Windows Analysis Report
https://sharefile8.pages.dev/b08+zb2ylref0qax

Overview

General Information

Sample URL: https://sharefile8.pages.dev/b08+zb2ylref0qax
Analysis ID: 1502061
Infos:

Detection

Score: 64
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

AI detected phishing page
Antivirus / Scanner detection for submitted sample
Phishing site detected (based on favicon image match)
Phishing site detected (based on logo match)
Detected non-DNS traffic on DNS port
HTML body contains low number of good links
HTML title does not match URL

Classification

AV Detection

barindex
Source: https://sharefile8.pages.dev/b08+zb2ylref0qax Avira URL Cloud: detection malicious, Label: phishing
Source: https://sharefile8.pages.dev/b08+zb2ylref0qax SlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering

Phishing

barindex
Source: https://sharefile8.pages.dev/b08+zb2ylref0qax?0dc76ab0dd308d6a261c143750b9eaf0m0haoys3=U2FsdGVkX1%2Bx%2BrtNATtHUgjMr7p8GXN0rISAjyQFtyvb7gycmSolKTr8OWrm593XWOHvyBWWh83TJoGR3fKvvWNGJjlYwTygUb6YSz%2BXkTzgkTMPojiEE%2Be2lvvzp%2Fx6%2FAyKC9BsHbP4NUOf10F5S1yqjllntRTpNu4hfJ1FBrx39J0xCJBkEkAaGpOFeAgvlMpsmlmMx8JBmlzTfIvB5Qp11o%2BWEmcE6KKosPe3fphrdXRngY7XgyPMg3OzvmB5%2Bj7tNILE20ZQpqoYadHVwtDWRaBQ86Qv%2BTkXYqoMbtqurdi4LaQsW0ytpEY3h4DmvAIWI5U5Yp4SOjcVlJvQsKnVOw4td%2BeHbiry6xVX4mq2aYy7nhqmXUSwga9chfMpCzuaaVDqYZS9WPTYN29YyYawVEmIiQ6%2BfHDW%2Bojj3UXtMasNwn0JvFnqC%2FiKIIb2NOGyf4ri5XsHZbgSknv36melZ1URrmTgnJu69G5MXbwzPaOQtl%2BbLM8j95aLK%2F1%2BH2qkza%2BOTjE5dBoazHQHu0Xc5iF693WC8w6B2KzesxbVwDo9dYgk2S3hi0RVDx%2F8E7%2BZB%2Ft%2FzWAj8NsbifpcNAKr%2BPrl8cqa%2B%2BvYoAHH1UMxOdf47IkCfaeQvLFSZ4qY54JDnadkn0MY3fle%2FTgch%2B3%2FySGd9B1XIdvR59qXCdT8LIYHrX%2FTbQq7Np1naD4ib7RwLgZeRHn0zmvK%2FlfBdscQbkGN%2FinP%2FVQxQCDy1g2GCeQ%2BHqU3ggykBqCJLu99fdhT3580Wl%2Bodgf6EjkLNkiixAWLgRNIL%2Bd2wij5zAx7psuMiX%2FrUOMatmmM9au1sAXraOQp8IkOL%2B7Y%2BuO8fQUcm%2BB%2BHXYjzJpJCS4pyzjz53%2BR7f9sD6CXSZrB9dv9sWq48Wjo3dTtjRp8POF7%2BFJnhOIdo5J2cgpqnFN9LhUqQv1uXGiyRekg3gzRC5QAJs6QV%2Bxw%2Fbj3KO5jufSm3QGarS%2Bc7kKCTZoY8vyyHccqcifm9RXYrZKrMJ%2FCtYTolEbAaMcAnnVpOTZ1wY39qGhBrm6INrmbPCTE9Q8Q1hZqfxJMUJbhL7rMNnk2H0x4JGycgsbslAp0fdMBDnHh7QnJoXfGbrXHZpJotxFR6V82l5WtXfccIsav3nXx6s3Xukujev9hE%2FdabuXRJE4SVDpjSuCWkyZPLvzepapHxSRp%2FQUbTZiGAJhQS7J68J1TRW91CN0tDIgHkfWc45IlIxqO5bFSNUyg0UUjfbNPhBnlZqNZqKN%2Bm8eJ6vUsFzEHJcQdub9B7GKAZXj20EFeU2pFLit0IZzOX9h%2FTCk7o4I6p2cue970MJ%2F9OxCz6v%2BqtdqKyXqQJ3S12BGgbst30IXOmoBW%2B3B2Xgo6Mbp9HYIC7onS3vJ6PBxzRQ0V2Tr3ci39%2FTWtCix5vb45NVuqn7kxMg7Ofts0NQCskYKjr%2BqD3hkmMtyQhMJwwI%2B72l9MJUvtWFdh2akv1CI4ntSkM5sRdHJCH2TKMYeMyosLElFHQn53086CdV5rHdgNkXsrn1y6%2BKHGEoN4Kk9gbeafVqvuLttbChPvWQ%2FAtCxZBR7t7BlJogWFdA4TQ2X75ySW%2BlOvRlEUgZivWvlMu5UFe7WMiv7UeXb8T1sUKfuDuSeGnzv%2FKIwE%2FB92jxzUeKo3qKX%2BlQwdcbiLzFHXxjSOPFBgiZdjc0eSOrrOvMeWif0ZQpPsFMKUvtkXgF3PpBiU7GsLss5JPkyTfQeMkQ0kYXt8WDyrjvw%2Ft0Cv9Qwhv7WfYi3fRrLBpXZBa6pspr%2BtbJmphBeAo3kRQwZCrMU16j3JJ%2FJDgiWmvAOWeBCU0SylIzTkx9NywRStIl91jh%2BUFbfYOji359qtLPQQc1mKgM%2FpBZKNtyfdC5zVlLxB2lMYkpwW5ktffRZYdzS7jbdOsogVs9YdVJIUZvGv15s%2FhWEqXu55xdXydNS%2B1UeODpJkAPUT6MJNJ5u9T3zgwOkiaISwovUU8%2BU7VnzR2PJuKCFkUpFSTSYoo1jP6m3Az2k3u79kuBr%2FzzmvQdm5yObiMmKOpaUK5YNBIFs7D%2BtE%2B66N%2BDvq22xpg63eM1UWg%2FyYONON7xu0Moml198WSQsjbBkzz0cKsZGCeQt6Zdiyj4z7W1833iJ1FrsQMSaFw0xsxEC69Go%2F42LuQnnZaMRkOFhjgPDtS0NSK0%2BslVf5K5bllBEXoFO%2FoCLI94s9HqZ%2FsqU4tDSJ2oKH5%2FylTSdsr4aQfYlUCJg2RKre9wAFrsOp60cD5zo1cqRNJ%2F1Zt%2FqlZjF2%2BMUhauJct8k4Z%2Fw12VfnxsBi%2FVKiLGMzgK9yWD0nqWID6b3Q0fAuloqZ3Oh3N0%2BnLJhJuvqYek37Mmd9r67j7NdyYvdO3yynAJstu4JQPpfOHIlDQqBRpIsGnYozlmo8U5Abo0p3PBkTrfXjnpvRhrYirZoSGLZoNihYOpeOhmddM3QIAn1lspDMkj%2Fc52ejQbcGYgxCNrgOtRO%2Bc0VY6OjsPTjpoMW2PFE%2F7zpqoUjVfRXfS5W8WsNK0ijQ8I0vTbtCePeYXlUyQh1kzQz0C8TuNuTsw6LgpoD8G%2FOMI%2BE0jE%2Frn5H48IwwOtGvW1AS9vuR1FcGWGK4%2B2jKpgqexloPy2dcLLI9cqQbpWQCeIfUQtvQQ%2B4E8ZHtcDu%2BciC9skXKkPFa5RsumrjDp953o7a8Ls%2B%2B4KswzrOGT25djSW25n8ZrWt8tAhnwrkdjXPwgix9LBalOrdbpE7RDWSj2zrm38lqp3jwF%2FmYZ6ctI1xV3ot98R61yvy8ZycsyDAQobK1aCxkc1S34H4It5fswUeouzi37kVCzdDzmEY4ouJ8rbvg9SNi4y%2F2bs8UVcellzLXPh1HAY%2BPm2%2FRYp%2BY8kvOWfoWMRpHOOK8%2F9Sv0jKv2fZqijAtNKTtEtDKKoejUh4dkSlQs%2BMBzX0q LLM: Score: 8 Reasons: The domain'sharefile8.pages.dev' is not a typical domain for a production OneDrive site. The use of the.dev gTLD, which is often used for development purposes, raises suspicions. The notification message and login form are consistent with a legitimate OneDrive page, but the unusual domain and lack of a typical OneDrive domain extension (e.g., onedrive.com) suggest that this may be a phishing attempt. DOM: 1.0.pages.csv
Source: https://sharefile8.pages.dev/b08+zb2ylref0qax?0dc76ab0dd308d6a261c143750b9eaf0m0haoys3=U2FsdGVkX1%2Bx%2BrtNATtHUgjMr7p8GXN0rISAjyQFtyvb7gycmSolKTr8OWrm593XWOHvyBWWh83TJoGR3fKvvWNGJjlYwTygUb6YSz%2BXkTzgkTMPojiEE%2Be2lvvzp%2Fx6%2FAyKC9BsHbP4NUOf10F5S1yqjllntRTpNu4hfJ1FBrx39J0xCJBkEkAaGpOFeAgvlMpsmlmMx8JBmlzTfIvB5Qp11o%2BWEmcE6KKosPe3fphrdXRngY7XgyPMg3OzvmB5%2Bj7tNILE20ZQpqoYadHVwtDWRaBQ86Qv%2BTkXYqoMbtqurdi4LaQsW0ytpEY3h4DmvAIWI5U5Yp4SOjcVlJvQsKnVOw4td%2BeHbiry6xVX4mq2aYy7nhqmXUSwga9chfMpCzuaaVDqYZS9WPTYN29YyYawVEmIiQ6%2BfHDW%2Bojj3UXtMasNwn0JvFnqC%2FiKIIb2NOGyf4ri5XsHZbgSknv36melZ1URrmTgnJu69G5MXbwzPaOQtl%2BbLM8j95aLK%2F1%2BH2qkza%2BOTjE5dBoazHQHu0Xc5iF693WC8w6B2KzesxbVwDo9dYgk2S3hi0RVDx%2F8E7%2BZB%2Ft%2FzWAj8NsbifpcNAKr%2BPrl8cqa%2B%2BvYoAHH1UMxOdf47IkCfaeQvLFSZ4qY54JDnadkn0MY3fle%2FTgch%2B3%2FySGd9B1XIdvR59qXCdT8LIYHrX%2FTbQq7Np1naD4ib7RwLgZeRHn0zmvK%2FlfBdscQbkGN%2FinP%2FVQxQCDy1g2GCeQ%2BHqU3ggykBqCJLu99fdhT3580Wl%2Bodgf6EjkLNkiixAWLgRNIL%2Bd2wij5zAx7psuMiX%2FrUOMatmmM9au1sAXraOQp8IkOL%2B7Y%2BuO8fQUcm%2BB%2BHXYjzJpJCS4pyzjz53%2BR7f9sD6CXSZrB9dv9sWq48Wjo3dTtjRp8POF7%2BFJnhOIdo5J2cgpqnFN9LhUqQv1uXGiyRekg3gzRC5QAJs6QV%2Bxw%2Fbj3KO5jufSm3QGarS%2Bc7kKCTZoY8vyyHccqcifm9RXYrZKrMJ%2FCtYTolEbAaMcAnnVpOTZ1wY39qGhBrm6INrmbPCTE9Q8Q1hZqfxJMUJbhL7rMNnk2H0x4JGycgsbslAp0fdMBDnHh7QnJoXfGbrXHZpJotxFR6V82l5WtXfccIsav3nXx6s3Xukujev9hE%2FdabuXRJE4SVDpjSuCWkyZPLvzepapHxSRp%2FQUbTZiGAJhQS7J68J1TRW91CN0tDIgHkfWc45IlIxqO5bFSNUyg0UUjfbNPhBnlZqNZqKN%2Bm8eJ6vUsFzEHJcQdub9B7GKAZXj20EFeU2pFLit0IZzOX9h%2FTCk7o4I6p2cue970MJ%2F9OxCz6v%2BqtdqKyXqQJ3S12BGgbst30IXOmoBW%2B3B2Xgo6Mbp9HYIC7onS3vJ6PBxzRQ0V2Tr3ci39%2FTWtCix5vb45NVuqn7kxMg7Ofts0NQCskYKjr%2BqD3hkmMtyQhMJwwI%2B72l9MJUvtWFdh2akv1CI4ntSkM5sRdHJCH2TKMYeMyosLElFHQn53086CdV5rHdgNkXsrn1y6%2BKHGEoN4Kk9gbeafVqvuLttbChPvWQ%2FAtCxZBR7t7BlJogWFdA4TQ2X75ySW%2BlOvRlEUgZivWvlMu5UFe7WMiv7UeXb8T1sUKfuDuSeGnzv%2FKIwE%2FB92jxzUeKo3qKX%2BlQwdcbiLzFHXxjSOPFBgiZdjc0eSOrrOvMeWif0ZQpPsFMKUvtkXgF3PpBiU7GsLss5JPkyTfQeMkQ0kYXt8WDyrjvw%2Ft0Cv9Qwhv7WfYi3fRrLBpXZBa6pspr%2BtbJmphBeAo3kRQwZCrMU16j3JJ%2FJDgiWmvAOWeBCU0SylIzTkx9NywRStIl91jh%2BUFbfYOji359qtLPQQc1mKgM%2FpBZKNtyfdC5zVlLxB2lMYkpwW5ktffRZYdzS7jbdOsogVs9YdVJIUZvGv15s%2FhWEqXu55xdXydNS%2B1UeODpJkAPUT6MJNJ5u9T3zgwOkiaISwovUU8%2BU7VnzR2PJuKCFkUpFSTSYoo1jP6m3Az2k3u79kuBr%2FzzmvQdm5yObiMmKOpaUK5YNBIFs7D%2BtE%2B66N%2BDvq22xpg63eM1UWg%2FyYONON7xu0Moml198WSQsjbBkzz0cKsZGCeQt6Zdiyj4z7W1833iJ1FrsQMSaFw0xsxEC69Go%2F42LuQnnZaMRkOFhjgPDtS0NSK0%2BslVf5K5bllBEXoFO%2FoCLI94s9HqZ%2FsqU4tDSJ2oKH5%2FylTSdsr4aQfYlUCJg2RKre9wAFrsOp60cD5zo1cqRNJ%2F1Zt%2FqlZjF2%2BMUhauJct8k4Z%2Fw12VfnxsBi%2FVKiLGMzgK9yWD0nqWID6b3Q0fAuloqZ3Oh3N0%2BnLJhJuvqYek37Mmd9r67j7NdyYvdO3yynAJstu4JQPpfOHIlDQqBRpIsGnYozlmo8U5Abo0p3PBkTrfXjnpvRhrYirZoSGLZoNihYOpeOhmddM3QIAn1lspDMkj%2Fc52ejQbcGYgxCNrgOtRO%2Bc0VY6OjsPTjpoMW2PFE%2F7zpqoUjVfRXfS5W8WsNK0ijQ8I0vTbtCePeYXlUyQh1kzQz0C8TuNuTsw6LgpoD8G%2FOMI%2BE0jE%2Frn5H48IwwOtGvW1AS9vuR1FcGWGK4%2B2jKpgqexloPy2dcLLI9cqQbpWQCeIfUQtvQQ%2B4E8ZHtcDu%2BciC9skXKkPFa5RsumrjDp953o7a8Ls%2B%2B4KswzrOGT25djSW25n8ZrWt8tAhnwrkdjXPwgix9LBalOrdbpE7RDWSj2zrm38lqp3jwF%2FmYZ6ctI1xV3ot98R61yvy8ZycsyDAQobK1aCxkc1S34H4It5fswUeouzi37kVCzdDzmEY4ouJ8rbvg9SNi4y%2F2bs8UVcellzLXPh1HAY%2BPm2%2FRYp%2BY8kvOWfoWMRpHOOK8%2F9Sv0jKv2fZqijAtNKTtEtDKKoejUh4dkSlQs%2BMBzX0q Matcher: Template: onedrive matched with high similarity
Source: https://sharefile8.pages.dev/b08+zb2ylref0qax?0dc76ab0dd308d6a261c143750b9eaf0m0haoys3=U2FsdGVkX1%2Bx%2BrtNATtHUgjMr7p8GXN0rISAjyQFtyvb7gycmSolKTr8OWrm593XWOHvyBWWh83TJoGR3fKvvWNGJjlYwTygUb6YSz%2BXkTzgkTMPojiEE%2Be2lvvzp%2Fx6%2FAyKC9BsHbP4NUOf10F5S1yqjlln Matcher: Template: microsoft matched
Source: https://sharefile8.pages.dev/b08+zb2ylref0qax?0dc76ab0dd308d6a261c143750b9eaf0m0haoys3=U2FsdGVkX1%2Bx%2BrtNATtHUgjMr7p8GXN0rISAjyQFtyvb7gycmSolKTr8OWrm593XWOHvyBWWh83TJoGR3fKvvWNGJjlYwTygUb6YSz%2BXkTzgkTMPojiEE%2Be2lvvzp%2Fx6%2FAyKC9BsHbP4NUOf10F5S1yqjllntRTpNu4hfJ1FBrx39J0xCJBkEkAaGpOFeAgvlMpsmlmMx8JBmlzTfIvB5Qp11o%2BWEmcE6KKosPe3fphrdXRngY7XgyPMg3OzvmB5%2Bj7tNILE20ZQpqoYadHVwtDWRaBQ86Qv%2BTkXYqoMbtqurdi4LaQsW0ytpEY3h4DmvAIWI5U5Yp4SOjcVlJvQsKnVOw4td%2BeHbiry6xVX4mq2aYy7nhqmXUSwga9chfMpCzuaaVDqYZS9WPTYN29YyYawVEmIiQ6%2BfHDW%2Bojj3UXtMasNwn0JvFnqC%2FiKIIb2NOGyf4ri5XsHZbgSknv36melZ1URrmTgnJu69G5MXbwzPaOQtl%2BbLM8j95aLK%2F1%2BH2qkza%2BOTjE5dBoazHQHu0Xc5iF693WC8w6B2KzesxbVwDo9dYgk2S3hi0RVDx%2F8E7%2BZB%2Ft%2FzWAj8NsbifpcNAKr%2BPrl8cqa%2B%2BvYoAHH1UMxOdf47IkCfaeQvLFSZ4qY54JDnadkn0MY3fle%2FTgch%2B3%2FySGd9B1XIdvR59qXCdT8LIYHrX%2FTbQq7Np1naD4ib7RwLgZeRHn0zmvK%2FlfBdscQbkGN%2FinP%2FVQxQCDy1g2GCeQ%2BHqU3ggykBqCJLu99fdhT3580Wl%2Bodgf6EjkLNkiixAWLgRNIL%2Bd2wij5zAx7psuMiX%2FrUOMatmmM9au1sAXraOQp8IkOL%2B7Y%2BuO8fQUcm%2BB%2... HTTP Parser: Number of links: 0
Source: https://sharefile8.pages.dev/b08+zb2ylref0qax?0dc76ab0dd308d6a261c143750b9eaf0m0haoys3=U2FsdGVkX1%2Bx%2BrtNATtHUgjMr7p8GXN0rISAjyQFtyvb7gycmSolKTr8OWrm593XWOHvyBWWh83TJoGR3fKvvWNGJjlYwTygUb6YSz%2BXkTzgkTMPojiEE%2Be2lvvzp%2Fx6%2FAyKC9BsHbP4NUOf10F5S1yqjllntRTpNu4hfJ1FBrx39J0xCJBkEkAaGpOFeAgvlMpsmlmMx8JBmlzTfIvB5Qp11o%2BWEmcE6KKosPe3fphrdXRngY7XgyPMg3OzvmB5%2Bj7tNILE20ZQpqoYadHVwtDWRaBQ86Qv%2BTkXYqoMbtqurdi4LaQsW0ytpEY3h4DmvAIWI5U5Yp4SOjcVlJvQsKnVOw4td%2BeHbiry6xVX4mq2aYy7nhqmXUSwga9chfMpCzuaaVDqYZS9WPTYN29YyYawVEmIiQ6%2BfHDW%2Bojj3UXtMasNwn0JvFnqC%2FiKIIb2NOGyf4ri5XsHZbgSknv36melZ1URrmTgnJu69G5MXbwzPaOQtl%2BbLM8j95aLK%2F1%2BH2qkza%2BOTjE5dBoazHQHu0Xc5iF693WC8w6B2KzesxbVwDo9dYgk2S3hi0RVDx%2F8E7%2BZB%2Ft%2FzWAj8NsbifpcNAKr%2BPrl8cqa%2B%2BvYoAHH1UMxOdf47IkCfaeQvLFSZ4qY54JDnadkn0MY3fle%2FTgch%2B3%2FySGd9B1XIdvR59qXCdT8LIYHrX%2FTbQq7Np1naD4ib7RwLgZeRHn0zmvK%2FlfBdscQbkGN%2FinP%2FVQxQCDy1g2GCeQ%2BHqU3ggykBqCJLu99fdhT3580Wl%2Bodgf6EjkLNkiixAWLgRNIL%2Bd2wij5zAx7psuMiX%2FrUOMatmmM9au1sAXraOQp8IkOL%2B7Y%2BuO8fQUcm%2BB%2... HTTP Parser: Title: Microsoft OneDrive does not match URL
Source: https://sharefile8.pages.dev/b08+zb2ylref0qax?0dc76ab0dd308d6a261c143750b9eaf0m0haoys3=U2FsdGVkX1%2Bx%2BrtNATtHUgjMr7p8GXN0rISAjyQFtyvb7gycmSolKTr8OWrm593XWOHvyBWWh83TJoGR3fKvvWNGJjlYwTygUb6YSz%2BXkTzgkTMPojiEE%2Be2lvvzp%2Fx6%2FAyKC9BsHbP4NUOf10F5S1yqjllntRTpNu4hfJ1FBrx39J0xCJBkEkAaGpOFeAgvlMpsmlmMx8JBmlzTfIvB5Qp11o%2BWEmcE6KKosPe3fphrdXRngY7XgyPMg3OzvmB5%2Bj7tNILE20ZQpqoYadHVwtDWRaBQ86Qv%2BTkXYqoMbtqurdi4LaQsW0ytpEY3h4DmvAIWI5U5Yp4SOjcVlJvQsKnVOw4td%2BeHbiry6xVX4mq2aYy7nhqmXUSwga9chfMpCzuaaVDqYZS9WPTYN29YyYawVEmIiQ6%2BfHDW%2Bojj3UXtMasNwn0JvFnqC%2FiKIIb2NOGyf4ri5XsHZbgSknv36melZ1URrmTgnJu69G5MXbwzPaOQtl%2BbLM8j95aLK%2F1%2BH2qkza%2BOTjE5dBoazHQHu0Xc5iF693WC8w6B2KzesxbVwDo9dYgk2S3hi0RVDx%2F8E7%2BZB%2Ft%2FzWAj8NsbifpcNAKr%2BPrl8cqa%2B%2BvYoAHH1UMxOdf47IkCfaeQvLFSZ4qY54JDnadkn0MY3fle%2FTgch%2B3%2FySGd9B1XIdvR59qXCdT8LIYHrX%2FTbQq7Np1naD4ib7RwLgZeRHn0zmvK%2FlfBdscQbkGN%2FinP%2FVQxQCDy1g2GCeQ%2BHqU3ggykBqCJLu99fdhT3580Wl%2Bodgf6EjkLNkiixAWLgRNIL%2Bd2wij5zAx7psuMiX%2FrUOMatmmM9au1sAXraOQp8IkOL%2B7Y%2BuO8fQUcm%2BB%2 HTTP Parser: No <meta name="author".. found
Source: https://sharefile8.pages.dev/b08+zb2ylref0qax?0dc76ab0dd308d6a261c143750b9eaf0m0haoys3=U2FsdGVkX1%2Bx%2BrtNATtHUgjMr7p8GXN0rISAjyQFtyvb7gycmSolKTr8OWrm593XWOHvyBWWh83TJoGR3fKvvWNGJjlYwTygUb6YSz%2BXkTzgkTMPojiEE%2Be2lvvzp%2Fx6%2FAyKC9BsHbP4NUOf10F5S1yqjllntRTpNu4hfJ1FBrx39J0xCJBkEkAaGpOFeAgvlMpsmlmMx8JBmlzTfIvB5Qp11o%2BWEmcE6KKosPe3fphrdXRngY7XgyPMg3OzvmB5%2Bj7tNILE20ZQpqoYadHVwtDWRaBQ86Qv%2BTkXYqoMbtqurdi4LaQsW0ytpEY3h4DmvAIWI5U5Yp4SOjcVlJvQsKnVOw4td%2BeHbiry6xVX4mq2aYy7nhqmXUSwga9chfMpCzuaaVDqYZS9WPTYN29YyYawVEmIiQ6%2BfHDW%2Bojj3UXtMasNwn0JvFnqC%2FiKIIb2NOGyf4ri5XsHZbgSknv36melZ1URrmTgnJu69G5MXbwzPaOQtl%2BbLM8j95aLK%2F1%2BH2qkza%2BOTjE5dBoazHQHu0Xc5iF693WC8w6B2KzesxbVwDo9dYgk2S3hi0RVDx%2F8E7%2BZB%2Ft%2FzWAj8NsbifpcNAKr%2BPrl8cqa%2B%2BvYoAHH1UMxOdf47IkCfaeQvLFSZ4qY54JDnadkn0MY3fle%2FTgch%2B3%2FySGd9B1XIdvR59qXCdT8LIYHrX%2FTbQq7Np1naD4ib7RwLgZeRHn0zmvK%2FlfBdscQbkGN%2FinP%2FVQxQCDy1g2GCeQ%2BHqU3ggykBqCJLu99fdhT3580Wl%2Bodgf6EjkLNkiixAWLgRNIL%2Bd2wij5zAx7psuMiX%2FrUOMatmmM9au1sAXraOQp8IkOL%2B7Y%2BuO8fQUcm%2BB%2... HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49757 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.4:57600 -> 162.159.36.2:53
