Windows Analysis Report
https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq

Overview

General Information

Sample URL: https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmm
Analysis ID: 1502065
Infos:

Detection

Score: 64
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

AI detected phishing page
Antivirus / Scanner detection for submitted sample
Phishing site detected (based on favicon image match)
Phishing site detected (based on logo match)
Detected non-DNS traffic on DNS port
HTML body contains low number of good links
HTML title does not match URL

Classification

AV Detection

barindex
Source: https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq Avira URL Cloud: detection malicious, Label: phishing
Source: https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq SlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering

Phishing

barindex
Source: https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq?ef5cb60b3eb712165be9aa2e8432255dm0haqp1l=U2FsdGVkX1%2F54Vi5k0fpJopgxlpTE%2Fwt1JbQBXUwtHI23IsXwilEibczOtXIyEafGUqvIxelPBKzraUcUZYsXddxVc0shoqZRiLuOtEQo8KQVHVVuhOjGpqAXb2ikXZcbMrR3pLVYbbERPy3QEAprq0jX%2F8t0p34IN%2BfftC4hK3%2Bs1g90JwifgjP3PTpK1aoAXRSeuyZNO%2BH9gJzHQNdJE58%2F1O7kPWQUEDNBeiPMexEwjzhqyPS9sJwf0XY9a6%2BVhLlq7y81V6%2FcHskp%2BgdCzxqfr2n7lQ1IzSUDClcGHZRzUhWfautY7xVjrLnzgh7ZdWqSUKbXwS23VjXs%2FdDRWpe82DNrAmaKQbf9Na%2B%2Bp6FxgINSz%2FMl0rbKTfp%2F%2FB8Lz5SQtpMofgzRCNhzPatp%2BV5xmEtnUqea565l6q9U5MRShooxYUyXTQVvbgAlt0sKy1Zn%2BcT%2FslFRCHHR0zWoJWY3C6nqLsoAd%2F%2FoO4Kuru019imWUO6zMl%2Bck5uBY464whKgUjunYedrNn084WCIbOmkMucwZLKqm3bOAd%2FibGCLBme5AHdSITb2ryus7xe9v4kpSTw2biTnqZDObxiPxx%2FlIUJVqeZ3GCPECdUF8rVpu8FzjC3cJ9NKqT7zzV6mx%2FvZ%2FeytMk04I%2BoShNpqBGNK%2F6JWx25ptmkQXmET2SmB3YR9%2BoDTAQck88otqYtCYclKM0QWtWB1tYqqWOTcaxOMY6Jyj9uCJYmdjaz8gZEQMrQV%2F%2F7zGMrvWJkTGBd5ZVAxlTgiZxSssmS7G8hxPZYko1qgdRYB3Rcs5ketzHki2q2AI%2B0419%2B3z%2F1p5C95LC%2FDKwEQstBzJpMFW14hw8dP1SrF%2BLer4byED8x6QLVs2uSAr2ZN5Npn%2FWGhkikTh0XfdYXRJYJDCIHQVl8rrn8IFKNMRipYsoBiK9seKTi5U%2BnLxt2M%2FW5Gk0C0kvDHUx%2FSXD4P%2Fm0M6JKyHJsy2XtTaidIQf6ZyOY3Za45NkaBz%2Bmkyhxmf1K8D8GPTiIZ%2Bza39mOrw3VObLpIhUeIDAPPUVhhUVJ0oa9z7AJbFvKCrpBqGibr4oC%2BvzZouiWBJVncfh2PO3S9Hh2YcihlUxohfNbREwAhpJwmW%2BMV8VCzGI2VkWlVQx9IIW0SrcLiHIaiEHCWsgRRAP2g%2FDQ4XIIYVQ2%2Fu09gskYVpVExbtDpkqLfE4KypMVJZURUEwfGEpQAk4cK9Kl%2F55pn2VZdQqvjk7To5abhxFnOUZEXVAgybYOgnawk1eL%2Bqjhf6BmTbs0nEh1lKH9LBRXla42rpVhGdKuhppKZnXDtBP0nB4jx8Y8Eb7LRhu%2F6cymoMKfZ4kBJZYdE6tlc3ZQz3XPwEEsuqaQs0IKmlkhNB3YG0wtDp%2Br%2BBp1VcN%2Bbh2wOvpj1yc1ql0gHSPWlhjfUAl8sSbKMGnTUPEDuw%2FVyrxgCa8ukv2uPqke3x4LIg1BbH3QKmlrosSrKfpeXmrNBI9zcnVwdhVQw%2BR7oR6UzGdbnr20AG%2BA4R5QB6%2BtqDQjSJQoG80E48DdKuzV6QsQyyWG8KeT%2FOGXRd1sD8y44IF%2FQ2Ztb07vAIDokEXsM0wwQw9id9tlLh7nx5qxzGAZlvJrAoJnVtecQwYSDIKwoPj45mD0hxJTLOM%2BkUKEWpJSxC8%2FRZQ%2Bk0PnA4QFzfkFXUggmcvcFJ%2FMXnqRCtfVaZtR2a4%2Ba6VPD9CtbfLeNRVrHhDhd38rERYekFZRYol38YqE25ogDn1i5zQG6YfvVTBLDIa0C8H2gqoUdmrwMEU0Hr2CTzL%2F6a0bo21PlhpnvdWrdoouQx1j%2FmFULtRPuapD8WFkZYJ016K3l%2BvhkW%2F1036TmoK5WlGStZ8t%2FTG5XXP%2FNwol6HKGW%2B9XNIHRSnq4f4tccEqqy%2BuKpq3Sze9iJGibyKm2lEDFfU4V5%2FLgh4ZhCI%2BlOCzjNSHqPDhHAdRdNNk95gSPn6%2B0E3z5F%2Bfu3on3JoDKsCDAXfmXdX6K8sPGkzcqucX72%2BsVzCBBbJ0Fephn407z5yjL5VDHmQ%2BaZ4sO8Go5tXsSLzLj%2Bcyva6IiqTL6Oy1t3NZqMCQwLZ76OyjIi95zD5b2BMaQF50e3SV6wEhymXxGuc0vJot2weKFS08Kxis9OOayYmqC3l3xgpV0fg%2FYsC5zudvXgLyNYn%2Bc5YeYNeEbZoXuKkWknKBI%2FYviyPiOgHczbUjfnC1VwDI4X1rwYWDLaA6NK%2BH2stpktIkYBxnw%2BtYEe63EqBbKMsOkj79cXD%2BAw8D%2BT1q1t5ferlfAYftv6SykMbzBsSs0aJC6xHS8oF%2BrFZQOlm9t6LlCglt1HmGc9Xi9YkyIMGcs4bUaCkSx6SlrQ8EqWuu5N%2F43WY0JbtaGBHAGLVVi98h3wOjmTI51zb8mPd12l28QMjljyfqj%2BmwoEEL8nFUujAKyJtVfNTVA8UbYKzJ26gSsk5VMAQryHlefOKe5c8igmywyEInX8fMECnmhV%2BErnL2qk9iUg4xBSDWTrjmTf8RpmR5nxatcQzNkXwdd%2FmZZAkbHKhafHuh4wlpucrXQNl1k4jje3xUewfzD%2FUu%2BT1UJl3hnMhpa1boGdjbQAwRJZ95zqaKA1YRBmBsEXuQKxT5GNWhsIbC8mYo6UoBQuipyI8yhS5g9nbd86DGHHNkxqvjMtQF04IoenFEjqpOhSVHtba8EdLLBSPUJP7SWgI7fl3jAYQ5MxpfSQ%2FOVxWtfWhTQcdDtXInzb8WFWxxwT7RLyz77451jFfnnaqtjUR6hlx7ZvmcFVNCc%2BkaYoCzh8LlnoEvlZRmX9tvtuRLq2UMvdgMJZii9OBxaJlvIjRC9isp0OkrWx5xM717uxFXvTcbj6uMlM41GjJzARSYJXBZxgBBsWPnsK1BwTKJwigqO%2B%2Bkf8Vpqg%2F5dbkY0yGDtq%2FEKfDTjzaZQ61XfM45A LLM: Score: 8 Reasons: The domain'sharefile8.pages.dev' is not a typical domain for a production OneDrive site, and the.dev gTLD is often used for development purposes. The login form and notification message are consistent with a OneDrive login page, but the unusual domain and lack of a typical OneDrive domain (e.g., onedrive.com) suggest a potential phishing attempt. DOM: 1.0.pages.csv
Source: https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq?ef5cb60b3eb712165be9aa2e8432255dm0haqp1l=U2FsdGVkX1%2F54Vi5k0fpJopgxlpTE%2Fwt1JbQBXUwtHI23IsXwilEibczOtXIyEafGUqvIxelPBKzraUcUZYsXddxVc0shoqZRiLuOtEQo8KQVHVVuhOjGpqAXb2ikXZcbMrR3pLVYbbERPy3QEAprq0jX%2F8t0p34IN%2BfftC4hK3%2Bs1g90JwifgjP3PTpK1aoAXRSeuyZNO%2BH9gJzHQNdJE58%2F1O7kPWQUEDNBeiPMexEwjzhqyPS9sJwf0XY9a6%2BVhLlq7y81V6%2FcHskp%2BgdCzxqfr2n7lQ1IzSUDClcGHZRzUhWfautY7xVjrLnzgh7ZdWqSUKbXwS23VjXs%2FdDRWpe82DNrAmaKQbf9Na%2B%2Bp6FxgINSz%2FMl0rbKTfp%2F%2FB8Lz5SQtpMofgzRCNhzPatp%2BV5xmEtnUqea565l6q9U5MRShooxYUyXTQVvbgAlt0sKy1Zn%2BcT%2FslFRCHHR0zWoJWY3C6nqLsoAd%2F%2FoO4Kuru019imWUO6zMl%2Bck5uBY464whKgUjunYedrNn084WCIbOmkMucwZLKqm3bOAd%2FibGCLBme5AHdSITb2ryus7xe9v4kpSTw2biTnqZDObxiPxx%2FlIUJVqeZ3GCPECdUF8rVpu8FzjC3cJ9NKqT7zzV6mx%2FvZ%2FeytMk04I%2BoShNpqBGNK%2F6JWx25ptmkQXmET2SmB3YR9%2BoDTAQck88otqYtCYclKM0QWtWB1tYqqWOTcaxOMY6Jyj9uCJYmdjaz8gZEQMrQV%2F%2F7zGMrvWJkTGBd5ZVAxlTgiZxSssmS7G8hxPZYko1qgdRYB3Rcs5ketzHki2q2AI%2B0419%2B3z%2F1p5C95LC%2FDKwEQstBzJpMFW14hw8dP1SrF%2BLer4byED8x6QLVs2uSAr2ZN5Npn%2FWGhkikTh0XfdYXRJYJDCIHQVl8rrn8IFKNMRipYsoBiK9seKTi5U%2BnLxt2M%2FW5Gk0C0kvDHUx%2FSXD4P%2Fm0M6JKyHJsy2XtTaidIQf6ZyOY3Za45NkaBz%2Bmkyhxmf1K8D8GPTiIZ%2Bza39mOrw3VObLpIhUeIDAPPUVhhUVJ0oa9z7AJbFvKCrpBqGibr4oC%2BvzZouiWBJVncfh2PO3S9Hh2YcihlUxohfNbREwAhpJwmW%2BMV8VCzGI2VkWlVQx9IIW0SrcLiHIaiEHCWsgRRAP2g%2FDQ4XIIYVQ2%2Fu09gskYVpVExbtDpkqLfE4KypMVJZURUEwfGEpQAk4cK9Kl%2F55pn2VZdQqvjk7To5abhxFnOUZEXVAgybYOgnawk1eL%2Bqjhf6BmTbs0nEh1lKH9LBRXla42rpVhGdKuhppKZnXDtBP0nB4jx8Y8Eb7LRhu%2F6cymoMKfZ4kBJZYdE6tlc3ZQz3XPwEEsuqaQs0IKmlkhNB3YG0wtDp%2Br%2BBp1VcN%2Bbh2wOvpj1yc1ql0gHSPWlhjfUAl8sSbKMGnTUPEDuw%2FVyrxgCa8ukv2uPqke3x4LIg1BbH3QKmlrosSrKfpeXmrNBI9zcnVwdhVQw%2BR7oR6UzGdbnr20AG%2BA4R5QB6%2BtqDQjSJQoG80E48DdKuzV6QsQyyWG8KeT%2FOGXRd1sD8y44IF%2FQ2Ztb07vAIDokEXsM0wwQw9id9tlLh7nx5qxzGAZlvJrAoJnVtecQwYSDIKwoPj45mD0hxJTLOM%2BkUKEWpJSxC8%2FRZQ%2Bk0PnA4QFzfkFXUggmcvcFJ%2FMXnqRCtfVaZtR2a4%2Ba6VPD9CtbfLeNRVrHhDhd38rERYekFZRYol38YqE25ogDn1i5zQG6YfvVTBLDIa0C8H2gqoUdmrwMEU0Hr2CTzL%2F6a0bo21PlhpnvdWrdoouQx1j%2FmFULtRPuapD8WFkZYJ016K3l%2BvhkW%2F1036TmoK5WlGStZ8t%2FTG5XXP%2FNwol6HKGW%2B9XNIHRSnq4f4tccEqqy%2BuKpq3Sze9iJGibyKm2lEDFfU4V5%2FLgh4ZhCI%2BlOCzjNSHqPDhHAdRdNNk95gSPn6%2B0E3z5F%2Bfu3on3JoDKsCDAXfmXdX6K8sPGkzcqucX72%2BsVzCBBbJ0Fephn407z5yjL5VDHmQ%2BaZ4sO8Go5tXsSLzLj%2Bcyva6IiqTL6Oy1t3NZqMCQwLZ76OyjIi95zD5b2BMaQF50e3SV6wEhymXxGuc0vJot2weKFS08Kxis9OOayYmqC3l3xgpV0fg%2FYsC5zudvXgLyNYn%2Bc5YeYNeEbZoXuKkWknKBI%2FYviyPiOgHczbUjfnC1VwDI4X1rwYWDLaA6NK%2BH2stpktIkYBxnw%2BtYEe63EqBbKMsOkj79cXD%2BAw8D%2BT1q1t5ferlfAYftv6SykMbzBsSs0aJC6xHS8oF%2BrFZQOlm9t6LlCglt1HmGc9Xi9YkyIMGcs4bUaCkSx6SlrQ8EqWuu5N%2F43WY0JbtaGBHAGLVVi98h3wOjmTI51zb8mPd12l28QMjljyfqj%2BmwoEEL8nFUujAKyJtVfNTVA8UbYKzJ26gSsk5VMAQryHlefOKe5c8igmywyEInX8fMECnmhV%2BErnL2qk9iUg4xBSDWTrjmTf8RpmR5nxatcQzNkXwdd%2FmZZAkbHKhafHuh4wlpucrXQNl1k4jje3xUewfzD%2FUu%2BT1UJl3hnMhpa1boGdjbQAwRJZ95zqaKA1YRBmBsEXuQKxT5GNWhsIbC8mYo6UoBQuipyI8yhS5g9nbd86DGHHNkxqvjMtQF04IoenFEjqpOhSVHtba8EdLLBSPUJP7SWgI7fl3jAYQ5MxpfSQ%2FOVxWtfWhTQcdDtXInzb8WFWxxwT7RLyz77451jFfnnaqtjUR6hlx7ZvmcFVNCc%2BkaYoCzh8LlnoEvlZRmX9tvtuRLq2UMvdgMJZii9OBxaJlvIjRC9isp0OkrWx5xM717uxFXvTcbj6uMlM41GjJzARSYJXBZxgBBsWPnsK1BwTKJwigqO%2B%2Bkf8Vpqg%2F5dbkY0yGDtq%2FEKfDTjzaZQ61XfM45A Matcher: Template: onedrive matched with high similarity
Source: https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq?ef5cb60b3eb712165be9aa2e84 Matcher: Template: microsoft matched
Source: https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq?ef5cb60b3eb712165be9aa2e8432255dm0haqp1l=U2FsdGVkX1%2F54Vi5k0fpJopgxlpTE%2Fwt1JbQBXUwtHI23IsXwilEibczOtXIyEafGUqvIxelPBKzraUcUZYsXddxVc0shoqZRiLuOtEQo8KQVHVVuhOjGpqAXb2ikXZcbMrR3pLVYbbERPy3QEAprq0jX%2F8t0p34IN%2BfftC4hK3%2Bs1g90JwifgjP3PTpK1aoAXRSeuyZNO%2BH9gJzHQNdJE58%2F1O7kPWQUEDNBeiPMexEwjzhqyPS9sJwf0XY9a6%2BVhLlq7y81V6%2FcHskp%2BgdCzxqfr2n7lQ1IzSUDClcGHZRzUhWfautY7xVjrLnzgh7ZdWqSUKbXwS23VjXs%2FdDRWpe82DNrAmaKQbf9Na%2B%2Bp6FxgINSz%2FMl0rbKTfp%2F%2FB8Lz5SQtpMofgzRCNhzPatp%2BV5xmEtnUqea565l6q9U5MRShooxYUyXTQVvbgAlt0sKy1Zn%2BcT%2FslFRCHHR0zWoJWY3C6nqLsoAd%2F%2FoO4Kuru019imWUO6zMl%2Bck5uBY464whKgUjunYedrNn084WCIbOmkMucwZLKqm3bOAd%2FibGCLBme5AHdSITb2ryus7xe9v4kpSTw2biTnqZDObxiPxx%2FlIUJVqeZ3GCPECdUF8rVpu8FzjC3cJ9NKqT7zzV6mx%2FvZ%2FeytMk04I%2BoShNpqBGNK%2F6JWx25ptmkQXmET2SmB3YR9%2BoDTAQc... HTTP Parser: Number of links: 0
Source: https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq?ef5cb60b3eb712165be9aa2e8432255dm0haqp1l=U2FsdGVkX1%2F54Vi5k0fpJopgxlpTE%2Fwt1JbQBXUwtHI23IsXwilEibczOtXIyEafGUqvIxelPBKzraUcUZYsXddxVc0shoqZRiLuOtEQo8KQVHVVuhOjGpqAXb2ikXZcbMrR3pLVYbbERPy3QEAprq0jX%2F8t0p34IN%2BfftC4hK3%2Bs1g90JwifgjP3PTpK1aoAXRSeuyZNO%2BH9gJzHQNdJE58%2F1O7kPWQUEDNBeiPMexEwjzhqyPS9sJwf0XY9a6%2BVhLlq7y81V6%2FcHskp%2BgdCzxqfr2n7lQ1IzSUDClcGHZRzUhWfautY7xVjrLnzgh7ZdWqSUKbXwS23VjXs%2FdDRWpe82DNrAmaKQbf9Na%2B%2Bp6FxgINSz%2FMl0rbKTfp%2F%2FB8Lz5SQtpMofgzRCNhzPatp%2BV5xmEtnUqea565l6q9U5MRShooxYUyXTQVvbgAlt0sKy1Zn%2BcT%2FslFRCHHR0zWoJWY3C6nqLsoAd%2F%2FoO4Kuru019imWUO6zMl%2Bck5uBY464whKgUjunYedrNn084WCIbOmkMucwZLKqm3bOAd%2FibGCLBme5AHdSITb2ryus7xe9v4kpSTw2biTnqZDObxiPxx%2FlIUJVqeZ3GCPECdUF8rVpu8FzjC3cJ9NKqT7zzV6mx%2FvZ%2FeytMk04I%2BoShNpqBGNK%2F6JWx25ptmkQXmET2SmB3YR9%2BoDTAQc... HTTP Parser: Title: Microsoft OneDrive does not match URL
Source: https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq?ef5cb60b3eb712165be9aa2e8432255dm0haqp1l=U2FsdGVkX1%2F54Vi5k0fpJopgxlpTE%2Fwt1JbQBXUwtHI23IsXwilEibczOtXIyEafGUqvIxelPBKzraUcUZYsXddxVc0shoqZRiLuOtEQo8KQVHVVuhOjGpqAXb2ikXZcbMrR3pLVYbbERPy3QEAprq0jX%2F8t0p34IN%2BfftC4hK3%2Bs1g90JwifgjP3PTpK1aoAXRSeuyZNO%2BH9gJzHQNdJE58%2F1O7kPWQUEDNBeiPMexEwjzhqyPS9sJwf0XY9a6%2BVhLlq7y81V6%2FcHskp%2BgdCzxqfr2n7lQ1IzSUDClcGHZRzUhWfautY7xVjrLnzgh7ZdWqSUKbXwS23VjXs%2FdDRWpe82DNrAmaKQbf9Na%2B%2Bp6FxgINSz%2FMl0rbKTfp%2F%2FB8Lz5SQtpMofgzRCNhzPatp%2BV5xmEtnUqea565l6q9U5MRShooxYUyXTQVvbgAlt0sKy1Zn%2BcT%2FslFRCHHR0zWoJWY3C6nqLsoAd%2F%2FoO4Kuru019imWUO6zMl%2Bck5uBY464whKgUjunYedrNn084WCIbOmkMucwZLKqm3bOAd%2FibGCLBme5AHdSITb2ryus7xe9v4kpSTw2biTnqZDObxiPxx%2FlIUJVqeZ3GCPECdUF8rVpu8FzjC3cJ9NKqT7zzV6mx%2FvZ%2FeytMk04I%2BoShNpqBGNK%2F6JWx25ptmkQXmET2SmB3YR9%2BoDTAQc HTTP Parser: No <meta name="author".. found
Source: https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq?ef5cb60b3eb712165be9aa2e8432255dm0haqp1l=U2FsdGVkX1%2F54Vi5k0fpJopgxlpTE%2Fwt1JbQBXUwtHI23IsXwilEibczOtXIyEafGUqvIxelPBKzraUcUZYsXddxVc0shoqZRiLuOtEQo8KQVHVVuhOjGpqAXb2ikXZcbMrR3pLVYbbERPy3QEAprq0jX%2F8t0p34IN%2BfftC4hK3%2Bs1g90JwifgjP3PTpK1aoAXRSeuyZNO%2BH9gJzHQNdJE58%2F1O7kPWQUEDNBeiPMexEwjzhqyPS9sJwf0XY9a6%2BVhLlq7y81V6%2FcHskp%2BgdCzxqfr2n7lQ1IzSUDClcGHZRzUhWfautY7xVjrLnzgh7ZdWqSUKbXwS23VjXs%2FdDRWpe82DNrAmaKQbf9Na%2B%2Bp6FxgINSz%2FMl0rbKTfp%2F%2FB8Lz5SQtpMofgzRCNhzPatp%2BV5xmEtnUqea565l6q9U5MRShooxYUyXTQVvbgAlt0sKy1Zn%2BcT%2FslFRCHHR0zWoJWY3C6nqLsoAd%2F%2FoO4Kuru019imWUO6zMl%2Bck5uBY464whKgUjunYedrNn084WCIbOmkMucwZLKqm3bOAd%2FibGCLBme5AHdSITb2ryus7xe9v4kpSTw2biTnqZDObxiPxx%2FlIUJVqeZ3GCPECdUF8rVpu8FzjC3cJ9NKqT7zzV6mx%2FvZ%2FeytMk04I%2BoShNpqBGNK%2F6JWx25ptmkQXmET2SmB3YR9%2BoDTAQc... HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 20.44.239.154:443 -> 192.168.2.7:49708 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49717 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.31.71:443 -> 192.168.2.7:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49729 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.31.71:443 -> 192.168.2.7:49745 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.119.249.228:443 -> 192.168.2.7:49747 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.7:49748 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.7:49750 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.7:49751 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.7:49846 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.7:49845 -> 1.1.1.1:53
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknown TCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknown TCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknown TCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknown TCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknown TCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknown TCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknown TCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknown TCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknown TCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknown TCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknown TCP traffic detected without corresponding DNS query: 20.44.239.154
Source: unknown TCP traffic detected without corresponding DNS query: 20.44.239.154
Source: unknown TCP traffic detected without corresponding DNS query: 20.44.239.154
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 20.44.239.154
Source: unknown TCP traffic detected without corresponding DNS query: 20.44.239.154
Source: unknown TCP traffic detected without corresponding DNS query: 20.44.239.154
Source: unknown TCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.44.239.154
Source: unknown TCP traffic detected without corresponding DNS query: 20.44.239.154
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.71
Source: global traffic HTTP traffic detected: GET /xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq HTTP/1.1Host: sharefile8.pages.devConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ajax/libs/font-awesome/4.7.0/css/font-awesome.css HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://sharefile8.pages.devsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://sharefile8.pages.dev/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /json/ HTTP/1.1Host: ipapi.coConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://sharefile8.pages.devSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://sharefile8.pages.dev/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq?ef5cb60b3eb712165be9aa2e8432255dm0haqp1l=U2FsdGVkX1%2F54Vi5k0fpJopgxlpTE%2Fwt1JbQBXUwtHI23IsXwilEibczOtXIyEafGUqvIxelPBKzraUcUZYsXddxVc0shoqZRiLuOtEQo8KQVHVVuhOjGpqAXb2ikXZcbMrR3pLVYbbERPy3QEAprq0jX%2F8t0p34IN%2BfftC4hK3%2Bs1g90JwifgjP3PTpK1aoAXRSeuyZNO%2BH9gJzHQNdJE58%2F1O7kPWQUEDNBeiPMexEwjzhqyPS9sJwf0XY9a6%2BVhLlq7y81V6%2FcHskp%2BgdCzxqfr2n7lQ1IzSUDClcGHZRzUhWfautY7xVjrLnzgh7ZdWqSUKbXwS23VjXs%2FdDRWpe82DNrAmaKQbf9Na%2B%2Bp6FxgINSz%2FMl0rbKTfp%2F%2FB8Lz5SQtpMofgzRCNhzPatp%2BV5xmEtnUqea565l6q9U5MRShooxYUyXTQVvbgAlt0sKy1Zn%2BcT%2FslFRCHHR0zWoJWY3C6nqLsoAd%2F%2FoO4Kuru019imWUO6zMl%2Bck5uBY464whKgUjunYedrNn084WCIbOmkMucwZLKqm3bOAd%2FibGCLBme5AHdSITb2ryus7xe9v4kpSTw2biTnqZDObxiPxx%2FlIUJVqeZ3GCPECdUF8rVpu8FzjC3cJ9NKqT7zzV6mx%2FvZ%2FeytMk04I%2BoShNpqBGNK%2F6JWx25ptmkQXmET2SmB3YR9%2BoDTAQck88otqYtCYclKM0QWtWB1tYqqWOTcaxOMY6Jyj9uCJYmdjaz8gZEQMrQV%2F%2F7zGMrvWJkTGBd5ZVAxlTgiZxSssmS7G8hxPZYko1qgdRYB3Rcs5ketzHki2q2AI%2B0419%2B3z%2F1p5C95LC%2FDKwEQstBzJpMFW14hw8dP1SrF%2BLer4byED8x6QLVs2uSAr2ZN5Npn%2FWGhkikTh0XfdYXRJYJDCIHQVl8rrn8IFKNMRipYsoBiK9seKTi5U%2BnLxt2M%2FW5Gk0C0kvDHUx%2FSXD4P%2Fm0M6JKyHJsy2XtTaidIQf6ZyOY3Za45NkaBz%2Bmkyhxmf1K8D8GPTiIZ%2Bza39mOrw3VObLpIhUeIDAPPUVhhUVJ0oa9z7AJbFvKCrpBqGibr4oC%2BvzZouiWBJVncfh2PO3S9Hh2YcihlUxohfNbREwAhpJwmW%2BMV8VCzGI2VkWlVQx9IIW0SrcLiHIaiEHCWsgRRAP2g%2FDQ4XIIYVQ2%2Fu09gskYVpVExbtDpkqLfE4KypMVJZURUEwfGEpQAk4cK9Kl%2F55pn2VZdQqvjk7To5abhxFnOUZEXVAgybYOgnawk1eL%2Bqjhf6BmTbs0nEh1lKH9LBRXla42rpVhGdKuhppKZnXDtBP0nB4jx8Y8Eb7LRhu%2F6cymoMKfZ4kBJZYdE6tlc3ZQz3XPwEEsuqaQs0IKmlkhNB3YG0wtDp%2Br%2BBp1VcN%2Bbh2wOvpj1yc1ql0gHSPWlhjfUAl8sSbKMGnTUPEDuw%2FVyrxgCa8ukv2uPqke3x4LIg1BbH3QKmlrosSrKfpeXmrNBI9zcnVwdhVQw%2BR7oR6UzGdbnr20AG%2BA4R5QB6%2BtqDQjSJQoG80E48DdKuzV6QsQyyWG8KeT%2FOGXRd1sD8y44IF%2FQ2Ztb07vAIDokEXsM0wwQw9id9tlLh7nx5qxzGAZlvJrAoJnVtecQwYSDIKwoPj45mD0hxJTLOM%2BkUKEWpJSxC8%2FRZQ%2Bk0PnA4QFzfkFXUggmcvcFJ%2FMXnqRCtfVaZtR2a4%2Ba6VPD9CtbfLeNRVrHhDhd38rERYekFZRYol38YqE25ogDn1i5zQG6YfvVTBLDIa0C8H2gqoUdmrwMEU0Hr2CTzL%2F6a0bo21PlhpnvdWrdoouQx1j%2FmFULtRPuapD8WFkZYJ016K3l%2BvhkW%2F1036TmoK5WlGStZ8t%2FTG5XXP%2FNwol6HKGW%2B9XNIHRSnq4f4tccEqqy%2BuKpq3Sze9iJGibyKm2lEDFfU4V5%2FLgh4ZhCI%2BlOCzjNSHqPDhHAdRdNNk95gSPn6%2B0E3z5F%2Bfu3on3JoDKsCDAXfmXdX6K8sPGkzcqucX72%2BsVzCBBbJ0Fephn407z5yjL5VDHmQ%2BaZ4sO8Go5tXsSLzLj%2Bcyva6IiqTL6Oy1t3NZqMCQwLZ76OyjIi95zD5b2BMaQF50e3SV6wEhymXxGuc0vJot2weKFS08Kxis9OOayYmqC3l3xgpV0fg%2FYsC5zudvXgLyNYn%2Bc5YeYNeEbZoXuKkWknKBI%2FYviyPiOgHczbUjfnC1VwDI4X1rwYWDLaA6NK%2BH2stpktIkYBxnw%2BtYEe63EqBbKMsOkj79cXD%2BAw8D%2BT1q1t5ferlfAYftv6SykMbzBsSs0aJC6xHS8oF%2BrFZQOlm9t6LlCglt1HmGc9Xi9YkyIMGcs4bUaCkSx6SlrQ8EqWuu5N%2F43WY0JbtaGBHAGLVVi98h3wOjmTI51zb8mPd12l28QMjljyfqj%2BmwoEEL8nFUujAKyJtVfNTVA8UbYKzJ26gSsk5VMAQryHlefOKe5c8igmywyEInX8fMECnmhV%2BErnL2qk9iUg4xBSDWTrjmTf8RpmR5nxatcQzNkXwdd%2FmZZAkbHKhafHuh4wlpucrXQNl1k4jje3xUe
Source: global traffic HTTP traffic detected: GET /json/ HTTP/1.1Host: ipapi.coConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic DNS traffic detected: DNS query: sharefile8.pages.dev
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: cdn.jsdelivr.net
Source: global traffic DNS traffic detected: DNS query: ipapi.co
Source: global traffic DNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: unknown HTTP traffic detected: POST /RST2.srf HTTP/1.0Connection: Keep-AliveContent-Type: application/soap+xmlAccept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 24.10.0.19045.0.0; IDCRL-cfg 16.000.29743.00; App svchost.exe, 10.0.19041.1806, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})Content-Length: 3592Host: login.live.com
Source: chromecache_128.6.dr, chromecache_121.6.dr String found in binary or memory: http://creativecommons.org/ns#
Source: chromecache_120.6.dr String found in binary or memory: http://fontawesome.io
Source: chromecache_120.6.dr String found in binary or memory: http://fontawesome.io/license
Source: chromecache_128.6.dr, chromecache_121.6.dr String found in binary or memory: http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd
Source: chromecache_128.6.dr, chromecache_121.6.dr String found in binary or memory: http://www.inkscape.org/)
Source: chromecache_128.6.dr, chromecache_121.6.dr String found in binary or memory: http://www.inkscape.org/namespaces/inkscape
Source: chromecache_117.6.dr, chromecache_132.6.dr String found in binary or memory: https://6481f63faf008522217341.cotradifyu.workers.dev/checkDomain
Source: chromecache_122.6.dr, chromecache_118.6.dr String found in binary or memory: https://cdn.jsdelivr.net/gh/uihkdslijsjd/captivating-app-lyoubgs5
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEz0dL_nz.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEz4dL_nz.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEz8dL_nz.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEzAdLw.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEzMdL_nz.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEzQdL_nz.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOiCnqEu92Fr1Mu51QrEzwdL_nz.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc-CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc0CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc1CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc2CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc3CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc5CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51S7ACc6CsQ.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc-CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc0CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc1CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc2CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc3CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc5CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TjASc6CsQ.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic-CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic0CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic1CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic2CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic3CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic5CsTKlA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOjCnqEu92Fr1Mu51TzBic6CsQ.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxEIzIFKw.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxFIzIFKw.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxGIzIFKw.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxHIzIFKw.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxIIzI.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxLIzIFKw.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1MmgVxMIzIFKw.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xEIzIFKw.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xFIzIFKw.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xGIzIFKw.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xHIzIFKw.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xIIzI.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xLIzIFKw.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOkCnqEu92Fr1Mu51xMIzIFKw.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fABc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fBBc4.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fBxc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fCBc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fCRc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fChc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmEU9fCxc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fABc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fBBc4.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fBxc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fCBc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fCRc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fChc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmSU5fCxc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfABc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfBBc4.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfBxc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfCBc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfCRc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfChc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOlCnqEu92Fr1MmWUlfCxc4EsA.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu4WxKOzY.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu4mxK.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu5mxKOzY.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu72xKOzY.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu7GxKOzY.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu7WxKOzY.woff2)
Source: chromecache_129.6.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu7mxKOzY.woff2)
Source: chromecache_117.6.dr, chromecache_132.6.dr String found in binary or memory: https://ipapi.co/json/
Source: chromecache_117.6.dr, chromecache_132.6.dr String found in binary or memory: https://locate.ipinit.workers.dev/
Source: chromecache_117.6.dr, chromecache_132.6.dr String found in binary or memory: https://onedrive.live.com/?authkey=%21AP4dQQ7hoSgcKIBIw%26cid=28E9EC3AAC12FF13%26id=28E9EC3AAC12FF13
Source: unknown Network traffic detected: HTTP traffic on port 49708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 49699 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 49672 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49717 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49699
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49850
Source: unknown Network traffic detected: HTTP traffic on port 49671 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49846
Source: unknown Network traffic detected: HTTP traffic on port 49674 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49719 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49850 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49719
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49717
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 49677 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49708
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 49846 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown HTTPS traffic detected: 20.44.239.154:443 -> 192.168.2.7:49708 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49717 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.31.71:443 -> 192.168.2.7:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49729 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.31.71:443 -> 192.168.2.7:49745 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.119.249.228:443 -> 192.168.2.7:49747 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.7:49748 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.7:49750 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.7:49751 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.231.128.59:443 -> 192.168.2.7:49846 version: TLS 1.2
Source: classification engine Classification label: mal64.phis.win@21/34@14/6
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1980,i,12944064432080657643,2785131983954265400,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1980,i,12944064432080657643,2785131983954265400,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs