ2lY0QCes2bNnZ1xyXDUZyLfw=; b=ZoXXaANQ7dGqf0efAYt1YGblpEzpD1pHwD4X0novC7z1wqRFmAs5jaBgWxnKy5Tg//d+V3eLBYOjWKVzc56M4t16vMGw8QlwFIzLt6t/3omSHU5nuf6u6/50XKIbPba10neNanV+BenNc3KdXRb0oD12P+u2rF9PBX5o3bAMYW0=
                              FromDany Ratte <dany.ratte@metalus.qc.ca>
                              To"c9025caf-ebfb-4a55-8a88-3cf1915dac7c@ca.phisher.knowbe4.com" <c9025caf-ebfb-4a55-8a88-3cf1915dac7c@ca.phisher.knowbe4.com>
                              Subject[Phish Alert] BT154296 Rapport
                              Thread-Topic[Phish Alert] BT154296 Rapport
                              Thread-IndexAQHbZomhBVA7VOSlu0GGLkLPjHc6OLMWUxnb
                              DateTue, 14 Jan 2025 14:24:57 +0000
                              Message-ID <YT2PR01MB5902B2566F657096A055BC3AD7182@YT2PR01MB5902.CANPRD01.PROD.OUTLOOK.COM>
                              References <321142741700100.1736519291.417025327682495-openerp-166767-project.task@ampv177> <213102271628307.1736861886.346633911132812-openerp-166767-project.task@ampv177> <213102271628307.1736861886.346633911132812-openerp-166767-project.task@ampv177>
                              In-Reply-To <213102271628307.1736861886.346633911132812-openerp-166767-project.task@ampv177>
                              Accept-Languagefr-FR, en-US
                              Content-Languageen-US
                              X-MS-Has-Attachyes
                              X-MS-TNEF-Correlator
                              authentication-resultsdkim=none (message not signed) header.d=none;dmarc=none action=none header.from=metalus.qc.ca;
                              x-ms-publictraffictypeEmail
                              x-ms-traffictypediagnosticYT2PR01MB5902:EE_|YT2PR01MB8261:EE_
                              x-ms-office365-filtering-correlation-ide2b568eb-63a8-48bd-4559-08dd34a73901
                              x-ms-exchange-atpmessagepropertiesSA
                              x-ms-exchange-senderadcheck1
                              x-ms-exchange-antispam-relay0
                              x-microsoft-antispam BCL:0;ARA:13230040|69100299015|376014|1800799024|366016|8096899003|38070700018;
                              x-microsoft-antispam-message-info zKeCm3TVVekPyy24gv9kqkqwTB8j9HKUdeQso/WtTY/DNTjvTNgLVIqJ5ToucI0jhTJhoKzi3+X2sKcntCNGaR2O1I2sJtGlD/s9RobZLYvLXzrv/wg03R6xUbILys4xxxnfHQoQQ9UrQOv3gI84BPOFogeIus3lfcgcSq1imcIbk9E2IWySaEXM4AvkF8OIQ3Uo+5H98XnB43tF6K6uNPPSsT3RyVmYq9Uiu/ZIcAvChvyoDXJlaowhMOpap5M96LBD17toqcWbbcohi2G2EqFJR5kTR8lxher63jGnNihC7bHT9VxQszm8b9i9+6JbPBuZqgWcSFzekBVb5xT1aBRH6l4Xsnb0QGnP8YDrVdkOHSRTcXdtyiFIC3+RI1r8itHNp7p1Wi3j9W30uQUCDNyR66afCcnTlkDPKb0DSQYSGC+JCmoY4bHIygOWWq2558kdSMd3BBzzXJgshw3iaCL5MbDNbhsne1LOARZ+bJ8QguM8XFFdpLNA77Kj94NACuzfhfexxPxhAxO13ayyqxE94ZCvwnNZrMwlVKoUvBZP1k7vdAYe7tQoCQoZJhPLzb6On4HvoPsmBvAtYcwloD2cISzRJT0hFQJr8NxI9YegEP650QWZvmFrf2v+p7mrS3bq01bLBvEEiQiI3fJtmpIQdL3+5n5wtq2IUUqQSXl3lyjd4GxMPgwnJo/7030H7L/g0mkpFXJ2zymu4goR8/Qe3QWZQVy4rv2WGj4u4Daz6LCZOxTFqcX1Mr6lTkcFr/bxgLnvfc+oNINfwZfSy22vnTZPOO6J/4J/UrF6G+nDv0cKtG8JquITkzYv9F05Li7BLfA1ZedDQv6kH20GWOAG1a65PBG928K4V+q5yM1ZqLbSicAwvvN0ZaRKYVnWHG6TecY7CzZPxPIV6cTPoZ41EvYG7ZcULKDrXzotDr+5eYKYpcpVdeIdspcx1SNJbaZ+x8TCFn6m+KWm3QWC48yQy1Ra1ekj1GQ6IeQ/EA2F9roPiksoSrp2tNsIWBuzl/c4JfekjzU0g3oKIYZlhMQr4AHYCPHQJPuwq3cI5nCsw5PZextfF/9FwuvABkfZVwYMvfWgqN5XYT8y/3HuWk7dUg2DpyOBQkdhtn7TUTGs3JpgBIDt/423Ojd7XbjmlMg48u5xD7Zpf6L0gPOxvyjQ6etbS+ogEI6apcekSxiTw4YS03ELk6DSiR3XR7E3AA6G1ChHR24YoFvDH6RtiObZAcY+gzdgJOq3v1GWvrAvdm4PtPXpoKepGiVifqzcnZf930GRupPLFa4I6R3G061DdX9sRb8GGt9Xwn3Wq5x9j7VBG2Iy8/pZaoz9E2cs
                              x-forefront-antispam-report CIP:255.255.255.255;CTRY:;LANG:fr;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:YT2PR01MB5902.CANPRD01.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(69100299015)(376014)(1800799024)(366016)(8096899003)(38070700018);DIR:OUT;SFP:1102;
                              x-ms-exchange-antispam-messagedata-chunkcount1
                              x-ms-exchange-antispam-messagedata-0 RiZCk2rOMJ5lZnrVs1WFZ46BrmJGRgEu1bktH0qMGcH78JDthdHr48LsO8/0uETCpvvxep4Da8FvQUxp9RSr/9z5jY+CPiReA9cb1o6Ej8ujOML4tQZyLnggedkJt+DXOAZWUsML7ZwNVlfkzVVCQZ6jJ7w9GRl5QlqK8MlFUQslvDWokIXlYc54arbfd+FE4X34MXR7TIoC5PiV6UkUC0B0DT9t3pAfIgUVrP5XLHONEctN5ZgtIXGDTDm9Zs3XfTExrSDuO1DSFBecgqzO7FjIk8CVHbYEJOGs71MvfpaW8y92ZFvvY8hGW18ODS09dz5eT1Fezdt0WDL4oc8k8Cdu9PJhn8gdrz07o2d6fvHRUf/HQUYqN4UHubAis5MVg/eppW5DjTB+UtwYJ3vPwYmY0yLhyeocbWETTzHfjZQQ4czTf67kIgwUjxyWXc9d3tIlfCqMFZjKFR01Wr3FCDxy5kQjrLtCQ4h8ERzQAPh1H2O4MTDA9aljySA3SkRU1GknpX4cReBLMs9uwmvZTxUbFLCsZU6F7OvCyURk9iJjzxdr6lNDFAWvNDns3HdMzWZS4pgnR8fUD4vkleZRBkPdO8DfHb2MwL83mHFtF5j6Sq8CrIHoNIhkzuDlenmX34QioFiA3nVsQaYmgs/MdNFCig2/IBlmK+GFmwu53Wwp72q3PxN2I3Z0avpEXJ7F9nBM16ZBOSLxqlfh4yHPp/ME8ur0jzrMXASWHk5U/Z0vlP81RlLphphz+OW0PHAWucK+BXvIJ29aFoSrN+ar+u1bZWfm+hXphAsvvNmhT76yz7WPTgIEliPAoQx9ImoMGhX9No5+4lNWNBTYa0+qL53gGoxw6DmgGMPZLFrsGh0QjNfhtXJx1nzOR4aolRFXMRPtCYWUdP10ktlTw7h71XWZaal9lv85jMqipVWx/aPfLDkHR0haFYUAjsW/cunq17VwKSTIx6Mf6qX9sEk5RA2DZLqG9za1GuZpWvbE4wpIXmAN1EPizWX8BreW9YUOm9k2yc7MZIyyE8E0+LRKkvApqccqdF8H39FeyBjcyQBreZR9Dg53Gj65KtZ/AfK2JAVb7qegAKoLqe+RCd6JUPQ9Dzn8BLFQ4RV818T2lyo8PpZgcUeiv4ZJSjG379xy3HLbnmb7pZUAx4r/cSMFpipsWzDMaWSEkGEGXZzTZnv9ZbDahnyKXXopiBd5QNFvwH3zCxBONX9GSqw1A7nov8C4T/TBU/foBUbMpb35YnVo0DLDvqs6wsFeDS61DQBN70DUh0Krbwdu+lyJxV66OX0e5o2VfS3FeA8NQxc9tfjERv4Jp3IOaqY+DqGpG/rciLL+1uSpatyhr/WVg674nftOQB2maf6fsrXP7A6DQ4NAnsJWw671tVRPjY0DpbNxgeVFWAiDrfe/QI6oXVQQ6hLFObuof/EDk/w1cJ823TRI3oK0c59F6opVZcTtipNvspsBSH34phlOdPKuBF9bGzzWQxhv5Pg30LMHGWtxxNxuJI4v2sRikY0Kex/j1H5Butw3WtrPDPS8yMltp7s+DQekVsKA/CVMn2J7VCWQqs+R/F0nMB1J9tZtREKKbEHY
                              Content-Typemultipart/mixed; boundary="_005_YT2PR01MB5902B2566F657096A055BC3AD7182YT2PR01MB5902CANP_"
                              MIME-Version1.0
                              X-OriginatorOrgmetalus.qc.ca
                              X-MS-Exchange-CrossTenant-AuthAsInternal
                              X-MS-Exchange-CrossTenant-AuthSourceYT2PR01MB5902.CANPRD01.PROD.OUTLOOK.COM
                              X-MS-Exchange-CrossTenant-Network-Message-Ide2b568eb-63a8-48bd-4559-08dd34a73901
                              X-MS-Exchange-CrossTenant-originalarrivaltime14 Jan 2025 14:24:57.6486 (UTC)
                              X-MS-Exchange-CrossTenant-fromentityheaderHosted
                              X-MS-Exchange-CrossTenant-id4f85cc14-eaa8-4e0b-8291-93aab6969f78
                              X-MS-Exchange-CrossTenant-mailboxtypeHOSTED
                              X-MS-Exchange-CrossTenant-userprincipalnameJ+sxeTeNY4LpToO6eFGPQYdgqL+S0PDgIu9QPdBFa7nDqZIWO5itjefT4ynlUe8lt8oZdHgjBjx3367P/jCyH2k7DSv5vhVcSKDaNf2bC2k=
                              X-MS-Exchange-Transport-CrossTenantHeadersStampedYT2PR01MB8261

                              Icon Hash:46070c0a8e0c67d6