Edit tour

Windows Analysis Report
https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9

Overview

General Information

Sample URL:https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9
Analysis ID:1672068
Infos:

Detection

Score:1
Range:0 - 100
Confidence:100%

Signatures

HTML body contains low number of good links
HTML title does not match URL
Submit button contains javascript call

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 6892 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 7116 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2012,i,13306627981988917978,8185626661155826467,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2220 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 6068 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9" MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9HTTP Parser: Number of links: 0
Source: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9HTTP Parser: Title: Sharing Link Validation does not match URL
Source: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9HTTP Parser: On click: javascript:WebForm_DoPostBackWithOptions(new WebForm_PostBackOptions("btnSubmitEmail", "", true, "", "", false, true))
Source: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9HTTP Parser: No <meta name="author".. found
Source: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9HTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.16:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.222.3.232:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: chrome.exeMemory has grown: Private usage: 12MB later: 34MB
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownTCP traffic detected without corresponding DNS query: 84.201.221.38
Source: unknownTCP traffic detected without corresponding DNS query: 84.201.221.38
Source: unknownTCP traffic detected without corresponding DNS query: 192.178.49.195
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /WebResource.axd?d=mfEtoIhNDztfYoPjQ9yuEhQJPmB22UXQljmZyA_ivVmL7b0_Yc5nOzvvlspJQOir_DiV-sNmoWu1NqKRV1Td1w03gmDQYyll1HijRPRsiZQ1&t=638793884494602352 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ScriptResource.axd?d=6xb0mkx3Nd8Zsr209JxKxK23NhWrjYYSbzucpWroW7ohyBYMsUIuJF99Od9L2nWysT44x1B9dKBAJzhgGKl7ITTmoFzK06Uf1w27Ok8hitXsuDDT-1mXHqXqjFWmm7p_GbE7jyVkGUS2bBirgORbxWVyL57Dx1NEre1a7J1sIjw1&t=ffffffffc7a8e318 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ScriptResource.axd?d=GQCmJqA4eYb2TSj214APFzQ5EqHp3NSyob8OyQH2vxnRwPZ7PlQBTRYUTxkgHfw930FVDteHks5LyOzPET6wUnzcNhFB84NsrrMckwzm4NHixroqL0G023Sv5v-tia5NzG1FQJ6b5iRoJj5NU_CNj4Ky8ACDkrLIGhVfuhfXr-Rj8BxCFKOVh4yD9ma2PG_s0&t=2a9d95e3 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ScriptResource.axd?d=GzWV25QV8vPNhs705rgdHQQxNt24Q5ePhEvJcl-IdAmZKO4pefK8GDBzcBVRFrgSddNUiGhNdfG225JwEowhF_Xr_E_W10AEh9Ww6_e4fFk8LJ4UYvxi5ByRXJXe16_xouXXOXnQe0xzC9k0R6hlpI5kO33nDrCIHbUAb-m391LAYl3_GgSHxXjLVxfClvT90&t=2a9d95e3 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_layouts/15/images/microsoft-logo.png HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_layouts/15/images/favicon.ico?rev=47 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_layouts/15/images/microsoft-logo.png HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_layouts/15/images/favicon.ico?rev=47 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: strateweldingsupply0-my.sharepoint.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: m365cdn.nel.measure.office.net
Source: unknownHTTP traffic detected: POST /api/report?FrontEnd=AkamaiCDNWorldWide&DestinationEndpoint=TEMPE&ASN=20940&Country=US&Region=AZ&RequestIdentifier=0.17c1c917.1745413133.28369d9&TotalRTCDNTime=139&CompressionType=&FileSize=215 HTTP/1.1Host: m365cdn.nel.measure.office.netConnection: keep-aliveContent-Length: 531Content-Type: application/reports+jsonOrigin: https://res-1.cdn.office.netUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.250.69.4:443 -> 192.168.2.16:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.222.3.232:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: classification engineClassification label: clean1.win@22/10@8/133
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2012,i,13306627981988917978,8185626661155826467,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2220 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2012,i,13306627981988917978,8185626661155826467,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2220 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Extra Window Memory Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=90%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=6xb0mkx3Nd8Zsr209JxKxK23NhWrjYYSbzucpWroW7ohyBYMsUIuJF99Od9L2nWysT44x1B9dKBAJzhgGKl7ITTmoFzK06Uf1w27Ok8hitXsuDDT-1mXHqXqjFWmm7p_GbE7jyVkGUS2bBirgORbxWVyL57Dx1NEre1a7J1sIjw1&t=ffffffffc7a8e3180%Avira URL Cloudsafe
https://strateweldingsupply0-my.sharepoint.com/_layouts/15/images/favicon.ico?rev=470%Avira URL Cloudsafe
https://strateweldingsupply0-my.sharepoint.com/_layouts/15/images/microsoft-logo.png0%Avira URL Cloudsafe
https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=GzWV25QV8vPNhs705rgdHQQxNt24Q5ePhEvJcl-IdAmZKO4pefK8GDBzcBVRFrgSddNUiGhNdfG225JwEowhF_Xr_E_W10AEh9Ww6_e4fFk8LJ4UYvxi5ByRXJXe16_xouXXOXnQe0xzC9k0R6hlpI5kO33nDrCIHbUAb-m391LAYl3_GgSHxXjLVxfClvT90&t=2a9d95e30%Avira URL Cloudsafe
https://strateweldingsupply0-my.sharepoint.com/WebResource.axd?d=mfEtoIhNDztfYoPjQ9yuEhQJPmB22UXQljmZyA_ivVmL7b0_Yc5nOzvvlspJQOir_DiV-sNmoWu1NqKRV1Td1w03gmDQYyll1HijRPRsiZQ1&t=6387938844946023520%Avira URL Cloudsafe
https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=GQCmJqA4eYb2TSj214APFzQ5EqHp3NSyob8OyQH2vxnRwPZ7PlQBTRYUTxkgHfw930FVDteHks5LyOzPET6wUnzcNhFB84NsrrMckwzm4NHixroqL0G023Sv5v-tia5NzG1FQJ6b5iRoJj5NU_CNj4Ky8ACDkrLIGhVfuhfXr-Rj8BxCFKOVh4yD9ma2PG_s0&t=2a9d95e30%Avira URL Cloudsafe
https://m365cdn.nel.measure.office.net/api/report?FrontEnd=AkamaiCDNWorldWide&DestinationEndpoint=TEMPE&ASN=20940&Country=US&Region=AZ&RequestIdentifier=0.17c1c917.1745413133.28369d9&TotalRTCDNTime=139&CompressionType=&FileSize=2150%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
dual-spo-0005.spo-msedge.net
13.107.136.10
truefalse
    high
    a726.dscd.akamai.net
    23.209.84.44
    truefalse
      high
      www.google.com
      142.250.69.4
      truefalse
        high
        a1894.dscb.akamai.net
        23.222.3.232
        truefalse
          high
          strateweldingsupply0-my.sharepoint.com
          unknown
          unknownfalse
            unknown
            m365cdn.nel.measure.office.net
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=6xb0mkx3Nd8Zsr209JxKxK23NhWrjYYSbzucpWroW7ohyBYMsUIuJF99Od9L2nWysT44x1B9dKBAJzhgGKl7ITTmoFzK06Uf1w27Ok8hitXsuDDT-1mXHqXqjFWmm7p_GbE7jyVkGUS2bBirgORbxWVyL57Dx1NEre1a7J1sIjw1&t=ffffffffc7a8e318false
              • Avira URL Cloud: safe
              unknown
              https://strateweldingsupply0-my.sharepoint.com/_layouts/15/images/favicon.ico?rev=47false
              • Avira URL Cloud: safe
              unknown
              https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=GQCmJqA4eYb2TSj214APFzQ5EqHp3NSyob8OyQH2vxnRwPZ7PlQBTRYUTxkgHfw930FVDteHks5LyOzPET6wUnzcNhFB84NsrrMckwzm4NHixroqL0G023Sv5v-tia5NzG1FQJ6b5iRoJj5NU_CNj4Ky8ACDkrLIGhVfuhfXr-Rj8BxCFKOVh4yD9ma2PG_s0&t=2a9d95e3false
              • Avira URL Cloud: safe
              unknown
              https://strateweldingsupply0-my.sharepoint.com/_layouts/15/images/microsoft-logo.pngfalse
              • Avira URL Cloud: safe
              unknown
              https://strateweldingsupply0-my.sharepoint.com/WebResource.axd?d=mfEtoIhNDztfYoPjQ9yuEhQJPmB22UXQljmZyA_ivVmL7b0_Yc5nOzvvlspJQOir_DiV-sNmoWu1NqKRV1Td1w03gmDQYyll1HijRPRsiZQ1&t=638793884494602352false
              • Avira URL Cloud: safe
              unknown
              https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9false
                unknown
                https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=GzWV25QV8vPNhs705rgdHQQxNt24Q5ePhEvJcl-IdAmZKO4pefK8GDBzcBVRFrgSddNUiGhNdfG225JwEowhF_Xr_E_W10AEh9Ww6_e4fFk8LJ4UYvxi5ByRXJXe16_xouXXOXnQe0xzC9k0R6hlpI5kO33nDrCIHbUAb-m391LAYl3_GgSHxXjLVxfClvT90&t=2a9d95e3false
                • Avira URL Cloud: safe
                unknown
                https://m365cdn.nel.measure.office.net/api/report?FrontEnd=AkamaiCDNWorldWide&DestinationEndpoint=TEMPE&ASN=20940&Country=US&Region=AZ&RequestIdentifier=0.17c1c917.1745413133.28369d9&TotalRTCDNTime=139&CompressionType=&FileSize=215false
                • Avira URL Cloud: safe
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                142.250.69.3
                unknownUnited States
                15169GOOGLEUSfalse
                142.250.69.4
                www.google.comUnited States
                15169GOOGLEUSfalse
                142.250.68.234
                unknownUnited States
                15169GOOGLEUSfalse
                1.1.1.1
                unknownAustralia
                13335CLOUDFLARENETUSfalse
                13.107.136.10
                dual-spo-0005.spo-msedge.netUnited States
                8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                74.125.137.84
                unknownUnited States
                15169GOOGLEUSfalse
                192.178.49.174
                unknownUnited States
                15169GOOGLEUSfalse
                192.178.49.163
                unknownUnited States
                15169GOOGLEUSfalse
                23.222.3.232
                a1894.dscb.akamai.netUnited States
                8612TISCALI-ITfalse
                23.209.84.44
                a726.dscd.akamai.netUnited States
                16625AKAMAI-ASUSfalse
                142.250.68.238
                unknownUnited States
                15169GOOGLEUSfalse
                142.250.69.14
                unknownUnited States
                15169GOOGLEUSfalse
                142.250.101.84
                unknownUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.16
                192.168.2.5
                Joe Sandbox version:42.0.0 Malachite
                Analysis ID:1672068
                Start date and time:2025-04-23 14:57:45 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:defaultwindowsinteractivecookbook.jbs
                Sample URL:https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:15
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • EGA enabled
                Analysis Mode:stream
                Analysis stop reason:Timeout
                Detection:CLEAN
                Classification:clean1.win@22/10@8/133
                • Exclude process from analysis (whitelisted): svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.69.3, 142.250.68.238, 192.178.49.174, 74.125.137.84
                • Excluded domains from analysis (whitelisted): clients2.google.com, accounts.google.com, redirector.gvt1.com, clientservices.googleapis.com, clients.l.google.com
                • Not all processes where analyzed, report is missing behavior information
                • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                • VT rate limit hit for: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&amp;at=9
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with very long lines (39257), with CRLF line terminators
                Category:downloaded
                Size (bytes):40326
                Entropy (8bit):5.245555585297941
                Encrypted:false
                SSDEEP:
                MD5:DA9DC1C32E89C02FC1E9EEB7E5AAB91E
                SHA1:3EFB110EFA6068CE6B586A67F87DA5125310BC30
                SHA-256:398CDF1B27EF247E5BC77805F266BB441E60355463FC3D1776F41AAE58B08CF1
                SHA-512:D4730EBC4CA62624B8300E292F27FD79D42A9277E409545DF7DC916189ED9DF13E46FAA37E3924B85A7C7EA8C76BF65A05ECA69B4029B550430536EC6DF8552A
                Malicious:false
                Reputation:unknown
                URL:https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=GzWV25QV8vPNhs705rgdHQQxNt24Q5ePhEvJcl-IdAmZKO4pefK8GDBzcBVRFrgSddNUiGhNdfG225JwEowhF_Xr_E_W10AEh9Ww6_e4fFk8LJ4UYvxi5ByRXJXe16_xouXXOXnQe0xzC9k0R6hlpI5kO33nDrCIHbUAb-m391LAYl3_GgSHxXjLVxfClvT90&t=2a9d95e3
                Preview://----------------------------------------------------------..// Copyright (C) Microsoft Corporation. All rights reserved...//----------------------------------------------------------..// MicrosoftAjaxWebForms.js..Type._registerScript("MicrosoftAjaxWebForms.js",["MicrosoftAjaxCore.js","MicrosoftAjaxSerialization.js","MicrosoftAjaxNetwork.js","MicrosoftAjaxComponentModel.js"]);Type.registerNamespace("Sys.WebForms");Sys.WebForms.BeginRequestEventArgs=function(c,b,a){Sys.WebForms.BeginRequestEventArgs.initializeBase(this);this._request=c;this._postBackElement=b;this._updatePanelsToUpdate=a};Sys.WebForms.BeginRequestEventArgs.prototype={get_postBackElement:function(){return this._postBackElement},get_request:function(){return this._request},get_updatePanelsToUpdate:function(){return this._updatePanelsToUpdate?Array.clone(this._updatePanelsToUpdate):[]}};Sys.WebForms.BeginRequestEventArgs.registerClass("Sys.WebForms.BeginRequestEventArgs",Sys.EventArgs);Sys.WebForms.EndRequestEventArgs=fun
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with very long lines (65329), with CRLF line terminators
                Category:downloaded
                Size (bytes):102801
                Entropy (8bit):5.336080509196147
                Encrypted:false
                SSDEEP:
                MD5:C89EAA5B28DF1E17376BE71D71649173
                SHA1:2B34DF4C66BB57DE5A24A2EF0896271DFCA4F4CD
                SHA-256:66B804E7A96A87C11E1DD74EA04AC2285DF5AD9043F48046C3E5000114D39B1C
                SHA-512:B73D56304986CD587DA17BEBF21341B450D41861824102CC53885D863B118F6FDF2456B20791B9A7AE56DF91403F342550AF9E46F7401429FBA1D4A15A6BD3C0
                Malicious:false
                Reputation:unknown
                URL:https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=GQCmJqA4eYb2TSj214APFzQ5EqHp3NSyob8OyQH2vxnRwPZ7PlQBTRYUTxkgHfw930FVDteHks5LyOzPET6wUnzcNhFB84NsrrMckwzm4NHixroqL0G023Sv5v-tia5NzG1FQJ6b5iRoJj5NU_CNj4Ky8ACDkrLIGhVfuhfXr-Rj8BxCFKOVh4yD9ma2PG_s0&t=2a9d95e3
                Preview://----------------------------------------------------------..// Copyright (C) Microsoft Corporation. All rights reserved...//----------------------------------------------------------..// MicrosoftAjax.js..Function.__typeName="Function";Function.__class=true;Function.createCallback=function(b,a){return function(){var e=arguments.length;if(e>0){var d=[];for(var c=0;c<e;c++)d[c]=arguments[c];d[e]=a;return b.apply(this,d)}return b.call(this,a)}};Function.createDelegate=function(a,b){return function(){return b.apply(a,arguments)}};Function.emptyFunction=Function.emptyMethod=function(){};Function.validateParameters=function(c,b,a){return Function._validateParams(c,b,a)};Function._validateParams=function(g,e,c){var a,d=e.length;c=c||typeof c==="undefined";a=Function._validateParameterCount(g,e,c);if(a){a.popStackFrame();return a}for(var b=0,i=g.length;b<i;b++){var f=e[Math.min(b,d-1)],h=f.name;if(f.parameterArray)h+="["+(b-d+1)+"]";else if(!c&&b>=d)break;a=Function._validateParameter(g[b],f
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with no line terminators
                Category:downloaded
                Size (bytes):16
                Entropy (8bit):3.702819531114783
                Encrypted:false
                SSDEEP:
                MD5:858372DD32511CB4DD08E48A93B4F175
                SHA1:CE4555B7B2EFBBD644D8E34CF3453A0E8CAA3C43
                SHA-256:3D18F3E1469C83D62CF3A39BA93F8EAA5B22447FE630E59F39DC1B7747635359
                SHA-512:6A57E0D4A1C23CB693AA9312F6FDAA1FC4309B5BC91D1B2279B5792BEE3534749FD3693C19AA95E0768800472D11D438EC3116F337679A249C28BE0E038E6DE0
                Malicious:false
                Reputation:unknown
                URL:https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIZCZJtfF1WN2xyEgUN9IJXIiHbWQnLEsP1zw==?alt=proto
                Preview:CgkKBw30glciGgA=
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with CRLF line terminators
                Category:downloaded