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknown TCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknown TCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknown TCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknown TCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknown TCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /b08+zb2ylref0qax HTTP/1.1Host: sharefile8.pages.devConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /gh/uihkdslijsjd/captivating-app-lyoubgs5@internal-2024-07-16-20-02-58/139a8cd2-d10c-4336-ba04-3f1c53ba8cb6.js?hash=6b06db943f081ebee689f376c8b231d1&EDlFh6SOBK9HUECofCEkAbqDF=2jfjZA9wDmRlYg1TXOXJNITl98qS9siwV6pdy8cw8fSU8meMhDoHo3q0Wbk1NRTITsfyJdv71rAKgx7GjU1BNOfiiUNKNWJ2iHxPYldtdzwOsYPXlYZ5aId3UaBDD4OaPO0ZZpW8vf4Tz0t3vdO1dR7zBRTwMf8AMoFNk8pvuQel106aEmb5Q0X HTTP/1.1Host: cdn.jsdelivr.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://sharefile8.pages.dev/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ajax/libs/font-awesome/4.7.0/css/font-awesome.css HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://sharefile8.pages.devsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://sharefile8.pages.dev/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /json/ HTTP/1.1Host: ipapi.coConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://sharefile8.pages.devSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://sharefile8.pages.dev/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /b08+zb2ylref0qax?0dc76ab0dd308d6a261c143750b9eaf0m0haoys3=U2FsdGVkX1%2Bx%2BrtNATtHUgjMr7p8GXN0rISAjyQFtyvb7gycmSolKTr8OWrm593XWOHvyBWWh83TJoGR3fKvvWNGJjlYwTygUb6YSz%2BXkTzgkTMPojiEE%2Be2lvvzp%2Fx6%2FAyKC9BsHbP4NUOf10F5S1yqjllntRTpNu4hfJ1FBrx39J0xCJBkEkAaGpOFeAgvlMpsmlmMx8JBmlzTfIvB5Qp11o%2BWEmcE6KKosPe3fphrdXRngY7XgyPMg3OzvmB5%2Bj7tNILE20ZQpqoYadHVwtDWRaBQ86Qv%2BTkXYqoMbtqurdi4LaQsW0ytpEY3h4DmvAIWI5U5Yp4SOjcVlJvQsKnVOw4td%2BeHbiry6xVX4mq2aYy7nhqmXUSwga9chfMpCzuaaVDqYZS9WPTYN29YyYawVEmIiQ6%2BfHDW%2Bojj3UXtMasNwn0JvFnqC%2FiKIIb2NOGyf4ri5XsHZbgSknv36melZ1URrmTgnJu69G5MXbwzPaOQtl%2BbLM8j95aLK%2F1%2BH2qkza%2BOTjE5dBoazHQHu0Xc5iF693WC8w6B2KzesxbVwDo9dYgk2S3hi0RVDx%2F8E7%2BZB%2Ft%2FzWAj8NsbifpcNAKr%2BPrl8cqa%2B%2BvYoAHH1UMxOdf47IkCfaeQvLFSZ4qY54JDnadkn0MY3fle%2FTgch%2B3%2FySGd9B1XIdvR59qXCdT8LIYHrX%2FTbQq7Np1naD4ib7RwLgZeRHn0zmvK%2FlfBdscQbkGN%2FinP%2FVQxQCDy1g2GCeQ%2BHqU3ggykBqCJLu99fdhT3580Wl%2Bodgf6EjkLNkiixAWLgRNIL%2Bd2wij5zAx7psuMiX%2FrUOMatmmM9au1sAXraOQp8IkOL%2B7Y%2BuO8fQUcm%2BB%2BHXYjzJpJCS4pyzjz53%2BR7f9sD6CXSZrB9dv9sWq48Wjo3dTtjRp8POF7%2BFJnhOIdo5J2cgpqnFN9LhUqQv1uXGiyRekg3gzRC5QAJs6QV%2Bxw%2Fbj3KO5jufSm3QGarS%2Bc7kKCTZoY8vyyHccqcifm9RXYrZKrMJ%2FCtYTolEbAaMcAnnVpOTZ1wY39qGhBrm6INrmbPCTE9Q8Q1hZqfxJMUJbhL7rMNnk2H0x4JGycgsbslAp0fdMBDnHh7QnJoXfGbrXHZpJotxFR6V82l5WtXfccIsav3nXx6s3Xukujev9hE%2FdabuXRJE4SVDpjSuCWkyZPLvzepapHxSRp%2FQUbTZiGAJhQS7J68J1TRW91CN0tDIgHkfWc45IlIxqO5bFSNUyg0UUjfbNPhBnlZqNZqKN%2Bm8eJ6vUsFzEHJcQdub9B7GKAZXj20EFeU2pFLit0IZzOX9h%2FTCk7o4I6p2cue970MJ%2F9OxCz6v%2BqtdqKyXqQJ3S12BGgbst30IXOmoBW%2B3B2Xgo6Mbp9HYIC7onS3vJ6PBxzRQ0V2Tr3ci39%2FTWtCix5vb45NVuqn7kxMg7Ofts0NQCskYKjr%2BqD3hkmMtyQhMJwwI%2B72l9MJUvtWFdh2akv1CI4ntSkM5sRdHJCH2TKMYeMyosLElFHQn53086CdV5rHdgNkXsrn1y6%2BKHGEoN4Kk9gbeafVqvuLttbChPvWQ%2FAtCxZBR7t7BlJogWFdA4TQ2X75ySW%2BlOvRlEUgZivWvlMu5UFe7WMiv7UeXb8T1sUKfuDuSeGnzv%2FKIwE%2FB92jxzUeKo3qKX%2BlQwdcbiLzFHXxjSOPFBgiZdjc0eSOrrOvMeWif0ZQpPsFMKUvtkXgF3PpBiU7GsLss5JPkyTfQeMkQ0kYXt8WDyrjvw%2Ft0Cv9Qwhv7WfYi3fRrLBpXZBa6pspr%2BtbJmphBeAo3kRQwZCrMU16j3JJ%2FJDgiWmvAOWeBCU0SylIzTkx9NywRStIl91jh%2BUFbfYOji359qtLPQQc1mKgM%2FpBZKNtyfdC5zVlLxB2lMYkpwW5ktffRZYdzS7jbdOsogVs9YdVJIUZvGv15s%2FhWEqXu55xdXydNS%2B1UeODpJkAPUT6MJNJ5u9T3zgwOkiaISwovUU8%2BU7VnzR2PJuKCFkUpFSTSYoo1jP6m3Az2k3u79kuBr%2FzzmvQdm5yObiMmKOpaUK5YNBIFs7D%2BtE%2B66N%2BDvq22xpg63eM1UWg%2FyYONON7xu0Moml198WSQsjbBkzz0cKsZGCeQt6Zdiyj4z7W1833iJ1FrsQMSaFw0xsxEC69Go%2F42LuQnnZaMRkOFhjgPDtS0NSK0%2BslVf5K5bllBEXoFO%2FoCLI94s9HqZ%2FsqU4tDSJ2oKH5%2FylTSdsr4aQfYlUCJg2RKre9wAFrsOp60cD5zo1cqRNJ%2F1Zt%2FqlZjF2%2BMUhauJct8k4Z%2Fw12VfnxsBi%2FVKiLGMzgK9yWD0nqWID6b3Q0fAuloqZ3Oh3N0%2BnLJhJuvqYek37Mmd9r67j7NdyYvdO3yynAJstu4JQPpfOHIlDQqBRpIsGnYozlmo8U5Abo0p3PBkTrfXjnpvRhrYirZoSGLZoNihYOpeOhmddM3QIAn1lspDMkj%2Fc52ejQbcGYgxCNrgOtRO%2Bc0VY6OjsPTjpoMW2PFE%2F7zpqoUjVfRXfS5W8WsNK0ijQ8I0vTbtCePeYXlUyQh1kzQz0C8TuNuTsw6LgpoD8G%2FOMI%2BE0jE%2Frn5H48IwwOtGvW1AS9vuR1FcGWGK4%2B2jKpgqexloPy2dcLLI9cqQbpWQCeIfUQtvQQ%2B4E8ZHtcDu%2BciC9skXKkPFa5RsumrjDp953o7a8Ls%2B%2B4KswzrOGT25djSW25n8ZrWt8tAhnwrkdjXPwgix9LBalO
Source: global traffic HTTP traffic detected: GET /gh/uihkdslijsjd/captivating-app-lyoubgs5@internal-2024-07-16-20-02-58/07308ee98aa47f067087.jpg HTTP/1.1Host: cdn.jsdelivr.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://sharefile8.pages.dev/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /gh/uihkdslijsjd/captivating-app-lyoubgs5@internal-2024-07-16-20-02-58/847fc5ec58b3a0af255c.svg HTTP/1.1Host: cdn.jsdelivr.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://sharefile8.pages.dev/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /gh/uihkdslijsjd/captivating-app-lyoubgs5@internal-2024-07-16-20-02-58/59947dbf5efae9de77d2.png HTTP/1.1Host: cdn.jsdelivr.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://sharefile8.pages.dev/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /gh/uihkdslijsjd/captivating-app-lyoubgs5@internal-2024-07-16-20-02-58/fa37e6e4fd65b2e85394.ico HTTP/1.1Host: cdn.jsdelivr.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://sharefile8.pages.dev/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic DNS traffic detected: DNS query: sharefile8.pages.dev
Source: global traffic DNS traffic detected: DNS query: cdn.jsdelivr.net
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: ipapi.co
Source: global traffic DNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: 15.164.165.52.in-addr.arpa
Source: unknown HTTP traffic detected: POST /report/v4?s=0M5NRKmOxyBq8l%2FlUNMo5aJkOfp8LtCgvBHAgduYqDBrvqz3NnCxNB4D7rFOFXjAd2h9dx4EuvCE4G8MFx0%2FzC%2FLDTzJqMxsWL9kQ2g7iZ4s0Yym8tXUuwGy HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 410Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: chromecache_60.2.dr, chromecache_66.2.dr String found in binary or memory: http://creativecommons.org/ns#
