IOC Report
https://rdhomes-my.sharepoint.com/:f:/g/personal/petrina_ryandesignerhomes_com_au/EtwntXraOOdMp3Nx1zZ6gF8Bf8aWSwNn9o_57nz1-Z9h0A?e=arAOsK

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\OneDrive_2024-10-01.zip (copy)
Zip archive data, at least v2.0 to extract, compression method=store
dropped
malicious
C:\Users\user\AppData\Local\Temp\u1g2kedq.eh0\Payment Advise\CLICK HERE TO REVIEW DOCUMENT.url
MS Windows 95 Internet shortcut text (URL=<https://qE5vHYe.tathyslam.com/Qt2rOX3/>), ASCII text
dropped
C:\Users\user\AppData\Local\Temp\unarchiver.log
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Downloads\587456cc-2310-48c7-9983-c07d2d274362.tmp
Zip archive data, at least v2.0 to extract, compression method=store
dropped
C:\Users\user\Downloads\OneDrive_2024-10-01.zip.crdownload (copy)
Zip archive data, at least v2.0 to extract, compression method=store
dropped
Chrome Cache Entry: 441
ASCII text, with very long lines (9675)
downloaded
Chrome Cache Entry: 442
Web Open Font Format, TrueType, length 15684, version 1.3277
downloaded
Chrome Cache Entry: 443
ASCII text, with very long lines (30298)
downloaded
Chrome Cache Entry: 444
ASCII text, with very long lines (5383)
downloaded
Chrome Cache Entry: 445
Unicode text, UTF-8 text, with very long lines (22121)
dropped
Chrome Cache Entry: 446
ASCII text, with very long lines (10633)
downloaded
Chrome Cache Entry: 447
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 448
ASCII text, with very long lines (30298)
dropped
Chrome Cache Entry: 449
ASCII text, with very long lines (59376)
downloaded
Chrome Cache Entry: 450
ASCII text, with very long lines (4979)
downloaded
Chrome Cache Entry: 451
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 452
ASCII text, with very long lines (911)
dropped
Chrome Cache Entry: 453
ASCII text, with very long lines (23437), with CRLF line terminators
dropped
Chrome Cache Entry: 454
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 455
ASCII text, with very long lines (14090)
dropped
Chrome Cache Entry: 456
ASCII text, with very long lines (63602)
downloaded
Chrome Cache Entry: 457
ASCII text, with very long lines (7031)
downloaded
Chrome Cache Entry: 458
Unicode text, UTF-8 text, with very long lines (18796)
downloaded
Chrome Cache Entry: 459
ASCII text, with very long lines (30298)
dropped
Chrome Cache Entry: 460
ASCII text, with very long lines (35238), with no line terminators
dropped
Chrome Cache Entry: 461
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 462
Web Open Font Format, TrueType, length 2524, version 4.-22282
downloaded
Chrome Cache Entry: 463
XML 1.0 document, ASCII text, with very long lines (443), with no line terminators
dropped
Chrome Cache Entry: 464
ASCII text, with very long lines (22018)
downloaded
Chrome Cache Entry: 465
ASCII text, with very long lines (2203)
downloaded
Chrome Cache Entry: 466
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 467
ASCII text, with very long lines (65461)
downloaded
Chrome Cache Entry: 468
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
Chrome Cache Entry: 469
ASCII text, with very long lines (57563)
downloaded
Chrome Cache Entry: 470
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 471
Unicode text, UTF-8 text, with very long lines (18796)
dropped
Chrome Cache Entry: 473
ASCII text, with very long lines (65457)
downloaded
Chrome Cache Entry: 475
ASCII text, with very long lines (7246)
dropped
Chrome Cache Entry: 476
Web Open Font Format, TrueType, length 12324, version 1.3277
downloaded
Chrome Cache Entry: 477
PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 478
ASCII text, with very long lines (4715)
dropped
Chrome Cache Entry: 479
ASCII text, with very long lines (3834)
downloaded
Chrome Cache Entry: 480
Web Open Font Format, TrueType, length 15908, version 1.3277
downloaded
Chrome Cache Entry: 481
Web Open Font Format, TrueType, length 16776, version 1.3277
downloaded
Chrome Cache Entry: 482
Unicode text, UTF-8 text, with very long lines (45476)
downloaded
Chrome Cache Entry: 483
ASCII text, with very long lines (4715)
downloaded
Chrome Cache Entry: 484
Unicode text, UTF-8 text, with very long lines (10393)
downloaded
Chrome Cache Entry: 485
Unicode text, UTF-8 text, with very long lines (65308), with no line terminators
downloaded
Chrome Cache Entry: 486
ASCII text, with very long lines (48337)
downloaded
Chrome Cache Entry: 487
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 72x72, components 3
downloaded
Chrome Cache Entry: 488
Zip archive data, at least v2.0 to extract, compression method=store
downloaded
Chrome Cache Entry: 489
ASCII text, with very long lines (40143)
dropped
Chrome Cache Entry: 490
Unicode text, UTF-8 text, with very long lines (41512)
downloaded
Chrome Cache Entry: 491
ASCII text, with very long lines (4621)
dropped
Chrome Cache Entry: 492
Web Open Font Format, TrueType, length 27376, version 1.3277
downloaded
Chrome Cache Entry: 493
ASCII text, with very long lines (849)
downloaded
Chrome Cache Entry: 494
ASCII text
downloaded
Chrome Cache Entry: 495
ASCII text, with very long lines (19653)
downloaded
Chrome Cache Entry: 496
JSON data
dropped
Chrome Cache Entry: 497
ASCII text, with very long lines (42754)
dropped
Chrome Cache Entry: 498
ASCII text, with very long lines (48337)
dropped
Chrome Cache Entry: 499
Unicode text, UTF-8 text, with very long lines (18788)
downloaded
Chrome Cache Entry: 500
Web Open Font Format, TrueType, length 15812, version 1.3277
downloaded
Chrome Cache Entry: 501
Unicode text, UTF-8 text, with very long lines (32703)
downloaded
Chrome Cache Entry: 502
JSON data
dropped
Chrome Cache Entry: 503
ASCII text, with very long lines (24798)
dropped
Chrome Cache Entry: 504
ASCII text, with very long lines (4621)
downloaded
Chrome Cache Entry: 505
C source, ASCII text, with very long lines (11334)
downloaded
Chrome Cache Entry: 506
ASCII text, with very long lines (5172)
dropped
Chrome Cache Entry: 507
Unicode text, UTF-8 text, with very long lines (36614)
downloaded
Chrome Cache Entry: 508
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 509
ASCII text, with very long lines (42754)
downloaded
Chrome Cache Entry: 510
ASCII text, with very long lines (42914)
downloaded
Chrome Cache Entry: 511
ASCII text, with very long lines (17016)
downloaded
Chrome Cache Entry: 512
ASCII text, with very long lines (4078)
downloaded
Chrome Cache Entry: 513
ASCII text, with very long lines (62513)
downloaded
Chrome Cache Entry: 514
ASCII text, with very long lines (20803)
dropped
Chrome Cache Entry: 515
ASCII text, with very long lines (48918)
dropped
Chrome Cache Entry: 516
Web Open Font Format, TrueType, length 17724, version 1.3277
downloaded
Chrome Cache Entry: 517
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 518
Unicode text, UTF-8 text, with very long lines (45476)
dropped
Chrome Cache Entry: 519
ASCII text, with very long lines (5172)
downloaded
Chrome Cache Entry: 520
ASCII text, with very long lines (3109)
downloaded
Chrome Cache Entry: 521
JSON data
dropped
Chrome Cache Entry: 522
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 40329
downloaded
Chrome Cache Entry: 523
ASCII text, with very long lines (7235)
downloaded
Chrome Cache Entry: 524
Unicode text, UTF-8 text, with very long lines (7518)
downloaded
Chrome Cache Entry: 525
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 526
ASCII text, with very long lines (7031)
dropped
Chrome Cache Entry: 527
ASCII text, with very long lines (17997)
downloaded
Chrome Cache Entry: 528
ASCII text, with very long lines (4670)
downloaded
Chrome Cache Entry: 529
ASCII text, with very long lines (4670)
dropped
Chrome Cache Entry: 530
ASCII text, with very long lines (855)
dropped
Chrome Cache Entry: 531
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 532
ASCII text, with very long lines (4186)
downloaded
Chrome Cache Entry: 533
ASCII text, with very long lines (4551), with no line terminators
downloaded
Chrome Cache Entry: 534
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 535
Unicode text, UTF-8 text, with very long lines (5314)
downloaded
Chrome Cache Entry: 536
ASCII text, with very long lines (52343)
downloaded
Chrome Cache Entry: 537
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
downloaded
Chrome Cache Entry: 538
ASCII text, with very long lines (23437), with CRLF line terminators
downloaded
Chrome Cache Entry: 539
JSON data
dropped
Chrome Cache Entry: 540
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 541
ASCII text, with very long lines (4142)
downloaded
Chrome Cache Entry: 542
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 543
ASCII text, with very long lines (10554)
downloaded
Chrome Cache Entry: 544
ASCII text, with very long lines (44971)
dropped
Chrome Cache Entry: 545
ASCII text, with very long lines (4142)
dropped
Chrome Cache Entry: 546
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 547
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 102804
dropped
Chrome Cache Entry: 548
ASCII text, with very long lines (56951)
downloaded
Chrome Cache Entry: 549
ASCII text, with very long lines (10191)
dropped
Chrome Cache Entry: 550
ASCII text, with very long lines (14852)
downloaded
Chrome Cache Entry: 551
XML 1.0 document, ASCII text, with very long lines (443), with no line terminators
dropped
Chrome Cache Entry: 552
JSON data
dropped
Chrome Cache Entry: 553
ASCII text, with very long lines (16804)
dropped
Chrome Cache Entry: 554
ASCII text, with very long lines (6279)
downloaded
Chrome Cache Entry: 555
ASCII text, with very long lines (35304)
downloaded
Chrome Cache Entry: 556
Java source, ASCII text, with very long lines (23464)
downloaded
Chrome Cache Entry: 557
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 558
ASCII text, with very long lines (11745)
downloaded
Chrome Cache Entry: 559
ASCII text, with very long lines (3858)
downloaded
Chrome Cache Entry: 560
Unicode text, UTF-8 text, with very long lines (65308), with no line terminators
dropped
Chrome Cache Entry: 561
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 562
ASCII text, with very long lines (25927)
downloaded
Chrome Cache Entry: 563
ASCII text, with very long lines (5159)
downloaded
Chrome Cache Entry: 564
ASCII text, with very long lines (13520)
downloaded
Chrome Cache Entry: 565
ASCII text, with very long lines (6090)
downloaded
Chrome Cache Entry: 566
ASCII text, with very long lines (24798)
downloaded
Chrome Cache Entry: 567
ASCII text, with very long lines (63602)
dropped
Chrome Cache Entry: 569
ASCII text, with very long lines (7071)
downloaded
Chrome Cache Entry: 570
ASCII text, with very long lines (3095)
dropped
Chrome Cache Entry: 571
Web Open Font Format, TrueType, length 16704, version 1.3277
downloaded
Chrome Cache Entry: 572
Unicode text, UTF-8 text, with very long lines (32703)
dropped
Chrome Cache Entry: 574
Web Open Font Format, TrueType, length 4420, version 1.3277
downloaded
Chrome Cache Entry: 575
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 576
ASCII text, with very long lines (13140)
dropped
Chrome Cache Entry: 577
HTML document, ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 578
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 579
Web Open Font Format, TrueType, length 15284, version 1.3277
downloaded
Chrome Cache Entry: 580
ASCII text, with very long lines (59425)
dropped
Chrome Cache Entry: 581
ASCII text, with very long lines (34942)
dropped
Chrome Cache Entry: 582
ASCII text, with very long lines (59425)
downloaded
Chrome Cache Entry: 583
ASCII text, with very long lines (12800)
dropped
Chrome Cache Entry: 584
ASCII text, with very long lines (58499)
downloaded
Chrome Cache Entry: 585
ASCII text, with very long lines (48918)
downloaded
Chrome Cache Entry: 586
ASCII text
downloaded
Chrome Cache Entry: 587
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 588
Web Open Font Format, TrueType, length 14648, version 1.3277
downloaded
Chrome Cache Entry: 589
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 590
Unicode text, UTF-8 text, with very long lines (41512)
dropped
Chrome Cache Entry: 591
ASCII text, with very long lines (59376)
dropped
Chrome Cache Entry: 592
ASCII text, with very long lines (2283)
downloaded
Chrome Cache Entry: 593
PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 595
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 597
ASCII text, with very long lines (14090)
downloaded
Chrome Cache Entry: 598
ASCII text, with very long lines (35304)
dropped
Chrome Cache Entry: 599
ASCII text, with very long lines (456), with no line terminators
downloaded
Chrome Cache Entry: 600
Web Open Font Format, TrueType, length 15152, version 1.3277
downloaded
Chrome Cache Entry: 601
Web Open Font Format, TrueType, length 16456, version 1.3277
downloaded
Chrome Cache Entry: 602
ASCII text, with very long lines (64938)
downloaded
Chrome Cache Entry: 603
ASCII text, with very long lines (12337)
downloaded
Chrome Cache Entry: 604
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 72x72, components 3
dropped
Chrome Cache Entry: 605
Web Open Font Format, TrueType, length 11912, version 1.3277
downloaded
Chrome Cache Entry: 606
ASCII text, with very long lines (3109)
dropped
Chrome Cache Entry: 607
ASCII text, with very long lines (62741)
downloaded
Chrome Cache Entry: 608
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 609
ASCII text, with very long lines (13112)
downloaded
Chrome Cache Entry: 610
Web Open Font Format, TrueType, length 17344, version 1.3277
downloaded
Chrome Cache Entry: 611
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 612
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 613
ASCII text, with very long lines (5178)
downloaded
Chrome Cache Entry: 614
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 615
Unicode text, UTF-8 text, with very long lines (65471)
downloaded
Chrome Cache Entry: 616
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 617
ASCII text, with very long lines (11014)
downloaded
Chrome Cache Entry: 618
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 619
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 620
ASCII text, with very long lines (7711)
downloaded
Chrome Cache Entry: 621
JSON data
downloaded
Chrome Cache Entry: 622
ASCII text, with very long lines (13140)
downloaded
Chrome Cache Entry: 623
ASCII text, with very long lines (36588)
downloaded
Chrome Cache Entry: 624
Web Open Font Format, TrueType, length 13164, version 1.3277
downloaded
Chrome Cache Entry: 625
ASCII text, with very long lines (688)
downloaded
Chrome Cache Entry: 626
ASCII text, with very long lines (6813)
downloaded
Chrome Cache Entry: 627
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 628
Web Open Font Format, TrueType, length 14892, version 1.3277
downloaded
Chrome Cache Entry: 629
ASCII text, with very long lines (911)
downloaded
Chrome Cache Entry: 630
JSON data
dropped
Chrome Cache Entry: 631
Web Open Font Format, TrueType, length 15504, version 1.3277
downloaded
Chrome Cache Entry: 632
Unicode text, UTF-8 text, with very long lines (23196)
downloaded
Chrome Cache Entry: 633
Unicode text, UTF-8 text, with very long lines (22121)
downloaded
Chrome Cache Entry: 634
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 635
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 636
ASCII text, with very long lines (45422)
downloaded
Chrome Cache Entry: 637
JSON data
dropped
Chrome Cache Entry: 638
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 639
ASCII text, with very long lines (4606)
downloaded
Chrome Cache Entry: 640
Unicode text, UTF-8 text, with very long lines (45743)
downloaded
Chrome Cache Entry: 641
ASCII text, with very long lines (5436)
downloaded
Chrome Cache Entry: 642
ASCII text, with very long lines (8692)
downloaded
Chrome Cache Entry: 643
Java source, ASCII text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 644
HTML document, ASCII text, with very long lines (56779), with CRLF line terminators
downloaded
Chrome Cache Entry: 645
Unicode text, UTF-8 text, with very long lines (5314)
dropped
Chrome Cache Entry: 646
ASCII text, with very long lines (62513)
dropped
Chrome Cache Entry: 647
Web Open Font Format, TrueType, length 17844, version 1.3277
downloaded
Chrome Cache Entry: 648
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 649
ASCII text, with very long lines (42914)
dropped
Chrome Cache Entry: 650
ASCII text, with very long lines (12139)
dropped
Chrome Cache Entry: 651
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 652
ASCII text, with very long lines (12167)
downloaded
Chrome Cache Entry: 653
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 40329
dropped
Chrome Cache Entry: 654
ASCII text, with very long lines (20803)
downloaded
Chrome Cache Entry: 656
ASCII text, with very long lines (45422)
dropped
Chrome Cache Entry: 658
ASCII text, with very long lines (6639)
downloaded
Chrome Cache Entry: 659
ASCII text, with very long lines (16727)
downloaded
Chrome Cache Entry: 661
ASCII text, with very long lines (4825)
downloaded
Chrome Cache Entry: 662
ASCII text, with very long lines (7235)
dropped
Chrome Cache Entry: 663
Web Open Font Format, TrueType, length 17436, version 1.3277
downloaded
Chrome Cache Entry: 664
ASCII text, with very long lines (7715)
downloaded
Chrome Cache Entry: 665
ASCII text, with very long lines (65461)
dropped
Chrome Cache Entry: 666
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 667
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 668
Unicode text, UTF-8 text, with very long lines (10402)
dropped
Chrome Cache Entry: 669
Java source, ASCII text
dropped
Chrome Cache Entry: 670
Java source, ASCII text
downloaded
Chrome Cache Entry: 671
ASCII text, with very long lines (30298)
downloaded
Chrome Cache Entry: 672
ASCII text, with very long lines (2626)
downloaded
Chrome Cache Entry: 673
ASCII text, with very long lines (40143)
downloaded
Chrome Cache Entry: 674
ASCII text, with very long lines (35238), with no line terminators
downloaded
Chrome Cache Entry: 675
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 676
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 677
Web Open Font Format, TrueType, length 13772, version 1.3277
downloaded
Chrome Cache Entry: 678
ASCII text, with very long lines (6813)
dropped
Chrome Cache Entry: 679
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 680
ASCII text, with very long lines (9848)
dropped
Chrome Cache Entry: 681
ASCII text, with very long lines (3467)
downloaded
Chrome Cache Entry: 682
ASCII text, with very long lines (7246)
downloaded
Chrome Cache Entry: 683
ASCII text, with very long lines (44971)
downloaded
Chrome Cache Entry: 684
ASCII text, with very long lines (11906)
downloaded
Chrome Cache Entry: 685
ASCII text, with very long lines (9456)
downloaded
Chrome Cache Entry: 686
Web Open Font Format, TrueType, length 15620, version 1.3277
downloaded
Chrome Cache Entry: 687
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 688
ASCII text, with very long lines (9848)
downloaded
Chrome Cache Entry: 689
Unicode text, UTF-8 text, with very long lines (36614)
dropped
Chrome Cache Entry: 690
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 691
ASCII text, with very long lines (34942)
downloaded
Chrome Cache Entry: 692
JSON data
downloaded
Chrome Cache Entry: 693
Unicode text, UTF-8 text, with very long lines (7518)
dropped
Chrome Cache Entry: 694
ASCII text, with very long lines (3095)
downloaded
Chrome Cache Entry: 695
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 696
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 102804
downloaded
Chrome Cache Entry: 697
Unicode text, UTF-8 text, with very long lines (10101)
downloaded
Chrome Cache Entry: 698
ASCII text, with very long lines (43609)
dropped
Chrome Cache Entry: 699
ASCII text, with very long lines (3834)
dropped
Chrome Cache Entry: 700
ASCII text, with very long lines (10633)
dropped
Chrome Cache Entry: 701
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 702
ASCII text, with very long lines (43609)
downloaded
Chrome Cache Entry: 703
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 704
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 705
ASCII text, with very long lines (44683)
downloaded
Chrome Cache Entry: 706
ASCII text, with very long lines (12337)
dropped
Chrome Cache Entry: 707
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 708
Unicode text, UTF-8 text, with very long lines (27058)
downloaded
Chrome Cache Entry: 709
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 710
ASCII text, with very long lines (12139)
downloaded
Chrome Cache Entry: 711
ASCII text, with very long lines (17016)
dropped
Chrome Cache Entry: 712
ASCII text, with very long lines (5436)
dropped
Chrome Cache Entry: 713
ASCII text, with very long lines (16804)
downloaded
Chrome Cache Entry: 714
ASCII text, with very long lines (14852)
dropped
Chrome Cache Entry: 715
Unicode text, UTF-8 text, with very long lines (10402)
downloaded
Chrome Cache Entry: 718
ASCII text, with very long lines (10191)
downloaded
Chrome Cache Entry: 719
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 720
ASCII text, with very long lines (21706)
downloaded
Chrome Cache Entry: 721
ASCII text, with very long lines (12800)
downloaded
Chrome Cache Entry: 722
Web Open Font Format, TrueType, length 12708, version 1.3277
downloaded
Chrome Cache Entry: 723
ASCII text, with very long lines (27907)
downloaded
Chrome Cache Entry: 724
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 725
ASCII text, with very long lines (4551), with no line terminators
dropped
Chrome Cache Entry: 726
C source, ASCII text, with very long lines (11334)
dropped
Chrome Cache Entry: 727
ASCII text, with very long lines (65457)
dropped
Chrome Cache Entry: 728
ASCII text, with very long lines (855)
downloaded
Chrome Cache Entry: 729
JSON data
downloaded
Chrome Cache Entry: 730
ASCII text, with very long lines (36588)
dropped
Chrome Cache Entry: 731
ASCII text, with very long lines (456), with no line terminators
dropped
Chrome Cache Entry: 732
ASCII text, with very long lines (16126)
downloaded
There are 277 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=2004,i,17339215039468375399,16465300689793914417,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://rdhomes-my.sharepoint.com/:f:/g/personal/petrina_ryandesignerhomes_com_au/EtwntXraOOdMp3Nx1zZ6gF8Bf8aWSwNn9o_57nz1-Z9h0A?e=arAOsK"
malicious
C:\Windows\SysWOW64\unarchiver.exe
"C:\Windows\SysWOW64\unarchiver.exe" "C:\Users\user\Downloads\OneDrive_2024-10-01.zip"
C:\Windows\SysWOW64\7za.exe
"C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\u1g2kedq.eh0" "C:\Users\user\Downloads\OneDrive_2024-10-01.zip"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1

URLs

Name
IP
Malicious
https://rdhomes-my.sharepoint.com/:f:/g/personal/petrina_ryandesignerhomes_com_au/EtwntXraOOdMp3Nx1zZ6gF8Bf8aWSwNn9o_57nz1-Z9h0A?e=arAOsK
malicious
https://rdhomes-my.sharepoint.com/:f:/g/personal/petrina_ryandesignerhomes_com_au/EtwntXraOOdMp3Nx1zZ6gF8Bf8aWSwNn9o_57nz1-Z9h0A?e=arAOsK
13.107.136.10
malicious
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-light.woff
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semilight.woff2
unknown
https://support.office.com/en-us/article/Manage-lists-and-libraries-with-many-items-b8588dae-9387-48
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/leelawadeeui-thai/leelawadeeui-regula
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-light.woff
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semibold.woff2
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-semibold.w
unknown
http://www.opensource.org/licenses/mit-license.php
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-bold.woff
unknown
https://tr-ooc-atm.office.com/apc/trans.gif?2b08f9d53a3bc8b8eeadf020fb4d1bbf
52.98.243.50
https://northcentralus1-medias.svc.ms
unknown
https://rdhomes-my.sharepoint.com/_layouts/15/1033/styles/error.css?rev=tF7fyfzbaQzNoASoSDlV4A%3D%3DTAG333
13.107.136.10
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-light.woff2
unknown
https://onedrive.live.com/?gologin=1
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-light.wo
unknown
https://rdhomes-my.sharepoint.com/ScriptResource.axd?d=RM75uyDL_1HzyT9ToywPpglCKODr-jurQwop5oMS0Ct9To3fnFYw3EVieBMggiyU74uzbFgSPHNe_w5tWfV7LMLy7NSy8Sa-HZdPz0B-vc2CexWwOjVVxkRSdqmTwggsPwqN4Wn19IGobSdxCHuRAcSBXTwkoLEGSIyftOW0nP2oP1hJ_-duhpMQQjPeoVCf0&t=7a0cc936
13.107.136.10
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-regular.woff2
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-light.woff2
unknown
https://df53bbda866f9adda00180748207353e.fp.measure.office.com/apc/trans.gif?2056613d49f3680555b42f2edb81ea38
13.107.18.254
https://rdhomes-my.sharepoint.com/_layouts/15/1033/styles/corev15.css?rev=m%2Fe%2BPmKMYmkX%2Fs1lVR9Uww%3D%3DTAG333
13.107.136.10
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-light.woff2
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-bold.woff
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-semibold.woff
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-semilight.
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-semibold.woff2
unknown
https://rdhomes-my.sharepoint.com/_layouts/15/spwebworkerproxy.ashx
13.107.136.10
https://rdhomes-my.sharepoint.com/_layouts/15/SPComponentRegistry.ashx?projects=[%22spfx%22]&languages=%5B%5D
13.107.136.10
https://1drv.com/
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-bold.wof
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-light.woff
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-bold.woff
unknown
https://rdhomes-my.sharepoint.com/personal/petrina_ryandesignerhomes_com_au/_layouts/15/CSPReporting.aspx
13.107.136.10
https://substrate.office.com
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-semibold
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-regular.woff
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-regular.woff2
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-bold.woff2
unknown
https://rdhomes-my.sharepoint.com/ScriptResource.axd?d=UhxNYNt_5o7-HOUFXNVapCERBXDl1SzdJ7TVVQdGC2_UlRyMZbz_tyq5n3XHL8oPM09VWzdOJi1by2ySbanlnfZssdsl8dEzCoxVmBBEUyDKaDsvJ_OpRK5fxXo92jgkO7T6142f4Buq1lbVlnMXoFJFmFIBH8yxtms1EuveTS-gkLrh5DhTv6y57DRN1JXm0&t=7a0cc936
13.107.136.10
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-regular.woff
unknown
https://onedrive.dev.cloud.microsoft
unknown
https://rdhomes-my.sharepoint.com/personal/petrina_ryandesignerhomes_com_au/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fpetrina%5Fryandesignerhomes%5Fcom%5Fau%2FDocuments%2FAcquisition%20Report%2FPayment%20Advise&ga=1
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-bold.woff2
unknown
https://www.office.com/login?prompt=select_account&ru=%2Flaunch%2Fonedrive
unknown
https://tr-ooc-atm.office.com/apc/trans.gif?51e00f218cabd44b99060e5002358d66
52.98.243.50
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-regular.
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-light.wo
unknown
https://www.office.com/login?ru=%2Flaunch%2F$
unknown
https://shellppe.msocdn.com
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-semibold.woff
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-semibold.wof
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-bold.woff2
unknown
https://australiaeast1-mediap.svc.ms/transform/zip?cs=fFNQTw
13.107.136.10
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-semiligh
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semilight.woff
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-regular.wo
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/leelawadeeui-thai/leelawadeeui-bold.w
unknown
https://microsoft.spfx3rdparty.com
unknown
https://rdhomes-my.sharepoint.com/personal/petrina_ryandesignerhomes_com_au/_layouts/15/undefined/_layouts/15/onedrive.aspx?view=1
13.107.136.10
https://reactjs.org/link/react-polyfills
unknown
https://login.microsoftonline.com
unknown
https://onedrive.live.com/sa
unknown
https://outlook.office365.com/apc/trans.gif?fb9a2c9e0d9837477e572377fccc77a4
52.98.178.226
https://onedrive.cloud.microsoft
unknown
https://shellprod.msocdn.com
unknown
https://rdhomes-my.sharepoint.com/_layouts/15/odspserviceworkerproxy.aspx?swManifestName=spserviceworker&debug=false&bypass=false&navigationPreloadHeaderValue=%7B%22supportsFeatures%22%3A%5B1855%2C61313%5D%7D&dataHost=Nucleus&applications=%5B%7B%22id%22%3A%22STS%22%2C%22swPrefetchManifestName%22%3A%22stsserviceworkerprefetch%22%7D%2C%7B%22id%22%3A%22SPHome%22%7D%2C%7B%22id%22%3A%22SitePages%22%7D%2C%7B%22id%22%3A%22Embed%22%7D%2C%7B%22id%22%3A%22CreateGroup%22%7D%2C%7B%22id%22%3A%22SingleWebPart%22%7D%2C%7B%22id%22%3A%22VivaHome%22%7D%2C%7B%22id%22%3A%22BrokerLogon%22%7D%2C%7B%22id%22%3A%22Clipchamp%22%7D%2C%7B%22id%22%3A%22MeeBridge%22%7D%2C%7B%22id%22%3A%22SPStart%22%7D%2C%7B%22id%22%3A%22Agreements%22%7D%5D&list=v2&prefetchListData=true&defaultBrotli=true&authenticateFast=true&inlineAuth=v2&wwData=true&enableTheming=true&prefetchFilebrowserPageInTeams=true&FUIV9Flights=[-83099905,3]&spStartApplicationWebBundle=true&enableIntegrities=true&streamViewServerLoad=true&streamInlineScript=true
13.107.136.10
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-regular.woff2
unknown
https://www.office.com/login?prompt=select_account&ru=%2Flaunch%2F$
unknown
https://centralus1-mediad.svc.ms
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-semilight.wo
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-regular.woff
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-semibold.woff2
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-bold.woff2
unknown
https://portal.office.com/
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-bold.woff
unknown
https://rdhomes-my.sharepoint.com/_layouts/15/images/odbfavicon.ico?rev=47
13.107.136.10
https://clients.config.office.net/user/v1.0/web/policies
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-light.woff
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-semilight.woff
unknown
https://outlook.office365.com/apc/trans.gif?6266b47f5d4f7c5029fc76391e8ad3b4
52.98.178.226
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-semilight.woff
unknown
http://fb.me/use-check-prop-types
unknown
https://spoprod-a.akamaihd.net/files/odsp-common-library-prod_2019-02-15_20190219.002/require.js
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-light.woff
unknown
https://rdhomes-my.sharepoint.com/WebResource.axd?d=BCu1gpTsV1AN-0NglPD8LdIdsuUyLJN9GzPvdz8u3hKjsxegdY033hpynTH4RBUGPpvOvu1taVmJZIpI3UDKZXIBPlGpx8EoA5-3Uy221o01&t=638588829843638381
13.107.136.10
https://df53bbda866f9adda00180748207353e.fp.measure.office.com/apc/trans.gif?649a4e95f7bceeb22c56993e172709bb
13.107.18.254
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-light.woff2
unknown
https://livefilestore.com/
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-regular.woff
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-bold.wof
unknown
https://messaging-int.msonerm.com/
unknown
https://qE5vHYe.tathyslam.com/Qt2rOX3/
unknown
http://www.contoso.com
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-regular.
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-semibold
unknown
https://rdhomes-my.sharepoint.com/personal/petrina_ryandesignerhomes_com_au/_api/v2.1/graphql
13.107.136.10
https://rdhomes-my.sharepoint.com/personal/petrina_ryandesignerhomes_com_au/_layouts/15/AccessDenied.aspx?correlation=dd9b55a1%2D90aa%2D3000%2Dd75a%2D064be18980e4
13.107.136.10
https://static2.sharepointonline.com/files/fabric/assets/fonts/leelawadeeui-thai/leelawadeeui-semili
unknown
https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-bold.woff2
unknown
https://www.office.com/login?ru=%2Flaunch%2Fonedrive
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
dual-spo-0005.spo-msedge.net
13.107.136.10
k-9999.k-msedge.net
13.107.18.254
196391-ipv4v6.farm.dprodmgd106.aa-rt.sharepoint.com
52.105.235.41
mira-ooc.tm-4.office.com
52.98.243.50
www.google.com
142.250.186.36
FRA-efz.ms-acdc.office.com
52.98.178.226
fp2e7a.wpc.phicdn.net
192.229.221.95
df53bbda866f9adda00180748207353e.fp.measure.office.com
unknown
rdhomes-my.sharepoint.com
unknown
r4.res.office365.com
unknown
australiaeast1-mediap.svc.ms
unknown
upload.fp.measure.office.com
unknown
config.fp.measure.office.com
unknown
m365cdn.nel.measure.office.net
unknown
rdhomes.sharepoint.com
unknown
tr-ooc-atm.office.com
unknown
outlook.office365.com
unknown
spo.nel.measure.office.net
unknown
There are 9 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
52.98.179.210
unknown
United States
13.107.136.10
dual-spo-0005.spo-msedge.net
United States
52.105.235.41
196391-ipv4v6.farm.dprodmgd106.aa-rt.sharepoint.com
United States
192.168.2.4
unknown
unknown
52.98.243.50
mira-ooc.tm-4.office.com
United States
142.250.186.36
www.google.com
United States
239.255.255.250
unknown
Reserved
52.98.178.226
FRA-efz.ms-acdc.office.com
United States
13.107.18.254
k-9999.k-msedge.net
United States
40.99.157.18
unknown
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
137D000
stack
page read and write
358A000
trusted library allocation
page read and write
12FB000
stack
page read and write
16BA000
trusted library allocation
page execute and read and write
900000
heap
page read and write
12F6000
stack
page read and write
59DE000
stack
page read and write
359A000
trusted library allocation
page read and write
16BC000
trusted library allocation
page execute and read and write
13BD000
heap
page read and write
35AB000
trusted library allocation
page read and write
910000
heap
page read and write
16F7000
trusted library allocation
page execute and read and write
16DA000
trusted library allocation
page execute and read and write
DB0000
heap
page read and write
138E000
heap
page read and write
1750000
heap
page read and write
1AF0000
heap
page read and write
C3E000
stack
page read and write
DB5000
heap
page read and write
1380000
heap
page read and write
167F000
stack
page read and write
1940000
trusted library allocation
page read and write
DF0000
heap
page read and write
12F9000
stack
page read and write
35A0000
trusted library allocation
page read and write
D80000
heap
page read and write
D3F000
stack
page read and write
558E000
stack
page read and write
14A0000
heap
page read and write
358C000
trusted library allocation
page read and write
16E0000
heap
page read and write
138B000
heap
page read and write
35B3000
trusted library allocation
page read and write
16B2000
trusted library allocation
page execute and read and write
173E000
stack
page read and write
16AA000
trusted library allocation
page execute and read and write
187F000
stack
page read and write
3580000
trusted library allocation
page read and write
16B0000
trusted library allocation
page read and write
1690000
trusted library allocation
page read and write
1950000
heap
page execute and read and write
FEE000
stack
page read and write
8F0000
heap
page read and write
73C000
stack
page read and write
83D000
stack
page read and write
320F000
stack
page read and write
5C1E000
stack
page read and write
14A5000
heap
page read and write
35AD000
trusted library allocation
page read and write
16D2000
trusted library allocation
page execute and read and write
5ADE000
stack
page read and write
585D000
stack
page read and write
35C0000
trusted library allocation
page read and write
D7E000
stack
page read and write
35B0000
trusted library allocation
page read and write
1770000
heap
page read and write
599D000
stack
page read and write
FD0000
heap
page read and write
5690000
trusted library allocation
page execute and read and write
4551000
trusted library allocation
page read and write
568E000
stack
page read and write
FE0000
heap
page read and write
16F0000
trusted library allocation
page read and write
35B8000
trusted library allocation
page read and write
16FB000
trusted library allocation
page execute and read and write
589E000
stack
page read and write
7F1B0000
trusted library allocation
page execute and read and write
2790000
heap
page read and write
16A2000
trusted library allocation
page execute and read and write
F6C000
stack
page read and write
5B1E000
stack
page read and write
3551000
trusted library allocation
page read and write
D90000
trusted library allocation
page read and write
35BC000
trusted library allocation
page read and write
DF8000
heap
page read and write
35A5000
trusted library allocation
page read and write
13A7000
heap
page read and write
133E000
stack
page read and write
575D000
stack
page read and write
There are 70 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
https://rdhomes-my.sharepoint.com/personal/petrina_ryandesignerhomes_com_au/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fpetrina%5Fryandesignerhomes%5Fcom%5Fau%2FDocuments%2FAcquisition%20Report%2FPayment%20Advise&ga=1
https://rdhomes-my.sharepoint.com/personal/petrina_ryandesignerhomes_com_au/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fpetrina%5Fryandesignerhomes%5Fcom%5Fau%2FDocuments%2FAcquisition%20Report%2FPayment%20Advise&ga=1
https://rdhomes-my.sharepoint.com/personal/petrina_ryandesignerhomes_com_au/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fpetrina%5Fryandesignerhomes%5Fcom%5Fau%2FDocuments%2FAcquisition%20Report%2FPayment%20Advise&ga=1
https://rdhomes-my.sharepoint.com/personal/petrina_ryandesignerhomes_com_au/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fpetrina%5Fryandesignerhomes%5Fcom%5Fau%2FDocuments%2FAcquisition%20Report%2FPayment%20Advise&ga=1