                Size (bytes):26951
                Entropy (8bit):4.514992390210281
                Encrypted:false
                SSDEEP:
                MD5:B3D7A123BE5203A1A3F0F10233ED373F
                SHA1:F4C61F321D8F79A805B356C6EC94090C0D96215C
                SHA-256:EF9453F74B2617D43DCEF4242CF5845101FCFB57289C81BCEB20042B0023A192
                SHA-512:A01BFE8546E59C8AF83280A795B3F56DFA23D556B992813A4EB70089E80621686C7B51EE87B3109502667CAF1F95CBCA074BF607E543A0390BF6F8BB3ECD992B
                Malicious:false
                Reputation:unknown
                URL:https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=6xb0mkx3Nd8Zsr209JxKxK23NhWrjYYSbzucpWroW7ohyBYMsUIuJF99Od9L2nWysT44x1B9dKBAJzhgGKl7ITTmoFzK06Uf1w27Ok8hitXsuDDT-1mXHqXqjFWmm7p_GbE7jyVkGUS2bBirgORbxWVyL57Dx1NEre1a7J1sIjw1&t=ffffffffc7a8e318
                Preview:var Page_ValidationVer = "125";..var Page_IsValid = true;..var Page_BlockSubmit = false;..var Page_InvalidControlToBeFocused = null;..var Page_TextTypes = /^(text|password|file|search|tel|url|email|number|range|color|datetime|date|month|week|time|datetime-local)$/i;..function ValidatorUpdateDisplay(val) {.. if (typeof(val.display) == "string") {.. if (val.display == "None") {.. return;.. }.. if (val.display == "Dynamic") {.. val.style.display = val.isvalid ? "none" : "inline";.. return;.. }.. }.. if ((navigator.userAgent.indexOf("Mac") > -1) &&.. (navigator.userAgent.indexOf("MSIE") > -1)) {.. val.style.display = "inline";.. }.. val.style.visibility = val.isvalid ? "hidden" : "visible";..}..function ValidatorUpdateIsValid() {.. Page_IsValid = AllValidatorsValid(Page_Validators);..}..function AllValidatorsValid(validators) {.. if ((typeof(validators) != "undefined") && (validators != null)) {
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text
                Category:downloaded
                Size (bytes):215
                Entropy (8bit):5.322742823523759
                Encrypted:false
                SSDEEP:
                MD5:AEA040A867F7CA1E6D5B6F01A586BF85
                SHA1:6A1FD86D16986D834D40E882A5201247471E0C43
                SHA-256:0961A48EEE0AE79F95CBAF1745108E370FC3D807B938F85B1997E24F49AF3483
                SHA-512:A487DA8A3A22E96879572D39B2225CBD10B94E5A86A558C085D4C437BB3D215E8FC486C97E3EB913A356120F5F92106173CCF92C4BF036F072007F22929EA0DC
                Malicious:false
                Reputation:unknown
                URL:https://res-1.cdn.office.net/files/odsp-web-prod_2025-04-11.009/@uifabric/file-type-icons/lib/initializeFileTypeIcons.js
                Preview:.<?xml version="1.0" encoding="utf-8"?><Error><Code>BlobNotFound</Code><Message>The specified blob does not exist..RequestId:09e5317c-201e-0021-084f-b44c7b000000.Time:2025-04-23T12:58:53.8247260Z</Message></Error>
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with very long lines (17444)
                Category:downloaded
                Size (bytes):17672
                Entropy (8bit):5.233316811547578
                Encrypted:false
                SSDEEP:
                MD5:6EFDDF589864D2E146A55C01C6764A35
                SHA1:EFA8BBA46CB97877EEC5430C43F0AC32585B6B2F
                SHA-256:2D92F0CE8491D2F9A27EA16D261A15089C4A9BE879D1EEDCB6F4A3859E7F1999
                SHA-512:1AFC735660AAE010C04EF89C732D08EBA1B87BE6048164F273BEAEBECA3F30062812B4CD141DDF0291A6AB54F730875D597678A3564C0EED2AAC11E5400F951A
                Malicious:false
                Reputation:unknown
                URL:https://res-1.cdn.office.net/bld/_layouts/15/16.0.26002.12010/require.js
                Preview:/** vim: et:ts=4:sw=4:sts=4. * @license RequireJS 2.1.22 Copyright (c) 2010-2015, The Dojo Foundation All Rights Reserved.. * Available via the MIT or new BSD license.. * see: http://github.com/jrburke/requirejs for details. */.var requirejs,require,define;!function(global){function isFunction(e){return"[object Function]"===ostring.call(e)}function isArray(e){return"[object Array]"===ostring.call(e)}function each(e,t){if(e){var r;for(r=0;r<e.length&&(!e[r]||!t(e[r],r,e));r+=1);}}function eachReverse(e,t){if(e){var r;for(r=e.length-1;r>-1&&(!e[r]||!t(e[r],r,e));r-=1);}}function hasProp(e,t){return hasOwn.call(e,t)}function getOwn(e,t){return hasProp(e,t)&&e[t]}function eachProp(e,t){var r;for(r in e)if(hasProp(e,r)&&t(e[r],r))break}function mixin(e,t,r,i){return t&&eachProp(t,function(t,n){(r||!hasProp(e,n))&&(!i||"object"!=typeof t||!t||isArray(t)||isFunction(t)||t instanceof RegExp?e[n]=t:(e[n]||(e[n]={}),mixin(e[n],t,r,i)))}),e}function bind(e,t){return function(){return t.apply(e,ar
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:HTML document, ASCII text, with very long lines (30522), with CRLF, LF line terminators
                Category:downloaded
                Size (bytes):69550
                Entropy (8bit):5.6713345539952025
                Encrypted:false
                SSDEEP:
                MD5:8A7D4863ED8E7F373A76AC06AFF1246B
                SHA1:B7449E4517B7D94C0E4997AB9A901127C9BE822D
                SHA-256:3BC14575CA239290F9029A38D4F9C92086232B786C6B7835607DBB93F96E6874
                SHA-512:7516A7A84093F14F69FE07114160E53BB650177BD0E10567BA631ACF31CC35F819143F94FD06F8602720C71EF359E4E64E0658C683D93DFA0D0A573419FA912D
                Malicious:false
                Reputation:unknown
                URL:https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9
                Preview:..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns:o="urn:schemas-microsoft-com:office:office" lang="en-us" dir="ltr">..<head><meta name="GENERATOR" content="Microsoft SharePoint" /><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta http-equiv="Expires" content="0" /><meta name="Robots" content="NOHTMLINDEX" /><meta charset="UTF-8" /><meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1" /><meta http-equiv="X-UA-Compatible" content="IE=edge" /><link id="favicon" rel="shortcut icon" href="/_layouts/15/images/favicon.ico?rev=47" type="image/vnd.microsoft.icon" /><title>...Sharing Link Validation..</title>...<style type="text/css" media="screen, print, projection">....html{line-height:1.15;-ms-text-size-adjust:100%;-webkit-text-size-adjust:100%}body{margin:0}article,aside,footer,header,nav,section{display:block}h1{font-size:2em;margin:.67em 0}figcaption,figure,ma
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
                Category:downloaded
                Size (bytes):7886
                Entropy (8bit):3.9482833105763633
                Encrypted:false
                SSDEEP:
                MD5:0B60F3C9E4DA6E807E808DA7360F24F2
                SHA1:9AFC7ABB910DE855EFB426206E547574A1E074B7
                SHA-256:ADDEEDEEEF393B6B1BE5BBB099B656DCD797334FF972C495CCB09CFCB1A78341
                SHA-512:1328363987ABBAD1B927FC95F0A3D5646184EF69D66B42F32D1185EE06603AE1A574FAC64472FB6E349C2CE99F9B54407BA72B2908CA7AB01D023EC2F47E7E80
                Malicious:false
                Reputation:unknown
                URL:https://strateweldingsupply0-my.sharepoint.com/_layouts/15/images/favicon.ico?rev=47
                Preview:...... .... .....6......... ............... .h...f...(... ...@..... ...........................................................................70..7...7...7...7...7...7...70..............................................................................................7`..7...7...7...7...7...7...7...7...7`......................................................................................7P..7...7...7...7...7...7...7...7...7...7...7P..............................................................................7...7...7...7...7...7...7...7...7...7...7...7...7...7...........................................................................7`..7...7...7...7...7...7...7...7...7...7...7...7...7`..........................................................................,...,...,...,...,...,...,.......7...7...7...7...7...7...........................................................................'...'...'...'...'...'...'...'...2...7...7...7...7...,....................`..........................
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with CRLF line terminators
                Category:downloaded
                Size (bytes):23063
                Entropy (8bit):4.7535440881548165
                Encrypted:false
                SSDEEP:
                MD5:90EA7274F19755002360945D54C2A0D7
                SHA1:647B5D8BF7D119A2C97895363A07A0C6EB8CD284
                SHA-256:40732E9DCFA704CF615E4691BB07AECFD1CC5E063220A46E4A7FF6560C77F5DB
                SHA-512:7474667800FF52A0031029CC338F81E1586F237EB07A49183008C8EC44A8F67B37E5E896573F089A50283DF96A1C8F185E53D667741331B647894532669E2C07
                Malicious:false
                Reputation:unknown
                URL:https://strateweldingsupply0-my.sharepoint.com/WebResource.axd?d=mfEtoIhNDztfYoPjQ9yuEhQJPmB22UXQljmZyA_ivVmL7b0_Yc5nOzvvlspJQOir_DiV-sNmoWu1NqKRV1Td1w03gmDQYyll1HijRPRsiZQ1&t=638793884494602352
                Preview:function WebForm_PostBackOptions(eventTarget, eventArgument, validation, validationGroup, actionUrl, trackFocus, clientSubmit) {.. this.eventTarget = eventTarget;.. this.eventArgument = eventArgument;.. this.validation = validation;.. this.validationGroup = validationGroup;.. this.actionUrl = actionUrl;.. this.trackFocus = trackFocus;.. this.clientSubmit = clientSubmit;..}..function WebForm_DoPostBackWithOptions(options) {.. var validationResult = true;.. if (options.validation) {.. if (typeof(Page_ClientValidate) == 'function') {.. validationResult = Page_ClientValidate(options.validationGroup);.. }.. }.. if (validationResult) {.. if ((typeof(options.actionUrl) != "undefined") && (options.actionUrl != null) && (options.actionUrl.length > 0)) {.. theForm.action = options.actionUrl;.. }.. if (options.trackFocus) {.. var lastFocus = theForm.elements["__LASTFOCUS"];.. if ((typeo
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:ASCII text, with very long lines (45270)
                Category:downloaded
                Size (bytes):48261
                Entropy (8bit):5.404731705082535
                Encrypted:false
                SSDEEP:
                MD5:F5E62C426483ADAA5EC8CAD01EA2D175
                SHA1:5F7BD8E2C5E0CCD99D5727C5F4D06B1838887814
                SHA-256:8A2A5156B743C44F307158E8692CAFB47E3DF1F485AEFBC9BF3E52C175AAEB92
                SHA-512:B0083B9B5B3DD5CD0F562B2CA747A295BCF4086F92BCDED5C6114F4534EA612C034C87C6D4B050099B31FF0ECFEA8481AC360D504E094E46BF57942A4175DA45
                Malicious:false
                Reputation:unknown
                URL:https://res-1.cdn.office.net/files/odsp-web-prod_2025-04-11.009/spoguestaccesswebpack/spoguestaccess.js
                Preview:/*! For license information please see spoguestaccess.js.LICENSE.txt */.document.currentScript,define("@fluentui/react-file-type-icons",[],()=>{var e;return(()=>{"use strict";var t=[e=>{var t=Object.getOwnPropertySymbols,n=Object.prototype.hasOwnProperty,a=Object.prototype.propertyIsEnumerable;function i(e){if(null==e)throw new TypeError("Object.assign cannot be called with null or undefined");return Object(e)}e.exports=function(){try{if(!Object.assign)return!1;var e=new String("abc");if(e[5]="de","5"===Object.getOwnPropertyNames(e)[0])return!1;for(var t={},n=0;n<10;n++)t["_"+String.fromCharCode(n)]=n;if("0123456789"!==Object.getOwnPropertyNames(t).map(function(e){return t[e]}).join(""))return!1;var a={};return"abcdefghijklmnopqrst".split("").forEach(function(e){a[e]=e}),"abcdefghijklmnopqrst"===Object.keys(Object.assign({},a)).join("")}catch(e){return!1}}()?Object.assign:function(e,r){for(var o,s,c=i(e),d=1;d<arguments.length;d++){for(var l in o=Object(arguments[d]))n.call(o,l)&&(c[l]
                No static file info