Windows Analysis Report
https://eur.safelink.emails.azure.net/redirect/?destination=https%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3Flinkid%3D2230573&p=bT00YjEyOTdiMS03M2E3LTRkMTgtYWY3Ni0yZTFhYTM4NmFhNjQmdT1hZW8mbD1md2xpbmtfMg%3D%3D

Overview

General Information

Sample URL: https://eur.safelink.emails.azure.net/redirect/?destination=https%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3Flinkid%3D2230573&p=bT00YjEyOTdiMS03M2E3LTRkMTgtYWY3Ni0yZTFhYTM4NmFhNjQmdT1hZW8mbD1md2xpbmtfMg%3
Analysis ID: 1522717
Infos:

Detection

Score: 2
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Found iframes
HTML page contains hidden javascript code
Program does not show much activity (idle)
Stores files to the Windows start menu directory

Classification

Source: https://www.linkedin.com/uas/login?session_redirect=https%3A%2F%2Fwww.linkedin.com%2Ffeed%2F%3FshareActive%3Dtrue%26text%3DToday%2520I%2520completed%2520%2522Automatic%2520deletion%2520of%2520Power%2520Platform%2520environments%2520-%2520Power%2520Platform%2520%257C%2520Microsoft%2520Learn%2522%21%2520I%2527m%2520so%2520proud%2520to%2520be%2520celebrating%2520this%2520achievement%2520and%2520hope%2520this%2520inspires%2520you%2520to%2520start%2520your%2520own%2520%2540MicrosoftLearn%2520journey%21%250A%250D%250Ahttps%253A%252F%252Flearn.microsoft.com%252Fen-us%252Fpower-platform%252Fadmin%252Fautomatic-environment-cleanup%253FWT.mc_id%253Dppac_inproduct_email%2526WT.mc_id%253Dlinkedin HTTP Parser: Iframe src: https://lnkd.demdex.net/dest5.html?d_nsid=0#https%3A%2F%2Fwww.linkedin.com
Source: https://www.facebook.com/share_channel/?link=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dfacebook&app_id=966242223397117&source_surface=external_reshare&display&hashtag HTTP Parser: Base64 decoded: {"w":1280,"h":1024,"aw":1280,"ah":984,"c":24}
Source: https://www.linkedin.com/uas/login?session_redirect=https%3A%2F%2Fwww.linkedin.com%2Ffeed%2F%3FshareActive%3Dtrue%26text%3DToday%2520I%2520completed%2520%2522Automatic%2520deletion%2520of%2520Power%2520Platform%2520environments%2520-%2520Power%2520Platform%2520%257C%2520Microsoft%2520Learn%2522%21%2520I%2527m%2520so%2520proud%2520to%2520be%2520celebrating%2520this%2520achievement%2520and%2520hope%2520this%2520inspires%2520you%2520to%2520start%2520your%2520own%2520%2540MicrosoftLearn%2520journey%21%250A%250D%250Ahttps%253A%252F%252Flearn.microsoft.com%252Fen-us%252Fpower-platform%252Fadmin%252Fautomatic-environment-cleanup%253FWT.mc_id%253Dppac_inproduct_email%2526WT.mc_id%253Dlinkedin HTTP Parser: <input type="password" .../> found
Source: https://www.facebook.com/share_channel/?link=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dfacebook&app_id=966242223397117&source_surface=external_reshare&display&hashtag HTTP Parser: <input type="password" .../> found
Source: https://learn.microsoft.com/en-us/power-platform/admin/automatic-environment-cleanup?WT.mc_id=ppac_inproduct_email#definition-of-user-activity HTTP Parser: No favicon
Source: https://learn.microsoft.com/en-us/power-platform/admin/automatic-environment-cleanup?WT.mc_id=ppac_inproduct_email#environments-in-a-tenant-with-an-expired-subscription HTTP Parser: No favicon
Source: https://learn.microsoft.com/pdf?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Ftoc.json HTTP Parser: No favicon
Source: https://learn.microsoft.com/en-us/power-platform/admin/automatic-environment-cleanup?WT.mc_id=ppac_inproduct_email#view-the-status-of-your-environments HTTP Parser: No favicon
Source: https://learn.microsoft.com/en-us/power-platform/admin/automatic-environment-cleanup?WT.mc_id=ppac_inproduct_email#view-the-status-of-your-environments HTTP Parser: No favicon
Source: file:///C:/Users/user/Downloads/downloaded.pdf HTTP Parser: No favicon
Source: https://www.linkedin.com/uas/login?session_redirect=https%3A%2F%2Fwww.linkedin.com%2Ffeed%2F%3FshareActive%3Dtrue%26text%3DToday%2520I%2520completed%2520%2522Automatic%2520deletion%2520of%2520Power%2520Platform%2520environments%2520-%2520Power%2520Platform%2520%257C%2520Microsoft%2520Learn%2522%21%2520I%2527m%2520so%2520proud%2520to%2520be%2520celebrating%2520this%2520achievement%2520and%2520hope%2520this%2520inspires%2520you%2520to%2520start%2520your%2520own%2520%2540MicrosoftLearn%2520journey%21%250A%250D%250Ahttps%253A%252F%252Flearn.microsoft.com%252Fen-us%252Fpower-platform%252Fadmin%252Fautomatic-environment-cleanup%253FWT.mc_id%253Dppac_inproduct_email%2526WT.mc_id%253Dlinkedin HTTP Parser: No <meta name="author".. found
