Edit tour

Windows Analysis Report
https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9

Overview

General Information

Sample URL:https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9
Analysis ID:1672208
Infos:

Detection

Score:2
Range:0 - 100
Confidence:80%

Signatures

Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
HTML body contains low number of good links
HTML title does not match URL
Submit button contains javascript call

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 6276 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 6468 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1992,i,3108777188001462109,3549964953622845867,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2208 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • chrome.exe (PID: 1728 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9" MD5: E81F54E6C1129887AEA47E7D092680BF)
    • MpCmdRun.exe (PID: 5596 cmdline: "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable MD5: B3676839B2EE96983F9ED735CD044159)
      • conhost.exe (PID: 1940 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9HTTP Parser: Number of links: 0
Source: https://strateweldingsupply0-my.sharepoint.com/personal/strate12_strateweldingsupply_com/_layouts/15/guestaccess.aspx?e=4%3aeOZ6Ey&at=9&share=EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFwHTTP Parser: Number of links: 0
Source: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9HTTP Parser: Title: Sharing Link Validation does not match URL
Source: https://strateweldingsupply0-my.sharepoint.com/personal/strate12_strateweldingsupply_com/_layouts/15/guestaccess.aspx?e=4%3aeOZ6Ey&at=9&share=EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFwHTTP Parser: Title: Sharing Link Validation does not match URL
Source: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9HTTP Parser: On click: javascript:WebForm_DoPostBackWithOptions(new WebForm_PostBackOptions("btnSubmitEmail", "", true, "", "", false, true))
Source: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9HTTP Parser: On click: javascript:WebForm_DoPostBackWithOptions(new WebForm_PostBackOptions("btnSubmitEmail", "", true, "", "", false, true))
Source: https://strateweldingsupply0-my.sharepoint.com/personal/strate12_strateweldingsupply_com/_layouts/15/guestaccess.aspx?e=4%3aeOZ6Ey&at=9&share=EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFwHTTP Parser: On click: javascript:WebForm_DoPostBackWithOptions(new WebForm_PostBackOptions("btnSubmitEmail", "", true, "", "", false, true))
Source: https://strateweldingsupply0-my.sharepoint.com/personal/strate12_strateweldingsupply_com/_layouts/15/guestaccess.aspx?e=4%3aeOZ6Ey&at=9&share=EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFwHTTP Parser: On click: javascript:WebForm_DoPostBackWithOptions(new WebForm_PostBackOptions("btnSubmitEmail", "", true, "", "", false, true))
Source: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9HTTP Parser: No <meta name="author".. found
Source: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9HTTP Parser: No <meta name="author".. found
Source: https://strateweldingsupply0-my.sharepoint.com/personal/strate12_strateweldingsupply_com/_layouts/15/guestaccess.aspx?e=4%3aeOZ6Ey&at=9&share=EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFwHTTP Parser: No <meta name="author".. found
Source: https://strateweldingsupply0-my.sharepoint.com/personal/strate12_strateweldingsupply_com/_layouts/15/guestaccess.aspx?e=4%3aeOZ6Ey&at=9&share=EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFwHTTP Parser: No <meta name="author".. found
Source: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9HTTP Parser: No <meta name="copyright".. found
Source: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9HTTP Parser: No <meta name="copyright".. found
Source: https://strateweldingsupply0-my.sharepoint.com/personal/strate12_strateweldingsupply_com/_layouts/15/guestaccess.aspx?e=4%3aeOZ6Ey&at=9&share=EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFwHTTP Parser: No <meta name="copyright".. found
Source: https://strateweldingsupply0-my.sharepoint.com/personal/strate12_strateweldingsupply_com/_layouts/15/guestaccess.aspx?e=4%3aeOZ6Ey&at=9&share=EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFwHTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49719 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.16:49721 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.222.3.228:443 -> 192.168.2.16:49736 version: TLS 1.2
Source: chrome.exeMemory has grown: Private usage: 1MB later: 39MB
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ScriptResource.axd?d=6xb0mkx3Nd8Zsr209JxKxK23NhWrjYYSbzucpWroW7ohyBYMsUIuJF99Od9L2nWysT44x1B9dKBAJzhgGKl7ITTmoFzK06Uf1w27Ok8hitXsuDDT-1mXHqXqjFWmm7p_GbE7jyVkGUS2bBirgORbxWVyL57Dx1NEre1a7J1sIjw1&t=ffffffffc7a8e318 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ScriptResource.axd?d=GQCmJqA4eYb2TSj214APFzQ5EqHp3NSyob8OyQH2vxnRwPZ7PlQBTRYUTxkgHfw930FVDteHks5LyOzPET6wUnzcNhFB84NsrrMckwzm4NHixroqL0G023Sv5v-tia5NzG1FQJ6b5iRoJj5NU_CNj4Ky8ACDkrLIGhVfuhfXr-Rj8BxCFKOVh4yD9ma2PG_s0&t=2a9d95e3 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /WebResource.axd?d=mfEtoIhNDztfYoPjQ9yuEhQJPmB22UXQljmZyA_ivVmL7b0_Yc5nOzvvlspJQOir_DiV-sNmoWu1NqKRV1Td1w03gmDQYyll1HijRPRsiZQ1&t=638768124586963462 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ScriptResource.axd?d=GzWV25QV8vPNhs705rgdHQQxNt24Q5ePhEvJcl-IdAmZKO4pefK8GDBzcBVRFrgSddNUiGhNdfG225JwEowhF_Xr_E_W10AEh9Ww6_e4fFk8LJ4UYvxi5ByRXJXe16_xouXXOXnQe0xzC9k0R6hlpI5kO33nDrCIHbUAb-m391LAYl3_GgSHxXjLVxfClvT90&t=2a9d95e3 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_layouts/15/images/microsoft-logo.png HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_layouts/15/images/favicon.ico?rev=47 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_layouts/15/images/microsoft-logo.png HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_layouts/15/images/favicon.ico?rev=47 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /WebResource.axd?d=mfEtoIhNDztfYoPjQ9yuEhQJPmB22UXQljmZyA_ivVmL7b0_Yc5nOzvvlspJQOir_DiV-sNmoWu1NqKRV1Td1w03gmDQYyll1HijRPRsiZQ1&t=638793884494602352 HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://strateweldingsupply0-my.sharepoint.com/personal/strate12_strateweldingsupply_com/_layouts/15/guestaccess.aspx?e=4%3aeOZ6Ey&at=9&share=EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFwAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: strateweldingsupply0-my.sharepoint.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: m365cdn.nel.measure.office.net