Source: chromecache_59.2.dr String found in binary or memory: http://fontawesome.io
Source: chromecache_59.2.dr String found in binary or memory: http://fontawesome.io/license
Source: chromecache_60.2.dr, chromecache_66.2.dr String found in binary or memory: http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd
Source: chromecache_60.2.dr, chromecache_66.2.dr String found in binary or memory: http://www.inkscape.org/)
Source: chromecache_60.2.dr, chromecache_66.2.dr String found in binary or memory: http://www.inkscape.org/namespaces/inkscape
Source: chromecache_69.2.dr, chromecache_57.2.dr String found in binary or memory: https://6481f63faf008522217341.cotradifyu.workers.dev/checkDomain
Source: chromecache_56.2.dr, chromecache_65.2.dr String found in binary or memory: https://cdn.jsdelivr.net/gh/uihkdslijsjd/captivating-app-lyoubgs5
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEz0dL_nz.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEz4dL_nz.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEz8dL_nz.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEzAdLw.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEzMdL_nz.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEzQdL_nz.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEzwdL_nz.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc-CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc0CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc1CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc2CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc3CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc5CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc6CsQ.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc-CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc0CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc1CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc2CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc3CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc5CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc6CsQ.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic-CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic0CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic1CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic2CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic3CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic5CsTKlA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic6CsQ.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxEIzIFKw.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxFIzIFKw.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxGIzIFKw.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxHIzIFKw.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxIIzI.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxLIzIFKw.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxMIzIFKw.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xEIzIFKw.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xFIzIFKw.