Windows
Analysis Report
original.eml
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- OUTLOOK.EXE (PID: 6840 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \Root\Offi ce16\OUTLO OK.EXE" /e ml "C:\Use rs\user\De sktop\orig inal.eml" MD5: 91A5292942864110ED734005B7E005C0) - ai.exe (PID: 6576 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \root\vfs\ ProgramFil esCommonX6 4\Microsof t Shared\O ffice16\ai .exe" "A27 B1353-F78E -41CB-B0F8 -11E7263BE 425" "F4A2 E0B0-23B1- 4F6F-94CF- 29A684FB31 9C" "6840" "C:\Progr am Files ( x86)\Micro soft Offic e\Root\Off ice16\OUTL OOK.EXE" " WordCombin edFloatieL reOnline.o nnx" MD5: EC652BEDD90E089D9406AFED89A8A8BD) - OUTLOOK.EXE (PID: 5404 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \root\Offi ce16\OUTLO OK.EXE" /e ml "C:\Use rs\user\Ap pData\Loca l\Microsof t\Windows\ INetCache\ Content.Ou tlook\KQHS MYVS\phish _alert_sp2 _2.0.0.0.e ml" MD5: 91A5292942864110ED734005B7E005C0) - Acrobat.exe (PID: 6360 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Micro soft\Windo ws\INetCac he\Content .Outlook\K QHSMYVS\Wo rksheet BT 154296 - M ETALUS PLA N VICTORIA VILLE.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 6416 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 6756 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=22 48 --field -trial-han dle=1556,i ,756146435 4657488856 ,135888451 5024351852 5,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - chrome.exe (PID: 4016 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// can01.safe links.prot ection.out look.com/? url=http%3 A%2F%2Fwww .techlift. ca%2Fmail% 2Fview%3Fm odel%3Dpro ject.task% 26res_id%3 D166767%26 access_tok en%3Db8f79 f62-9a1a-4 f0f-8b02-a d8868e93ff 6%26auth_s ignup_toke n%3DeTAQ1X 91NMP6dRJV qneq&data= 05%7C02%7C dany.ratte %40metalus .qc.ca%7C5 3624b36948 c4e181b550 8dd34a0b22 b%7C4f85cc 14eaa84e0b 829193aab6 969f78%7C0 %7C0%7C638 7245872375 91513%7CUn known%7CTW FpbGZsb3d8 eyJFbXB0eU 1hcGkiOnRy dWUsIlYiOi IwLjAuMDAw MCIsIlAiOi JXaW4zMiIs IkFOIjoiTW FpbCIsIldU IjoyfQ%3D% 3D%7C0%7C% 7C%7C&sdat a=ev37I7Vo FUBfa7Lk84 FtS%2BnKwD Pw9NN1cCQV VWEXz7Q%3D &reserved= 0 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6928 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2148 --fi eld-trial- handle=186 8,i,146927 9643803985 6495,12729 4673699490 85797,2621 44 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction / prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: frack113: |
Click to jump to signature section
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | Joe Sandbox AI: |
Source: | Classification: |
Source: | Memory has grown: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | File created: |
Source: | File created: |
Source: | File read: |
Source: | Key opened: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: | ||
Source: | Section loaded: |
Source: | Key value queried: |
Source: | Window found: |
Source: | Window detected: |
Source: | Key opened: |
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: |
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: | ||
Source: | Process information set: |
Source: | File Volume queried: |
Source: | Process information queried: |
Source: | Queries volume information: |
Source: | Key value queried: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 21 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 DLL Side-Loading | Security Account Manager | 14 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 Extra Window Memory Injection | 1 Extra Window Memory Injection | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 4 Application Layer Protocol | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
can01.safelinks.eop-tm2.outlook.com | 104.47.75.220 | true | false | unknown | |
bg.microsoft.map.fastly.net | 199.232.214.172 | true | false | high | |
analytics-alv.google.com | 216.239.38.181 | true | false | high | |
googleads.g.doubleclick.net | 142.250.185.98 | true | false | high | |
edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com | 217.20.57.34 | true | false | high | |
techlift.odoo.com | 35.224.169.167 | true | false | unknown | |
www.google.com | 142.250.186.164 | true | false | high | |
stats.g.doubleclick.net | 173.194.76.157 | true | false | high | |
can01.safelinks.protection.outlook.com | unknown | unknown | false | high | |
www.techlift.ca | unknown | unknown | false | unknown | |
x1.i.lencr.org | unknown | unknown | false | high | |
analytics.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false | unknown | ||
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false | unknown | ||
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
173.194.76.157 | stats.g.doubleclick.net | United States | 15169 | GOOGLEUS | false | |
52.109.89.119 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
216.239.38.181 | analytics-alv.google.com | United States | 15169 | GOOGLEUS | false | |
216.58.206.36 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.185.202 | unknown | United States | 15169 | GOOGLEUS | false | |
23.56.162.204 | unknown | United States | 16625 | AKAMAI-ASUS | false | |
23.209.209.135 | unknown | United States | 23693 | TELKOMSEL-ASN-IDPTTelekomunikasiSelularID | false | |
52.109.32.97 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
199.232.214.172 | bg.microsoft.map.fastly.net | United States | 54113 | FASTLYUS | false | |
142.250.184.227 | unknown | United States | 15169 | GOOGLEUS | false | |
172.64.41.3 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
52.113.194.132 | unknown | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
54.224.241.105 | unknown | United States | 14618 | AMAZON-AESUS | false | |
1.1.1.1 | unknown | Australia | 13335 | CLOUDFLARENETUS | false | |
172.217.18.8 | unknown | United States | 15169 | GOOGLEUS | false | |
74.125.133.84 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.184.194 | unknown | United States | 15169 | GOOGLEUS | false | |
2.23.240.205 | unknown | European Union | 8781 | QA-ISPQA | false | |
142.250.185.136 | unknown | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.185.195 | unknown | United States | 15169 | GOOGLEUS | false | |
104.47.75.220 | can01.safelinks.eop-tm2.outlook.com | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
35.224.169.167 | techlift.odoo.com | United States | 15169 | GOOGLEUS | false | |
142.250.186.164 | www.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.184.238 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.185.74 | unknown | United States | 15169 | GOOGLEUS | false | |
20.42.73.31 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false | |
172.217.18.100 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.185.98 | googleads.g.doubleclick.net | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1590925 |
Start date and time: | 2025-01-14 15:35:26 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 22 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | stream |
Analysis stop reason: | Timeout |
Sample name: | original.eml |
Detection: | MAL |
Classification: | mal48.winEML@38/104@21/172 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe
- Excluded IPs from analysis (whitelisted): 2.23.242.162
- Excluded domains from analysis (whitelisted): fs.microsoft.com, e16604.g.akamaiedge.net, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtQueryAttributesFile calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtSetValueKey calls found.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: can01.safelinks.eop-tm2.outlook.com
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.188867494932004 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8FD411E05C6A9463CF26B946A38B0D61 |
SHA1: | 772D30E096BB6A51AABDE513FAD9DBC5E216C60F |
SHA-256: | 1DAE14437BA4921F95ECACEFDA5B9F870DA80F9321C5DB7A523D5B1A358B273C |
SHA-512: | 1C6078ACB52A943E65415A9F1BACF38D0FEBE1DA7E7B9642BA6D53D1DDC11FD6FC219CED2FEF97B2E4E27194815DAFC81D45D460C3920977BB5F02F1E16E70D2 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.21190461716513 |
Encrypted: | false |
SSDEEP: | |
MD5: | 664DFF188F91CDF3FB8C9B369CEC87C0 |
SHA1: | AE4D86A69B48D3A38B69D5AFA4B00253F52FB041 |
SHA-256: | 62C48CDCE62F1C998B8EB595A6D9932FB12AD99160F3DF26EFC242905EAA557A |
SHA-512: | 53DF42BD51C9118145CA631479500EBBA534F392E613FFB1596A9E2A9D3EEBBA6358F5D6D73185586DC0CBE528EA45546BC74D4EC4AE622CC63305AC3CBC85A2 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\9dc5b654-0d97-49dd-9c62-4fc062dcc53a.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 403 |
Entropy (8bit): | 4.9699165732968 |
Encrypted: | false |
SSDEEP: | |
MD5: | A93586925464029BB36C90E69C7B3DA1 |
SHA1: | B9DA34D49A3E6AD56EC8016E20DEC7C0066BAE42 |
SHA-256: | EABB0D72875F438B47CAEC43EAC5F82693420CD633D5500BB0BAAF5832CD7600 |
SHA-512: | 01FF255615D0A71A57097DB2FF6D1A662BE1640F49AF09A7D49AAA23B72E8E2F6E2268C7A4B25C0DF6B897005822E9ABBCF2C10938E799D5ED072C8513504061 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 0 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | |
MD5: | A93586925464029BB36C90E69C7B3DA1 |
SHA1: | B9DA34D49A3E6AD56EC8016E20DEC7C0066BAE42 |
SHA-256: | EABB0D72875F438B47CAEC43EAC5F82693420CD633D5500BB0BAAF5832CD7600 |
SHA-512: | 01FF255615D0A71A57097DB2FF6D1A662BE1640F49AF09A7D49AAA23B72E8E2F6E2268C7A4B25C0DF6B897005822E9ABBCF2C10938E799D5ED072C8513504061 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.233354969637357 |
Encrypted: | false |
SSDEEP: | |
MD5: | D2545FFF03D669E9E55778BE1AAA9FB6 |
SHA1: | AD7EC2E86BD135D847DE9A10AF115E97A0017DB7 |
SHA-256: | 45D48EB00B2B1C096EF72660961ACB22450561B836A993815B03FBA2ED379612 |
SHA-512: | C76FBE68E747964AD93332B0DF9B10EF443C3A458662CC98A4F927C01BD3CE3C4F4FF7DA08901EA0FADA468BF104F836CC119A90D10D0660FCB45C97D909B533 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.267148347408719 |
Encrypted: | false |
SSDEEP: | |
MD5: | C457A12F7997227A48A4E3FDCF61874D |
SHA1: | 9E85BA66B7E00E8F2E5C69BE62ADDDF6FF46BD91 |
SHA-256: | A88D94A7CFD910BBA1F655E9391127E2E36280FE6EA73391C5E14E126BA39B56 |
SHA-512: | E0666A9CBE5AA9AB03F51BBAD8C3978148DB4F216F50B602C0E6C5262BE3DA120FC7121860F492BF2D3A8724C70431C15A6E9C6E5BA39C628C717E62DD9BEF54 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-250114143702Z-169.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71190 |
Entropy (8bit): | 2.3404177371019603 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3784A93EB5381519B8B956E0B5F3957A |
SHA1: | DC6D776F8B1BC8921C88C3D0B40E455085976FE7 |
SHA-256: | B968D94AECCE07FD61BF4007366E956B0737867F2A7B4E8B6F43B5C889D05ED4 |
SHA-512: | E51D4A385A65179B9564B68AA7F2BBB88BDBAC246122C1D07B4FABD7386B068D034BDCADD83CDB017015A446BCCDFB77009546F4A240260421B188C49BFF5880 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 57344 |
Entropy (8bit): | 3.291927920232006 |
Encrypted: | false |
SSDEEP: | |
MD5: | A4D5FECEFE05F21D6F81ACF4D9A788CF |
SHA1: | 1A9AC236C80F2A2809F7DE374072E2FCCA5A775C |
SHA-256: | 83BE4623D80FFB402FBDEC4125671DF532845A3828A1B378D99BD243A4FD8FF2 |
SHA-512: | FF106C6B9E1EA4B1F3E3AB01FAEA21BA24A885E63DDF0C36EB0A8C3C89A9430FE676039C076C50D7C46DC4E809F6A7E35A4BFED64D9033FEBD6121AC547AA5E9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16928 |
Entropy (8bit): | 1.21288622268763 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4EEF4E040611769DDADE2C8A66AC37F3 |
SHA1: | C9772D2DA90FF4CE7792F9418A2651346B4E5E9F |
SHA-256: | 2152C8D05A5398C3FBB10AA2880C792EFD047E47CF952DA614D28681294EAE90 |
SHA-512: | 1B9667F31342607C68D5AE26741BBC19412518E2FDD146A9A67993D7921D6918034058762D1FF5E01BCB8D29DA569A3B553D8596DCA8E073B02C234508049B30 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.756901573172974 |
Encrypted: | false |
SSDEEP: | |
MD5: | 34E60EA098A96654B59504674ABA7F73 |
SHA1: | 29DD032C0395E6A7F0205B5375C598B409CDCDE8 |
SHA-256: | 0D71A7CCF9375DB52896D9892077EA83ACC397F7EB41F2A9200DE237C2E653D2 |
SHA-512: | 16127F150D20CF60E3DFB7F3B78D4E0F410AD2F243070402A2D25B9F200BF798CB67DE63AAFD2179630EB6BB02D6D4C583B3D413FFFBD7AE2240AEF2ADDCCAD6 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.2478978672539016 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0352D8314CD8007E9EBBB8FC62215A5B |
SHA1: | 611989A4579E6170BC698B7DD11A790417372281 |
SHA-256: | E5470849044B24DD9CE3A7E0A0E3827A31A29CFBAB156552A1C4C5B8254DEAB4 |
SHA-512: | 758A8FB3A10AB8D06D7442DD0AAF814E47AED148649F73FCC6ADA9FE46577601E8C1B46F44AA30962D21931330B2C749E4EEAE46F8A8EE23CECDA39FFE142DA9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.360444744536055 |
Encrypted: | false |
SSDEEP: | |
MD5: | CEDE111B2A83CBB9F4D84DCFF9275186 |
SHA1: | 45C2AA4FF0F348B7014AECE9B118C1A6BAA59A51 |
SHA-256: | 43A3E121A7D156CB0DE39FF45455FF3A3EB42C861160A9BD2D2DF2F08199AF47 |
SHA-512: | B74D212B1520B81CEDA40A8C3132CE499D7864CDA3BD8ED727AACC9A5CB49017A784A8CCE9A9C03AFE0FF241E63720A9EC50AFC5D385D2FF49B65BA1865535BA |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.310136967991502 |
Encrypted: | false |
SSDEEP: | |
MD5: | 092C18FEF662CBD3A5EEE27D70A8E4DE |
SHA1: | 563DB647394DD234BDA1DE464C0C287A741762CA |
SHA-256: | B39227C9A15448C4CB8377165F92EAF3A493B0D34EFB7E095F4BFDB70328C7D1 |
SHA-512: | 861839915DD1B24F3A3B39D00CE036F767A57B936921A2F140478FF894D066AA0B2DFCC582F0D1F7684A3D47ADF956F25E8E342A53AB1B7D060943D7656A4F8C |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.28839646334931 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3803582C25DEBDD73FB16197F4C847F6 |
SHA1: | 663A148110D9F347FE9D87C8E2039F76567F9093 |
SHA-256: | 2FD00533748FD82C9BD7136D365ECEEC8C9981972D76C2426C46732B274F518F |
SHA-512: | 7484B212FA5953C20C12A666BD61FA73E26575659E64B385FADBF49B191346F84C6270584B8AFD69AB76B511729AAC98710D034DE6B52E19D3DA405684B31685 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.3487225247935015 |
Encrypted: | false |
SSDEEP: | |
MD5: | B980F922A9AE3A9E16B1292CB209458A |
SHA1: | EE057E18B70E1E5CB1D7F27C4D07959B4706AB41 |
SHA-256: | 29ECCCC9DB67B5329A11899BF129203F085254989CD7430EA69D86C9FCF16670 |
SHA-512: | 03EE8853B5204C27C140ED367804397187E7A8BB7CD2E7F4F6265E5DF86E2F003E875AD707E9D4EBDF685E91A246871F739F9B9866930F046A32498ECB191AA1 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.693152053187803 |
Encrypted: | false |
SSDEEP: | |
MD5: | 011CF041D58AC6B35D74290BF11CADFE |
SHA1: | 728B131216AE6D0E8B9FA06428836AB3935F87B6 |
SHA-256: | E31A1CDE277735BB483DE109CB1D0C066040CA89891B835886C3197568A92775 |
SHA-512: | 19421760F41285990DF585E6FF551D117E70CEE9FF12FDEBF794381745E8479B66549F1D5CE41BB0853AE78DF860E884F4D0DB89EE989752439E07F3332956A3 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.299713850775975 |
Encrypted: | false |
SSDEEP: | |
MD5: | B3899B8856E0536E03169DA6A82B53B8 |
SHA1: | 83B06F73ADE658510A60F3ECA010D53B8CCE5827 |
SHA-256: | AE635BE39446DC123FBE008AEE209F4E824FB7A339ABD905D63F79591586878B |
SHA-512: | A54EB38E831016376A0F5D0F148DD305EC478EFDFC54C1A5452BF457603F42FA485B758A31B37769D2E73449B869470053B2F93ACC814DD1E7C20C8B55CB2BEB |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.302659842203466 |
Encrypted: | false |
SSDEEP: | |
MD5: | 640EB0E09443A0E7BB870465DCFDB853 |
SHA1: | 8AC6056F1012C89E1C010C8048BA8B2AC7ED6E8B |
SHA-256: | 0064DB6C864AE1A93C55D066FA7434F1AD831E12343C23B6319FC1C5317CE945 |
SHA-512: | 4BA3EF504053B605D753D65EFF1E5BC04AA8306E211400AAC7A2F03FA4EAB78BF3495A43FF1254819FC798C6FAF40DE7918F575197942421DBA7F2CD9FD2EC87 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3112834470550245 |
Encrypted: | false |
SSDEEP: | |
MD5: | 49BE2F6B489C207B8AE3B578BC580CD1 |
SHA1: | 76F3FABDABC79C43BF2ED259720047289F824D2E |
SHA-256: | 22C88E0C6D3F368FC313C5E8CED97FF818B74C6F1D67E779BC988531CC73A0FD |
SHA-512: | F64570004EF621891FC34DBDBF10C0C3ADAAC080558339ACB67F835A0BFBE8E0FABBCD8113DFD23F41FF401A628AE616302948E8F28D7B8FE1EA3C12AD9EEA11 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.325526654692105 |
Encrypted: | false |
SSDEEP: | |
MD5: | 486A7060A2FBAA8882E4701E4A7F1F09 |
SHA1: | 7F8BB2EC5A3F2A7AC18BD072BF231C73191A1461 |
SHA-256: | A9F505F25B5D985A94E0FF6A719158263AFDE0D225F03D6ECDF071440291A342 |
SHA-512: | A45A95E944CF18FCD06A307B3FA8DF1FF6C272890E8D30DC6CAD622E049BBBA5EB5228341416D7A23B07EC9BAEA11BED3B3E31696E8C4AE49961C1C9DBE04070 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.306298349724066 |
Encrypted: | false |
SSDEEP: | |
MD5: | DE77726EE294E92F77536165181F66FB |
SHA1: | 929126DEDDA609811491A3C3FBEE4268FCFF78A4 |
SHA-256: | 57A5C74048E728C89A5F3BDA73E78659FFF4CE915CF63FB1A3D69F2E374AA11E |
SHA-512: | EE19EE06090B2895658741890A1C54FBF25D91A4A62656C3BE8840D527E82EFB5C7C218D5616C07A7D44920678C25DC2AF21821A3C450716A17BBA9280A91FEA |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.292459608985744 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3BD75DC39E80999A4C3EA8237AFACAEC |
SHA1: | 2D7E5E0DD19C21B56E534000F4EFA45AA3BF90F2 |
SHA-256: | 4206335E2D2A8FFECF8A476F5984C0BAE1C96764280B9981751ECC7886FB43E8 |
SHA-512: | 80A72E4A67CE6D52333D4D9A193B608CA05A7BF529511FB52E7C9089DB288E0AA4E9D4A3FC1E810A4E3580E459E0DE5FE21A7ED84EFA05EC636369E3D431F5E6 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.28980215977096 |
Encrypted: | false |
SSDEEP: | |
MD5: | 19DFBAAA7952C3398DB7F46B34733F28 |
SHA1: | 57B6C4DA9938A7417A96CBE9E64DAEDE238BDFBA |
SHA-256: | 7642AB5F80602671BAAA1914C56A65E86F4D48254C57C95B1D0323C4FD6F4EC7 |
SHA-512: | 1DD27BB2DEA25E77ADE80041FA2AFBBA7F8C3A45715D179E7CE5B89F201CB78B3FDD3C6796941A254A4977ECC99371D02E2B230D78DC33DF241C20B91D51A16F |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.293270658650349 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2F3876DB63346D6D105F2348B0AAA5FA |
SHA1: | 33EE4E0E5D5AF19ACCC51B49FB9160A3CBF2D579 |
SHA-256: | 5B0836434BD29336038EDA5A8B773453EA24531C883DBBF5995A4F595B4AAA02 |
SHA-512: | 4022E137F454135AA59E7AC760CB1A076CEF78E0B66194B6A53283EFCB96F78332B9F5D98BE0990A2AE8ED202284A06B05E8E2E0D2B5ED418B1E10E84CD10F97 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.667619335815281 |
Encrypted: | false |
SSDEEP: | |
MD5: | 418F1F54418F13ED480FA4AA160D6838 |
SHA1: | 59B3F1DDA9B7A755E1CF1645466F2EB34D1D3CD7 |
SHA-256: | C34C82AD9C681503F7608680AC9C852682488AE8D164B80DD26B40407DE10F79 |
SHA-512: | F6AA8B61640CA479A025B23E05658563595A175E80EC72F2B81C219BAC621CFF8FFAA661B02E94F88851E93D597579D1BACC413357C110AB85D736E7A34985A5 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.270923126018789 |
Encrypted: | false |
SSDEEP: | |
MD5: | 7449B2CA4BD70CEE0C9CF7418D742A69 |
SHA1: | 413ED6DDAD310384F0894CB2603BA2967B0D0056 |
SHA-256: | 3DA4AECEFE5C336BA3DF96A77BE508FAB9884F3C954147F54DD6D4A1638CF3CE |
SHA-512: | F58A8144E34BB4548409432461F62FA7EED4CCB184427F56517C2D3DC68C4CFF207D03DD81A2A968DD4D5813F3274927D5297382F6CCA007EB9F8B2B2C15FF78 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.2759528892398455 |
Encrypted: | false |
SSDEEP: | |
MD5: | 6073685B0A6995A61F679D8BA8C9CC56 |
SHA1: | AD23A5CE93DF71612C8604DB4CB5E76ABC7E4EC0 |
SHA-256: | D708E3A9571C6744EB16BEB73816DD614F59C24E6FF87F76B6B090D88D45669F |
SHA-512: | 718E0FDD64832F9FD1F71DB3674D062083F7A4E6513CBE00638AFA972E0C3DDB4AC256221CCA848C2C804710C01FAE06F437CD9184A9CD838F437B95198AE23A |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.136622864569504 |
Encrypted: | false |
SSDEEP: | |
MD5: | A76FB65BE9BCB8B4377A043346516DED |
SHA1: | FB4CB726070A1660C4B84303196E2C56227F15A6 |
SHA-256: | FCD7DA792E19DE056E3ECD4F9F53F14AE7F68C19A0A6D438C789912A5B2D3CF3 |
SHA-512: | 86EA4386E293FC67E3A9293530E1FE92EDC1ABF172FE6B1400BA249F4D3F602C851BF76F37390A825DC081D1CD9846C5A1B23776773E4EEF30A23926756726D2 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 0.9884020261887027 |
Encrypted: | false |
SSDEEP: | |
MD5: | A8FB99CBA64EAF7AD57EF0FDDFBCB5CA |
SHA1: | A7B3F8C1FEC673D5E5444C5568E50BA38117AD18 |
SHA-256: | 8A17AD2102123D5E79187A14D473E0D2E402322AA7E1DE4969D383BC133458A2 |
SHA-512: | CA4870A0EB5D53C24FF50F77310A18AA22999422F30E393383121576249B72EED5E905E4CDC6FDE44498F9E85EAD1A33F49ACECE2C5915EA31E510FF50917724 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.344446999809957 |
Encrypted: | false |
SSDEEP: | |
MD5: | F24A96DDC00BB2AFCF40630421AC6F65 |
SHA1: | A351ADC9DE3AD895817422DD8086F561AEBF0200 |
SHA-256: | C060E311BE4A771EA60E8B08653BA2425803638FEEA2009BA00B833AD9500DD8 |
SHA-512: | 95A3D49602D0922D3D5C282B896EB097D4333B84EC473C0E4E70749FBC395ADE47713D46F448FC5644C9E2F1D03BA8E39C28FF13B47D3873B2942C923919FDFA |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | |
MD5: | 47FC6A5550AEB3281860DBD797E9A14C |
SHA1: | 62AEFAA0AA942E91A4B2E2D14361FA438325DB47 |
SHA-256: | 630F955B1F4609EECB56D6886098506C6799CCEDBB35F37E55F368B4F11975BC |
SHA-512: | 209AF4A1B2325B61A35AE1F293F4006865E8FD2BA1BBC015E0C5235F6AEB660C24187998AF1DDA9FFE5CC35656A98C077B4BFCD0C61DFAF69330D8D776AA65DF |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5390718303530573 |
Encrypted: | false |
SSDEEP: | |
MD5: | AB02F743A8D2ED867EA2C57B76DF38A9 |
SHA1: | 8A064EC70CD3E5E990F8F7A8E12CE6F17B007C77 |
SHA-256: | 15FC24CDA6980D162187EF6BFF6015C077FD23905D46CB25017BD4729ADF52A1 |
SHA-512: | 4F642F3B8BD4AC6517208E4304C1E149CB172C2ED46A34655A3ECDCD028696740C0E9674521AE2D7597F0147FDBF75CC9222E376B22F305FAE404222D8DEDFD6 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20250114T0936380105-6840.etl
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | modified |
Size (bytes): | 118784 |
Entropy (8bit): | 4.513100762077878 |
Encrypted: | false |
SSDEEP: | |
MD5: | DE2BF2669C5B915B67B2833517C021A3 |
SHA1: | 8E92C740530B3B4F2BECD116F3FFC0C0D813CC6E |
SHA-256: | 3E3255F07DE16D3FABFA25059BF530EEF6AFC1FB66D815AB6AEA2A23FFBF2F47 |
SHA-512: | A0392746768C6F9A8B26F8FE8249548581D433AFB6615BA39CF3F22FBCE021BAD4953A0392C770596EAC056EE7148659F6F9D03D01BB34FC4E09F67756527B32 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20250114T0936500163-5404.etl
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 3.553687546821918 |
Encrypted: | false |
SSDEEP: | |
MD5: | BC37E667118384CD4A1348E7B8C0D5A8 |
SHA1: | 058FC38AC696AC426AB4AF72E6CFA5978F3ABD19 |
SHA-256: | 6AD45E23E3599011C7AF0D5B76667CCF99B820F96DE5C89CBE3A7C50200069DB |
SHA-512: | 967DE7A385D79422A97B999A4FE1FCD4529DDFBA5D9AA7D472542EC158DEB3C0BE339FE171C1E9C4EC5BA4F3B75888B73E63F56C23DEC739A60F8A74CC139716 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-14 09-37-00-763.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.353642815103214 |
Encrypted: | false |
SSDEEP: | |
MD5: | 91F06491552FC977E9E8AF47786EE7C1 |
SHA1: | 8FEB27904897FFCC2BE1A985D479D7F75F11CEFC |
SHA-256: | 06582F9F48220653B0CB355A53A9B145DA049C536D00095C57FCB3E941BA90BB |
SHA-512: | A63E6E0D25B88EBB6602885AB8E91167D37267B24516A11F7492F48876D3DDCAE44FFC386E146F3CF6EB4FA6AF251602143F254687B17FCFE6F00783095C5082 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.420386620749323 |
Encrypted: | false |
SSDEEP: | |
MD5: | 11B193961799E7F6A1AAE0C185E0F375 |
SHA1: | 94CC79055225F4B88A42A1AB1D1F4FD332A57A6C |
SHA-256: | EE3BCA5DA4B086F8D76F881EB538A018154A5BFDDFEA06F422CB004B4678FD51 |
SHA-512: | 87A6EDE6DCCEBE67CD5244D8C57E38C914FEF6B87C595D3E07EFDD3096FC213986669E9AF139A91C48D023E5EA9F1F5C6C88582E4A5CFAD93AF863C323674B4A |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | |
MD5: | 59EE5E2FB56A099CAA8EDFD7AF821ED6 |
SHA1: | F5DC4F876768D57B69EC894ADE0A66E813BFED92 |
SHA-256: | E100AAAA4FB2B3D78E3B6475C3B48BE189C5A39F73CFC2D22423F2CE928D3E75 |
SHA-512: | 77A45C89F6019F92576D88AE67B59F9D6D36BA6FDC020419DAB55DBD8492BA97B3DAC18278EB0210F90758B3D643EA8DCF8EC2BD1481930A59B8BB515E7440FE |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | |
MD5: | 1D64D25345DD73F100517644279994E6 |
SHA1: | DE807F82098D469302955DCBE1A963CD6E887737 |
SHA-256: | 0A05C4CE0C4D8527D79A3C9CEE2A8B73475F53E18544622E4656C598BC814DFC |
SHA-512: | C0A37437F84B4895A7566E278046CFD50558AD84120CA0BD2EAD2259CA7A30BD67F0BDC4C043D73257773C607259A64B6F6AE4987C8B43BB47241F3C78EB9416 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | |
MD5: | BE0B75D7B096B44CBB2A7F9140209151 |
SHA1: | FCE18CAA51DF1C9E5FA036FF1D1267212A48AAC2 |
SHA-256: | A571984DB01CF39DA8A828152CDEC864004CB56158C4BF6DFC2888A32A54B0E9 |
SHA-512: | 7090CCAE1C6724F611C54A96D28016FB17E64FA8C9E71EB0A0C8E9034750565068FA279BD2F8FB02A17DC3FC89763D531EEFF4777836E9FDF018ED6BE184E5F3 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9796931204021773 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3C41A4FF18242941D0FA15703724C5BE |
SHA1: | E5E73528577B1A69B0E6DF70018704B23EE60DE0 |
SHA-256: | 5AEDC85B60E7943462D7DE1907EC3ACCB6672F3C93AEF906A019930D7F182B0E |
SHA-512: | 2696CDF61A452FF14F31A63B556A27FEB5F80058DB356B617CF0E055407743C9A0ED98970B191DE080C7AE9B593A1A63CDFB5CC32669E28F636366B151E7C1B8 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 3.996103440733677 |
Encrypted: | false |
SSDEEP: | |
MD5: | E020CDD7498849CED1B94ACDD3C2E507 |
SHA1: | ED0CEA66F00D3C0280BF9B65ACBF0EDF898B5F15 |
SHA-256: | 4DE5E76802D17CC26A102914F95ACA536025FD66220B85E392D838A2C4AFB8A7 |
SHA-512: | D639863AC61F6BC5297A5DF642867ADC4FEDA5CE90E6C4826B850A106F54A4188736F983DADDA6B62B678A910014B0BE7FEFA4914B3F72BB1909024524DFA01C |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.005870319348876 |
Encrypted: | false |
SSDEEP: | |
MD5: | 51A36150AF6BFD8253E6578FE0E467CD |
SHA1: | 69E338AAC5D5696DE7E19AF4F8641C5E1724E5EA |
SHA-256: | DE15F3A260507E7DD076EB8BFC1126D60E617C3337906DC49857D0B9C4FA9D98 |
SHA-512: | 6039CA7B42BA2F835E1BB68871C28FECCFEB29783EF25AA01B4FCB2688E9050E876828A476BA1FC749744BDE910E97A8278F776D2F9D84D4310B1CD5C05BBC02 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9942672723846604 |
Encrypted: | false |
SSDEEP: | |
MD5: | 65E9525B0644A691250EBA1127AFEF28 |
SHA1: | 9FBEB9F6C08B515EB0FCB15E9558368397852B19 |
SHA-256: | CA011E88B029543859342889A9BEDCE378E318845B40049802552EC07185504D |
SHA-512: | D881E6C0224683C4FEA1C2E0C8293FDA70DD5EF192128F5FE9463CE3FADD375610E2BBDB5550E7268A87E7F25F4457B6D98A834D9BA790F49D53B34C70CBF71A |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.98588685600956 |
Encrypted: | false |
SSDEEP: | |
MD5: | EB2F617E1922A0ED7ABF7E2EA4FDB9D2 |
SHA1: | 5716463E947071F819768F97BB7C5F68E98D50C0 |
SHA-256: | 5D55D2C18085955AA17222CDABF5F0EF75B03997EC0AADB1BE00AB18EA16B6F9 |
SHA-512: | A80F3AAE13A0B7021A889F141A553202D591CD377505CE3305BC10932B84EDEDD1A4D15D2D16E890D5E41862788D04905086D969232E4216A5820E1942504B8A |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.994402922013063 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3B2E75CEA427D2EF2BF192B8ADD234F2 |
SHA1: | FF732F46390C2C093D385F2677890AD40E2FA572 |
SHA-256: | AA5DA6AC721D8C5FF8963E4AD09C174D80704A444A5D31905FB785F166B138B1 |
SHA-512: | 2767957CB637A9FA7552531B1288116E97BCC223E23928D0927A8D444F5D1A12FC267A36823CCD5B6D574C9E00D717E052E97A4802CB7A00D0D42BAC14D1A0C0 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 2302976 |
Entropy (8bit): | 1.6778741447261982 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3F6508787099EB1149CADBF5F68EC8BF |
SHA1: | 82941A24A35C61307CC9EBCCC7EA6DB8A4A0EC29 |
SHA-256: | 8AD6382D8E3FF9392CF6EA1E1894C2C4E9E9403FC304E4797B7A5254AF6AE6A9 |
SHA-512: | B7F9B95DCE2B89C3A8B307586617DE22B82CB33632C83A0F8957C902E8CA4C16A31AA80A7B82EAE9934526FFB96139E6CD2027562F382996FD3DCC942E0F7180 |
Malicious: | true |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 393216 |
Entropy (8bit): | 6.472615504848319 |
Encrypted: | false |
SSDEEP: | |
MD5: | DF6D6BC0A32330940AFD2DF528D85C0C |
SHA1: | B375A3E2BB10190C6F13866F3B64796C2C1EE9CA |
SHA-256: | 08B8FEE293221D8E7F7D2DBC706779A029CF3BEE73EEA868A98016BCB4784798 |
SHA-512: | 99925F8ED3E53B7F872F0DA434165F66A82E96E73038413E028141D998BED619931C082CAAA1158FCCE2C71DAE622FF9EE877F151301550625D540C563B5E959 |
Malicious: | true |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 427449 |
Entropy (8bit): | 5.644803133009802 |
Encrypted: | false |
SSDEEP: | |
MD5: | DA659EDA8F6B1531BCC671866590ABC0 |
SHA1: | 3B8BC42FEB5D3BAA3EC559836062A32CD111965E |
SHA-256: | 3A287A39E31BA11C693C68E06D4986B6B5A2C5ABB0D8C0B750504FBACEA42E35 |
SHA-512: | E84C10352AC67038A63D2A69C87D1345CBDC26646F4D032CF2495A4508C0D48AA9A04D300E103249CC344C57F8E72B54D41A37060A33F6D1B5ECB1452FE1E01B |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7579 |
Entropy (8bit): | 7.974047556858248 |
Encrypted: | false |
SSDEEP: | |
MD5: | D1D6D600F1B68D5A905DF6706ED9CAD1 |
SHA1: | 7726A606E293CB7395D992CF92733A2852555671 |
SHA-256: | 5D84610F9E3685DB0505DADC0F9741462E8EA4F5FFF24CAAB307A4B9A262EA6A |
SHA-512: | 24BF3C522CF9068381F8CEB42F5E3CEC74F708B585D4D3C92F67C6C5FE0503D9E4DF20F30101B2245C8A513D112E8CC91C5D089B056E52FA021F386DCB1C36AF |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 851077 |
Entropy (8bit): | 7.99948611448095 |
Encrypted: | true |
SSDEEP: | |
MD5: | 550A9C8C178B90F8B800F2D1B974686E |
SHA1: | 392707C5271AF5B71AD362B2DAC842F97B8B5954 |
SHA-256: | 85B96E7D2EC0082B4CCE974758AC1A7FCDAD3FA192B9647C99E5DFB041004146 |
SHA-512: | 57F474507BB51ECEA0F79E34460E14DA4B9A1DB21921D2B3DCCE704598DD70674FA3780E11ED910F1605883A1EBBECEC0B821EC9CABBA8471A29E301B7680662 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 427440 |
Entropy (8bit): | 5.644779443085709 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2F820BF5BA8F3F5C96B5CE8CD1690535 |
SHA1: | 8185FF0B4274E9AC5397406DA2C9FC620CE55CAC |
SHA-256: | 999CC6152868086841BA4A5EC3E17701987A40CA44EFB3B7E14E209601803ED9 |
SHA-512: | 088753A3B0FCA60F6213A508989D1F0094CC6B84500504C2BC4993D5D2AD3211E4383EE3A193D648A1F0CD65512BB57B21B41DCAE5A469CB0F3A913CCAD479AD |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 306891 |
Entropy (8bit): | 7.998389586941649 |
Encrypted: | true |
SSDEEP: | |
MD5: | B62060AE2B544609E55034DC634690E1 |
SHA1: | 9BB25FD350EA3E34703B747AF6870B90AC74723F |
SHA-256: | C740BD9DEB9BCD0ADF90C726498EBF933A552C575B976BAC3F1961891038DB8E |
SHA-512: | 1F05C78ED2636951DE921C0FA44EB1F18FE7AD6CD8B907A55A307129ACE1C590F792C37DE50B836A2465AA9E87F7B47FDEC20CA8637119C48CBD209A41E16A2E |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/web/assets/1278119-68fc4ee/1/web.assets_frontend_lazy.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4798 |
Entropy (8bit): | 7.764392139121034 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0DCA18187C9C002522A6DE8BB166C121 |
SHA1: | 6E0543EFE50AC2BC0062B2AA14225E0F2C3A2AB0 |
SHA-256: | 786ECC496082CBA365686DC8E445A38DD78EAB818C15DA50E8A17EA99C83679A |
SHA-512: | 13482E95AC7D99A0C11BBAE54A9B4BE90443E4F644247C1014A2712167D48756C1F4B49BD6E0488685E5191B63D11F1DC877558C77EE43A1E8D78669CBD3BD59 |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/web/static/img/logo.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4665 |
Entropy (8bit): | 5.827669931000862 |
Encrypted: | false |
SSDEEP: | |
MD5: | B4CBF28FE57D0FB0E62F9349155608B2 |
SHA1: | 26F2E4523A634EC6B0F5CD5EFCD3E16755467A43 |
SHA-256: | AC10A4ED8E6F91E812943101D9EC029B3A3333BA9570C01E59EE6EB349206361 |
SHA-512: | 60D791CA6434A8A42F9C032B6D828A159597AC9B772507596202E215986E18C94E50E5820A8F60A2FEB790417EF7057655BC355DD80FCA62707D897A83E52B40 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 17635 |
Entropy (8bit): | 7.9459992917167455 |
Encrypted: | false |
SSDEEP: | |
MD5: | 43064A5957CC2C9795A539954A8372FA |
SHA1: | 97819DC8E7C4308AA282A11C9CC8FCD3F20C7F38 |
SHA-256: | 3B7F55439345FEAF20AE1ECF4A9BD618D4DBE252534993225A61D6C67685CA12 |
SHA-512: | F4DBAF3D2ED9CBC2BC9A6A014E4D80DF5AECD474DE7B957A773531845D5631A0D7FA4600484EC3AE522EB1E9C24FBAB05BB7786267E3FAAD879103F17C8AF6B1 |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/web/image/website/1/favicon?unique=6b367a2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 48236 |
Entropy (8bit): | 7.994912604882335 |
Encrypted: | true |
SSDEEP: | |
MD5: | 015C126A3520C9A8F6A27979D0266E96 |
SHA1: | 2ACF956561D44434A6D84204670CF849D3215D5F |
SHA-256: | 3C4D6A1421C7DDB7E404521FE8C4CD5BE5AF446D7689CD880BE26612EAAD3CFA |
SHA-512: | 02A20F2788BB1C3B2C7D3142C664CDEC306B6BA5366E57E33C008EDB3EB78638B98DC03CDF932A9DC440DED7827956F99117E7A3A4D55ACADD29B006032D9C5C |
Malicious: | false |
Reputation: | unknown |
URL: | https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTS-muw.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 408845 |
Entropy (8bit): | 5.650371905757697 |
Encrypted: | false |
SSDEEP: | |
MD5: | 6AF196E08C718B63F45AB75DA465C3BA |
SHA1: | 0E0F278AE7E984ABFDA478DAB8A5826B18EF2B38 |
SHA-256: | 554DC5A55220C75AEADEEA15FE1F136A291A4A1B565EC642DB9DA76524267921 |
SHA-512: | 1245E435482BE23585E7CB2EEEFF1B08755AC19520377EA581847050124160D107BC1A06F5844F440AFB066DF0142561401238DA46EDCAC25E3A40536AD4D35E |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 427466 |
Entropy (8bit): | 5.644905775568932 |
Encrypted: | false |
SSDEEP: | |
MD5: | D6AD724041CCF19B6D4B881A816DCC79 |
SHA1: | F5FCF44152C76D77AD1EC64B5CF16F7AB51FA206 |
SHA-256: | DA0718D9ECD266B06F150E6DF2DC0A059C26D31993F76EF208E55CCD4F6EFBDA |
SHA-512: | 25B3CDA48AF609DA332A6A8FCFCBF1D9858D1215A492B969B106D8B9B11AA63135F9D329E6DBBA02A5D87CE9FE70D06DDF6BF0EB02D0F67E1598FA895B7D78F1 |
Malicious: | false |
Reputation: | unknown |
URL: | https://www.googletagmanager.com/gtag/js?id=G-Q7QQB9B00Q&l=dataLayer&cx=c>m=45be51d0v9105953142za200 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 427466 |
Entropy (8bit): | 5.6448839239094495 |
Encrypted: | false |
SSDEEP: | |
MD5: | ABE287842BD0FF1A33E39B35B406D4DB |
SHA1: | 0599722C48B3BE8D5034FF4DF11ECFC5D39B0E7A |
SHA-256: | 55F690713B3F74BC8D19795E4F8FC270FBEF438807F93C071CDB72D06DDBABB4 |
SHA-512: | 8B952EBED3F75BB97A9C9284FB9873CEE22332576A05E03F11F7D44F37190C862DAD19937A0ED7AC4830D90CBD8D9684D86A5DC9F93410ED4A72504C0C7668CC |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5119 |
Entropy (8bit): | 7.9355710305729765 |
Encrypted: | false |
SSDEEP: | |
MD5: | 30DC7ABAF799EE72C7877E3FFAFEDB1F |
SHA1: | FB6999F776300DCE95105330A54D0427B57301BC |
SHA-256: | 287B8D845CC68250AAE39929582858A6E70CB253158208078394269CB70A39CB |
SHA-512: | B2387A6222353FB65A968E3CDB14FB12C9AFECB792C4334CCFFFC2254F55DA7E0AEEB0A7D66BC306D17BD39B9E4273E06EF0E834CD14C10509A3D854E06EDA08 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 9670 |
Entropy (8bit): | 7.982334172849447 |
Encrypted: | false |
SSDEEP: | |
MD5: | 554B3FC761E34FBCDAAD750DDEAED338 |
SHA1: | 49074BF06A16AEC0EFE2D2896573DBC0D1439816 |
SHA-256: | F2FBC237EB359CFFA15C7EF1131D3DB0F39316A09CE9D4B1747BAF2403B8EC36 |
SHA-512: | C1A19BB4A2AC3BBEFD048322D8EED8D0FF10A2B664F9F03BCD3908B8B585E28CD61E36028BC2EEDEE7BA61C41AFA98B36A8D1CAA727DD04496485EF31FD3DB91 |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/en_CA/my/task/166767/worksheet?access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 77160 |
Entropy (8bit): | 7.996509451516447 |
Encrypted: | true |
SSDEEP: | |
MD5: | AF7AE505A9EED503F8B8E6982036873E |
SHA1: | D6F48CBA7D076FB6F2FD6BA993A75B9DC1ECBF0C |
SHA-256: | 2ADEFCBC041E7D18FCF2D417879DC5A09997AA64D675B7A3C4B6CE33DA13F3FE |
SHA-512: | 838FEFDBC14901F41EDF995A78FDAC55764CD4912CCB734B8BEA4909194582904D8F2AFDF2B6C428667912CE4D65681A1044D045D1BC6DE2B14113F0315FC892 |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/web/static/lib/fontawesome/fonts/fontawesome-webfont.woff2?v=4.7.0 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 274192 |
Entropy (8bit): | 5.562363538760156 |
Encrypted: | false |
SSDEEP: | |
MD5: | 66FE243CA8726878220F2EAB148614FE |
SHA1: | C9FEF410A74E53CDDE787FC9C9E127490AA067EB |
SHA-256: | ECB41A8E804A97AD43AABD965890C27DEF98723EB782389E34463192883FA123 |
SHA-512: | 45C54554F06FD4A70B9E6A27C28D4B108DEC1707F0214098C45BBB7292AA3B025C2D4F9C74FC091E027AB8D9934D09127D57D8B178DBFC3254BED7FDC72F1980 |
Malicious: | false |
Reputation: | unknown |
URL: | https://www.googletagmanager.com/gtag/js?id=AW-652382924 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4524 |
Entropy (8bit): | 5.815854714295377 |
Encrypted: | false |
SSDEEP: | |
MD5: | 5D5200F59F21F357EB576191C8DF5561 |
SHA1: | 15A7EBEF1A33F7BF1D786ADE01A52D4CFCF58F37 |
SHA-256: | 1D234383C06342C5ED2C347AD38CE50F7A16A821F0A1990C1219F0B80E59193D |
SHA-512: | B979C99BE6CD270151C3567E04C306BA8723C3BA17168A8EDC9981E9AFC5AA7F53089C30AD81FAB5A55B50DB5500F4B8FDF11C5736026D703C75F606415F4250 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1685 |
Entropy (8bit): | 7.889402704019235 |
Encrypted: | false |
SSDEEP: | |
MD5: | D4250A891290D72C955E88131351A712 |
SHA1: | 3F651BCB7EA1EDAC681AF7D17EEF33CED81A09AE |
SHA-256: | 1D2F23132446AA11D46DCFFDEC4550A555545094BFA77BAFC81FEA22C7218CD2 |
SHA-512: | FA8B9F4318362124CF66AAB2D5BAF6BE5A79501F9578BB1B1F28CD8B4DC59A2D054997C511605CC8C812EDFD9F2FD593775E2E66F94FC50099F906CF981BE075 |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/portal_rating/static/src/xml/portal_chatter.xml |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 274176 |
Entropy (8bit): | 5.562238955079305 |
Encrypted: | false |
SSDEEP: | |
MD5: | 54609EECACB08E53231FE4485E84EAD2 |
SHA1: | B28C00FBB3D28D034F93118A3FFBC28BEC10C396 |
SHA-256: | DF8A4130354CB98F80FB9FBEE1BEBF723689C556CCB6A7C2771A6FCA4664EA4F |
SHA-512: | 8D9BCFAE3404CC391E70847EEC10FA473CA33197296011C63E612DA0345272A016D1A8B1A6E6B592D0A22E2122DC2CB666F2F76D660544E46451E52B901F9443 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.75 |
Encrypted: | false |
SSDEEP: | |
MD5: | BCE442D3D579E92EF0F38FC6DF2EC79B |
SHA1: | 330033083823FE496110493FC29EE379C6A77447 |
SHA-256: | E07A46D6EA3A298335A56522CF17A9CBB8965482DCB0662EA96899BED67631EF |
SHA-512: | E2E0CB25A487930435668E90D8F76709CDF54CA919FF276B913B46661BF0B6965BB05560EEB04F6F69A76E7F50BE1A81146CE19D57355EEE97B0827C376935C3 |
Malicious: | false |
Reputation: | unknown |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAmuX6-zkbkKJhIFDcZosPw=?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 207484 |
Entropy (8bit): | 5.537632220900244 |
Encrypted: | false |
SSDEEP: | |
MD5: | 51A1BB2FDB9F5D803FF65073EB1513BF |
SHA1: | 6386C712F3C1DD44FB1E3D5DFE0C52C210FE1807 |
SHA-256: | 50D00EBBB20AF8B3A25960D1A3639B0B348CD464073C4CBD20E99AFA410A7CE2 |
SHA-512: | 980B838E9997CD1CFA0CC31E1CF5C92018A17ED0C9714DCFB474D51EAB4845AC70A936B2BC0688DDB063779CC58445E17DE1A53BFC9B038A459405DFC23C3F64 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1575 |
Entropy (8bit): | 7.881913433779521 |
Encrypted: | false |
SSDEEP: | |
MD5: | CFA5060A844610EDC288F608D3A1AE14 |
SHA1: | 2351D84BD87142E61D5F19FFCDCF857E7A9EB0BA |
SHA-256: | 280E4453CC3B1C930F2CE09632354D90F36E0A09B3DED5DF59142F25AAE0B025 |
SHA-512: | 9A822EC8956EA18F54AD63D3BAC17B78E1CF5FEB9E3A108637EEBAE1E4ED47EF04E72ABAFE86D6558B4A0A2974E8169E5470A1C3005A5B07155FA18AD2C69B1C |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/website/static/src/xml/website.xml |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2819 |
Entropy (8bit): | 7.851441305371096 |
Encrypted: | false |
SSDEEP: | |
MD5: | E9D91562DE782832220A92B29C6609B6 |
SHA1: | 6BE00CAB4372C2C66EB2ED1F3AFC00995CDCBCC2 |
SHA-256: | DC4A36A31941A836EAD97BEB5A8E34FC0E7505465712C3513174A4F73FF06A8E |
SHA-512: | 1883F2088FD2F199660FB19818B1F6A924A8222FA81AD5C7E5B29804638934DE8100E9FAF343A0A056A05C056F863B0EED8A1E3E0FB0960EE9B6EC5A4704873A |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/base/static/img/country_flags/ca.png?height=25 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4665 |
Entropy (8bit): | 5.831478542748506 |
Encrypted: | false |
SSDEEP: | |
MD5: | 288814208969787288A106BF6CD26104 |
SHA1: | 0E4846A8BB1748D108A8F259381DD6797D848F97 |
SHA-256: | C76AC1FCF4CC9A0A0A46AE66BB066A2C36299EC27F9147A9A2860AB84F2B9D04 |
SHA-512: | F9AB23221520C4BBE1885123A613CD5CB6CE5CF995A3D186994091FF15C855F8F35F5DC458CE15203FD87CB7CCF5FDC49409C9F40DD7D75AE2DD2AFF4127F21A |
Malicious: | false |
Reputation: | unknown |
URL: | https://googleads.g.doubleclick.net/pagead/viewthroughconversion/652382924/?random=1736865485355&cv=11&fst=1736865485355&bg=ffffff&guid=ON&async=1>m=45be51d0v9105953142za200&gcd=13l3l3l3l1l1&dma=0&tag_exp=101925629~102067555~102067808~102081485~102123607~102198178&u_w=1280&u_h=1024&url=http%3A%2F%2Fwww.techlift.ca%2Fen_CA%2Fmy%2Ftask%2F166767%2Fworksheet%3Faccess_token%3Db8f79f62-9a1a-4f0f-8b02-ad8868e93ff6&ref=http%3A%2F%2Fwww.techlift.ca%2Fen_CA%2Fmy%2Ftask%2F166767%3Fmodel%3Dproject.task%26res_id%3D166767%26access_token%3Db8f79f62-9a1a-4f0f-8b02-ad8868e93ff6&hn=www.googleadservices.com&frm=0&tiba=My%20Worksheets%20%7C%20Techlift&npa=0&pscdl=noapi&auid=1511753366.1736865478&fdr=QA&data=event%3Dgtag.config&rfmt=3&fmt=4 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 408842 |
Entropy (8bit): | 5.650424177995092 |
Encrypted: | false |
SSDEEP: | |
MD5: | D5CCC3887FC25B841D2818F0C550CF60 |
SHA1: | 88774035A9C0717004D28057B461E4FAF90F7CE6 |
SHA-256: | 639C0200C86CF9C759F4927FDBEFCD99AC61E290834A738E16943F54897D2706 |
SHA-512: | 5758F5A1597753E49A2CFEB070D38751A9103A2B0C954452B50F5C4926301CADA52CC6B1DFABF8877B558CF1D861DD2BE5A1AFEB6616DC0A8633B2640CFACAC4 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1894 |
Entropy (8bit): | 7.90598778708296 |
Encrypted: | false |
SSDEEP: | |
MD5: | 38489A501C457065840D0A6929023D6C |
SHA1: | 9C33061EFEE6B34E7B531239A563ED130759B6D1 |
SHA-256: | 356E179147777CE88D06FF3656F9A5C936911B0B7E2712C7ABD0BA9731819E44 |
SHA-512: | AE3D5BE8993E372247D2D843262B1EA25C126DEE5369EB39FF5F2F2729683DEDC9591B89CDD07EAA5224F5422225B1A966B4AFFA22C60F5BC88D3359FD7B7A52 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 289 |
Entropy (8bit): | 7.188742336728925 |
Encrypted: | false |
SSDEEP: | |
MD5: | B607EFB0476ED7370D9BBB457071EA16 |
SHA1: | EEC6DAB8ED6903D0D66DCC04930F70861DD58210 |
SHA-256: | A6E28119827FD5666D1D062F146C3F7D9C0FCBBB2C0B48D6EF213F45E7FE2327 |
SHA-512: | D1F14E7AAA724C78FC744023D9187DAF323C3B597E14CA00B2095C326325DAFEA72B44A1C211FC07D010112D934928AEFD63DA0EB5338CBDD8AE54BA7CB0687C |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/website_sale_hide_price/static/src/xml/website_sale_templates.xml |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 207483 |
Entropy (8bit): | 5.537530993862335 |
Encrypted: | false |
SSDEEP: | |
MD5: | BE2B00D56F050FDBF64F0FC03E45E3EE |
SHA1: | AB7B1E475E724550F8EC20B8322673F164F00B19 |
SHA-256: | 42F932BB4C896F4D7F96B35B2FB6B4BDD1D856AF2256199EEDC115663FD2B6D7 |
SHA-512: | 8A86870EC71ED16AE75610855462EE3376E205F0B2C012B470A3965272681566F87D56BF729FE9E04401E1B34077770D768A686EBDDB60A05E597C500E1A08B2 |
Malicious: | false |
Reputation: | unknown |
URL: | https://www.googletagmanager.com/gtm.js?id=GTM-T5BWKR8 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 36171 |
Entropy (8bit): | 5.345618653817642 |
Encrypted: | false |
SSDEEP: | |
MD5: | 32E0116AFC6049A232076B1CAD87550F |
SHA1: | 4AE0622C65805DEEB6BA96CCA5EB14A7403EC559 |
SHA-256: | 5054D8D8F1849AD858FFBC7913BED1A80DDF3712FE200482BE874A7E39BC10D8 |
SHA-512: | 940EBDE0CB5BDE2D3187B9755BC236ED0124164E5A0B794B2089107AC53ACD8968A9BB2F74DCF29F765F89F220B3A83F0DFE956C0D5983BB74A6EC00C7FF605D |
Malicious: | false |
Reputation: | unknown |
URL: | "https://fonts.googleapis.com/css?family=Open+Sans:300,300i,400,400i,700,700i&display=swap" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1159 |
Entropy (8bit): | 7.810218654131982 |
Encrypted: | false |
SSDEEP: | |
MD5: | 71C8AC6BE7E69844E08A63E67C8F3C89 |
SHA1: | 1128E74034F4CE79280E663EE119DDF18732B942 |
SHA-256: | 8287A52CEF2E9C9105B92D7E61B697E469AE625703CAF5FE8BC455F68D24C4FC |
SHA-512: | 8D1B8B6A7547F1691485DD3AA51FF1C87C1C08F5D59EA87F04C7DF9DA5CAC361F09C55355777D8BF3EA81E73659E07173646C296CFDC2FDF3AB0F4C0342F0C05 |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/e3k_invoice_sale_renting/static/src/xml/signature_form.xml |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 574 |
Entropy (8bit): | 7.64476026674318 |
Encrypted: | false |
SSDEEP: | |
MD5: | 790739E4FA354A6CF6A69C1EBDB26B33 |
SHA1: | F30040F4CB0CFB086440B6E3249EEA91E0F91AC1 |
SHA-256: | EC396981C10AA43E1BF3B8E8FD31E67E8CFFFE2D9BE3A51F47D377D825424E51 |
SHA-512: | CF7424104C6471480863FE6C7F0E6AE64084DF224662800CB54227389069C4B91BA77D12121162BB7D3D0F411C83921E9A38475CD9373F57C9858074EAF2BBEA |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 408862 |
Entropy (8bit): | 5.650459678249728 |
Encrypted: | false |
SSDEEP: | |
MD5: | D28DEF4100F3234227356A9BA6053871 |
SHA1: | 7CD6DD868A64C58608DEB2EA96E423F8665C0C31 |
SHA-256: | 9C0770AC4F305E32A83951AE0568F9237B477A6D716752D1EE13B67920B7D3EF |
SHA-512: | B1DA7516FE5F1781AD5FD84012CFDFC0E72A3B68D44F324A0F4067D6F758CCCB24932B8B2EEC31F72FDB6BB588950E01519A679E420464D704574E1B3908A742 |
Malicious: | false |
Reputation: | unknown |
URL: | https://www.googletagmanager.com/gtag/js?id=G-NBRWDBNKYM&l=dataLayer&cx=c>m=45He51d0za200 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2113 |
Entropy (8bit): | 4.70654581047032 |
Encrypted: | false |
SSDEEP: | |
MD5: | 4D15968CF9252D5BA0640CA89942A200 |
SHA1: | 8F1C88ABB3D1A2EF3F3886CCAF54EA982B08E310 |
SHA-256: | 5B5AD8BA4240A3445F08C30E623495B0A4E3756CD7035CE49FCBD7B991C3030A |
SHA-512: | F18A1B33FE1E4055B85FFECDE127AB570CF244EB68E18F3EB9927B91266575B5199184FC554830E95912FDC363F210E9B17D2954ADB36DCA472F54D891EDD3A9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 408845 |
Entropy (8bit): | 5.650437029661594 |
Encrypted: | false |
SSDEEP: | |
MD5: | 39730525D4C38E5E301508EC39FCFCA9 |
SHA1: | D0830A6434F82CDB3EAA5640CBEAD5B6F7EDD451 |
SHA-256: | BFACF31E8EA9C9E97FA620AD3406CAA0928C1E6F675596DE4D7EE09DA39C9EDD |
SHA-512: | 0B82BBCD6FE16365F51DA8559BD4689C33A45478780205C2606AEE4AB1BB29EE1C8BFAE8316E39B15C98531084F85377C0590DA3989C4883E7A2B389588F221D |
Malicious: | false |
Reputation: | unknown |
URL: | https://www.googletagmanager.com/gtag/js?id=G-NBRWDBNKYM&l=dataLayer&cx=c>m=45be51d0v9105953142za200 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1826 |
Entropy (8bit): | 7.626542601861562 |
Encrypted: | false |
SSDEEP: | |
MD5: | 046FF94913D9BD7D4DD2B921645E70DA |
SHA1: | C2CEBDE40B18840EE6AD555B7FAC365361832E1F |
SHA-256: | E094D8EF4CAD3941C3EA143CF18EEB4B737EE9741EC50D4E052B870B35B3FF95 |
SHA-512: | 3A0CB584C08399CA29F519D584619D5A4AC046245499FA4261BF763E686AA417E55E26FF52128FECB4099B0BC9966CEAD286A3C6B23324793F7A58039375129E |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/web/image/mail.message/4579457/author_avatar/50x50 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 9195 |
Entropy (8bit): | 7.975337422870926 |
Encrypted: | false |
SSDEEP: | |
MD5: | C81F3886FB05216E7D34948BB0AC092B |
SHA1: | 2CCC17D38B9206D942CAD89BA73E29C095D815AF |
SHA-256: | 86828E4C3C0B91F489AFE4263F5464719638E4B3170B40C553EB05376795650B |
SHA-512: | 6CBD58ACBECE02FC2B502EE18A9700B0F4B541CAA56BF9924B290979C6556DA958B3497399A89CACB4CEBC65710EB341D047991FBA2B4FE1E552BEC2A54EA754 |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/web/assets/1126508-6596fbe/1/web.assets_common_minimal.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 25723 |
Entropy (8bit): | 4.696132463022503 |
Encrypted: | false |
SSDEEP: | |
MD5: | D2CDA605662B216D8920F346E8715245 |
SHA1: | CEC8F4F1A312D4BE2A9214BA98348E33E7D56CB7 |
SHA-256: | 9FF95C524A3A1DEFEDEF695CD55F0D051B9681AAA9D7B53DFB11554FB0D22751 |
SHA-512: | 2326395D83A1520C2B24856F6B11F3EDA422395599558D0E81DEEFE0EE385C72BF54F724C198E574DAF9B659218B8FB0589DBC779FB5753271B384B3D12D2400 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 928 |
Entropy (8bit): | 7.78374145371394 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8709B1FCCB89EC16F3A57B8D7068C747 |
SHA1: | 922A08D8FCC8BB6754D05DC721DCDE3DB4708F81 |
SHA-256: | D508DF761A4398CD7966D7C57703446FBBE35D8006666B02C80C14AACE0B2059 |
SHA-512: | 588FCC9227BCE1D076BAB24F4291C7AC68F4696BD5A60D07C38B85C5F6162D98A0FD0A85C4778FF14704529937B5D41B8D2A8F12D73D6F8E2C33FA16566E7162 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 28 |
Entropy (8bit): | 4.208966082694624 |
Encrypted: | false |
SSDEEP: | |
MD5: | 7C7A1894EE54EEA7BF3E9C709B2F8069 |
SHA1: | 46EA7D3D76197C0EB97606D608C94637CFF8AF92 |
SHA-256: | 471BA83A382AEAF294AEA8045C9C3C66FF2B69B8302BC39EBCED2192E3EC284E |
SHA-512: | 4D8BB5EE86E9575718A423C125BEA9C24A7EFD1949FBE1008FFBEF1675AA6BB85B15A6F05BDC6DFB898DA00D6351C656556CA5BDED4810874E0740BFA385F092 |
Malicious: | false |
Reputation: | unknown |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISFwnjhjVd9KALzhIFDaQqhI4SBQ1e0O9l?alt=proto |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 340481 |
Entropy (8bit): | 7.994454902700553 |
Encrypted: | true |
SSDEEP: | |
MD5: | 2A4504381C5379C7D5F6EFAF227827C8 |
SHA1: | 57F8C2ADF131980F10ED337A742EEF1024E583BD |
SHA-256: | 7EAE3496D623FD0C0CDB7CDC518B4DC3EEEF3FA6E88D2EFA04929538C316ECD6 |
SHA-512: | 81FE7DB8DBF0191B30301E9CE14A7398FFA370048ECF3E0F38E27E8A4C95D6BFE385B0500C1C0909682A4968FADE86D57967F71ADD7247F3D248B6D5D87EDB25 |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/en_CA/my/task/166767?model=project.task&res_id=166767&access_token=b8f79f62-9a1a-4f0f-8b02-ad8868e93ff6 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1209 |
Entropy (8bit): | 7.834273690580407 |
Encrypted: | false |
SSDEEP: | |
MD5: | CE3E1DF1114A5DD303A3C29DE5C07067 |
SHA1: | 1E62B06F189F90CCD68F46B569577050757A108E |
SHA-256: | 93B7061ED0B0D99F30DA8E3EB74242E58A618942E1EBC480560D72472B0A8426 |
SHA-512: | CC79BAC4BE6F97A1D7C8FFD293FD2850922FE09552AD7C72DABD3B7197102F2E68C946B50117858320FA23D0640077CA852D287EED84C9FBBE4341A70433F074 |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/website/static/src/snippets/s_searchbar/000.xml |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 4507 |
Entropy (8bit): | 5.807415618279847 |
Encrypted: | false |
SSDEEP: | |
MD5: | 41D5E2B589E3EBF3C1E34CCC5C6794B8 |
SHA1: | C3E2E001BFDA7E12C22306BDF30D52A5DD54A4A8 |
SHA-256: | C51E44096FDB26F53D6A3A35EA8C3A13D6378F3134EB9D3E043FF1EC67417D73 |
SHA-512: | 2C35EDCFE16A4780A40B40038E96534176E27C28285CBAFC9D1D07B554B856F70F567F6A84323B5D0C9080CD3BA9B20E236215EBF877504406A029A9E2C4D8D2 |
Malicious: | false |
Reputation: | unknown |
URL: | https://googleads.g.doubleclick.net/pagead/viewthroughconversion/652382924/?random=1736865477839&cv=11&fst=1736865477839&bg=ffffff&guid=ON&async=1>m=45be51d0v9105953142za200&gcd=13l3l3l3l1l1&dma=0&tag_exp=101925629~102067555~102067808~102081485~102123607~102198178&u_w=1280&u_h=1024&url=http%3A%2F%2Fwww.techlift.ca%2Fen_CA%2Fmy%2Ftask%2F166767%3Fmodel%3Dproject.task%26res_id%3D166767%26access_token%3Db8f79f62-9a1a-4f0f-8b02-ad8868e93ff6&hn=www.googleadservices.com&frm=0&tiba=My%20Task%20%7C%20Techlift&npa=0&pscdl=noapi&auid=1511753366.1736865478&fdr=QA&data=event%3Dgtag.config&rfmt=3&fmt=4 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2555 |
Entropy (8bit): | 7.936213103186253 |
Encrypted: | false |
SSDEEP: | |
MD5: | B6242AD6021EB9AA230E7FCE7116F938 |
SHA1: | C848EE626FB4E4713F2EFE9DD3180FEA952EC411 |
SHA-256: | FC7534B5F35A6C00E845B836E1C5A61C530451A88C05215CD38C4F7D10C7EEE8 |
SHA-512: | F2969DF8A360CFB87466E937177666B5E0FC94273BDC39B31030A26D089F95405733CE24B3ED8A284202D2D3190E62C927EDCCC443584B92307CDB14C96B31F0 |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/portal/static/src/xml/portal_chatter.xml |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 48336 |
Entropy (8bit): | 7.995815173088384 |
Encrypted: | true |
SSDEEP: | |
MD5: | BFE7AD4AA54CFF8909B2D7632073CC30 |
SHA1: | 7C2E625BEA4D449CA78CDE09AB59DC6C9CB4726F |
SHA-256: | 47D477915FA5912616E2DC5DF8C5780F9202671678CF275472BD39F3381C0098 |
SHA-512: | B083C9E0766F281A39F582404F08B3D3314C7757AC151C4CB00BD3CECEB4FA06B12D08D881A2C6BF80A066ECAD22FECE7CFF41269D2DBD2BFE38D873922A31FF |
Malicious: | false |
Reputation: | unknown |
URL: | https://fonts.gstatic.com/s/raleway/v34/1Ptug8zYS_SKggPNyC0ITw.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2022 |
Entropy (8bit): | 7.898809506409665 |
Encrypted: | false |
SSDEEP: | |
MD5: | 52624DE813851B3E1B37696F791CF5FC |
SHA1: | 80CB58C5D4E122A0CEA7733B24975E469B8E865E |
SHA-256: | 817860C490C41A8BD6586090289497EC0A714E7F9AAC329076A05207FCEBA5D2 |
SHA-512: | C8EC2D05B5674B864763EF20C98F38B87E9C8FF56DBA627EF88D94E53C95F4494C877893781535E59E7D06679F985EDE27EDA0636B622BC0F4CF50435770245B |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/web/assets/1126511-81ea84f/1/web.assets_frontend_minimal.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 120540 |
Entropy (8bit): | 7.997440649645081 |
Encrypted: | true |
SSDEEP: | |
MD5: | 2495B9DAE793FB68BCA58182DC63225B |
SHA1: | 9F89E2660C111023A85692746BFD117270376ED3 |
SHA-256: | C22A643EBE9C4F959DFDF2A411CC71A2572284EA0DDC131897F35065D87E95F6 |
SHA-512: | 211D8F2375AEB577B3F4D3FD635367A31106B9F9B582CBBF7689D97EE5B9EE3A37EDDF66A54255863D70784F7AF3B08DA0C49EE2529FD75462943AAD1B95BAC3 |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/web/assets/1280054-689d2b2/1/web.assets_frontend.min.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1893 |
Entropy (8bit): | 7.900657806340236 |
Encrypted: | false |
SSDEEP: | |
MD5: | 757188384FC2CC2F049EC563B507F960 |
SHA1: | 18594A0A0CFAA25ED0380AE1056CFD8EA0630076 |
SHA-256: | 50D2C2788979028AA9D30E3C246105AD1CEDD5BD6CB0011E40EA7A929C8ECBE2 |
SHA-512: | 40A2DA24245F11CF7C18E474AD7ACA780710A9E85741CF46E842A29413210F3319A9EC78FE4C43815FF5859C05FD70627C5C83785AD7AED0E9C782607BC073E3 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 207476 |
Entropy (8bit): | 5.537428044758343 |
Encrypted: | false |
SSDEEP: | |
MD5: | 20865FB742C39E971C896F0E20055809 |
SHA1: | A20F05FB2E614646275B2F41A1FF00BFFECF1F87 |
SHA-256: | A96DDDD1C6C780F13891F575BD008709E96D80F42CB13D164833F9496BA27137 |
SHA-512: | 3329EDADE2DC2984E0AEEED87E89526E36B93B78BA9D23C9A0CD2F4295D4713CB6181B69C1A0C889B9224A72669B62955C389A88577C9CA58989077A0F7C30A3 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 408836 |
Entropy (8bit): | 5.650369091990868 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9193EDCD57CECCB183CBA2B3E1C58123 |
SHA1: | 98CE9DF2377F2106E1819BF5BC6CA02FDC3342B2 |
SHA-256: | 5D952A1D219A56B5EED697B27C3D1E5D68F7C88D0A9D354FD614D52C9DD84620 |
SHA-512: | 5542D631688433ECF9B1F7535EAB8D4D103EB95082AB95ECBDD59D0A5E2FAF6790C32616BF206279F70657802AFFA5B91CB4734BA68C45D6740A04A5D70569F0 |
Malicious: | false |
Reputation: | unknown |
URL: | https://www.googletagmanager.com/gtag/js?id=G-NBRWDBNKYM |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 32020 |
Entropy (8bit): | 7.9922416460661 |
Encrypted: | true |
SSDEEP: | |
MD5: | 1BF2EE104CE79D3A96D713BEF8E41176 |
SHA1: | EB51F35531005862AAC567D807C8E6CF2FA38BC5 |
SHA-256: | 09EF9EB09C3023DF07A233FEA8B82D837246158E5AA1A7021DCD8616066390A4 |
SHA-512: | 07AD4013EAEC30E8E25394257A57531548CCE33C2DCEEF05306D5E4B1B6606B544862A011C47C84134B422BBDBB0B4ED4008FEB2C3E133A2669EFB0C1776A77C |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/web/assets/1282895-916948a/1/web.assets_common.min.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 200 |
Entropy (8bit): | 6.842337377155746 |
Encrypted: | false |
SSDEEP: | |
MD5: | 285A18AD3221A019DAAA32ED266D79CE |
SHA1: | E343A05998662711D216D60E7C97E0F005E4ED6A |
SHA-256: | 9C45A15CC20CCA099405D1660611ADAC556108C1675C12522E9DA160540D69DB |
SHA-512: | 94F1388964254808A7CDEA12FA487F15D86BA0FBA61D00277E20A11A106EB745694FDFD4C29CCA5205B1527E7C3513059CFC801DEE3DC80C6AE2C10F4A6B1CD5 |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/en_CA/website/translations/04e840c3ed34e2d0b9fc364b60b58ef5e7bde60f?lang=en_CA |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.2979422256799085 |
Encrypted: | false |
SSDEEP: | |
MD5: | A64AC36ADB4B78FB9F3CFA8AF3605F15 |
SHA1: | B746CF4C949E22F6DDEC15F3766D107D700895CE |
SHA-256: | 24F234D392B45B89DE49FAED2A52FE0D2A45862D67B16E1509897D851217AB4A |
SHA-512: | 6D487D98D0DADE2E4AE91BD4033EFDB56D9331E3FE4F15388F92687AB5FC10C1A58A84D7A45B6CB16460331845DC92CF241EEF0D10E2D12BBB3F905638A4BA52 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1444 |
Entropy (8bit): | 7.859232652354463 |
Encrypted: | false |
SSDEEP: | |
MD5: | F4DC939E1ED1B242A85165E67A3707BD |
SHA1: | 0ABB6661A813CC17DEAE1668400DAC12185A479D |
SHA-256: | CF11DF2958C552618BAF06B0A2BA0F5470956003533FE68B572E8D3058F394FF |
SHA-512: | D8548BBD0150834611DE3F0C85171B20054BC7BDBE7E99965D6FC981A789F8119E412E18CB40CB359CB90525E5B7974BAE17CA9561DE41B29854384E0C18ACA1 |
Malicious: | false |
Reputation: | unknown |
URL: | http://www.techlift.ca/portal_rating/static/src/xml/portal_tools.xml |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 11064 |
Entropy (8bit): | 5.434791713418542 |
Encrypted: | false |
SSDEEP: | |
MD5: | ACDA726ED56EE5C80706788F85AE7D7D |
SHA1: | 8F28B484D17E511FEB89A65D5EE28CEB3F7E6674 |
SHA-256: | 5C3FAE529989A89A7D6E81D3B3CF9DD28206DC877394AA6EECC281E4B4797844 |
SHA-512: | 106313EAB8DB9BA8135213037AE733F6E1EAB4F9FCFE86EDBB17C1F8682410BBA0E9FAD6082C8D64957DA7EA33FDB42F7C2A08C7788D2FB91F3310CAC8FFD811 |
Malicious: | false |
Reputation: | unknown |
URL: | "https://fonts.googleapis.com/css?family=Raleway:300,300i,400,400i,700,700i&display=swap" |
Preview: |
File type: | |
Entropy (8bit): | 6.047194286417916 |
TrID: |
|
File name: | original.eml |
File size: | 243'555 bytes |
MD5: | 96c43f66e14e2fa5782d19584b26f335 |
SHA1: | 3e56151ad9584754141986f6374fac15afe157e0 |
SHA256: | 44c374171a3dfc7380266297d4952b51e3c81980fdcf9c17b8a61278198fffca |
SHA512: | 0790b3e18b9d5de82245545286cf8bcb60ddfcd05b5299be51fbdb9414c7fc6f27a8b5dd81cc536f6ff67a62c1f4094092cf2905b40b4a4ae66658cec66295be |
SSDEEP: | 6144:h4ISuDv4U4ArXuT4PVNR58c4cdX9OiZxdlyeghmUpd0gFs/Xz:h4IShAXu0Vp4AgiZxfyegP2z |
TLSH: | E534CE37938029A4CB55492BD017767E3FB41BC7CDB128FD279ABE2B978CCB29194148 |
File Content Preview: | Return-Path: <dany.ratte@metalus.qc.ca>..Received: from YT3PR01CU008.outbound.protection.outlook.com (mail-canadacentralazon11020103.outbound.protection.outlook.com [52.101.189.103]).. by inbound-smtp.us-east-1.amazonaws.com with SMTP id 4ipabbfal85lj03ot |
Subject: | [Phish Alert] BT154296 Rapport |
From: | Dany Ratte <dany.ratte@metalus.qc.ca> |
To: | "c9025caf-ebfb-4a55-8a88-3cf1915dac7c@ca.phisher.knowbe4.com" <c9025caf-ebfb-4a55-8a88-3cf1915dac7c@ca.phisher.knowbe4.com> |
Cc: | |
BCC: | |
Date: | Tue, 14 Jan 2025 14:24:57 +0000 |
Communications: |
|
Attachments: |
|
Key | Value |
---|---|
Return-Path | <dany.ratte@metalus.qc.ca> |
Received | from YT2PR01MB5902.CANPRD01.PROD.OUTLOOK.COM ([fe80::7c97:a276:a7af:a379]) by YT2PR01MB5902.CANPRD01.PROD.OUTLOOK.COM ([fe80::7c97:a276:a7af:a379%3]) with mapi id 15.20.8356.010; Tue, 14 Jan 2025 14:24:57 +0000 |
Received-SPF | pass (spfCheck: domain of metalus.qc.ca designates 52.101.189.103 as permitted sender) client-ip=52.101.189.103; envelope-from=dany.ratte@metalus.qc.ca; helo=YT3PR01CU008.outbound.protection.outlook.com; |
Authentication-Results | amazonses.com; spf=pass (spfCheck: domain of metalus.qc.ca designates 52.101.189.103 as permitted sender) client-ip=52.101.189.103; envelope-from=dany.ratte@metalus.qc.ca; helo=YT3PR01CU008.outbound.protection.outlook.com; dkim=pass header.i=@metalusinc.onmicrosoft.com; dmarc=pass header.from=metalus.qc.ca; |
X-SES-RECEIPT | AEFBQUFBQUFBQUFHOEJJUFYzRGdUbllNKzAyd01zYktMek12RGZmK1Y4RWdUZnpzQlhZdzlWOUhhQjRzSTVubFIyOEVwMXgvUjR0aHdkbnJXYnU1S0o1RUl4emczaW5hcXpZQXdBK2d5TzBBQ0J2UWwwT1ROT0dVcWhPRVh5clErRnpicWhIYWJDdnNaQ1hnTlpYSG5XRHdLSEF3WWY2dXRjd1I4cjd0RFN6UndTWkd1M2I5V2FvUStLM2M2K252VzE5WXVieUNkRU5VSGZxemV0NGI2TkMvekZPTFhmdGFlRWsrVnN1Wkg0bTJIRzJGQkZMazBtSlpzOUVDZjlOTnZab1JRUkJjZmFMY0hjUzhpbTVtQUk2bXZUejgyck84eURQdXQwYnVpRWQ5cE1GempMdW9sMEd2eEJ2aHdQR0ZHeFVGa3g4Z3RmV3c9 |
X-SES-DKIM-SIGNATURE | a=rsa-sha256; q=dns/txt; b=a/HwiU/9Q2iVkMK+VNMVQNgZ01t9vohBrpXbuQcZ9wiypqc3W6NU5ySAc4Sr2RPq1dolZUhBssVJ7p8XreRo3GL7BgoFt7MBZXtANJwe0yC1GK0JaIQVjWGOUmnIqeCNcjwgBxzB5QoAvJkn4joEmTN/w5yIeZF5eIcud+UFr4U=; c=relaxed/simple; s=ug7nbtf4gccmlpwj322ax3p6ow6yfsug; d=amazonses.com; t=1736864700; v=1; bh=t9kFyp28PrA5e3fk1kxLQvNefk4qwS57j8ftKdOH3QM=; h=From:To:Cc:Bcc:Subject:Date:Message-ID:MIME-Version:Content-Type:X-SES-RECEIPT; |
ARC-Seal | i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=El0G4FvrH760NU28wmyNovNH0lU6fLgXZlbPPwNVc/uaOuoO0FW69KI8R0hZmHD0D5KU6sBL+8f7y5hhTE5ULqCFGcFh5Zulm+1RYA14JtuAFKesV057zQBN2apxleXd9TdPTnug1XsFO9xSZwsN7cwHY0bTq9BWcRTM+9TPtSjgzhKCKtAHm/z90fOvZz0Yt80pv0nTyhxMxcGVCnNhm/il+btt3tHS6lE79tzQv4wUSmrMYVrzcijhGlPbYHRp31Qa6X76y/g7+xblHVCn2EIzmCf8ROZIZ9MjQd9lnmL5KUd7aTyEB09cHzPx/WD/wr+5q3JG+B/A8Inh7+Lj5A== |
ARC-Message-Signature | i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=TTvxgXKer2vt3XR3QBQ2lY0QCes2bNnZ1xyXDUZyLfw=; b=KMf9/MyQecVbmIUiF06jW3cArGeWsRNIJK4Ya8hfMpvYNPSjI4pLYXkSLhB6yzF2B+k6+eHeqN8zeSWdHRT/0Zhedyt6Ojqt8Noxo5ISfyWnEO4PywixjWE1tsujgR5qCe3iiysra8Hr1S3gIOdJ5nwRNa4Nf4TH6EOsXXJ56OTfBxpPF2vW8uE+v9nL8jjyC6lpQhfjrhROXTvw6BYMBmDBvxO6dhRoqTrrd+wAL3nR2qtwZR5B1AvBv3vzrfeztoXOdbnu97wzUXebKKMzztE/KTvTFL/E1Z01CVTQQLYFv6odgeiI9HApGnP06XsLcaKWCXXMOAJfY6sypUNuzw== |
ARC-Authentication-Results | i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=metalus.qc.ca; dmarc=pass action=none header.from=metalus.qc.ca; dkim=pass header.d=metalus.qc.ca; arc=none |
DKIM-Signature | v=1; a=rsa-sha256; c=relaxed/relaxed; d=metalusinc.onmicrosoft.com; s=selector1-metalusinc-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=TTvxgXKer2vt3XR3QBQ2lY0QCes2bNnZ1xyXDUZyLfw=; b=ZoXXaANQ7dGqf0efAYt1YGblpEzpD1pHwD4X0novC7z1wqRFmAs5jaBgWxnKy5Tg//d+V3eLBYOjWKVzc56M4t16vMGw8QlwFIzLt6t/3omSHU5nuf6u6/50XKIbPba10neNanV+BenNc3KdXRb0oD12P+u2rF9PBX5o3bAMYW0= |
From | Dany Ratte <dany.ratte@metalus.qc.ca> |
To | "c9025caf-ebfb-4a55-8a88-3cf1915dac7c@ca.phisher.knowbe4.com" <c9025caf-ebfb-4a55-8a88-3cf1915dac7c@ca.phisher.knowbe4.com> |
Subject | [Phish Alert] BT154296 Rapport |
Thread-Topic | [Phish Alert] BT154296 Rapport |
Thread-Index | AQHbZomhBVA7VOSlu0GGLkLPjHc6OLMWUxnb |
Date | Tue, 14 Jan 2025 14:24:57 +0000 |
Message-ID | <YT2PR01MB5902B2566F657096A055BC3AD7182@YT2PR01MB5902.CANPRD01.PROD.OUTLOOK.COM> |
References | <321142741700100.1736519291.417025327682495-openerp-166767-project.task@ampv177> <213102271628307.1736861886.346633911132812-openerp-166767-project.task@ampv177> <213102271628307.1736861886.346633911132812-openerp-166767-project.task@ampv177> |
In-Reply-To | <213102271628307.1736861886.346633911132812-openerp-166767-project.task@ampv177> |
Accept-Language | fr-FR, en-US |
Content-Language | en-US |
X-MS-Has-Attach | yes |
X-MS-TNEF-Correlator | |
authentication-results | dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=metalus.qc.ca; |
x-ms-publictraffictype | |
x-ms-traffictypediagnostic | YT2PR01MB5902:EE_|YT2PR01MB8261:EE_ |
x-ms-office365-filtering-correlation-id | e2b568eb-63a8-48bd-4559-08dd34a73901 |
x-ms-exchange-atpmessageproperties | SA |
x-ms-exchange-senderadcheck | 1 |
x-ms-exchange-antispam-relay | 0 |
x-microsoft-antispam | BCL:0;ARA:13230040|69100299015|376014|1800799024|366016|8096899003|38070700018; |
x-microsoft-antispam-message-info | zKeCm3TVVekPyy24gv9kqkqwTB8j9HKUdeQso/WtTY/DNTjvTNgLVIqJ5ToucI0jhTJhoKzi3+X2sKcntCNGaR2O1I2sJtGlD/s9RobZLYvLXzrv/wg03R6xUbILys4xxxnfHQoQQ9UrQOv3gI84BPOFogeIus3lfcgcSq1imcIbk9E2IWySaEXM4AvkF8OIQ3Uo+5H98XnB43tF6K6uNPPSsT3RyVmYq9Uiu/ZIcAvChvyoDXJlaowhMOpap5M96LBD17toqcWbbcohi2G2EqFJR5kTR8lxher63jGnNihC7bHT9VxQszm8b9i9+6JbPBuZqgWcSFzekBVb5xT1aBRH6l4Xsnb0QGnP8YDrVdkOHSRTcXdtyiFIC3+RI1r8itHNp7p1Wi3j9W30uQUCDNyR66afCcnTlkDPKb0DSQYSGC+JCmoY4bHIygOWWq2558kdSMd3BBzzXJgshw3iaCL5MbDNbhsne1LOARZ+bJ8QguM8XFFdpLNA77Kj94NACuzfhfexxPxhAxO13ayyqxE94ZCvwnNZrMwlVKoUvBZP1k7vdAYe7tQoCQoZJhPLzb6On4HvoPsmBvAtYcwloD2cISzRJT0hFQJr8NxI9YegEP650QWZvmFrf2v+p7mrS3bq01bLBvEEiQiI3fJtmpIQdL3+5n5wtq2IUUqQSXl3lyjd4GxMPgwnJo/7030H7L/g0mkpFXJ2zymu4goR8/Qe3QWZQVy4rv2WGj4u4Daz6LCZOxTFqcX1Mr6lTkcFr/bxgLnvfc+oNINfwZfSy22vnTZPOO6J/4J/UrF6G+nDv0cKtG8JquITkzYv9F05Li7BLfA1ZedDQv6kH20GWOAG1a65PBG928K4V+q5yM1ZqLbSicAwvvN0ZaRKYVnWHG6TecY7CzZPxPIV6cTPoZ41EvYG7ZcULKDrXzotDr+5eYKYpcpVdeIdspcx1SNJbaZ+x8TCFn6m+KWm3QWC48yQy1Ra1ekj1GQ6IeQ/EA2F9roPiksoSrp2tNsIWBuzl/c4JfekjzU0g3oKIYZlhMQr4AHYCPHQJPuwq3cI5nCsw5PZextfF/9FwuvABkfZVwYMvfWgqN5XYT8y/3HuWk7dUg2DpyOBQkdhtn7TUTGs3JpgBIDt/423Ojd7XbjmlMg48u5xD7Zpf6L0gPOxvyjQ6etbS+ogEI6apcekSxiTw4YS03ELk6DSiR3XR7E3AA6G1ChHR24YoFvDH6RtiObZAcY+gzdgJOq3v1GWvrAvdm4PtPXpoKepGiVifqzcnZf930GRupPLFa4I6R3G061DdX9sRb8GGt9Xwn3Wq5x9j7VBG2Iy8/pZaoz9E2cs |
x-forefront-antispam-report | CIP:255.255.255.255;CTRY:;LANG:fr;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:YT2PR01MB5902.CANPRD01.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(69100299015)(376014)(1800799024)(366016)(8096899003)(38070700018);DIR:OUT;SFP:1102; |
x-ms-exchange-antispam-messagedata-chunkcount | 1 |
x-ms-exchange-antispam-messagedata-0 | RiZCk2rOMJ5lZnrVs1WFZ46BrmJGRgEu1bktH0qMGcH78JDthdHr48LsO8/0uETCpvvxep4Da8FvQUxp9RSr/9z5jY+CPiReA9cb1o6Ej8ujOML4tQZyLnggedkJt+DXOAZWUsML7ZwNVlfkzVVCQZ6jJ7w9GRl5QlqK8MlFUQslvDWokIXlYc54arbfd+FE4X34MXR7TIoC5PiV6UkUC0B0DT9t3pAfIgUVrP5XLHONEctN5ZgtIXGDTDm9Zs3XfTExrSDuO1DSFBecgqzO7FjIk8CVHbYEJOGs71MvfpaW8y92ZFvvY8hGW18ODS09dz5eT1Fezdt0WDL4oc8k8Cdu9PJhn8gdrz07o2d6fvHRUf/HQUYqN4UHubAis5MVg/eppW5DjTB+UtwYJ3vPwYmY0yLhyeocbWETTzHfjZQQ4czTf67kIgwUjxyWXc9d3tIlfCqMFZjKFR01Wr3FCDxy5kQjrLtCQ4h8ERzQAPh1H2O4MTDA9aljySA3SkRU1GknpX4cReBLMs9uwmvZTxUbFLCsZU6F7OvCyURk9iJjzxdr6lNDFAWvNDns3HdMzWZS4pgnR8fUD4vkleZRBkPdO8DfHb2MwL83mHFtF5j6Sq8CrIHoNIhkzuDlenmX34QioFiA3nVsQaYmgs/MdNFCig2/IBlmK+GFmwu53Wwp72q3PxN2I3Z0avpEXJ7F9nBM16ZBOSLxqlfh4yHPp/ME8ur0jzrMXASWHk5U/Z0vlP81RlLphphz+OW0PHAWucK+BXvIJ29aFoSrN+ar+u1bZWfm+hXphAsvvNmhT76yz7WPTgIEliPAoQx9ImoMGhX9No5+4lNWNBTYa0+qL53gGoxw6DmgGMPZLFrsGh0QjNfhtXJx1nzOR4aolRFXMRPtCYWUdP10ktlTw7h71XWZaal9lv85jMqipVWx/aPfLDkHR0haFYUAjsW/cunq17VwKSTIx6Mf6qX9sEk5RA2DZLqG9za1GuZpWvbE4wpIXmAN1EPizWX8BreW9YUOm9k2yc7MZIyyE8E0+LRKkvApqccqdF8H39FeyBjcyQBreZR9Dg53Gj65KtZ/AfK2JAVb7qegAKoLqe+RCd6JUPQ9Dzn8BLFQ4RV818T2lyo8PpZgcUeiv4ZJSjG379xy3HLbnmb7pZUAx4r/cSMFpipsWzDMaWSEkGEGXZzTZnv9ZbDahnyKXXopiBd5QNFvwH3zCxBONX9GSqw1A7nov8C4T/TBU/foBUbMpb35YnVo0DLDvqs6wsFeDS61DQBN70DUh0Krbwdu+lyJxV66OX0e5o2VfS3FeA8NQxc9tfjERv4Jp3IOaqY+DqGpG/rciLL+1uSpatyhr/WVg674nftOQB2maf6fsrXP7A6DQ4NAnsJWw671tVRPjY0DpbNxgeVFWAiDrfe/QI6oXVQQ6hLFObuof/EDk/w1cJ823TRI3oK0c59F6opVZcTtipNvspsBSH34phlOdPKuBF9bGzzWQxhv5Pg30LMHGWtxxNxuJI4v2sRikY0Kex/j1H5Butw3WtrPDPS8yMltp7s+DQekVsKA/CVMn2J7VCWQqs+R/F0nMB1J9tZtREKKbEHY |
Content-Type | multipart/mixed; boundary="_005_YT2PR01MB5902B2566F657096A055BC3AD7182YT2PR01MB5902CANP_" |
MIME-Version | 1.0 |
X-OriginatorOrg | metalus.qc.ca |
X-MS-Exchange-CrossTenant-AuthAs | Internal |
X-MS-Exchange-CrossTenant-AuthSource | YT2PR01MB5902.CANPRD01.PROD.OUTLOOK.COM |
X-MS-Exchange-CrossTenant-Network-Message-Id | e2b568eb-63a8-48bd-4559-08dd34a73901 |
X-MS-Exchange-CrossTenant-originalarrivaltime | 14 Jan 2025 14:24:57.6486 (UTC) |
X-MS-Exchange-CrossTenant-fromentityheader | Hosted |
X-MS-Exchange-CrossTenant-id | 4f85cc14-eaa8-4e0b-8291-93aab6969f78 |
X-MS-Exchange-CrossTenant-mailboxtype | HOSTED |
X-MS-Exchange-CrossTenant-userprincipalname | J+sxeTeNY4LpToO6eFGPQYdgqL+S0PDgIu9QPdBFa7nDqZIWO5itjefT4ynlUe8lt8oZdHgjBjx3367P/jCyH2k7DSv5vhVcSKDaNf2bC2k= |
X-MS-Exchange-Transport-CrossTenantHeadersStamped | YT2PR01MB8261 |
Icon Hash: | 46070c0a8e0c67d6 |