Source: https://www.linkedin.com/uas/login?session_redirect=https%3A%2F%2Fwww.linkedin.com%2Ffeed%2F%3FshareActive%3Dtrue%26text%3DToday%2520I%2520completed%2520%2522Automatic%2520deletion%2520of%2520Power%2520Platform%2520environments%2520-%2520Power%2520Platform%2520%257C%2520Microsoft%2520Learn%2522%21%2520I%2527m%2520so%2520proud%2520to%2520be%2520celebrating%2520this%2520achievement%2520and%2520hope%2520this%2520inspires%2520you%2520to%2520start%2520your%2520own%2520%2540MicrosoftLearn%2520journey%21%250A%250D%250Ahttps%253A%252F%252Flearn.microsoft.com%252Fen-us%252Fpower-platform%252Fadmin%252Fautomatic-environment-cleanup%253FWT.mc_id%253Dppac_inproduct_email%2526WT.mc_id%253Dlinkedin HTTP Parser: No <meta name="author".. found
Source: https://www.facebook.com/share_channel/?link=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dfacebook&app_id=966242223397117&source_surface=external_reshare&display&hashtag HTTP Parser: No <meta name="author".. found
Source: https://www.facebook.com/share_channel/?link=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dfacebook&app_id=966242223397117&source_surface=external_reshare&display&hashtag HTTP Parser: No <meta name="author".. found
Source: https://www.facebook.com/share_channel/?link=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dfacebook&app_id=966242223397117&source_surface=external_reshare&display&hashtag HTTP Parser: No <meta name="author".. found
Source: https://www.linkedin.com/uas/login?session_redirect=https%3A%2F%2Fwww.linkedin.com%2Ffeed%2F%3FshareActive%3Dtrue%26text%3DToday%2520I%2520completed%2520%2522Automatic%2520deletion%2520of%2520Power%2520Platform%2520environments%2520-%2520Power%2520Platform%2520%257C%2520Microsoft%2520Learn%2522%21%2520I%2527m%2520so%2520proud%2520to%2520be%2520celebrating%2520this%2520achievement%2520and%2520hope%2520this%2520inspires%2520you%2520to%2520start%2520your%2520own%2520%2540MicrosoftLearn%2520journey%21%250A%250D%250Ahttps%253A%252F%252Flearn.microsoft.com%252Fen-us%252Fpower-platform%252Fadmin%252Fautomatic-environment-cleanup%253FWT.mc_id%253Dppac_inproduct_email%2526WT.mc_id%253Dlinkedin HTTP Parser: No <meta name="copyright".. found
Source: https://www.linkedin.com/uas/login?session_redirect=https%3A%2F%2Fwww.linkedin.com%2Ffeed%2F%3FshareActive%3Dtrue%26text%3DToday%2520I%2520completed%2520%2522Automatic%2520deletion%2520of%2520Power%2520Platform%2520environments%2520-%2520Power%2520Platform%2520%257C%2520Microsoft%2520Learn%2522%21%2520I%2527m%2520so%2520proud%2520to%2520be%2520celebrating%2520this%2520achievement%2520and%2520hope%2520this%2520inspires%2520you%2520to%2520start%2520your%2520own%2520%2540MicrosoftLearn%2520journey%21%250A%250D%250Ahttps%253A%252F%252Flearn.microsoft.com%252Fen-us%252Fpower-platform%252Fadmin%252Fautomatic-environment-cleanup%253FWT.mc_id%253Dppac_inproduct_email%2526WT.mc_id%253Dlinkedin HTTP Parser: No <meta name="copyright".. found
Source: https://www.facebook.com/share_channel/?link=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dfacebook&app_id=966242223397117&source_surface=external_reshare&display&hashtag HTTP Parser: No <meta name="copyright".. found
Source: https://www.facebook.com/share_channel/?link=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dfacebook&app_id=966242223397117&source_surface=external_reshare&display&hashtag HTTP Parser: No <meta name="copyright".. found
Source: https://www.facebook.com/share_channel/?link=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dfacebook&app_id=966242223397117&source_surface=external_reshare&display&hashtag HTTP Parser: No <meta name="copyright".. found
Source: chromecache_380.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/A4tfXiHOGrs/ equals www.facebook.com (Facebook)
Source: chromecache_398.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/CCT5pM3qiNk/ equals www.facebook.com (Facebook)