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xGIzIFKw.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xHIzIFKw.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xIIzI.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xLIzIFKw.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xMIzIFKw.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fABc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fBBc4.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fBxc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fCBc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fCRc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fChc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fCxc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fABc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fBBc4.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fBxc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fCBc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fCRc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fChc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fCxc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfABc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfBBc4.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfBxc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfCBc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfCRc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfChc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfCxc4EsA.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu4WxKOzY.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu4mxK.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu5mxKOzY.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu72xKOzY.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu7GxKOzY.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu7WxKOzY.woff2)
Source: chromecache_67.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu7mxKOzY.woff2)
Source: chromecache_69.2.dr, chromecache_57.2.dr String found in binary or memory: https://ipapi.co/json/
Source: chromecache_69.2.dr, chromecache_57.2.dr String found in binary or memory: https://locate.ipinit.workers.dev/
Source: chromecache_69.2.dr, chromecache_57.2.dr String found in binary or memory: https://onedrive.live.com/?authkey=%21AP4dQQ7hoSgcKIBIw%26cid=28E9EC3AAC12FF13%26id=28E9EC3AAC12FF13
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57606
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57606 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49746 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.4:49757 version: TLS 1.2
Source: classification engine Classification label: mal64.phis.win@16/31@16/12
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2448 --field-trial-handle=2416,i,17885033267764913659,14688378653275137102,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sharefile8.pages.dev/b08+zb2ylref0qax"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2448 --field-trial-handle=2416,i,17885033267764913659,14688378653275137102,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs