IOC Report
https://eur.safelink.emails.azure.net/redirect/?destination=https%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3Flinkid%3D2230573&p=bT00YjEyOTdiMS03M2E3LTRkMTgtYWY3Ni0yZTFhYTM4NmFhNjQmdT1hZW8mbD1md2xpbmtfMg%3D%3D

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:49:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:49:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 09:52:18 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:49:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:49:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:49:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\Downloads\downloaded.pdf.crdownload
PDF document, version 1.4
dropped
Chrome Cache Entry: 264
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 265
Unicode text, UTF-8 text, with very long lines (3963)
downloaded
Chrome Cache Entry: 266
ASCII text, with very long lines (1609)
dropped
Chrome Cache Entry: 267
ASCII text, with very long lines (7566)
downloaded
Chrome Cache Entry: 268
ASCII text, with very long lines (2640)
dropped
Chrome Cache Entry: 269
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 270
ASCII text, with very long lines (1280)
downloaded
Chrome Cache Entry: 271
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 272
ASCII text, with very long lines (32344)
dropped
Chrome Cache Entry: 273
ASCII text, with very long lines (11608)
dropped
Chrome Cache Entry: 274
ASCII text, with very long lines (2290), with no line terminators
dropped
Chrome Cache Entry: 275
ASCII text, with very long lines (5868)
downloaded
Chrome Cache Entry: 276
ASCII text, with very long lines (11608)
downloaded
Chrome Cache Entry: 277
exported SGML document, ASCII text, with very long lines (29520)
dropped
Chrome Cache Entry: 278
Unicode text, UTF-8 text, with very long lines (65518), with no line terminators
dropped
Chrome Cache Entry: 279
ASCII text, with very long lines (1457)
dropped
Chrome Cache Entry: 280
ASCII text, with very long lines (17932)
downloaded
Chrome Cache Entry: 281
ASCII text, with very long lines (5962)
downloaded
Chrome Cache Entry: 282
Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
downloaded
Chrome Cache Entry: 283
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 284
ASCII text, with very long lines (4608)
downloaded
Chrome Cache Entry: 285
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 286
ASCII text, with very long lines (49786), with no line terminators
downloaded
Chrome Cache Entry: 287
ASCII text, with very long lines (1449)
downloaded
Chrome Cache Entry: 288
ASCII text, with very long lines (2115)
dropped
Chrome Cache Entry: 289
C source, ASCII text, with very long lines (4181)
dropped
Chrome Cache Entry: 290
ASCII text, with very long lines (1641)
downloaded
Chrome Cache Entry: 291
ASCII text, with very long lines (11163), with no line terminators
downloaded
Chrome Cache Entry: 292
ASCII text, with very long lines (1823)
downloaded
Chrome Cache Entry: 293
ASCII text, with very long lines (10054)
dropped
Chrome Cache Entry: 294
Unicode text, UTF-8 text, with very long lines (55964)
downloaded
Chrome Cache Entry: 295
ASCII text, with very long lines (4284)
downloaded
Chrome Cache Entry: 296
Unicode text, UTF-8 text, with very long lines (65307), with no line terminators
dropped
Chrome Cache Entry: 297
ASCII text, with very long lines (1449)
dropped
Chrome Cache Entry: 298
ASCII text, with very long lines (3146)
downloaded
Chrome Cache Entry: 299
ASCII text, with very long lines (55183)
dropped
Chrome Cache Entry: 300
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 301
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 302
ASCII text, with very long lines (1792)
dropped
Chrome Cache Entry: 303
ASCII text, with very long lines (7664)
downloaded
Chrome Cache Entry: 304
ASCII text, with very long lines (5076)
dropped
Chrome Cache Entry: 305
ASCII text, with very long lines (9961)
downloaded
Chrome Cache Entry: 306
ASCII text, with very long lines (10401)
dropped
Chrome Cache Entry: 307
ASCII text, with very long lines (10054)
downloaded
Chrome Cache Entry: 308
ASCII text, with very long lines (3158)
downloaded
Chrome Cache Entry: 309
ASCII text, with very long lines (24926)
dropped
Chrome Cache Entry: 310
C source, ASCII text, with very long lines (438)
downloaded
Chrome Cache Entry: 311
ASCII text, with very long lines (6221)
downloaded
Chrome Cache Entry: 312
ASCII text, with very long lines (3787)
downloaded
Chrome Cache Entry: 313
ASCII text, with very long lines (10252)
dropped
Chrome Cache Entry: 314
ASCII text, with very long lines (32344)
downloaded
Chrome Cache Entry: 315
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 316
ASCII text, with very long lines (23876)
dropped
Chrome Cache Entry: 317
ASCII text, with very long lines (41541)
downloaded
Chrome Cache Entry: 318
PNG image data, 171 x 56, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 319
ASCII text, with very long lines (1280)
dropped
Chrome Cache Entry: 320
ASCII text, with very long lines (65410)
dropped
Chrome Cache Entry: 321
ASCII text, with very long lines (8477)
downloaded
Chrome Cache Entry: 322
ASCII text, with very long lines (1609)
downloaded
Chrome Cache Entry: 323
ASCII text, with very long lines (6282)
downloaded
Chrome Cache Entry: 324
ASCII text, with very long lines (3146)
dropped
Chrome Cache Entry: 325
Unicode text, UTF-8 text, with very long lines (6334)
downloaded
Chrome Cache Entry: 326
JSON data
dropped
Chrome Cache Entry: 327
ASCII text, with very long lines (8314)
downloaded
Chrome Cache Entry: 328
ASCII text, with very long lines (65410)
downloaded
Chrome Cache Entry: 329
ASCII text, with very long lines (7003)
downloaded
Chrome Cache Entry: 330
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 331
ASCII text, with very long lines (3512)
downloaded
Chrome Cache Entry: 332
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 333
ASCII text, with very long lines (908)
downloaded
Chrome Cache Entry: 334
Unicode text, UTF-8 text, with very long lines (65529), with no line terminators
dropped
Chrome Cache Entry: 335
Unicode text, UTF-8 text, with very long lines (65307), with no line terminators
downloaded
Chrome Cache Entry: 336
PNG image data, 171 x 56, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 337
ASCII text, with very long lines (4608)
dropped
Chrome Cache Entry: 338
Unicode text, UTF-8 text, with very long lines (65529), with no line terminators
downloaded
Chrome Cache Entry: 339
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
dropped
Chrome Cache Entry: 340
JSON data
downloaded
Chrome Cache Entry: 341
ASCII text, with very long lines (3583)
downloaded
Chrome Cache Entry: 342
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=6, orientation=upper-left, xresolution=86, yresolution=94, resolutionunit=2], baseline, precision 8, 1000x300, components 3
downloaded
Chrome Cache Entry: 343
ASCII text, with very long lines (8663)
dropped
Chrome Cache Entry: 344
ASCII text, with very long lines (1792)
downloaded
Chrome Cache Entry: 345
Unicode text, UTF-8 text, with very long lines (65518), with no line terminators
downloaded
Chrome Cache Entry: 346
ASCII text, with very long lines (1465)
downloaded
Chrome Cache Entry: 347
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 348
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 349
Unicode text, UTF-8 text, with very long lines (2022)
dropped
Chrome Cache Entry: 350
ASCII text, with very long lines (6735)
dropped
Chrome Cache Entry: 351
Unicode text, UTF-8 text, with very long lines (42823)
downloaded
Chrome Cache Entry: 352
exported SGML document, ASCII text, with very long lines (29520)
downloaded
Chrome Cache Entry: 353
ASCII text, with very long lines (1309)
downloaded
Chrome Cache Entry: 354
ASCII text, with very long lines (5502)
dropped
Chrome Cache Entry: 355
PNG image data, 692 x 274, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 356
ASCII text, with very long lines (2143)
dropped
Chrome Cache Entry: 357
ASCII text, with very long lines (12633)
dropped
Chrome Cache Entry: 358
ASCII text, with very long lines (1670)
downloaded
Chrome Cache Entry: 359
ASCII text, with very long lines (3787)
dropped
Chrome Cache Entry: 360
Unicode text, UTF-8 text, with very long lines (2022)
downloaded
Chrome Cache Entry: 361
ASCII text, with very long lines (4371)
dropped
Chrome Cache Entry: 362
ASCII text, with very long lines (1966)
downloaded
Chrome Cache Entry: 363
ASCII text, with very long lines (10401)
downloaded
Chrome Cache Entry: 364
ASCII text, with very long lines (49786), with no line terminators
dropped
Chrome Cache Entry: 365
ASCII text, with very long lines (2143)
downloaded
Chrome Cache Entry: 366
ASCII text, with very long lines (2587)
dropped
Chrome Cache Entry: 367
ASCII text, with very long lines (1670)
dropped
Chrome Cache Entry: 368
ASCII text, with very long lines (1130)
downloaded
Chrome Cache Entry: 369
ASCII text, with very long lines (1239)
downloaded
Chrome Cache Entry: 370
ASCII text, with very long lines (3987)
dropped
Chrome Cache Entry: 371
Unicode text, UTF-8 text, with very long lines (47992)
dropped
Chrome Cache Entry: 372
ASCII text, with very long lines (32588)
downloaded
Chrome Cache Entry: 373
ASCII text, with very long lines (2115)
downloaded
Chrome Cache Entry: 374
ASCII text, with very long lines (52717), with no line terminators
dropped
Chrome Cache Entry: 375
ASCII text, with very long lines (3169)
dropped
Chrome Cache Entry: 376
ASCII text, with very long lines (17932)
dropped
Chrome Cache Entry: 377
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 378
ASCII text, with very long lines (23587)
downloaded
Chrome Cache Entry: 379
PNG image data, 192 x 192, 8-bit gray+alpha, non-interlaced
dropped
Chrome Cache Entry: 380
ASCII text, with very long lines (20398)
downloaded
Chrome Cache Entry: 381
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 382
Unicode text, UTF-8 text, with very long lines (47992)
downloaded
Chrome Cache Entry: 383
Unicode text, UTF-8 text, with very long lines (3963)
dropped
Chrome Cache Entry: 384
ASCII text, with very long lines (52717), with no line terminators
downloaded
Chrome Cache Entry: 385
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 386
ASCII text, with very long lines (23069)
downloaded
Chrome Cache Entry: 387
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 388
ASCII text, with very long lines (12633)
downloaded
Chrome Cache Entry: 389
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 390
ASCII text, with very long lines (8663)
downloaded
Chrome Cache Entry: 391
ASCII text, with very long lines (55183)
downloaded
Chrome Cache Entry: 392
ASCII text, with very long lines (28914)
downloaded
Chrome Cache Entry: 393
ASCII text, with very long lines (8314)
dropped
Chrome Cache Entry: 394
ASCII text, with very long lines (24926)
downloaded
Chrome Cache Entry: 395
ASCII text, with very long lines (3583)
dropped
Chrome Cache Entry: 396
ASCII text, with very long lines (23587)
dropped
Chrome Cache Entry: 397
ASCII text, with very long lines (5692)
dropped
Chrome Cache Entry: 398
ASCII text, with very long lines (6573)
downloaded
Chrome Cache Entry: 399
MS Windows icon resource - 4 icons, 64x64, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 400
ASCII text, with very long lines (5076)
downloaded
Chrome Cache Entry: 401
ASCII text, with very long lines (2346)
downloaded
Chrome Cache Entry: 402
ASCII text, with very long lines (5962)
dropped
Chrome Cache Entry: 403
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=6, orientation=upper-left, xresolution=86, yresolution=94, resolutionunit=2], baseline, precision 8, 1000x300, components 3
dropped
Chrome Cache Entry: 404
ASCII text, with very long lines (4284)
dropped
Chrome Cache Entry: 405
C source, ASCII text, with very long lines (4181)
downloaded
Chrome Cache Entry: 406
Unicode text, UTF-8 text, with very long lines (49298), with no line terminators
downloaded
Chrome Cache Entry: 407
ASCII text, with very long lines (8976)
dropped
Chrome Cache Entry: 408
ASCII text, with very long lines (21121)
downloaded
Chrome Cache Entry: 409
ASCII text, with very long lines (6863)
downloaded
Chrome Cache Entry: 410
ASCII text, with very long lines (8477)
dropped
Chrome Cache Entry: 411
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 412
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 413
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 414
Unicode text, UTF-8 text, with very long lines (55964)
dropped
Chrome Cache Entry: 415
ASCII text, with very long lines (5412)
downloaded
Chrome Cache Entry: 416
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 417
ASCII text, with very long lines (2166), with no line terminators
downloaded
Chrome Cache Entry: 418
ASCII text, with very long lines (1457)
downloaded
Chrome Cache Entry: 419
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 420
ASCII text, with very long lines (1160)
downloaded
Chrome Cache Entry: 421
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 422
Unicode text, UTF-8 text, with very long lines (65529), with no line terminators
dropped
Chrome Cache Entry: 423
ASCII text, with very long lines (46884)
dropped
Chrome Cache Entry: 424
JSON data
dropped
Chrome Cache Entry: 425
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 426
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 427
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 428
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 429
ASCII text, with very long lines (23069)
dropped
Chrome Cache Entry: 430
ASCII text, with very long lines (2166), with no line terminators
dropped
Chrome Cache Entry: 431
ASCII text, with very long lines (4404)
downloaded
Chrome Cache Entry: 432
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped
Chrome Cache Entry: 433
ASCII text, with very long lines (2607)
downloaded
Chrome Cache Entry: 434
C source, ASCII text, with very long lines (4739)
dropped
Chrome Cache Entry: 435
Unicode text, UTF-8 text, with very long lines (36775)
dropped
Chrome Cache Entry: 436
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
dropped
Chrome Cache Entry: 437
ASCII text, with very long lines (6221)
dropped
Chrome Cache Entry: 438
ASCII text, with very long lines (28914)
dropped
Chrome Cache Entry: 439
ASCII text, with very long lines (12515)
downloaded
Chrome Cache Entry: 440
ASCII text, with very long lines (7566)
dropped
Chrome Cache Entry: 441
ASCII text, with very long lines (5876)
downloaded
Chrome Cache Entry: 442
JSON data
downloaded
Chrome Cache Entry: 443
ASCII text, with very long lines (2607)
dropped
Chrome Cache Entry: 444
C source, ASCII text, with very long lines (1984)
downloaded
Chrome Cache Entry: 445
ASCII text, with very long lines (1584)
dropped
Chrome Cache Entry: 446
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 447
ASCII text, with very long lines (4775)
dropped
Chrome Cache Entry: 448
ASCII text, with very long lines (4284)
downloaded
Chrome Cache Entry: 449
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 450
Unicode text, UTF-8 text, with very long lines (42823)
dropped
Chrome Cache Entry: 451
C source, ASCII text, with very long lines (1984)
dropped
Chrome Cache Entry: 452
ASCII text, with very long lines (1130)
dropped
Chrome Cache Entry: 453
ASCII text, with very long lines (4775)
downloaded
Chrome Cache Entry: 454
ASCII text, with very long lines (11167)
dropped
Chrome Cache Entry: 455
ASCII text, with very long lines (10853), with no line terminators
downloaded
Chrome Cache Entry: 456
ASCII text, with very long lines (1823)
dropped
Chrome Cache Entry: 457
ASCII text, with very long lines (23876)
downloaded
Chrome Cache Entry: 458
Unicode text, UTF-8 text, with very long lines (49298), with no line terminators
dropped
Chrome Cache Entry: 459
ASCII text, with very long lines (32588)
dropped
Chrome Cache Entry: 460
Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
dropped
Chrome Cache Entry: 461
ASCII text, with very long lines (9961)
dropped
Chrome Cache Entry: 462
C source, ASCII text, with very long lines (4739)
downloaded
Chrome Cache Entry: 463
ASCII text, with very long lines (4314)
dropped
Chrome Cache Entry: 464
Unicode text, UTF-8 text, with very long lines (65342), with no line terminators
dropped
Chrome Cache Entry: 465
PNG image data, 192 x 192, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 466
ASCII text, with very long lines (11167)
downloaded
Chrome Cache Entry: 467
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
dropped
Chrome Cache Entry: 468
ASCII text, with very long lines (2587)
downloaded
Chrome Cache Entry: 469
ASCII text, with very long lines (1309)
dropped
Chrome Cache Entry: 470
JSON data
dropped
Chrome Cache Entry: 471
ASCII text, with very long lines (630)
dropped
Chrome Cache Entry: 472
ASCII text, with very long lines (2640)
downloaded
Chrome Cache Entry: 473
ASCII text, with very long lines (1748)
downloaded
Chrome Cache Entry: 474
ASCII text, with very long lines (1424)
dropped
Chrome Cache Entry: 475
ASCII text, with very long lines (1641)
dropped
Chrome Cache Entry: 476
ASCII text, with very long lines (2287)
downloaded
Chrome Cache Entry: 477
ASCII text, with very long lines (1354)
dropped
Chrome Cache Entry: 478
ASCII text, with very long lines (1354)
downloaded
Chrome Cache Entry: 479
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 480
ASCII text, with very long lines (10252)
downloaded
Chrome Cache Entry: 481
Unicode text, UTF-8 text, with very long lines (65342), with no line terminators
downloaded
Chrome Cache Entry: 482
ASCII text, with very long lines (1424)
downloaded
Chrome Cache Entry: 483
ASCII text, with very long lines (3512)
dropped
Chrome Cache Entry: 484
ASCII text, with very long lines (4314)
downloaded
Chrome Cache Entry: 485
JSON data
dropped
Chrome Cache Entry: 486
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 487
ASCII text, with very long lines (4962)
dropped
Chrome Cache Entry: 488
ASCII text, with very long lines (7664)
dropped
Chrome Cache Entry: 489
ASCII text, with very long lines (21121)
dropped
Chrome Cache Entry: 490
ASCII text, with very long lines (2290), with no line terminators
downloaded
Chrome Cache Entry: 491
ASCII text, with very long lines (3169)
downloaded
Chrome Cache Entry: 492
ASCII text, with very long lines (1465)
dropped
Chrome Cache Entry: 493
C source, ASCII text, with very long lines (438)
dropped
Chrome Cache Entry: 494
ASCII text, with very long lines (11163), with no line terminators
dropped
Chrome Cache Entry: 495
C source, Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
downloaded
Chrome Cache Entry: 496
ASCII text, with very long lines (1596)
downloaded
Chrome Cache Entry: 497
Web Open Font Format (Version 2), TrueType, length 44660, version 1.0
downloaded
Chrome Cache Entry: 498
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 499
JSON data
downloaded
Chrome Cache Entry: 500
ASCII text, with very long lines (5555)
downloaded
Chrome Cache Entry: 501
ASCII text, with very long lines (6735)
downloaded
Chrome Cache Entry: 502
ASCII text, with very long lines (3260)
downloaded
Chrome Cache Entry: 503
ASCII text, with very long lines (3158)
dropped
Chrome Cache Entry: 504
JSON data
downloaded
Chrome Cache Entry: 505
ASCII text, with very long lines (5555)
dropped
Chrome Cache Entry: 506
HTML document, Unicode text, UTF-8 text, with very long lines (675), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 507
Web Open Font Format (Version 2), TrueType, length 45016, version 1.0
downloaded
Chrome Cache Entry: 508
C source, Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
dropped
Chrome Cache Entry: 509
ASCII text, with very long lines (10261)
downloaded
Chrome Cache Entry: 510
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 511
JSON data
dropped
Chrome Cache Entry: 512
ASCII text, with very long lines (3987)
downloaded
Chrome Cache Entry: 513
Web Open Font Format (Version 2), TrueType, length 19360, version 1.0
downloaded
Chrome Cache Entry: 514
ASCII text, with very long lines (5868)
dropped
Chrome Cache Entry: 515
ASCII text, with very long lines (1748)
dropped
Chrome Cache Entry: 516
ASCII text, with very long lines (908)
dropped
Chrome Cache Entry: 517
ASCII text, with very long lines (6863)
dropped
Chrome Cache Entry: 518
ASCII text, with very long lines (4490)
dropped
Chrome Cache Entry: 519
ASCII text, with very long lines (1966)
dropped
Chrome Cache Entry: 520
ASCII text, with very long lines (1596)
dropped
Chrome Cache Entry: 521
ASCII text, with very long lines (6573)
dropped
Chrome Cache Entry: 522
ASCII text, with very long lines (10261)
dropped
Chrome Cache Entry: 523
ASCII text, with very long lines (630)
downloaded
Chrome Cache Entry: 524
Unicode text, UTF-8 text, with very long lines (36775)
downloaded
Chrome Cache Entry: 525
PNG image data, 692 x 274, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 526
ASCII text, with very long lines (12515)
dropped
Chrome Cache Entry: 527
ASCII text, with very long lines (8280)
downloaded
Chrome Cache Entry: 528
Unicode text, UTF-8 text, with very long lines (65529), with no line terminators
downloaded
Chrome Cache Entry: 529
ASCII text, with very long lines (1584)
downloaded
Chrome Cache Entry: 530
ASCII text, with very long lines (8280)
dropped
Chrome Cache Entry: 531
ASCII text, with very long lines (46884)
downloaded
Chrome Cache Entry: 532
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 533
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 534
Unicode text, UTF-8 text, with very long lines (6334)
dropped
Chrome Cache Entry: 535
MS Windows icon resource - 4 icons, 64x64, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 536
ASCII text, with very long lines (5876)
dropped
Chrome Cache Entry: 537
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 538
ASCII text, with very long lines (7003)
dropped
Chrome Cache Entry: 539
ASCII text, with very long lines (4490)
downloaded
Chrome Cache Entry: 540
ASCII text, with very long lines (8976)
downloaded
Chrome Cache Entry: 541
ASCII text, with very long lines (10853), with no line terminators
dropped
Chrome Cache Entry: 542
ASCII text, with very long lines (20398)
dropped
Chrome Cache Entry: 543
ASCII text, with very long lines (533), with no line terminators
downloaded
Chrome Cache Entry: 544
ASCII text, with very long lines (3260)
dropped
Chrome Cache Entry: 545
ASCII text, with very long lines (2346)
dropped
Chrome Cache Entry: 546
ASCII text, with very long lines (5502)
downloaded
Chrome Cache Entry: 547
ASCII text, with very long lines (1808)
dropped
Chrome Cache Entry: 548
ASCII text, with very long lines (4962)
downloaded
Chrome Cache Entry: 549
ASCII text, with very long lines (1808)
downloaded
Chrome Cache Entry: 550
ASCII text, with very long lines (4371)
downloaded
Chrome Cache Entry: 551
ASCII text, with very long lines (41541)
dropped
Chrome Cache Entry: 552
ASCII text, with very long lines (2287)
dropped
Chrome Cache Entry: 553
ASCII text, with very long lines (5692)
downloaded
There are 288 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=1920,i,14918702719771116416,4743946418574674215,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://eur.safelink.emails.azure.net/redirect/?destination=https%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3Flinkid%3D2230573&p=bT00YjEyOTdiMS03M2E3LTRkMTgtYWY3Ni0yZTFhYTM4NmFhNjQmdT1hZW8mbD1md2xpbmtfMg%3D%3D"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=6040 --field-trial-handle=1920,i,14918702719771116416,4743946418574674215,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=6280 --field-trial-handle=1920,i,14918702719771116416,4743946418574674215,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://eur.safelink.emails.azure.net/redirect/?destination=https%3A%2F%2Fgo.microsoft.com%2Ffwlink%2F%3Flinkid%3D2230573&p=bT00YjEyOTdiMS03M2E3LTRkMTgtYWY3Ni0yZTFhYTM4NmFhNjQmdT1hZW8mbD1md2xpbmtfMg%3D%3D
https://forms.office.com/FormsPro/Pages/ResponsePage.aspx?id=v4j5cvGGr0GRqy180BHbRxclc4NDdL5CqxoDKPh
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/modules.audio.8d83897a.j
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.AboutThisA
unknown
https://blogs.windows.com/msedgedev/microsoft-edge-legacy-end-of-support)
unknown
https://crt.sh/?d=8568700)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.directMess
unknown
http://underscorejs.org
unknown
https://app.powerbi.com/)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/i18n/en.246d31ea.js.map
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/modules.common.0481c12a.
unknown
https://developers.google.com/identity/gsi/web/guides/fedcm-migration?s=dc#skipped_moment
unknown
https://portal.azure.com/)
unknown
https://trials.dynamics.com/)
unknown
https://www.internalfb.com/intern/invariant/
unknown
https://raw.githubusercontent.com/stefanpenner/es6-promise/master/LICENSE
unknown
https://auth.gfx.ms/)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.AccountAna
unknown
https://aka.ms/powerpagesideas)
unknown
https://lcs.dynamics.com/)
unknown
https://community.dynamics.com/forums/thread/)
unknown
https://home.dynamics.com/)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.DMDrawer~b
unknown
https://aka.ms/powerappsidea)
unknown
https://support.office.com/article/Assign-admin-roles-in-Office-365-eac4d046-1afd-4f1a-85fc-8219c79e
unknown
https://help.x.com/rules-and-policies/twitter-cookies
unknown
https://portal.microsoftonline.com/)
unknown
https://ms.portal.azure.com/)
unknown
https://mem.gfx.ms/)
unknown
file:///C:/Users/user/Downloads/downloaded.pdf
https://github.com/emn178/js-md5
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.AudioSpace
unknown
https://aka.ms/learn-pdf-feedback)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.Compose~on
unknown
https://github.com/microsoft/powerapps-tools/tree/master/Administration/AdminInADay)
unknown
https://community.dynamics.com/crm/b/dynamicscrmsupportblog/archive/2016/11/15/new-diagnostic-scenar
unknown
https://my.visualstudio.com/)
unknown
https://crt.sh/?d=8656329)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/loader.AppModules.8e4960
unknown
https://crt.sh/?d=3422153451)
unknown
https://community.dynamics.com/)
unknown
https://office.com/)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/loader.richScribeAction.
unknown
https://datatracker.ietf.org/doc/html/rfc5246#section-7.4.2)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.AudioDock~
unknown
https://contoso.crm.dynamics.com/)
unknown
https://support.office.com/article/About-the-Office-365-admin-center-758befc4-0888-4009-9f14-0d14740
unknown
https://www.powershellgallery.com/packages/Microsoft.PowerApps.Administration.PowerShell/2.0.1)
unknown
https://ms.portal.azure.com/#create/Microsoft.Template)
unknown
https://support.office.com/article/Create-or-edit-users-435ccec3-09dd-4587-9ebd-2f3cad6bc2bc)
unknown
https://crt.sh/?d=3422153452)
unknown
https://aka.ms/powerautomateideas)
unknown
https://crt.sh/?d=853428)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.ReaderMode
unknown
https://www.powershellgallery.com/)
unknown
https://support.office.com/article/What-is-PSTN-calling-3dc773b9-95e0-4448-b2f1-887c54022429)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/i18n/emoji-en.3afd1e4a.j
unknown
http://login.microsoftonline-p.com/)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/loader.AudioDock.af72bcb
unknown
https://x.com/en/privacy
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.AppModules
unknown
https://aka.ms/stp)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/loader.SideNav.e8d0899a.
unknown
https://products.office.com/business/manage-office-365-admin-app)
unknown
http://git.io/TrdQbw
unknown
https://github.com/focus-trap/tabbable/blob/master/LICENSE
unknown
https://crt.sh/?d=2545289014)
unknown
https://developers.google.com/identity/gsi/web/guides/fedcm-migration
unknown
https://meet.google.com
unknown
https://office.com/apps)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.Birdwatch~
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.Communitie
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~ondemand.InlinePl
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/loader.AudioOnlyVideoPla
unknown
https://aka.ms/powervirtualagentideas)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/bundle.NetworkInstrument
unknown
https://aka.ms/powerbiideas)
unknown
https://nmap.org/)
unknown
https://aka.ms/ppac)
unknown
https://status.office.com/)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.Typeahead~
unknown
https://apps.powerapps.com/trial)
unknown
https://www.ssllabs.com/ssltest/analyze.html)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.TwitterArt
unknown
https://developers.google.com/identity/gsi/web/guides/fedcm-migration?s=dc#cross_origin)
unknown
https://portal.office.com/)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/vendor.62d18e4a.js.map
unknown
https://portal.office.com/account/#subscriptions)
unknown
https://secure.aadcdn.microsoftonline-p.com/)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.Compose~bu
unknown
https://powerautomate.com/)
unknown
https://support.office.com/article/Add-your-users-and-domain-to-Office-365-ffdb2216-330d-4d73-832b-3
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.SideNav~bu
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/ondemand.Dropdown.78a54e
unknown
https://feross.org/opensource
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~loader.DashMenu~l
unknown
https://make.powerapps.com/)
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/ondemand.IntentPrompt.6d
unknown
https://ton.local.twitter.com/responsive-web-internal/sourcemaps/client-web/shared~bundle.LiveEvent~
unknown
https://lcs.dynamics.com/Logon/Index)
unknown
http://admin.powerplatform.com/azurebilling)
unknown
There are 90 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
13.107.246.42
unknown
United States
52.19.26.215
unknown
United States
20.189.173.9
unknown
United States
152.199.21.118
unknown
United States
13.107.246.45
unknown
United States
142.250.185.227
unknown
United States
192.168.2.5
unknown
unknown
172.64.146.215
unknown
United States
104.244.43.131
unknown
United States
142.250.184.226
unknown
United States
204.79.197.237
unknown
United States
142.250.184.196
unknown
United States
1.1.1.1
unknown
Australia
144.2.9.1
unknown
Netherlands
142.250.185.238
unknown
United States
52.16.68.25
unknown
United States
2.19.126.156
unknown
European Union
88.221.170.101
unknown
European Union
239.255.255.250
unknown
Reserved
157.240.253.35
unknown
United States
199.232.188.159
unknown
United States
142.250.185.206
unknown
United States
54.77.208.237
unknown
United States
192.168.2.16
unknown
unknown
13.107.246.60
unknown
United States
20.189.173.12
unknown
United States
52.17.201.122
unknown
United States
13.74.129.1
unknown
United States
142.250.185.162
unknown
United States
142.250.186.132
unknown
United States
151.101.120.158
unknown
United States
172.217.18.10
unknown
United States
157.240.252.35
unknown
United States
74.125.250.129
unknown
United States
66.102.1.84
unknown
United States
142.250.184.202
unknown
United States
104.244.42.66
unknown
United States
104.244.42.65
unknown
United States
104.18.41.41
unknown
United States
104.244.42.1
unknown
United States
216.58.212.138
unknown
United States
104.244.42.2
unknown
United States
54.229.152.53
unknown
United States
142.250.185.132
unknown
United States
184.28.89.167
unknown
United States
192.168.2.11
unknown
unknown
64.233.167.84
unknown
United States
152.199.22.144
unknown
United States
142.250.185.130
unknown
United States
142.250.185.131
unknown
United States
192.168.2.12
unknown
unknown
34.248.147.230
unknown
United States
157.240.253.1
unknown
United States
172.66.0.227
unknown
United States
There are 44 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://learn.microsoft.com/en-us/power-platform/admin/automatic-environment-cleanup?WT.mc_id=ppac_inproduct_email#definition-of-user-activity
https://learn.microsoft.com/en-us/power-platform/admin/automatic-environment-cleanup?WT.mc_id=ppac_inproduct_email#definition-of-user-activity
https://learn.microsoft.com/en-us/power-platform/admin/automatic-environment-cleanup?WT.mc_id=ppac_inproduct_email#environments-in-a-tenant-with-an-expired-subscription
https://learn.microsoft.com/pdf?url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Ftoc.json
https://www.linkedin.com/uas/login?session_redirect=https%3A%2F%2Fwww.linkedin.com%2Ffeed%2F%3FshareActive%3Dtrue%26text%3DToday%2520I%2520completed%2520%2522Automatic%2520deletion%2520of%2520Power%2520Platform%2520environments%2520-%2520Power%2520Platform%2520%257C%2520Microsoft%2520Learn%2522%21%2520I%2527m%2520so%2520proud%2520to%2520be%2520celebrating%2520this%2520achievement%2520and%2520hope%2520this%2520inspires%2520you%2520to%2520start%2520your%2520own%2520%2540MicrosoftLearn%2520journey%21%250A%250D%250Ahttps%253A%252F%252Flearn.microsoft.com%252Fen-us%252Fpower-platform%252Fadmin%252Fautomatic-environment-cleanup%253FWT.mc_id%253Dppac_inproduct_email%2526WT.mc_id%253Dlinkedin
https://www.linkedin.com/uas/login?session_redirect=https%3A%2F%2Fwww.linkedin.com%2Ffeed%2F%3FshareActive%3Dtrue%26text%3DToday%2520I%2520completed%2520%2522Automatic%2520deletion%2520of%2520Power%2520Platform%2520environments%2520-%2520Power%2520Platform%2520%257C%2520Microsoft%2520Learn%2522%21%2520I%2527m%2520so%2520proud%2520to%2520be%2520celebrating%2520this%2520achievement%2520and%2520hope%2520this%2520inspires%2520you%2520to%2520start%2520your%2520own%2520%2540MicrosoftLearn%2520journey%21%250A%250D%250Ahttps%253A%252F%252Flearn.microsoft.com%252Fen-us%252Fpower-platform%252Fadmin%252Fautomatic-environment-cleanup%253FWT.mc_id%253Dppac_inproduct_email%2526WT.mc_id%253Dlinkedin
https://www.linkedin.com/uas/login?session_redirect=https%3A%2F%2Fwww.linkedin.com%2Ffeed%2F%3FshareActive%3Dtrue%26text%3DToday%2520I%2520completed%2520%2522Automatic%2520deletion%2520of%2520Power%2520Platform%2520environments%2520-%2520Power%2520Platform%2520%257C%2520Microsoft%2520Learn%2522%21%2520I%2527m%2520so%2520proud%2520to%2520be%2520celebrating%2520this%2520achievement%2520and%2520hope%2520this%2520inspires%2520you%2520to%2520start%2520your%2520own%2520%2540MicrosoftLearn%2520journey%21%250A%250D%250Ahttps%253A%252F%252Flearn.microsoft.com%252Fen-us%252Fpower-platform%252Fadmin%252Fautomatic-environment-cleanup%253FWT.mc_id%253Dppac_inproduct_email%2526WT.mc_id%253Dlinkedin
https://learn.microsoft.com/en-us/power-platform/admin/automatic-environment-cleanup?WT.mc_id=ppac_inproduct_email#view-the-status-of-your-environments
https://learn.microsoft.com/en-us/power-platform/admin/automatic-environment-cleanup?WT.mc_id=ppac_inproduct_email#view-the-status-of-your-environments
https://x.com/intent/post?original_referer=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dtwitter&text=Today%20I%20completed%20%22Automatic%20deletion%20of%20Power%20Platform%20environments%20-%20Power%20Platform%20%7C%20Microsoft%20Learn%22!%20I%27m%20so%20proud%20to%20be%20celebrating%20this%20achievement%20and%20hope%20this%20inspires%20you%20to%20start%20your%20own%20%40MicrosoftLearn%20journey!&tw_p=tweetbutton&url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dtwitter&mx=2
https://x.com/intent/post?original_referer=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dtwitter&text=Today+I+completed+%22Automatic+deletion+of+Power+Platform+environments+-+Power+Platform+%7C+Microsoft+Learn%22%21+I%27m+so+proud+to+be+celebrating+this+achievement+and+hope+this+inspires+you+to+start+your+own+%40MicrosoftLearn+journey%21&tw_p=tweetbutton&url=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dtwitter
https://www.facebook.com/share_channel/?link=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dfacebook&app_id=966242223397117&source_surface=external_reshare&display&hashtag
https://www.facebook.com/share_channel/?link=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dfacebook&app_id=966242223397117&source_surface=external_reshare&display&hashtag
https://www.facebook.com/share_channel/?link=https%3A%2F%2Flearn.microsoft.com%2Fen-us%2Fpower-platform%2Fadmin%2Fautomatic-environment-cleanup%3FWT.mc_id%3Dppac_inproduct_email%26WT.mc_id%3Dfacebook&app_id=966242223397117&source_surface=external_reshare&display&hashtag
file:///C:/Users/user/Downloads/downloaded.pdf
There are 5 hidden doms, click here to show them.