Source: chromecache_380.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/Ga6vBwdwgUx/ equals www.facebook.com (Facebook)
Source: chromecache_398.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/MDzNl_j9yvg/ equals www.facebook.com (Facebook)
Source: chromecache_372.2.dr, chromecache_459.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/OKBVmODmb-W/ equals www.facebook.com (Facebook)
Source: chromecache_350.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/WRsJ32R7YJG/ equals www.facebook.com (Facebook)
Source: chromecache_398.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/aJoeSHn7XcN/ equals www.facebook.com (Facebook)
Source: chromecache_280.2.dr String found in binary or memory: * License: https://www.facebook.com/legal/license/t3hOLs8wlXy/ equals www.facebook.com (Facebook)
Source: chromecache_461.2.dr String found in binary or memory: __d("Chromedome",["fbt"],(function(a,b,c,d,e,f,g,h){function i(){if(document.domain==null)return null;var a=document.domain,b=/^intern\./.test(a);if(b)return null;b=/(^|\.)facebook\.(com|sg)$/.test(a);if(b)return"facebook";b=/(^|\.)instagram\.com$/.test(a);if(b)return"instagram";b=/(^|\.)threads\.net$/.test(a);if(b)return"threads";b=/(^|\.)messenger\.com$/.test(a);return b?"messenger":null}function j(a){if(a==="instagram")return h._("This is a browser feature intended for developers. If someone told you to copy-paste something here to enable an Instagram feature or \"hack\" someone's account, it is a scam and will give them access to your Instagram account.");return a==="threads"?h._("This is a browser feature intended for developers. If someone told you to copy-paste something here to enable a Threads feature or \"hack\" someone's account, it is a scam and will give them access to your Threads account."):h._("This is a browser feature intended for developers. If someone told you to copy and paste something here to enable a Facebook feature or \"hack\" someone's account, it is a scam and will give them access to your Facebook account.")}function a(a){if(top!==window)return;a=i();if(a==null)return;var b=h._("Stop!");a=j(a);var c=h._("See {url} for more information.",[h._param("url","https://www.facebook.com/selfxss")]),d="font-family:helvetica; font-size:20px; ";[[b,d+"font-size:50px; font-weight:bold; color:red; -webkit-text-stroke:1px black;"],[a,d],[c,d],["",""]].map(function(a){window.setTimeout(console.log.bind(console,"\n%c"+a[0].toString(),a[1]))})}g.start=a}),226); equals www.facebook.com (Facebook)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: http://admin.powerplatform.com/azurebilling)
Source: chromecache_392.2.dr, chromecache_282.2.dr, chromecache_551.2.dr, chromecache_422.2.dr String found in binary or memory: http://feross.org
Source: chromecache_414.2.dr String found in binary or memory: http://git.io/TrdQbw
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: http://login.microsoftonline-p.com/)
Source: chromecache_414.2.dr String found in binary or memory: http://underscorejs.org
Source: chromecache_375.2.dr String found in binary or memory: https://accounts.google.com/gsi/
Source: chromecache_375.2.dr, chromecache_477.2.dr String found in binary or memory: https://accounts.google.com/gsi/button
Source: chromecache_375.2.dr String found in binary or memory: https://accounts.google.com/gsi/fedcm.json
Source: chromecache_375.2.dr String found in binary or memory: https://accounts.google.com/gsi/fedcmcsp?client_id=
Source: chromecache_375.2.dr, chromecache_477.2.dr String found in binary or memory: https://accounts.google.com/gsi/iframe/select
Source: chromecache_477.2.dr String found in binary or memory: https://accounts.google.com/gsi/log
Source: chromecache_375.2.dr, chromecache_477.2.dr String found in binary or memory: https://accounts.google.com/gsi/revoke
Source: chromecache_375.2.dr, chromecache_477.2.dr String found in binary or memory: https://accounts.google.com/gsi/select
Source: chromecache_375.2.dr, chromecache_477.2.dr String found in binary or memory: https://accounts.google.com/gsi/status
Source: chromecache_375.2.dr, chromecache_477.2.dr String found in binary or memory: https://accounts.google.com/gsi/style
Source: chromecache_375.2.dr, chromecache_477.2.dr String found in binary or memory: https://accounts.google.com/o/oauth2/iframe
Source: chromecache_375.2.dr String found in binary or memory: https://accounts.google.com/o/oauth2/v2/auth
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://aka.ms/learn-pdf-feedback)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://aka.ms/platformlimits)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://aka.ms/powerappsidea)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://aka.ms/powerautomateideas)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://aka.ms/powerbiideas)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://aka.ms/powerpagesideas)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://aka.ms/powervirtualagentideas)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://aka.ms/ppac)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://aka.ms/stp)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://app.powerbi.com/)
Source: chromecache_267.2.dr, chromecache_440.2.dr String found in binary or memory: https://appleid.apple.com
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://apps.powerapps.com/trial)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://auth.gfx.ms/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://blogs.windows.com/msedgedev/microsoft-edge-legacy-end-of-support)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://community.dynamics.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://community.dynamics.com/crm/b/dynamicscrmsupportblog/archive/2016/11/15/new-diagnostic-scenar
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://community.dynamics.com/forums/thread/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://contoso.crm.dynamics.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://crt.sh/?d=2545289014)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://crt.sh/?d=2565145421)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://crt.sh/?d=2565151295)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://crt.sh/?d=3422153451)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://crt.sh/?d=3422153452)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://crt.sh/?d=853428)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://crt.sh/?d=8568700)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://crt.sh/?d=8656329)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://datatracker.ietf.org/doc/html/rfc5246#section-7.4.2)
Source: chromecache_375.2.dr String found in binary or memory: https://developers.google.com/identity/gsi/web/guides/fedcm-migration
Source: chromecache_375.2.dr String found in binary or memory: https://developers.google.com/identity/gsi/web/guides/fedcm-migration?s=dc#cross_origin)
Source: chromecache_375.2.dr String found in binary or memory: https://developers.google.com/identity/gsi/web/guides/fedcm-migration?s=dc#display_moment
Source: chromecache_375.2.dr String found in binary or memory: https://developers.google.com/identity/gsi/web/guides/fedcm-migration?s=dc#skipped_moment
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://experience.dynamics.com/ideas/categories/?forum=1afbfe0a-5439-ea11-a813-000d3a579c35&forumNa
Source: chromecache_392.2.dr, chromecache_551.2.dr, chromecache_422.2.dr String found in binary or memory: https://feross.org/opensource
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://forms.office.com/FormsPro/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbRxclc4NDdL5CqxoDKPh
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://forms.office.com/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbR-5Axi2KMXdNi_1eF9P36tZUN1FU
Source: chromecache_533.2.dr String found in binary or memory: https://github.com/emn178/js-md5
Source: chromecache_533.2.dr String found in binary or memory: https://github.com/focus-trap/tabbable/blob/master/LICENSE
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://github.com/microsoft/powerapps-tools/tree/master/Administration/AdminInADay)
Source: chromecache_463.2.dr, chromecache_484.2.dr String found in binary or memory: https://help.x.com/rules-and-policies/twitter-cookies
