Edit tour

Windows Analysis Report
https://email.d.kajabimail.net/c/eJxkkL2O4yAURp_GNKtYcI1NXFCstIq09T6AdYHrhCw_FpDx5O1HnsxU037NOedDa_MjtcU7LQcxMdy2JWEk_R_vaPyptlxoLTm1etpKdg_bfE7MaQIjBSMtlBxGUCAVo4g-LJFqxSst7bmR3inYHGmxhbCRWyJFQ4XdNJ8VThZR2JUP5izcilaO5-lsJjdOamZeA4eRSy6E4gpU70YB82rkYAeaYIZOcte_LA9un6ixoG-tbbUbfndw6eCy73t_z7cU8X2nENC

Overview

General Information

Sample URL:https://email.d.kajabimail.net/c/eJxkkL2O4yAURp_GNKtYcI1NXFCstIq09T6AdYHrhCw_FpDx5O1HnsxU037NOedDa_MjtcU7LQcxMdy2JWEk_R_vaPyptlxoLTm1etpKdg_bfE7MaQIjBSMtlBxGUCAVo4g-LJFqxSst7bmR3inYHGmxhbCRWyJFQ4XdNJ8
Analysis ID:1659819
Infos:

Detection

Score:2
Range:0 - 100
Confidence:100%

Signatures

Creates files inside the system directory
Deletes files inside the Windows folder
Detected suspicious crossdomain redirect
HTML body contains low number of good links

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 6960 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 7160 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1952,i,15095420858795128231,6333825698758395728,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2248 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 5804 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://email.d.kajabimail.net/c/eJxkkL2O4yAURp_GNKtYcI1NXFCstIq09T6AdYHrhCw_FpDx5O1HnsxU037NOedDa_MjtcU7LQcxMdy2JWEk_R_vaPyptlxoLTm1etpKdg_bfE7MaQIjBSMtlBxGUCAVo4g-LJFqxSst7bmR3inYHGmxhbCRWyJFQ4XdNJ8VThZR2JUP5izcilaO5-lsJjdOamZeA4eRSy6E4gpU70YB82rkYAeaYIZOcte_LA9un6ixoG-tbbUbfndw6eCy73t_z7cU8X2nENCio_jsbY4dXEK--sReRkc_gAQYp6Pku6FSclQWlyP6pH_ginaY-ojp6jFgcb6TfK_FHABWfaOvW0fW9D_f6NffPx0Mn8Obho8AAAD__z7Ffbg" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://www.johnmaxwellacademy.com/loginHTTP Parser: Number of links: 1
Source: https://www.johnmaxwellacademy.com/password/newHTTP Parser: Number of links: 1
Source: https://www.johnmaxwellacademy.com/loginHTTP Parser: <input type="password" .../> found
Source: https://www.johnmaxwellacademy.com/loginHTTP Parser: No favicon
Source: https://www.johnmaxwellacademy.com/password/newHTTP Parser: No favicon
Source: https://www.johnmaxwellacademy.com/loginHTTP Parser: No favicon
Source: https://www.johnmaxwellacademy.com/loginHTTP Parser: No <meta name="author".. found
Source: https://www.johnmaxwellacademy.com/password/newHTTP Parser: No <meta name="author".. found
Source: https://www.johnmaxwellacademy.com/loginHTTP Parser: No <meta name="author".. found
Source: https://www.johnmaxwellacademy.com/loginHTTP Parser: No <meta name="copyright".. found
Source: https://www.johnmaxwellacademy.com/password/newHTTP Parser: No <meta name="copyright".. found
Source: https://www.johnmaxwellacademy.com/loginHTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: 34.110.180.34:443 -> 192.168.2.16:49705 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.110.180.34:443 -> 192.168.2.16:49704 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.80.1:443 -> 192.168.2.16:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.64.151.34:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.64.151.34:443 -> 192.168.2.16:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.64.151.34:443 -> 192.168.2.16:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.64.151.34:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.64.151.34:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.36.222:443 -> 192.168.2.16:49720 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.65.228:443 -> 192.168.2.16:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.16:49724 version: TLS 1.2
Source: chrome.exeMemory has grown: Private usage: 13MB later: 42MB
Source: C:\Program Files\Google\Chrome\Application\chrome.exeHTTP traffic: Redirect from: email.d.kajabimail.net to https://www.johnmaxwellacademy.com/login
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.41.3
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.41.3
Source: global trafficHTTP traffic detected: GET /c/eJxkkL2O4yAURp_GNKtYcI1NXFCstIq09T6AdYHrhCw_FpDx5O1HnsxU037NOedDa_MjtcU7LQcxMdy2JWEk_R_vaPyptlxoLTm1etpKdg_bfE7MaQIjBSMtlBxGUCAVo4g-LJFqxSst7bmR3inYHGmxhbCRWyJFQ4XdNJ8VThZR2JUP5izcilaO5-lsJjdOamZeA4eRSy6E4gpU70YB82rkYAeaYIZOcte_LA9un6ixoG-tbbUbfndw6eCy73t_z7cU8X2nENCio_jsbY4dXEK--sReRkc_gAQYp6Pku6FSclQWlyP6pH_ginaY-ojp6jFgcb6TfK_FHABWfaOvW0fW9D_f6NffPx0Mn8Obho8AAAD__z7Ffbg HTTP/1.1Host: email.d.kajabimail.netConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /login HTTP/1.1Host: www.johnmaxwellacademy.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /assets/core-0b69763d58aed23197af55188eacc4614bb5a279443896ac77f6b2026c67ea29.js HTTP/1.1Host: kajabi-app-assets.kajabi-cdn.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://www.johnmaxwellacademy.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /kajabi-storefronts-production/themes/25900/assets/bootstrap.css?1646683851218475 HTTP/1.1Host: kajabi-storefronts-production.kajabi-cdn.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://www.johnmaxwellacademy.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /kajabi-storefronts-production/themes/25900/assets/styles.css?1646683851218475 HTTP/1.1Host: kajabi-storefronts-production.kajabi-cdn.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://www.johnmaxwellacademy.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /kajabi-storefronts-production/themes/25900/assets/login_image.jpg?1646683851218475 HTTP/1.1Host: kajabi-storefronts-production.kajabi-cdn.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://www.johnmaxwellacademy.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /kajabi-storefronts-production/themes/25900/assets/bootstrap.min.js?1646683851218475 HTTP/1.1Host: kajabi-storefronts-production.kajabi-cdn.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://www.johnmaxwellacademy.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /kajabi-storefronts-production/themes/25900/assets/login_image.jpg?1646683851218475 HTTP/1.1Host: kajabi-storefronts-production.kajabi-cdn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=EQ7NLOYAyUM20GFK4cZDSutEry.vQlBCc0_NdymHVPg-1744132947-1.0.1.1-YR5AUw9XRrfgB62ROJdtS1g.z9MOOm9dIjT0Ab937vLWqJy4_mUhhRI8yObIJqnOQcGuliJ80kCM82hRUq3ZceuJA2gd.I.dmOZXGlsoufQ
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.johnmaxwellacademy.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.johnmaxwellacademy.com/loginAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: AWSALBTG=jyOzt0zQAaiKTFIp5xJkJdCEBmmdVzXMq7Eh+qovuFXJXtNBFmsPO1PJXG6OO6Z4Z0i0HLl6v0l4rUGKax64LMJfxMDDhjGHMo/TtZa2Cr2w1yN42/LizKgi8FHVHGggSwCrMQJE3txTcm1W9kOjuByWFeHTAYI+rSJ7EeFk85kR; AWSALBTGCORS=jyOzt0zQAaiKTFIp5xJkJdCEBmmdVzXMq7Eh+qovuFXJXtNBFmsPO1PJXG6OO6Z4Z0i0HLl6v0l4rUGKax64LMJfxMDDhjGHMo/TtZa2Cr2w1yN42/LizKgi8FHVHGggSwCrMQJE3txTcm1W9kOjuByWFeHTAYI+rSJ7EeFk85kR; vs_uniques_template_metadata=eJyLNjI0MbcwMDE1No0FABHMAsA%3D; _csrf_token=eyJfcmFpbHMiOnsibWVzc2FnZSI6IkluRkNObWR2UlRGTVZqSnNPRkJ6VUVsR0wyNUVUVmhEZEU5eWVsQklWazlUV213MVRYWm9iM0pKYTAwOUlnPT0iLCJleHAiOiIyMDI2LTA0LTA4VDE3OjIyOjI2Ljk3N1oiLCJwdXIiOm51bGx9fQ%3D%3D--dc0ae5d17b6aef84e23dafed7df7f2b2430d47c0; _kjb_session=a9a58a8e3a5d2f91383c0f46c305b3d5; __cf_bm=jC_Ip3lipSIruSNm6Esur7Befafr66_Rip1S3ojxqQI-1744132946-1.0.1.1-utzJ3bbGdH0MPVPb7FJ5yxx_j9ip1_yTwplXezc.DzwGyNz9aOHVm8w8iMcJOcTWTxpEEpblDSWCfy5ELy9EwKFtpZ66eh_rau_E0l88IDw; __cfruid=5c439a7b8cfb819418f87df8beafa46791d782bd-1744132946; _cfuvid=Opbj7yckZxfJhQvX8HJ.U2N9055iuGz50SiBDHHVsWM-1744132946987-0.0.1.1-604800000; _kjb_ua_components=db107a024b5efc23fddd8f997d924a5f
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.johnmaxwellacademy.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: AWSALBTG=jyOzt0zQAaiKTFIp5xJkJdCEBmmdVzXMq7Eh+qovuFXJXtNBFmsPO1PJXG6OO6Z4Z0i0HLl6v0l4rUGKax64LMJfxMDDhjGHMo/TtZa2Cr2w1yN42/LizKgi8FHVHGggSwCrMQJE3txTcm1W9kOjuByWFeHTAYI+rSJ7EeFk85kR; AWSALBTGCORS=jyOzt0zQAaiKTFIp5xJkJdCEBmmdVzXMq7Eh+qovuFXJXtNBFmsPO1PJXG6OO6Z4Z0i0HLl6v0l4rUGKax64LMJfxMDDhjGHMo/TtZa2Cr2w1yN42/LizKgi8FHVHGggSwCrMQJE3txTcm1W9kOjuByWFeHTAYI+rSJ7EeFk85kR; vs_uniques_template_metadata=eJyLNjI0MbcwMDE1No0FABHMAsA%3D; _csrf_token=eyJfcmFpbHMiOnsibWVzc2FnZSI6IkluRkNObWR2UlRGTVZqSnNPRkJ6VUVsR0wyNUVUVmhEZEU5eWVsQklWazlUV213MVRYWm9iM0pKYTAwOUlnPT0iLCJleHAiOiIyMDI2LTA0LTA4VDE3OjIyOjI2Ljk3N1oiLCJwdXIiOm51bGx9fQ%3D%3D--dc0ae5d17b6aef84e23dafed7df7f2b2430d47c0; _kjb_session=a9a58a8e3a5d2f91383c0f46c305b3d5; __cf_bm=jC_Ip3lipSIruSNm6Esur7Befafr66_Rip1S3ojxqQI-1744132946-1.0.1.1-utzJ3bbGdH0MPVPb7FJ5yxx_j9ip1_yTwplXezc.DzwGyNz9aOHVm8w8iMcJOcTWTxpEEpblDSWCfy5ELy9EwKFtpZ66eh_rau_E0l88IDw; __cfruid=5c439a7b8cfb819418f87df8beafa46791d782bd-1744132946; _cfuvid=Opbj7yckZxfJhQvX8HJ.U2N9055iuGz50SiBDHHVsWM-1744132946987-0.0.1.1-604800000; _kjb_ua_components=db107a024b5efc23fddd8f997d924a5f
Source: global trafficHTTP traffic detected: GET /complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE HTTP/1.1Host: www.google.comConnection: keep-aliveX-Client-Data: CLbgygE=Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /password/new HTTP/1.1Host: www.johnmaxwellacademy.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://www.johnmaxwellacademy.com/loginAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: AWSALBTG=jyOzt0zQAaiKTFIp5xJkJdCEBmmdVzXMq7Eh+qovuFXJXtNBFmsPO1PJXG6OO6Z4Z0i0HLl6v0l4rUGKax64LMJfxMDDhjGHMo/TtZa2Cr2w1yN42/LizKgi8FHVHGggSwCrMQJE3txTcm1W9kOjuByWFeHTAYI+rSJ7EeFk85kR; AWSALBTGCORS=jyOzt0zQAaiKTFIp5xJkJdCEBmmdVzXMq7Eh+qovuFXJXtNBFmsPO1PJXG6OO6Z4Z0i0HLl6v0l4rUGKax64LMJfxMDDhjGHMo/TtZa2Cr2w1yN42/LizKgi8FHVHGggSwCrMQJE3txTcm1W9kOjuByWFeHTAYI+rSJ7EeFk85kR; vs_uniques_template_metadata=eJyLNjI0MbcwMDE1No0FABHMAsA%3D; _csrf_token=eyJfcmFpbHMiOnsibWVzc2FnZSI6IkluRkNObWR2UlRGTVZqSnNPRkJ6VUVsR0wyNUVUVmhEZEU5eWVsQklWazlUV213MVRYWm9iM0pKYTAwOUlnPT0iLCJleHAiOiIyMDI2LTA0LTA4VDE3OjIyOjI2Ljk3N1oiLCJwdXIiOm51bGx9fQ%3D%3D--dc0ae5d17b6aef84e23dafed7df7f2b2430d47c0; _kjb_session=a9a58a8e3a5d2f91383c0f46c305b3d5; __cf_bm=jC_Ip3lipSIruSNm6Esur7Befafr66_Rip1S3ojxqQI-1744132946-1.0.1.1-utzJ3bbGdH0MPVPb7FJ5yxx_j9ip1_yTwplXezc.DzwGyNz9aOHVm8w8iMcJOcTWTxpEEpblDSWCfy5ELy9EwKFtpZ66eh_rau_E0l88IDw; __cfruid=5c439a7b8cfb819418f87df8beafa46791d782bd-1744132946; _cfuvid=Opbj7yckZxfJhQvX8HJ.U2N9055iuGz50SiBDHHVsWM-1744132946987-0.0.1.1-604800000; _kjb_ua_components=db107a024b5efc23fddd8f997d924a5f
Source: global trafficDNS traffic detected: DNS query: email.d.kajabimail.net
Source: global trafficDNS traffic detected: DNS query: www.johnmaxwellacademy.com
Source: global trafficDNS traffic detected: DNS query: kajabi-storefronts-production.kajabi-cdn.com
Source: global trafficDNS traffic detected: DNS query: kajabi-app-assets.kajabi-cdn.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownHTTP traffic detected: POST /login HTTP/1.1Host: www.johnmaxwellacademy.comConnection: keep-aliveContent-Length: 208Cache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Origin: https://www.johnmaxwellacademy.comContent-Type: application/x-www-form-urlencodedUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://www.johnmaxwellacademy.com/loginAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: vs_uniques_template_metadata=eJyLNjI0MbcwMDE1No0FABHMAsA%3D; _kjb_session=a9a58a8e3a5d2f91383c0f46c305b3d5; __cf_bm=jC_Ip3lipSIruSNm6Esur7Befafr66_Rip1S3ojxqQI-1744132946-1.0.1.1-utzJ3bbGdH0MPVPb7FJ5yxx_j9ip1_yTwplXezc.DzwGyNz9aOHVm8w8iMcJOcTWTxpEEpblDSWCfy5ELy9EwKFtpZ66eh_rau_E0l88IDw; __cfruid=5c439a7b8cfb819418f87df8beafa46791d782bd-1744132946; _cfuvid=Opbj7yckZxfJhQvX8HJ.U2N9055iuGz50SiBDHHVsWM-1744132946987-0.0.1.1-604800000; _kjb_ua_components=db107a024b5efc23fddd8f997d924a5f; AWSALBTG=K4XfvkUd5iXMsJyX0HmRimg+BHcfVJ63Gyp0J151WJcNkLahf3QNVv7kvhXYpFxelTF34v+UizM9kqeOo0Y9KA47SkLonq5YRUShwITUTHuTjcm8v+lb25swK5Dl6DWD1XCGc8Mjcp5MTg0ZI2o1PjKVMLTZRCpXKatgxebj4TQG; AWSALBTGCORS=K4XfvkUd5iXMsJyX0HmRimg+BHcfVJ63Gyp0J151WJcNkLahf3QNVv7kvhXYpFxelTF34v+UizM9kqeOo0Y9KA47SkLonq5YRUShwITUTHuTjcm8v+lb25swK5Dl6DWD1XCGc8Mjcp5MTg0ZI2o1PjKVMLTZRCpXKatgxebj4TQG; _csrf_token=eyJfcmFpbHMiOnsibWVzc2FnZSI6IkluRkNObWR2UlRGTVZqSnNPRkJ6VUVsR0wyNUVUVmhEZEU5eWVsQklWazlUV213MVRYWm9iM0pKYTAwOUlnPT0iLCJleHAiOiIyMDI2LTA0LTA4VDE3OjIyOjUwLjgyM1oiLCJwdXIiOm51bGx9fQ%3D%3D--6a2d8e03d75e6de5368ca3919200f9bc72a4e150
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49673
Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 34.110.180.34:443 -> 192.168.2.16:49705 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.110.180.34:443 -> 192.168.2.16:49704 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.80.1:443 -> 192.168.2.16:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.64.151.34:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.64.151.34:443 -> 192.168.2.16:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.64.151.34:443 -> 192.168.2.16:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.64.151.34:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.64.151.34:443 -> 192.168.2.16:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.18.36.222:443 -> 192.168.2.16:49720 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.65.228:443 -> 192.168.2.16:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.16:49724 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir6960_1249816829
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir6960_1249816829
Source: classification engineClassification label: clean2.win@22/11@14/89
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1952,i,15095420858795128231,6333825698758395728,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2248 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://email.d.kajabimail.net/c/eJxkkL2O4yAURp_GNKtYcI1NXFCstIq09T6AdYHrhCw_FpDx5O1HnsxU037NOedDa_MjtcU7LQcxMdy2JWEk_R_vaPyptlxoLTm1etpKdg_bfE7MaQIjBSMtlBxGUCAVo4g-LJFqxSst7bmR3inYHGmxhbCRWyJFQ4XdNJ8VThZR2JUP5izcilaO5-lsJjdOamZeA4eRSy6E4gpU70YB82rkYAeaYIZOcte_LA9un6ixoG-tbbUbfndw6eCy73t_z7cU8X2nENCio_jsbY4dXEK--sReRkc_gAQYp6Pku6FSclQWlyP6pH_ginaY-ojp6jFgcb6TfK_FHABWfaOvW0fW9D_f6NffPx0Mn8Obho8AAAD__z7Ffbg"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1952,i,15095420858795128231,6333825698758395728,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2248 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Extra Window Memory Injection
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://email.d.kajabimail.net/c/eJxkkL2O4yAURp_GNKtYcI1NXFCstIq09T6AdYHrhCw_FpDx5O1HnsxU037NOedDa_MjtcU7LQcxMdy2JWEk_R_vaPyptlxoLTm1etpKdg_bfE7MaQIjBSMtlBxGUCAVo4g-LJFqxSst7bmR3inYHGmxhbCRWyJFQ4XdNJ8VThZR2JUP5izcilaO5-lsJjdOamZeA4eRSy6E4gpU70YB82rkYAeaYIZOcte_LA9un6ixoG-tbbUbfndw6eCy73t_z7cU8X2nENCio_jsbY4dXEK--sReRkc_gAQYp6Pku6FSclQWlyP6pH_ginaY-ojp6jFgcb6TfK_FHABWfaOvW0fW9D_f6NffPx0Mn8Obho8AAAD__z7Ffbg0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/login_image.jpg?16466838512184750%Avira URL Cloudsafe
https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/bootstrap.min.js?16466838512184750%Avira URL Cloudsafe
https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/styles.css?16466838512184750%Avira URL Cloudsafe
https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/bootstrap.css?16466838512184750%Avira URL Cloudsafe
https://www.johnmaxwellacademy.com/favicon.ico0%Avira URL Cloudsafe
https://kajabi-app-assets.kajabi-cdn.com/assets/core-0b69763d58aed23197af55188eacc4614bb5a279443896ac77f6b2026c67ea29.js0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
kajabi-app-assets.kajabi-cdn.com
172.64.151.34
truefalse
    unknown
    www.johnmaxwellacademy.com
    104.21.80.1
    truefalse
      unknown
      kajabi-storefronts-production.kajabi-cdn.com
      172.64.151.34
      truefalse
        high
        www.google.com
        142.250.65.228
        truefalse
          high
          mailgun.org
          34.110.180.34
          truefalse
            high
            email.d.kajabimail.net
            unknown
            unknownfalse
              unknown
              NameMaliciousAntivirus DetectionReputation
              https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/login_image.jpg?1646683851218475false
              • Avira URL Cloud: safe
              unknown
              https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/bootstrap.min.js?1646683851218475false
              • Avira URL Cloud: safe
              unknown
              https://email.d.kajabimail.net/c/eJxkkL2O4yAURp_GNKtYcI1NXFCstIq09T6AdYHrhCw_FpDx5O1HnsxU037NOedDa_MjtcU7LQcxMdy2JWEk_R_vaPyptlxoLTm1etpKdg_bfE7MaQIjBSMtlBxGUCAVo4g-LJFqxSst7bmR3inYHGmxhbCRWyJFQ4XdNJ8VThZR2JUP5izcilaO5-lsJjdOamZeA4eRSy6E4gpU70YB82rkYAeaYIZOcte_LA9un6ixoG-tbbUbfndw6eCy73t_z7cU8X2nENCio_jsbY4dXEK--sReRkc_gAQYp6Pku6FSclQWlyP6pH_ginaY-ojp6jFgcb6TfK_FHABWfaOvW0fW9D_f6NffPx0Mn8Obho8AAAD__z7Ffbgfalse
                unknown
                https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/bootstrap.css?1646683851218475false
                • Avira URL Cloud: safe
                unknown
                https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/styles.css?1646683851218475false
                • Avira URL Cloud: safe
                unknown
                https://www.johnmaxwellacademy.com/loginfalse
                  unknown
                  https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhEfalse
                    high
                    https://kajabi-app-assets.kajabi-cdn.com/assets/core-0b69763d58aed23197af55188eacc4614bb5a279443896ac77f6b2026c67ea29.jsfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://www.johnmaxwellacademy.com/favicon.icofalse
                    • Avira URL Cloud: safe
                    unknown
                    https://www.johnmaxwellacademy.com/password/newfalse
                      unknown
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      142.250.80.35
                      unknownUnited States
                      15169GOOGLEUSfalse
                      34.110.180.34
                      mailgun.orgUnited States
                      15169GOOGLEUSfalse
                      1.1.1.1
                      unknownAustralia
                      13335CLOUDFLARENETUSfalse
                      142.251.179.84
                      unknownUnited States
                      15169GOOGLEUSfalse
                      142.250.80.110
                      unknownUnited States
                      15169GOOGLEUSfalse
                      104.21.32.1
                      unknownUnited States
                      13335CLOUDFLARENETUSfalse
                      104.18.36.222
                      unknownUnited States
                      13335CLOUDFLARENETUSfalse
                      142.251.40.234
                      unknownUnited States
                      15169GOOGLEUSfalse
                      104.21.80.1
                      www.johnmaxwellacademy.comUnited States
                      13335CLOUDFLARENETUSfalse
                      142.250.80.67
                      unknownUnited States
                      15169GOOGLEUSfalse
                      142.250.81.227
                      unknownUnited States
                      15169GOOGLEUSfalse
                      142.250.81.238
                      unknownUnited States
                      15169GOOGLEUSfalse
                      142.250.65.228
                      www.google.comUnited States
                      15169GOOGLEUSfalse
                      172.64.151.34
                      kajabi-app-assets.kajabi-cdn.comUnited States
                      13335CLOUDFLARENETUSfalse
                      142.251.40.170
                      unknownUnited States
                      15169GOOGLEUSfalse
                      142.251.35.163
                      unknownUnited States
                      15169GOOGLEUSfalse
                      IP
                      192.168.2.16
                      Joe Sandbox version:42.0.0 Malachite
                      Analysis ID:1659819
                      Start date and time:2025-04-08 19:21:51 +02:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:defaultwindowsinteractivecookbook.jbs
                      Sample URL:https://email.d.kajabimail.net/c/eJxkkL2O4yAURp_GNKtYcI1NXFCstIq09T6AdYHrhCw_FpDx5O1HnsxU037NOedDa_MjtcU7LQcxMdy2JWEk_R_vaPyptlxoLTm1etpKdg_bfE7MaQIjBSMtlBxGUCAVo4g-LJFqxSst7bmR3inYHGmxhbCRWyJFQ4XdNJ8VThZR2JUP5izcilaO5-lsJjdOamZeA4eRSy6E4gpU70YB82rkYAeaYIZOcte_LA9un6ixoG-tbbUbfndw6eCy73t_z7cU8X2nENCio_jsbY4dXEK--sReRkc_gAQYp6Pku6FSclQWlyP6pH_ginaY-ojp6jFgcb6TfK_FHABWfaOvW0fW9D_f6NffPx0Mn8Obho8AAAD__z7Ffbg
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:12
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • EGA enabled
                      Analysis Mode:stream
                      Analysis stop reason:Timeout
                      Detection:CLEAN
                      Classification:clean2.win@22/11@14/89
                      • Exclude process from analysis (whitelisted): svchost.exe
                      • Excluded IPs from analysis (whitelisted): 142.250.80.110, 142.250.81.227, 142.250.81.238, 142.251.179.84, 142.250.80.14, 142.251.40.142, 142.250.65.174, 142.251.40.170, 142.250.80.67, 142.251.40.234, 142.250.80.106, 142.251.32.106, 142.250.80.74, 142.251.40.138, 142.250.64.106, 142.250.80.42, 142.250.64.74, 142.251.41.10, 142.251.40.106, 142.250.176.202, 142.250.72.106, 142.251.40.202, 142.251.35.170, 172.217.165.138
                      • Excluded domains from analysis (whitelisted): fonts.googleapis.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, content-autofill.googleapis.com, fonts.gstatic.com, clientservices.googleapis.com, clients.l.google.com
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size getting too big, too many NtCreateFile calls found.
                      • Report size getting too big, too many NtOpenFile calls found.
                      • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                      • VT rate limit hit for: https://email.d.kajabimail.net/c/eJxkkL2O4yAURp_GNKtYcI1NXFCstIq09T6AdYHrhCw_FpDx5O1HnsxU037NOedDa_MjtcU7LQcxMdy2JWEk_R_vaPyptlxoLTm1etpKdg_bfE7MaQIjBSMtlBxGUCAVo4g-LJFqxSst7bmR3inYHGmxhbCRWyJFQ4XdNJ8VThZR2JUP5izcilaO5-lsJjdOamZeA4eRSy6E4gpU70YB82rkYAeaYIZOcte_LA9un6ixoG-tbbUbfndw6eCy73t_z7cU8X2nENCio_jsbY4dXEK--sReRkc_gAQYp6Pku6FSclQWlyP6pH_ginaY-ojp6jFgcb6TfK_FHABWfaOvW0fW9D_f6NffPx0Mn8Obho8AAAD__z7Ffbg
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:Web Open Font Format (Version 2), TrueType, length 28600, version 1.0
                      Category:downloaded
                      Size (bytes):28600
                      Entropy (8bit):7.9924738417279935
                      Encrypted:true
                      SSDEEP:
                      MD5:DE104AB8ACB1088AEBEA1AAE24724A91
                      SHA1:B613F95C303C539EF3FE4FE65DB0FBC5E5A55FE1
                      SHA-256:C94F080A550A1F2D4FE07D371969B7A40C01606BD5624E8C03C976CBF5E06058
                      SHA-512:344C715EB0C1B94E5B21C42FB5F985780A82B46CF060176FAC3FDD0044BBF692C304C41DFE2BA87603C0B9E5877FD91DCBF14D070FB2689235EF5F1549FF5EA0
                      Malicious:false
                      Reputation:unknown
                      URL:https://fonts.gstatic.com/s/josefinsans/v32/Qw3aZQNVED7rKGKxtqIqX5EUDXx4.woff2
                      Preview:wOF2......o........H..oE..........................m..@...?HVAR.+.`?STAT..'*.../j....d.c..n.0..P.6.$..X. ..Z..|.....%.^w...M@.^.M..<.7...^O...6.P..%..=A.1|..#..6.....8j.n.9U.|...4...0h.._F.Zh.Y.o..+..Z....T.^.8..Y.!.....L'UNJ.F.*TB.bE....`[....EB...H.9.z..WX...U.>c....b..!...8TH.tH@...........:....0..G.5jXI.~>.B"ED.....(.....,.h.?.g..T.%...(....{.. .....O..g.w .R..wG.*..6.*.:kUNW....Gm..V.f,..l.U]U..8,...>xF.u.=B..G.}x@l{e.E3.C...NodN53.&`......F]N?o......>..l.v..d.q.@.K...;.Kp.u..a0..3;.....K.....vQ,T.4.-.......t.3!..@.c..D.g.. .....5|n./H.v"&'U>..v."..a..B.........\.s...MnD..I...Q*N..UO...{.KD;kj....ZZ.40..(.......^}......d..$<...W....~./..P.nQ....p.,..^7....c...0.T."b..........7....4.%(...Y.3....#...!..(.ti.t.|.<.......#.....>...wC.U..K...I..IQ6...t....u'[.O...GM|.._..u..@B.....2u....=..J=..wwDa...D.K.z\...n..d....n..Ki..eD..!1.....j..../.S.~9........~..^.. .xC<.l.X.R.....s...M..(.....&.HbhEs.d..R.Dd..... ..v..{}..jrw..c.~..a}......
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with no line terminators
                      Category:downloaded
                      Size (bytes):24
                      Entropy (8bit):4.084962500721157
                      Encrypted:false
                      SSDEEP:
                      MD5:E559242F88DBFF82FE37CD207D6EA035
                      SHA1:C8FC88FD6816163376B507D8FA6AE61FEA144275
                      SHA-256:82D1F80AF23E3A7C6EF7E9D3ACF0992897092A2D4E686D09C2BEE20DF69356EB
                      SHA-512:0AE15F5D682CC6FEC2989D30634CCC1ED25163B9FA317D71DCE4972DFEFB3C43657CEED506E3A062D7E0300A26D458E605A710602CCBDDFE7ECFB66E695D1797
                      Malicious:false
                      Reputation:unknown
                      URL:https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIZCYVSDO8InVMNEgUNUuhS0CFgW0KOpNFa7g==?alt=proto
                      Preview:Cg4KDA1S6FLQGgUImgEYAg==
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:HTML document, Unicode text, UTF-8 text, with very long lines (350)
                      Category:downloaded
                      Size (bytes):3167
                      Entropy (8bit):5.115822162161761
                      Encrypted:false
                      SSDEEP:
                      MD5:E72C605ACCC0F06618B0FFB123414D33
                      SHA1:10A02C94AE60481EFC1329676580EC8CC60E8AD3
                      SHA-256:25A4C1CDB125F44DA1EA5A2402B3E9DC5A342CCD16FD686B9F76B14E3D6EB108
                      SHA-512:5EEA019BC023F4640A272061C9E23FE480244EB5DB6A7CA4CB7572B9D06459F1F7F7C5C123CDE2D3960532EEC211C7C41C71DC851C4F45BF8A1F6DC71003CCD7
                      Malicious:false
                      Reputation:unknown
                      URL:https://www.johnmaxwellacademy.com/password/new
                      Preview:<!DOCTYPE html>.<html lang="en">. <head>. <meta charset="utf-8">. <meta http-equiv="X-UA-Compatible" content="IE=edge">. <meta name="viewport" content="width=device-width, initial-scale=1.0, user-scalable=no">. . <meta name="csrf-param" content="authenticity_token">. <meta name="csrf-token" content="6HGPR16wRileG6V0nVzV4GWHwprgJmDpo2WXtocefQFwsW1mk9UdWlaCxGyZrWXM+IBwFaiuW1A1TgT+BvNDUA==">. . <title>Maxwell Leadership</title>. <link href="//fonts.googleapis.com/css?family=Josefin+Sans:300,400,700,300italic,400italic,600italic,700italic" rel="stylesheet" type="text/css">. <link rel="stylesheet" media="screen" href="https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/bootstrap.css?1646683851218475" />. <link rel="stylesheet" media="screen" href="https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/styles.css?1646683851218475" />
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with very long lines (540)
                      Category:downloaded
                      Size (bytes):141580
                      Entropy (8bit):5.020396857110018
                      Encrypted:false
                      SSDEEP:
                      MD5:946B8186B0494196341B5E9299A29AC0
                      SHA1:7949EB57E7BB15D8E5A0F12CD896E9A084B1B892
                      SHA-256:B450C3972267BEC2D7ABB14BF9661E3EB7F1563EE4302089FDD4066F1A3AA029
                      SHA-512:5A4A857E599B488BD1B9928BEBEF53E5DCA2D98DD56B27A907562F27F9893D1A1644B1CE30C43E4E4563CB4958784F3F2A76FA2DA2F24116DE3C715BE48E023A
                      Malicious:false
                      Reputation:unknown
                      URL:https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/bootstrap.css?1646683851218475
                      Preview:/*!. * Bootstrap v3.3.4 (http://getbootstrap.com). * Copyright 2011-2015 Twitter, Inc.. * Licensed under MIT (https://github.com/twbs/bootstrap/blob/master/LICENSE). */../*! normalize.css v3.0.2 | MIT License | git.io/normalize */.html {. font-family: sans-serif;. -webkit-text-size-adjust: 100%;. -ms-text-size-adjust: 100%;.}.body {. margin: 0;.}.article,.aside,.details,.figcaption,.figure,.footer,.header,.hgroup,.main,.menu,.nav,.section,.summary {. display: block;.}.audio,.canvas,.progress,.video {. display: inline-block;. vertical-align: baseline;.}.audio:not([controls]) {. display: none;. height: 0;.}.[hidden],.template {. display: none;.}.a {. background-color: transparent;.}.a:active,.a:hover {. outline: 0;.}.abbr[title] {. border-bottom: 1px dotted;.}.b,.strong {. font-weight: bold;.}.dfn {. font-style: italic;.}.h1 {. margin: .67em 0;. font-size: 2em;.}.mark {. color: #000;. background: #ff0;.}.small {. font-size: 80%;.}.sub,.sup {. position: relative;.
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with very long lines (32025)
                      Category:downloaded
                      Size (bytes):35951
                      Entropy (8bit):5.18015436192836
                      Encrypted:false
                      SSDEEP:
                      MD5:8C237312864D2E4C4F03544CD4F9B195
                      SHA1:253711C6D825DE55A8360552573BE950DA180614
                      SHA-256:D5FD173D00D9733900834E0E1083DE86B532E048B15C0420BA5C2DB0623644B8
                      SHA-512:E18A5959736A9CEEF67B40DAF7964C519C678D680BBDA8D2C7679281F5D349A286C99B96CA24E7A8E64CE987D372D74AE12DA7255C606CCFE27AC13A35B5A3D2
                      Malicious:false
                      Reputation:unknown
                      URL:https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/bootstrap.min.js?1646683851218475
                      Preview:/*!. * Bootstrap v3.3.4 (http://getbootstrap.com). * Copyright 2011-2015 Twitter, Inc.. * Licensed under MIT (https://github.com/twbs/bootstrap/blob/master/LICENSE). */.if("undefined"==typeof jQuery)throw new Error("Bootstrap's JavaScript requires jQuery");+function(a){"use strict";var b=a.fn.jquery.split(" ")[0].split(".");if(b[0]<2&&b[1]<9||1==b[0]&&9==b[1]&&b[2]<1)throw new Error("Bootstrap's JavaScript requires jQuery version 1.9.1 or higher")}(jQuery),+function(a){"use strict";function b(){var a=document.createElement("bootstrap"),b={WebkitTransition:"webkitTransitionEnd",MozTransition:"transitionend",OTransition:"oTransitionEnd otransitionend",transition:"transitionend"};for(var c in b)if(void 0!==a.style[c])return{end:b[c]};return!1}a.fn.emulateTransitionEnd=function(b){var c=!1,d=this;a(this).one("bsTransitionEnd",function(){c=!0});var e=function(){c||a(d).trigger(a.support.transition.end)};return setTimeout(e,b),this},a(function(){a.support.transition=b(),a.support.transition&
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:assembler source, ASCII text, with very long lines (593)
                      Category:downloaded
                      Size (bytes):56557
                      Entropy (8bit):4.845931784955823
                      Encrypted:false
                      SSDEEP:
                      MD5:44EA22C0003FCBE90FCB04048E2BA292
                      SHA1:F923B9459E046991C01C0C014E7644DAB2698B26
                      SHA-256:471BCF9F2F958A41F52FDDF7FF302020A341622D22D89074408C25E92C75A297
                      SHA-512:7AE8795AA3A61426FD79FB3A8467A5FD79345AD3DF63AB326097B1450EF5F2DDEB57B90D8B11FA3D7E5C8DCB18D46D70A7F0573A8816702E62E6E5524C8CF86D
                      Malicious:false
                      Reputation:unknown
                      URL:https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/styles.css?1646683851218475
                      Preview:html {. height: 100%; }..body {. width: 100%;. height: 100%;. background-color: #FFF;. display: -webkit-box;. display: -webkit-flex;. display: -moz-flex;. display: -ms-flexbox;. display: flex;. -webkit-box-direction: normal;. -webkit-box-orient: vertical;. -webkit-flex-direction: column;. -moz-flex-direction: column;. -ms-flex-direction: column;. flex-direction: column; }...flex-wrap {. background-color: #ffffff;. -webkit-box-flex: 1;. -webkit-flex: 1 0 auto;. -moz-box-flex: 1;. -moz-flex: 1 0 auto;. -ms-flex: 1 0 auto;. flex: 1 0 auto; }...content {. background-color: #ffffff;. padding-top: 40px;. padding-bottom: 40px;. -moz-transition: all 0.2s ease-in-out;. -o-transition: all 0.2s ease-in-out;. -webkit-transition: all 0.2s ease-in-out;. transition: all 0.2s ease-in-out; }...content.flush-top {. padding-top: 0; }...content.flush-bottom {. padding-bottom: 0; }...section {. position: relative;. overflow: hidden;. display: block; }..@media (min-width: 9
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text
                      Category:downloaded
                      Size (bytes):8520
                      Entropy (8bit):5.3793925466733015
                      Encrypted:false
                      SSDEEP:
                      MD5:F71ACA77EA6D0984ECD41AF3890BECDD
                      SHA1:D47E3B67187E70B6D945A2B76F3F44640AC86D60
                      SHA-256:9C0D278FC8E8B72507393D9D64CB138DC8D07A2B8497A3FD20CD5A1E594E2C56
                      SHA-512:217BEEA4E8E2BA4FEB683F71A65F63EE6B6A363D00FFADA3E4BE607AE4F7F761AF895C77363E1E5A0A90A3274332181EB47AD1BC8502E5EA4C9C79991DA1821A
                      Malicious:false
                      Reputation:unknown
                      URL:"https://fonts.googleapis.com/css?family=Josefin+Sans:300,400,700,300italic,400italic,600italic,700italic"
                      Preview:/* vietnamese */.@font-face {. font-family: 'Josefin Sans';. font-style: italic;. font-weight: 300;. src: url(https://fonts.gstatic.com/s/josefinsans/v32/Qw3EZQNVED7rKGKxtqIqX5EUCEx1XHgciw.woff2) format('woff2');. unicode-range: U+0102-0103, U+0110-0111, U+0128-0129, U+0168-0169, U+01A0-01A1, U+01AF-01B0, U+0300-0301, U+0303-0304, U+0308-0309, U+0323, U+0329, U+1EA0-1EF9, U+20AB;.}./* latin-ext */.@font-face {. font-family: 'Josefin Sans';. font-style: italic;. font-weight: 300;. src: url(https://fonts.gstatic.com/s/josefinsans/v32/Qw3EZQNVED7rKGKxtqIqX5EUCEx0XHgciw.woff2) format('woff2');. unicode-range: U+0100-02BA, U+02BD-02C5, U+02C7-02CC, U+02CE-02D7, U+02DD-02FF, U+0304, U+0308, U+0329, U+1D00-1DBF, U+1E00-1E9F, U+1EF2-1EFF, U+2020, U+20A0-20AB, U+20AD-20C0, U+2113, U+2C60-2C7F, U+A720-A7FF;.}./* latin */.@font-face {. font-family: 'Josefin Sans';. font-style: italic;. font-weight: 300;. src: url(https://fonts.gstatic.com/s/josefinsans/v32/Qw3EZQNVED7rKGKxtqIqX5EUCE
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with very long lines (32914)
                      Category:downloaded
                      Size (bytes):292002
                      Entropy (8bit):5.34569971614266
                      Encrypted:false
                      SSDEEP:
                      MD5:E39B1E5C2C5F2268758C5C3968835B86
                      SHA1:24C702D39AB7DE44757B38AEA5A871EA5D56F0CA
                      SHA-256:0B69763D58AED23197AF55188EACC4614BB5A279443896AC77F6B2026C67EA29
                      SHA-512:1BEA59A5B45A71632FD425D2CC17AFD67BE41E29788058CA24EDABC4806134390C1A26C36F455096AEB6AF5DCFF971570B85D103CBB46C1CB0FE550140041460
                      Malicious:false
                      Reputation:unknown
                      URL:https://kajabi-app-assets.kajabi-cdn.com/assets/core-0b69763d58aed23197af55188eacc4614bb5a279443896ac77f6b2026c67ea29.js
                      Preview:function productTrackingListeners(){function e(){return $(d).data("token")}function t(e){return e&&"true"===e.attr(l)}function n(e,t){$.post(s,{token:e},t)}function i(e,t){$.post(s,{_method:"DELETE",token:e},t)}function r(e,t){t&&e.text(t)}function a(){var e=$(d);return e.length>0&&!!e.data("token")}function o(e,t){t=!!t,e.attr(l,String(t)),e.trigger("kajabi-post-completion",t)}var s="/tracking/completion",u="/tracking/progress",l="data-post-completion-toggle",d="a["+l+"]",c=$(document),f=null;c.on("kajabi-video-progress",function(t,n){a()&&(f=$.extend(n,{token:e()}))}),$(window).on("visibilitychange beforeunload",function(){if(!_.isEmpty(f)){if("undefined"!=typeof navigator.sendBeacon){var e=new FormData;for(var t in f)e.append(t,f[t]);navigator.sendBeacon(u,e)}else $.ajax({type:"POST",async:!1,url:u,data:f});f=null}}),c.on("kajabi-video-completed",function(){if(a()){var e=$(d);t(e)||e.trigger("click")}}),$(document).on("click",d,function(){var e=$(this),a=e.data("token");return t(e)?
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with no line terminators
                      Category:downloaded
                      Size (bytes):72
                      Entropy (8bit):4.685646925878171
                      Encrypted:false
                      SSDEEP:
                      MD5:4E61C9FC65164EAEE66562B0910325E0
                      SHA1:48DC6C206E651804AEB9E501391F35919939DDAC
                      SHA-256:2B03DF9E21CE4D48525D8AAB20D9647A6D5AD6683C370188A0D4ECB3A8173288
                      SHA-512:EBE2B4215B31D89A3792A250A437AA2A8D64C5D7A94A79ADD2B2956C0D3CD9234BCA2C1A1F0F898F6BC173658BCE1644742741280ABF8F9D6B298D5A16D0F71C
                      Malicious:false
                      Reputation:unknown
                      URL:https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIgCRvNColw78QoEgUNzSr0KRIFDXT2QJch5IF34uShD6A=?alt=proto
                      Preview:CjQKEQ3NKvQpGgQICRgBGgQIVhgCCh8NdPZAlxoECEwYAioSCApSDgoEIUAjKhABGP////8P
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:ASCII text, with very long lines (3608)
                      Category:downloaded
                      Size (bytes):3613
                      Entropy (8bit):5.845714936154449
                      Encrypted:false
                      SSDEEP:
                      MD5:83A1CCB0E7C70FBD1B794535515BB815
                      SHA1:E66B3F43177DC223389016DC21F8D1C1BEFDF644
                      SHA-256:42287FDA00DDDE1E295F3216D3FF2A8623A6354E39A4D2A1B0199BC02DB930E0
                      SHA-512:891CCE21B6790A338715CBFA36BD1975A19A28911D7226EBD4A5921D3426A2A356B5464A35AD306F6945D09C7CAD269D7C448280887D57446C942F7CC94631C9
                      Malicious:false
                      Reputation:unknown
                      URL:https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE
                      Preview:)]}'.["",["carolina panthers sign colin granger","mesa airlines republic merger","samsung galaxy one ui 7 update","aurora borealis forecast","harriet tubman national parks","nba lakers thunder","brooks \u0026 dunn","texas lottery"],["","","","","","","",""],[],{"google:clientdata":{"bpc":false,"tlw":false},"google:groupsinfo":"ChoIkk4SFQoRVHJlbmRpbmcgc2VhcmNoZXMoCg\u003d\u003d","google:suggestdetail":[{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"zl":10002},{"google:entityinfo":"CgovbS8wMWpjNmYzEgtNdXNpY2FsIGR1bzL/DmRhdGE6aW1hZ2UvanBlZztiYXNlNjQsLzlqLzRBQVFTa1pKUmdBQkFRQUFBUUFCQUFELzJ3Q0VBQWtHQndnSEJna0lCd2dLQ2drTERSWVBEUXdNRFJzVUZSQVdJQjBpSWlBZEh4OGtLRFFzSkNZeEp4OGZMVDB0TVRVM09qbzZJeXMvUkQ4NFF6UTVPamNCQ2dvS0RRd05HZzhQR2pjbEh5VTNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTnpjM056YzNOemMzTi8vQUFCRUlBRUFBUUFNQklnQUNFUUVERVFIL3hBQWFBQUVBQXdFQkFRQUFBQUFBQUFBQUFBQUhCQVVHQ0FJRC84UUFPUkFBQWdFREFnTUVDQUlLQXdBQUFBQUFBUUlEQUFRUkJSSUdJVEVUUVZHaEJ4UWl
                      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                      File Type:HTML document, Unicode text, UTF-8 text, with very long lines (363)
                      Category:downloaded
                      Size (bytes):4004
                      Entropy (8bit):5.00951259167584
                      Encrypted:false
                      SSDEEP:
                      MD5:8F8943FE313989E3E9669051C5FE1C82
                      SHA1:C5889AF81BCAC87429821A4219E08DD5586D9F78
                      SHA-256:AE6AD5F70CBD2B0A92B8DE4957B87ADF0C8FE51E89F0EE8D162E473E3D4EC624
                      SHA-512:5BFEC9ADA0BD75BCBA1F811E92D872E056FA72E5D9BC83FA3E18D4A9437AE7E28833E12E5897C3492A27B45D16FD9204D8E09F13417AF51783E28EB0F8209BFF
                      Malicious:false
                      Reputation:unknown
                      URL:https://www.johnmaxwellacademy.com/login
                      Preview:<!DOCTYPE html>.<html lang="en">. <head>. <meta charset="utf-8">. <meta http-equiv="X-UA-Compatible" content="IE=edge">. <meta name="viewport" content="width=device-width, initial-scale=1.0, user-scalable=no">. . <meta name="csrf-param" content="authenticity_token">. <meta name="csrf-token" content="d7uMLcwo01A7JfQd+vnIPGLKhjmSo/xjoeKeJ7ajOzTve24MAU2IIzO8lQX+CHgQ/800ttorx9o3yQ1vN04FZQ==">. . <title>Maxwell Leadership</title>. <link href="//fonts.googleapis.com/css?family=Josefin+Sans:300,400,700,300italic,400italic,600italic,700italic" rel="stylesheet" type="text/css">. <link rel="stylesheet" media="screen" href="https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/bootstrap.css?1646683851218475" />. <link rel="stylesheet" media="screen" href="https://kajabi-storefronts-production.kajabi-cdn.com/kajabi-storefronts-production/themes/25900/assets/styles.css?1646683851218475" />
                      No static file info