Source: unknownHTTP traffic detected: POST /personal/strate12_strateweldingsupply_com/_layouts/15/guestaccess.aspx?e=4%3aeOZ6Ey&at=9&share=EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw HTTP/1.1Host: strateweldingsupply0-my.sharepoint.comConnection: keep-aliveContent-Length: 1719Cache-Control: max-age=0sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Origin: https://strateweldingsupply0-my.sharepoint.comContent-Type: application/x-www-form-urlencodedUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49702 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49701 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49703 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.136.10:443 -> 192.168.2.16:49719 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.178.49.196:443 -> 192.168.2.16:49721 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.222.3.228:443 -> 192.168.2.16:49736 version: TLS 1.2
Source: classification engineClassification label: clean2.win@24/14@12/117
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:1940:120:WilError_03
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1992,i,3108777188001462109,3549964953622845867,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2208 /prefetch:3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1992,i,3108777188001462109,3549964953622845867,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2208 /prefetch:3
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: mpclient.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: secur32.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: sspicli.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: version.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: msasn1.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: userenv.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: gpapi.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: wbemcomn.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: amsi.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: profapi.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: wscapi.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: urlmon.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: iertutil.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: srvcli.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: netutils.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: slc.dll
Source: C:\Program Files\Windows Defender\MpCmdRun.exeSection loaded: sppc.dll
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\Windows Defender\MpCmdRun.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\SecurityCenter2 : AntiVirusProduct
Source: C:\Program Files\Windows Defender\MpCmdRun.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\SecurityCenter2 : AntiVirusProduct
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts1
Windows Management Instrumentation
1
Scripting
1
Process Injection
2
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
Extra Window Memory Injection
1
DLL Side-Loading
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Extra Window Memory Injection
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=90%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=GQCmJqA4eYb2TSj214APFzQ5EqHp3NSyob8OyQH2vxnRwPZ7PlQBTRYUTxkgHfw930FVDteHks5LyOzPET6wUnzcNhFB84NsrrMckwzm4NHixroqL0G023Sv5v-tia5NzG1FQJ6b5iRoJj5NU_CNj4Ky8ACDkrLIGhVfuhfXr-Rj8BxCFKOVh4yD9ma2PG_s0&t=2a9d95e30%Avira URL Cloudsafe
https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=6xb0mkx3Nd8Zsr209JxKxK23NhWrjYYSbzucpWroW7ohyBYMsUIuJF99Od9L2nWysT44x1B9dKBAJzhgGKl7ITTmoFzK06Uf1w27Ok8hitXsuDDT-1mXHqXqjFWmm7p_GbE7jyVkGUS2bBirgORbxWVyL57Dx1NEre1a7J1sIjw1&t=ffffffffc7a8e3180%Avira URL Cloudsafe
https://strateweldingsupply0-my.sharepoint.com/WebResource.axd?d=mfEtoIhNDztfYoPjQ9yuEhQJPmB22UXQljmZyA_ivVmL7b0_Yc5nOzvvlspJQOir_DiV-sNmoWu1NqKRV1Td1w03gmDQYyll1HijRPRsiZQ1&t=6387681245869634620%Avira URL Cloudsafe
https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=GzWV25QV8vPNhs705rgdHQQxNt24Q5ePhEvJcl-IdAmZKO4pefK8GDBzcBVRFrgSddNUiGhNdfG225JwEowhF_Xr_E_W10AEh9Ww6_e4fFk8LJ4UYvxi5ByRXJXe16_xouXXOXnQe0xzC9k0R6hlpI5kO33nDrCIHbUAb-m391LAYl3_GgSHxXjLVxfClvT90&t=2a9d95e30%Avira URL Cloudsafe
https://strateweldingsupply0-my.sharepoint.com/_layouts/15/images/favicon.ico?rev=470%Avira URL Cloudsafe
https://strateweldingsupply0-my.sharepoint.com/_layouts/15/images/microsoft-logo.png0%Avira URL Cloudsafe
https://strateweldingsupply0-my.sharepoint.com/WebResource.axd?d=mfEtoIhNDztfYoPjQ9yuEhQJPmB22UXQljmZyA_ivVmL7b0_Yc5nOzvvlspJQOir_DiV-sNmoWu1NqKRV1Td1w03gmDQYyll1HijRPRsiZQ1&t=6387938844946023520%Avira URL Cloudsafe
https://m365cdn.nel.measure.office.net/api/report?FrontEnd=AkamaiCDNWorldWide&DestinationEndpoint=TEMPE&ASN=20940&Country=US&Region=AZ&RequestIdentifier=0.19c1c917.1745421735.27cec71&TotalRTCDNTime=139&CompressionType=&FileSize=2150%Avira URL Cloudsafe
https://m365cdn.nel.measure.office.net/api/report?FrontEnd=AkamaiCDNWorldWide&DestinationEndpoint=TEMPE&ASN=20940&Country=US&Region=AZ&RequestIdentifier=0.19c1c917.1745421803.27db339&TotalRTCDNTime=140&CompressionType=&FileSize=2150%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
dual-spo-0005.spo-msedge.net
13.107.136.10
truefalse
    high
    a726.dscd.akamai.net
    23.209.84.66
    truefalse
      high
      www.google.com
      192.178.49.196
      truefalse
        high
        a1894.dscb.akamai.net
        23.222.3.228
        truefalse
          high
          strateweldingsupply0-my.sharepoint.com
          unknown
          unknownfalse
            high
            m365cdn.nel.measure.office.net
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              https://strateweldingsupply0-my.sharepoint.com/personal/strate12_strateweldingsupply_com/_layouts/15/guestaccess.aspx?e=4%3aeOZ6Ey&at=9&share=EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFwfalse
                unknown
                https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=6xb0mkx3Nd8Zsr209JxKxK23NhWrjYYSbzucpWroW7ohyBYMsUIuJF99Od9L2nWysT44x1B9dKBAJzhgGKl7ITTmoFzK06Uf1w27Ok8hitXsuDDT-1mXHqXqjFWmm7p_GbE7jyVkGUS2bBirgORbxWVyL57Dx1NEre1a7J1sIjw1&t=ffffffffc7a8e318false
                • Avira URL Cloud: safe
                unknown
                https://m365cdn.nel.measure.office.net/api/report?FrontEnd=AkamaiCDNWorldWide&DestinationEndpoint=TEMPE&ASN=20940&Country=US&Region=AZ&RequestIdentifier=0.19c1c917.1745421803.27db339&TotalRTCDNTime=140&CompressionType=&FileSize=215false
                • Avira URL Cloud: safe
                unknown
                https://strateweldingsupply0-my.sharepoint.com/_layouts/15/images/favicon.ico?rev=47false
                • Avira URL Cloud: safe
                unknown
                https://m365cdn.nel.measure.office.net/api/report?FrontEnd=AkamaiCDNWorldWide&DestinationEndpoint=TEMPE&ASN=20940&Country=US&Region=AZ&RequestIdentifier=0.19c1c917.1745421735.27cec71&TotalRTCDNTime=139&CompressionType=&FileSize=215false
                • Avira URL Cloud: safe
                unknown
                https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=GQCmJqA4eYb2TSj214APFzQ5EqHp3NSyob8OyQH2vxnRwPZ7PlQBTRYUTxkgHfw930FVDteHks5LyOzPET6wUnzcNhFB84NsrrMckwzm4NHixroqL0G023Sv5v-tia5NzG1FQJ6b5iRoJj5NU_CNj4Ky8ACDkrLIGhVfuhfXr-Rj8BxCFKOVh4yD9ma2PG_s0&t=2a9d95e3false
                • Avira URL Cloud: safe
                unknown
                https://strateweldingsupply0-my.sharepoint.com/_layouts/15/images/microsoft-logo.pngfalse
                • Avira URL Cloud: safe
                unknown
                https://strateweldingsupply0-my.sharepoint.com/WebResource.axd?d=mfEtoIhNDztfYoPjQ9yuEhQJPmB22UXQljmZyA_ivVmL7b0_Yc5nOzvvlspJQOir_DiV-sNmoWu1NqKRV1Td1w03gmDQYyll1HijRPRsiZQ1&t=638768124586963462false
                • Avira URL Cloud: safe
                unknown
                https://strateweldingsupply0-my.sharepoint.com/WebResource.axd?d=mfEtoIhNDztfYoPjQ9yuEhQJPmB22UXQljmZyA_ivVmL7b0_Yc5nOzvvlspJQOir_DiV-sNmoWu1NqKRV1Td1w03gmDQYyll1HijRPRsiZQ1&t=638793884494602352false
                • Avira URL Cloud: safe
                unknown
                https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9false
                  unknown
                  https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=GzWV25QV8vPNhs705rgdHQQxNt24Q5ePhEvJcl-IdAmZKO4pefK8GDBzcBVRFrgSddNUiGhNdfG225JwEowhF_Xr_E_W10AEh9Ww6_e4fFk8LJ4UYvxi5ByRXJXe16_xouXXOXnQe0xzC9k0R6hlpI5kO33nDrCIHbUAb-m391LAYl3_GgSHxXjLVxfClvT90&t=2a9d95e3false
                  • Avira URL Cloud: safe
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  142.250.69.3
                  unknownUnited States
                  15169GOOGLEUSfalse
                  23.209.84.29
                  unknownUnited States
                  16625AKAMAI-ASUSfalse
                  142.250.68.234
                  unknownUnited States
                  15169GOOGLEUSfalse
                  1.1.1.1
                  unknownAustralia
                  13335CLOUDFLARENETUSfalse
                  13.107.136.10
                  dual-spo-0005.spo-msedge.netUnited States
                  8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                  74.125.137.84
                  unknownUnited States
                  15169GOOGLEUSfalse
                  192.178.49.195
                  unknownUnited States
                  15169GOOGLEUSfalse
                  192.178.49.196
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  192.178.49.174
                  unknownUnited States
                  15169GOOGLEUSfalse
                  23.209.84.66
                  a726.dscd.akamai.netUnited States
                  16625AKAMAI-ASUSfalse
                  142.250.68.238
                  unknownUnited States
                  15169GOOGLEUSfalse
                  23.222.3.228
                  a1894.dscb.akamai.netUnited States
                  8612TISCALI-ITfalse
                  IP
                  192.168.2.16
                  Joe Sandbox version:42.0.0 Malachite
                  Analysis ID:1672208
                  Start date and time:2025-04-23 17:21:09 +02:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:defaultwindowsinteractivecookbook.jbs
                  Sample URL:https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:14
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • EGA enabled
                  Analysis Mode:stream
                  Analysis stop reason:Timeout
                  Detection:CLEAN
                  Classification:clean2.win@24/14@12/117
                  • Exclude process from analysis (whitelisted): svchost.exe
                  • Excluded IPs from analysis (whitelisted): 192.178.49.174, 192.178.49.195, 74.125.137.84, 142.250.68.238, 142.250.69.14, 142.250.68.234, 192.178.49.170, 192.178.49.202, 142.250.69.10, 23.209.84.66
                  • Excluded domains from analysis (whitelisted): clients2.google.com, accounts.google.com, redirector.gvt1.com, content-autofill.googleapis.com, clientservices.googleapis.com, res-1.cdn.office.net, clients.l.google.com, res-stls-prod.edgesuite.net
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size getting too big, too many NtOpenFile calls found.
                  • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                  • VT rate limit hit for: https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&amp;at=9
                  Process:C:\Program Files\Windows Defender\MpCmdRun.exe
                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                  Category:modified
                  Size (bytes):7388
                  Entropy (8bit):3.243333765414888
                  Encrypted:false
                  SSDEEP:
                  MD5:2A2E90D39BA36529D65225AA5DB1F86E
                  SHA1:ACC8E666B95444F4DC53D4187B35FAB0CA9D3BC0
                  SHA-256:85A47F7A41E25550E1BC62C44F8AC68FD5D3A08CC07B6693F1F7E198FE5D43F6
                  SHA-512:65B0EF53F0B31DD8196A2129FB4745DAE2D156C86A28F4CD70B0A1691A1BAE07DE855504126B3CB8AC673CA350C18CAED1F3D508BF3449253EA33889E60D97BD
                  Malicious:false
                  Reputation:unknown
                  Preview:..........-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.....M.p.C.m.d.R.u.n.:. .C.o.m.m.a.n.d. .L.i.n.e.:. .".C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.\.m.p.c.m.d.r.u.n...e.x.e.". .-.w.d.e.n.a.b.l.e..... .S.t.a.r.t. .T.i.m.e.:. .. F.r.i. .. O.c.t. .. 0.6. .. 2.0.2.3. .1.1.:.3.5.:.2.9.........M.p.E.n.s.u.r.e.P.r.o.c.e.s.s.M.i.t.i.g.a.t.i.o.n.P.o.l.i.c.y.:. .h.r. .=. .0.x.1.....W.D.E.n.a.b.l.e.....*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*. .W.S.C. .S.t.a.t.e. .I.n.f.o. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.....*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*. .A.n.t.i.V.i.r.u.s.P.r.o.d.u.c.t. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.....d.i.s.p.l.a.y.N.a.m.e. .=. .[.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.].....p.a.t.h.T.o.S.i.g.n.e.d.P.r.o.d.u.c.t.E.x.e. .=. .[.w.i.n.d.o.w.s.d.
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with very long lines (39257), with CRLF line terminators
                  Category:downloaded
                  Size (bytes):40326
                  Entropy (8bit):5.245555585297941
                  Encrypted:false
                  SSDEEP:
                  MD5:DA9DC1C32E89C02FC1E9EEB7E5AAB91E
                  SHA1:3EFB110EFA6068CE6B586A67F87DA5125310BC30
                  SHA-256:398CDF1B27EF247E5BC77805F266BB441E60355463FC3D1776F41AAE58B08CF1
                  SHA-512:D4730EBC4CA62624B8300E292F27FD79D42A9277E409545DF7DC916189ED9DF13E46FAA37E3924B85A7C7EA8C76BF65A05ECA69B4029B550430536EC6DF8552A
                  Malicious:false
                  Reputation:unknown
                  URL:https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=GzWV25QV8vPNhs705rgdHQQxNt24Q5ePhEvJcl-IdAmZKO4pefK8GDBzcBVRFrgSddNUiGhNdfG225JwEowhF_Xr_E_W10AEh9Ww6_e4fFk8LJ4UYvxi5ByRXJXe16_xouXXOXnQe0xzC9k0R6hlpI5kO33nDrCIHbUAb-m391LAYl3_GgSHxXjLVxfClvT90&t=2a9d95e3
                  Preview://----------------------------------------------------------..// Copyright (C) Microsoft Corporation. All rights reserved...//----------------------------------------------------------..// MicrosoftAjaxWebForms.js..Type._registerScript("MicrosoftAjaxWebForms.js",["MicrosoftAjaxCore.js","MicrosoftAjaxSerialization.js","MicrosoftAjaxNetwork.js","MicrosoftAjaxComponentModel.js"]);Type.registerNamespace("Sys.WebForms");Sys.WebForms.BeginRequestEventArgs=function(c,b,a){Sys.WebForms.BeginRequestEventArgs.initializeBase(this);this._request=c;this._postBackElement=b;this._updatePanelsToUpdate=a};Sys.WebForms.BeginRequestEventArgs.prototype={get_postBackElement:function(){return this._postBackElement},get_request:function(){return this._request},get_updatePanelsToUpdate:function(){return this._updatePanelsToUpdate?Array.clone(this._updatePanelsToUpdate):[]}};Sys.WebForms.BeginRequestEventArgs.registerClass("Sys.WebForms.BeginRequestEventArgs",Sys.EventArgs);Sys.WebForms.EndRequestEventArgs=fun
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, ASCII text, with very long lines (30522), with CRLF, LF line terminators
                  Category:downloaded
                  Size (bytes):69368
                  Entropy (8bit):5.669282675042478
                  Encrypted:false
                  SSDEEP:
                  MD5:E4D1F5AE92E3ADA01AA35698E5ED7918
                  SHA1:B373E291CE8E3DCF07D7A21A7ADA5C6E2FA10AC8
                  SHA-256:3250FF643C5D1E87ADEB962615CC1EAACCA87C608561BAB109DCCFA542B88CBB
                  SHA-512:55AFF498666D354735C4D4D8FC5CD5D3C08D081F4A82D11FEBD4C222191DCACA9E73C01DF19D31B700962C70C888123257599892912FBB5125C727FCAF6C894F
                  Malicious:false
                  Reputation:unknown
                  URL:https://strateweldingsupply0-my.sharepoint.com/personal/strate12_strateweldingsupply_com/_layouts/15/guestaccess.aspx?e=4%3aeOZ6Ey&at=9&share=EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw
                  Preview:..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns:o="urn:schemas-microsoft-com:office:office" lang="en-us" dir="ltr">..<head><meta name="GENERATOR" content="Microsoft SharePoint" /><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta http-equiv="Expires" content="0" /><meta name="Robots" content="NOHTMLINDEX" /><meta charset="UTF-8" /><meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1" /><meta http-equiv="X-UA-Compatible" content="IE=edge" /><link id="favicon" rel="shortcut icon" href="/_layouts/15/images/favicon.ico?rev=47" type="image/vnd.microsoft.icon" /><title>...Sharing Link Validation..</title>...<style type="text/css" media="screen, print, projection">....html{line-height:1.15;-ms-text-size-adjust:100%;-webkit-text-size-adjust:100%}body{margin:0}article,aside,footer,header,nav,section{display:block}h1{font-size:2em;margin:.67em 0}figcaption,figure,ma
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, ASCII text, with very long lines (30522), with CRLF, LF line terminators
                  Category:downloaded
                  Size (bytes):69376
                  Entropy (8bit):5.670032892939586
                  Encrypted:false
                  SSDEEP:
                  MD5:A0FCEFFF8A1503737EBA1864B18DA9AA
                  SHA1:E6BA7B480B91EA23DE731C22161E2D073E233F26
                  SHA-256:E4E6D0F375E7D3D7B9A6B4E820096EFB9BDB3DA1CB17044E2999E65C9B7FB526
                  SHA-512:42AA92408CA23D76E22DF2F2C366A40D1B3CB6649A96182B1F06E16D0675F7FDF7C78358253885A1D1963FD84EADFE2A31A97F0C603BA7CD48BE8272B47F42B8
                  Malicious:false
                  Reputation:unknown
                  URL:https://strateweldingsupply0-my.sharepoint.com/personal/strate12_strateweldingsupply_com/_layouts/15/guestaccess.aspx?e=4%3aeOZ6Ey&at=9&share=EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw
                  Preview:..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns:o="urn:schemas-microsoft-com:office:office" lang="en-us" dir="ltr">..<head><meta name="GENERATOR" content="Microsoft SharePoint" /><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta http-equiv="Expires" content="0" /><meta name="Robots" content="NOHTMLINDEX" /><meta charset="UTF-8" /><meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1" /><meta http-equiv="X-UA-Compatible" content="IE=edge" /><link id="favicon" rel="shortcut icon" href="/_layouts/15/images/favicon.ico?rev=47" type="image/vnd.microsoft.icon" /><title>...Sharing Link Validation..</title>...<style type="text/css" media="screen, print, projection">....html{line-height:1.15;-ms-text-size-adjust:100%;-webkit-text-size-adjust:100%}body{margin:0}article,aside,footer,header,nav,section{display:block}h1{font-size:2em;margin:.67em 0}figcaption,figure,ma
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with very long lines (65329), with CRLF line terminators
                  Category:downloaded
                  Size (bytes):102801
                  Entropy (8bit):5.336080509196147
                  Encrypted:false
                  SSDEEP:
                  MD5:C89EAA5B28DF1E17376BE71D71649173
                  SHA1:2B34DF4C66BB57DE5A24A2EF0896271DFCA4F4CD
                  SHA-256:66B804E7A96A87C11E1DD74EA04AC2285DF5AD9043F48046C3E5000114D39B1C
                  SHA-512:B73D56304986CD587DA17BEBF21341B450D41861824102CC53885D863B118F6FDF2456B20791B9A7AE56DF91403F342550AF9E46F7401429FBA1D4A15A6BD3C0
                  Malicious:false
                  Reputation:unknown
                  URL:https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=GQCmJqA4eYb2TSj214APFzQ5EqHp3NSyob8OyQH2vxnRwPZ7PlQBTRYUTxkgHfw930FVDteHks5LyOzPET6wUnzcNhFB84NsrrMckwzm4NHixroqL0G023Sv5v-tia5NzG1FQJ6b5iRoJj5NU_CNj4Ky8ACDkrLIGhVfuhfXr-Rj8BxCFKOVh4yD9ma2PG_s0&t=2a9d95e3
                  Preview://----------------------------------------------------------..// Copyright (C) Microsoft Corporation. All rights reserved...//----------------------------------------------------------..// MicrosoftAjax.js..Function.__typeName="Function";Function.__class=true;Function.createCallback=function(b,a){return function(){var e=arguments.length;if(e>0){var d=[];for(var c=0;c<e;c++)d[c]=arguments[c];d[e]=a;return b.apply(this,d)}return b.call(this,a)}};Function.createDelegate=function(a,b){return function(){return b.apply(a,arguments)}};Function.emptyFunction=Function.emptyMethod=function(){};Function.validateParameters=function(c,b,a){return Function._validateParams(c,b,a)};Function._validateParams=function(g,e,c){var a,d=e.length;c=c||typeof c==="undefined";a=Function._validateParameterCount(g,e,c);if(a){a.popStackFrame();return a}for(var b=0,i=g.length;b<i;b++){var f=e[Math.min(b,d-1)],h=f.name;if(f.parameterArray)h+="["+(b-d+1)+"]";else if(!c&&b>=d)break;a=Function._validateParameter(g[b],f
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with no line terminators
                  Category:downloaded
                  Size (bytes):16
                  Entropy (8bit):3.702819531114783
                  Encrypted:false
                  SSDEEP:
                  MD5:858372DD32511CB4DD08E48A93B4F175
                  SHA1:CE4555B7B2EFBBD644D8E34CF3453A0E8CAA3C43
                  SHA-256:3D18F3E1469C83D62CF3A39BA93F8EAA5B22447FE630E59F39DC1B7747635359
                  SHA-512:6A57E0D4A1C23CB693AA9312F6FDAA1FC4309B5BC91D1B2279B5792BEE3534749FD3693C19AA95E0768800472D11D438EC3116F337679A249C28BE0E038E6DE0
                  Malicious:false
                  Reputation:unknown
                  URL:https://content-autofill.googleapis.com/v1/pages/ChRDaHJvbWUvMTM0LjAuNjk5OC4zNhIZCZJtfF1WN2xyEgUN9IJXIiHbWQnLEsP1zw==?alt=proto
                  Preview:CgkKBw30glciGgA=
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:downloaded
                  Size (bytes):26951
                  Entropy (8bit):4.514992390210281
                  Encrypted:false
                  SSDEEP:
                  MD5:B3D7A123BE5203A1A3F0F10233ED373F
                  SHA1:F4C61F321D8F79A805B356C6EC94090C0D96215C
                  SHA-256:EF9453F74B2617D43DCEF4242CF5845101FCFB57289C81BCEB20042B0023A192
                  SHA-512:A01BFE8546E59C8AF83280A795B3F56DFA23D556B992813A4EB70089E80621686C7B51EE87B3109502667CAF1F95CBCA074BF607E543A0390BF6F8BB3ECD992B
                  Malicious:false
                  Reputation:unknown
                  URL:https://strateweldingsupply0-my.sharepoint.com/ScriptResource.axd?d=6xb0mkx3Nd8Zsr209JxKxK23NhWrjYYSbzucpWroW7ohyBYMsUIuJF99Od9L2nWysT44x1B9dKBAJzhgGKl7ITTmoFzK06Uf1w27Ok8hitXsuDDT-1mXHqXqjFWmm7p_GbE7jyVkGUS2bBirgORbxWVyL57Dx1NEre1a7J1sIjw1&t=ffffffffc7a8e318
                  Preview:var Page_ValidationVer = "125";..var Page_IsValid = true;..var Page_BlockSubmit = false;..var Page_InvalidControlToBeFocused = null;..var Page_TextTypes = /^(text|password|file|search|tel|url|email|number|range|color|datetime|date|month|week|time|datetime-local)$/i;..function ValidatorUpdateDisplay(val) {.. if (typeof(val.display) == "string") {.. if (val.display == "None") {.. return;.. }.. if (val.display == "Dynamic") {.. val.style.display = val.isvalid ? "none" : "inline";.. return;.. }.. }.. if ((navigator.userAgent.indexOf("Mac") > -1) &&.. (navigator.userAgent.indexOf("MSIE") > -1)) {.. val.style.display = "inline";.. }.. val.style.visibility = val.isvalid ? "hidden" : "visible";..}..function ValidatorUpdateIsValid() {.. Page_IsValid = AllValidatorsValid(Page_Validators);..}..function AllValidatorsValid(validators) {.. if ((typeof(validators) != "undefined") && (validators != null)) {
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:PNG image data, 226 x 48, 8-bit/color RGBA, non-interlaced
                  Category:dropped
                  Size (bytes):3331
                  Entropy (8bit):7.927896166439245
                  Encrypted:false
                  SSDEEP:
                  MD5:EF884BDEDEF280DF97A4C5604058D8DB
                  SHA1:6F04244B51AD2409659E267D308B97E09CE9062B
                  SHA-256:825DE044D5AC6442A094FF95099F9F67E9249A8110A2FBD57128285776632ADB
                  SHA-512:A083381C53070B65B3B8A7A7293D5D2674D2F6EC69C0E19748823D3FDD6F527E8D3D31D311CCEF8E26FC531770F101CDAF95F23ECC990DB405B5EF48B0C91BA2
                  Malicious:false
                  Reputation:unknown
                  Preview:.PNG........IHDR.......0............sRGB.........IDATx..=w....G.z..L.4fN.k\dS..._`..........r...~.F..e._.RZ.0.K.\..CB...1.{qq/..^|.G..o.......?....Or.......y~....]..V.a.mM...M.\k*H..@B`s.$"n...)!.@"b#4. !.9...7.u...hD ....T.........:EJ.4"..X........<|.pgkk+....>~.....pju1i"b.J.&!.!...=T....k..D7.....O.<.?}......./..(.`0..!.C..'.?..e..~.....l6...._.x1rmR...$|E...l.WKDH...f..... ...Y.0R....>...{...-..o........,...E../......_....eM.Q....@Q...w sp5.9..l.W)...Pq... .]..B..).../M.G.g....].V...5$<......Eb.9.....>LYAk.Z.k..b..]N%>}4a....4!S...t..d..<.8AH+.../r...._...!qt.:q..fR.:..KW.._...T...5..>.0!.hq.rbND\...XR.,2.uX..Q.b...wQ......g..X...F...~.....ikZE...UA....V.I!..]..Mm..R.....~k.VC.n..V.*B#W...\..yI.3.....2........6c....2J....,g..5O1.s.4V2.....f..K..Obf\....;.w...|.F>F>6_z..P.dU<.wVV......?.q.?&........O.>....l.S.upp....59.C_.......fJ.M.={v,......]Y_....n.?UF....v<.$..AD...p.....:$r =p...C.k.3....n.v..~.TGd!...l.W...s..
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:downloaded
                  Size (bytes):23063
                  Entropy (8bit):4.7535440881548165
                  Encrypted:false
                  SSDEEP:
                  MD5:90EA7274F19755002360945D54C2A0D7
                  SHA1:647B5D8BF7D119A2C97895363A07A0C6EB8CD284
                  SHA-256:40732E9DCFA704CF615E4691BB07AECFD1CC5E063220A46E4A7FF6560C77F5DB
                  SHA-512:7474667800FF52A0031029CC338F81E1586F237EB07A49183008C8EC44A8F67B37E5E896573F089A50283DF96A1C8F185E53D667741331B647894532669E2C07
                  Malicious:false
                  Reputation:unknown
                  URL:https://strateweldingsupply0-my.sharepoint.com/WebResource.axd?d=mfEtoIhNDztfYoPjQ9yuEhQJPmB22UXQljmZyA_ivVmL7b0_Yc5nOzvvlspJQOir_DiV-sNmoWu1NqKRV1Td1w03gmDQYyll1HijRPRsiZQ1&t=638768124586963462
                  Preview:function WebForm_PostBackOptions(eventTarget, eventArgument, validation, validationGroup, actionUrl, trackFocus, clientSubmit) {.. this.eventTarget = eventTarget;.. this.eventArgument = eventArgument;.. this.validation = validation;.. this.validationGroup = validationGroup;.. this.actionUrl = actionUrl;.. this.trackFocus = trackFocus;.. this.clientSubmit = clientSubmit;..}..function WebForm_DoPostBackWithOptions(options) {.. var validationResult = true;.. if (options.validation) {.. if (typeof(Page_ClientValidate) == 'function') {.. validationResult = Page_ClientValidate(options.validationGroup);.. }.. }.. if (validationResult) {.. if ((typeof(options.actionUrl) != "undefined") && (options.actionUrl != null) && (options.actionUrl.length > 0)) {.. theForm.action = options.actionUrl;.. }.. if (options.trackFocus) {.. var lastFocus = theForm.elements["__LASTFOCUS"];.. if ((typeo
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text
                  Category:downloaded
                  Size (bytes):215
                  Entropy (8bit):5.322320669499417
                  Encrypted:false
                  SSDEEP:
                  MD5:CA365124FCEB28F608A353D8F02126D3
                  SHA1:BF5456EEF84925F22738F2802C4768ACFD290DDD
                  SHA-256:5EFB80157016B9D3F4D440FDDE1AFCF0B90BE9E41B854750F207E276EDB50C52
                  SHA-512:3CA23D9BB82BC8835C169907C6058C99ADE14BB789F6D754FE45165BE96669B3D82393265499277B3D669AE65213A55F4519AA7AB08C0412CCB3E7327C20E811
                  Malicious:false
                  Reputation:unknown
                  URL:https://res-1.cdn.office.net/files/odsp-web-prod_2025-04-11.009/@uifabric/file-type-icons/lib/initializeFileTypeIcons.js
                  Preview:.<?xml version="1.0" encoding="utf-8"?><Error><Code>BlobNotFound</Code><Message>The specified blob does not exist..RequestId:2da43a6a-301e-003d-2863-b41e1b000000.Time:2025-04-23T15:23:23.1369745Z</Message></Error>
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with very long lines (17444)
                  Category:downloaded
                  Size (bytes):17672
                  Entropy (8bit):5.233316811547578
                  Encrypted:false
                  SSDEEP:
                  MD5:6EFDDF589864D2E146A55C01C6764A35
                  SHA1:EFA8BBA46CB97877EEC5430C43F0AC32585B6B2F
                  SHA-256:2D92F0CE8491D2F9A27EA16D261A15089C4A9BE879D1EEDCB6F4A3859E7F1999
                  SHA-512:1AFC735660AAE010C04EF89C732D08EBA1B87BE6048164F273BEAEBECA3F30062812B4CD141DDF0291A6AB54F730875D597678A3564C0EED2AAC11E5400F951A
                  Malicious:false
                  Reputation:unknown
                  URL:https://res-1.cdn.office.net/bld/_layouts/15/16.0.26002.12010/require.js
                  Preview:/** vim: et:ts=4:sw=4:sts=4. * @license RequireJS 2.1.22 Copyright (c) 2010-2015, The Dojo Foundation All Rights Reserved.. * Available via the MIT or new BSD license.. * see: http://github.com/jrburke/requirejs for details. */.var requirejs,require,define;!function(global){function isFunction(e){return"[object Function]"===ostring.call(e)}function isArray(e){return"[object Array]"===ostring.call(e)}function each(e,t){if(e){var r;for(r=0;r<e.length&&(!e[r]||!t(e[r],r,e));r+=1);}}function eachReverse(e,t){if(e){var r;for(r=e.length-1;r>-1&&(!e[r]||!t(e[r],r,e));r-=1);}}function hasProp(e,t){return hasOwn.call(e,t)}function getOwn(e,t){return hasProp(e,t)&&e[t]}function eachProp(e,t){var r;for(r in e)if(hasProp(e,r)&&t(e[r],r))break}function mixin(e,t,r,i){return t&&eachProp(t,function(t,n){(r||!hasProp(e,n))&&(!i||"object"!=typeof t||!t||isArray(t)||isFunction(t)||t instanceof RegExp?e[n]=t:(e[n]||(e[n]={}),mixin(e[n],t,r,i)))}),e}function bind(e,t){return function(){return t.apply(e,ar
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, ASCII text, with very long lines (30522), with CRLF, LF line terminators
                  Category:downloaded
                  Size (bytes):69551
                  Entropy (8bit):5.669234294686659
                  Encrypted:false
                  SSDEEP:
                  MD5:999D8465744E351472D480E510A361C3
                  SHA1:8EA780217F8983A0AF55A4B1E2374F8CDFF820ED
                  SHA-256:40C52E2F7B51021D62AEC3247EBC82DE6AAB271DE49FCCDB7B4E80C6BE620FB4
                  SHA-512:B0387D85E43B7E3D74F04A1315A683B1B0AC8C45F9F00C704C4315E662969EDA4BE610C8A6D00380FD02BDDA5B93CD86EA09F7D96A795C25EE64DD1E91463053
                  Malicious:false
                  Reputation:unknown
                  URL:https://strateweldingsupply0-my.sharepoint.com/:b:/g/personal/strate12_strateweldingsupply_com/EaHsj_nVZgpMr2t8b0-EVz8BpoZn0bBYspJRPwo3do3fFw?e=4%3aeOZ6Ey&at=9
                  Preview:..<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">..<html xmlns:o="urn:schemas-microsoft-com:office:office" lang="en-us" dir="ltr">..<head><meta name="GENERATOR" content="Microsoft SharePoint" /><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta http-equiv="Expires" content="0" /><meta name="Robots" content="NOHTMLINDEX" /><meta charset="UTF-8" /><meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1" /><meta http-equiv="X-UA-Compatible" content="IE=edge" /><link id="favicon" rel="shortcut icon" href="/_layouts/15/images/favicon.ico?rev=47" type="image/vnd.microsoft.icon" /><title>...Sharing Link Validation..</title>...<style type="text/css" media="screen, print, projection">....html{line-height:1.15;-ms-text-size-adjust:100%;-webkit-text-size-adjust:100%}body{margin:0}article,aside,footer,header,nav,section{display:block}h1{font-size:2em;margin:.67em 0}figcaption,figure,ma
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with very long lines (45270)
                  Category:downloaded
                  Size (bytes):48261
                  Entropy (8bit):5.404731705082535
                  Encrypted:false
                  SSDEEP:
                  MD5:F5E62C426483ADAA5EC8CAD01EA2D175
                  SHA1:5F7BD8E2C5E0CCD99D5727C5F4D06B1838887814
                  SHA-256:8A2A5156B743C44F307158E8692CAFB47E3DF1F485AEFBC9BF3E52C175AAEB92
                  SHA-512:B0083B9B5B3DD5CD0F562B2CA747A295BCF4086F92BCDED5C6114F4534EA612C034C87C6D4B050099B31FF0ECFEA8481AC360D504E094E46BF57942A4175DA45
                  Malicious:false
                  Reputation:unknown
                  URL:https://res-1.cdn.office.net/files/odsp-web-prod_2025-04-11.009/spoguestaccesswebpack/spoguestaccess.js
                  Preview:/*! For license information please see spoguestaccess.js.LICENSE.txt */.document.currentScript,define("@fluentui/react-file-type-icons",[],()=>{var e;return(()=>{"use strict";var t=[e=>{var t=Object.getOwnPropertySymbols,n=Object.prototype.hasOwnProperty,a=Object.prototype.propertyIsEnumerable;function i(e){if(null==e)throw new TypeError("Object.assign cannot be called with null or undefined");return Object(e)}e.exports=function(){try{if(!Object.assign)return!1;var e=new String("abc");if(e[5]="de","5"===Object.getOwnPropertyNames(e)[0])return!1;for(var t={},n=0;n<10;n++)t["_"+String.fromCharCode(n)]=n;if("0123456789"!==Object.getOwnPropertyNames(t).map(function(e){return t[e]}).join(""))return!1;var a={};return"abcdefghijklmnopqrst".split("").forEach(function(e){a[e]=e}),"abcdefghijklmnopqrst"===Object.keys(Object.assign({},a)).join("")}catch(e){return!1}}()?Object.assign:function(e,r){for(var o,s,c=i(e),d=1;d<arguments.length;d++){for(var l in o=Object(arguments[d]))n.call(o,l)&&(c[l]
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
                  Category:dropped
                  Size (bytes):7886
                  Entropy (8bit):3.9482833105763633
                  Encrypted:false
                  SSDEEP:
                  MD5:0B60F3C9E4DA6E807E808DA7360F24F2
                  SHA1:9AFC7ABB910DE855EFB426206E547574A1E074B7
                  SHA-256:ADDEEDEEEF393B6B1BE5BBB099B656DCD797334FF972C495CCB09CFCB1A78341
                  SHA-512:1328363987ABBAD1B927FC95F0A3D5646184EF69D66B42F32D1185EE06603AE1A574FAC64472FB6E349C2CE99F9B54407BA72B2908CA7AB01D023EC2F47E7E80
                  Malicious:false
                  Reputation:unknown
                  Preview:...... .... .....6......... ............... .h...f...(... ...@..... ...........................................................................70..7...7...7...7...7...7...70..............................................................................................7`..7...7...7...7...7...7...7...7...7`......................................................................................7P..7...7...7...7...7...7...7...7...7...7...7P..............................................................................7...7...7...7...7...7...7...7...7...7...7...7...7...7...........................................................................7`..7...7...7...7...7...7...7...7...7...7...7...7...7`..........................................................................,...,...,...,...,...,...,.......7...7...7...7...7...7...........................................................................'...'...'...'...'...'...'...'...2...7...7...7...7...,....................`..........................
                  No static file info