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://home.dynamics.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://lcs.dynamics.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://lcs.dynamics.com/Logon/Index)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://login.live.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://make.powerapps.com/)
Source: chromecache_375.2.dr String found in binary or memory: https://meet.google.com
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://mem.gfx.ms/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://ms.portal.azure.com/#create/Microsoft.Template)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://ms.portal.azure.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://my.visualstudio.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://nmap.org/)
Source: chromecache_375.2.dr String found in binary or memory: https://oauth2.googleapis.com/revoke
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://office.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://office.com/apps)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://portal.azure.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://portal.microsoftonline.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://portal.office.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://portal.office.com/account/#subscriptions)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://powerapps.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://powerautomate.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://products.office.com/business/manage-office-365-admin-app)
Source: chromecache_412.2.dr, chromecache_332.2.dr String found in binary or memory: https://raw.githubusercontent.com/stefanpenner/es6-promise/master/LICENSE
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://secure.aadcdn.microsoftonline-p.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://status.office.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://support.office.com/article/About-the-Office-365-admin-center-758befc4-0888-4009-9f14-0d14740
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://support.office.com/article/Add-your-users-and-domain-to-Office-365-ffdb2216-330d-4d73-832b-3
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://support.office.com/article/Assign-admin-roles-in-Office-365-eac4d046-1afd-4f1a-85fc-8219c79e
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://support.office.com/article/Create-or-edit-users-435ccec3-09dd-4587-9ebd-2f3cad6bc2bc)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://support.office.com/article/Set-an-individual-user-s-password-to-never-expire-f493e3af-e1d8-4
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://support.office.com/article/Verify-your-domain-in-Office-365-6383f56d-3d09-4dcb-9b41-b5f5a5ef
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://support.office.com/article/What-is-PSTN-calling-3dc773b9-95e0-4448-b2f1-887c54022429)
Source: chromecache_303.2.dr, chromecache_488.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/bundle.NetworkInstrument
Source: chromecache_278.2.dr, chromecache_345.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/i18n/emoji-en.3afd1e4a.j
Source: chromecache_335.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/i18n/en.246d31ea.js.map
Source: chromecache_382.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/loader.AppModules.8e4960
Source: chromecache_552.2.dr, chromecache_476.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/loader.AudioDock.af72bcb
Source: chromecache_293.2.dr, chromecache_307.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/loader.AudioOnlyVideoPla
Source: chromecache_351.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/loader.SideNav.e8d0899a.
Source: chromecache_333.2.dr, chromecache_516.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/loader.richScribeAction.
Source: chromecache_533.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/main.8912eaaa.js.map
Source: chromecache_464.2.dr, chromecache_481.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/modules.audio.8d83897a.j
Source: chromecache_425.2.dr, chromecache_385.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/modules.common.0481c12a.
Source: chromecache_514.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/ondemand.Dropdown.78a54e
Source: chromecache_313.2.dr, chromecache_480.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/ondemand.IntentPrompt.6d
Source: chromecache_302.2.dr, chromecache_397.2.dr, chromecache_553.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.AboutThisA
Source: chromecache_337.2.dr, chromecache_284.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.AccountAna
Source: chromecache_445.2.dr, chromecache_529.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.AudioSpace
Source: chromecache_547.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.Birdwatch~
Source: chromecache_279.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.Communitie
Source: chromecache_436.2.dr, chromecache_441.2.dr, chromecache_532.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.Compose~bu
Source: chromecache_311.2.dr, chromecache_437.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.Compose~lo
Source: chromecache_288.2.dr, chromecache_358.2.dr, chromecache_367.2.dr, chromecache_297.2.dr, chromecache_287.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.Compose~on
Source: chromecache_329.2.dr, chromecache_538.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.LiveEvent~
Source: chromecache_315.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.ReaderMode
Source: chromecache_534.2.dr, chromecache_522.2.dr, chromecache_409.2.dr, chromecache_517.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.TwitterArt
Source: chromecache_354.2.dr, chromecache_473.2.dr, chromecache_463.2.dr, chromecache_484.2.dr, chromecache_546.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.AppModules
Source: chromecache_334.2.dr, chromecache_396.2.dr, chromecache_290.2.dr, chromecache_467.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.AudioDock~
Source: chromecache_381.2.dr, chromecache_366.2.dr, chromecache_268.2.dr, chromecache_270.2.dr, chromecache_487.2.dr, chromecache_353.2.dr, chromecache_272.2.dr, chromecache_357.2.dr, chromecache_505.2.dr, chromecache_319.2.dr, chromecache_323.2.dr, chromecache_362.2.dr, chromecache_448.2.dr, chromecache_469.2.dr, chromecache_388.2.dr, chromecache_447.2.dr, chromecache_370.2.dr, chromecache_359.2.dr, chromecache_356.2.dr, chromecache_496.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.DMDrawer~b
Source: chromecache_299.2.dr, chromecache_443.2.dr, chromecache_401.2.dr, chromecache_363.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.DashMenu~l
Source: chromecache_390.2.dr, chromecache_407.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.SideNav~bu
Source: chromecache_383.2.dr, chromecache_550.2.dr, chromecache_331.2.dr, chromecache_281.2.dr, chromecache_474.2.dr, chromecache_322.2.dr, chromecache_439.2.dr, chromecache_402.2.dr, chromecache_392.2.dr, chromecache_265.2.dr, chromecache_266.2.dr, chromecache_349.2.dr, chromecache_429.2.dr, chromecache_386.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.Typeahead~
Source: chromecache_393.2.dr, chromecache_309.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.directMess
Source: chromecache_264.2.dr, chromecache_446.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~ondemand.InlinePl
Source: chromecache_414.2.dr String found in binary or memory: https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/vendor.62d18e4a.js.map
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://trials.dynamics.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://www.d365ccafpi.com/)
Source: chromecache_380.2.dr String found in binary or memory: https://www.internalfb.com/intern/invariant/
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://www.powershellgallery.com/)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://www.powershellgallery.com/packages/Microsoft.PowerApps.Administration.PowerShell/2.0.1)
Source: downloaded.pdf.crdownload.0.dr String found in binary or memory: https://www.ssllabs.com/ssltest/analyze.html)
Source: chromecache_335.2.dr, chromecache_296.2.dr String found in binary or memory: https://x.com/en/privacy
Source: classification engine Classification label: clean2.win@32/450@0/54
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=1920,i,14918702719771116416,4743946418574674215,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://eur.safelink.emails.azure.net/redirect/?destination=https%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3Flinkid%3D2230573&p=bT00YjEyOTdiMS03M2E3LTRkMTgtYWY3Ni0yZTFhYTM4NmFhNjQmdT1hZW8mbD1md2xpbmtfMg%3D%3D"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=6040 --field-trial-handle=1920,i,14918702719771116416,4743946418574674215,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=6280 --field-trial-handle=1920,i,14918702719771116416,4743946418574674215,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=1920,i,14918702719771116416,4743946418574674215,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=6040 --field-trial-handle=1920,i,14918702719771116416,4743946418574674215,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=6280 --field-trial-handle=1920,i,14918702719771116416,4743946418574674215,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Google Drive.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs