Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://we.tl/t-BVtGtb0HLz

Overview

General Information

Sample URL:https://we.tl/t-BVtGtb0HLz
Analysis ID:1528874

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected landing page (webpage, office document or email)
Phishing site detected (based on favicon image match)
Phishing site or detected (based on various text indicators)
Detected non-DNS traffic on DNS port
HTML page contains hidden javascript code
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6840 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 7052 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1924,i,6867516786048380989,2074778571567150778,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 7480 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5660 --field-trial-handle=1924,i,6867516786048380989,2074778571567150778,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6592 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://we.tl/t-BVtGtb0HLz" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: file:///C:/Users/user/Downloads/INDUSTRIAL%20CONNECTORS%20-%20COUPLINGS%20-%20DATA%20SHEET.pdfMatcher: Template: wetransfer matched with high similarity
Source: Chrome DOM: 0.9OCR Text: INDUSTRIAL CONNECTORS - COUPLINGS - DATA SHEET.pdf 1 Welcome to Microsoft privacy share point verification DOWNLOADS AREO DOCUMENT VIEW SHARED DOCUMENT Save your files and photos to OneDrive and get them from any device, anywhere
Source: https://wetransfer.com/downloads/f683cf602bf7ad0cbbb1d17af304e6e720241007131436/6732a7?t_exp=1728566076&t_lsid=63f04c2c-67b9-487a-8e60-0689842b0750&t_s=download_link&t_ts=1728306876HTTP Parser: Base64 decoded: <svg xmlns="http://www.w3.org/2000/svg" width="10" height="9" fill="none"><path fill="#fff" d="M3.448 8.706a1.023 1.023 0 0 0 1.558-.147l4.812-6.956A1.022 1.022 0 1 0 8.136.441l-4.12 5.955L1.74 4.157A1.023 1.023 0 0 0 .305 5.614l3.143 3.092Z"/></svg>
Source: https://wetransfer.com/downloads/f683cf602bf7ad0cbbb1d17af304e6e720241007131436/6732a7?t_exp=1728566076&t_lsid=63f04c2c-67b9-487a-8e60-0689842b0750&t_s=download_link&t_ts=1728306876HTTP Parser: No favicon
Source: https://wetransfer.com/downloads/f683cf602bf7ad0cbbb1d17af304e6e720241007131436/6732a7?t_exp=1728566076&t_lsid=63f04c2c-67b9-487a-8e60-0689842b0750&t_s=download_link&t_ts=1728306876HTTP Parser: No favicon
Source: https://wetransfer.com/downloads/f683cf602bf7ad0cbbb1d17af304e6e720241007131436/6732a7?t_exp=1728566076&t_lsid=63f04c2c-67b9-487a-8e60-0689842b0750&t_s=download_link&t_ts=1728306876HTTP Parser: No favicon
Source: https://wetransfer.com/downloads/f683cf602bf7ad0cbbb1d17af304e6e720241007131436/6732a7?t_exp=1728566076&t_lsid=63f04c2c-67b9-487a-8e60-0689842b0750&t_s=download_link&t_ts=1728306876HTTP Parser: No favicon
Source: https://wetransfer.com/downloads/f683cf602bf7ad0cbbb1d17af304e6e720241007131436/6732a7?t_exp=1728566076&t_lsid=63f04c2c-67b9-487a-8e60-0689842b0750&t_s=download_link&t_ts=1728306876HTTP Parser: No favicon
Source: https://wetransfer.com/downloads/f683cf602bf7ad0cbbb1d17af304e6e720241007131436/6732a7?t_exp=1728566076&t_lsid=63f04c2c-67b9-487a-8e60-0689842b0750&t_s=download_link&t_ts=1728306876HTTP Parser: No favicon
Source: https://wetransfer.com/downloads/f683cf602bf7ad0cbbb1d17af304e6e720241007131436/6732a7?t_exp=1728566076&t_lsid=63f04c2c-67b9-487a-8e60-0689842b0750&t_s=download_link&t_ts=1728306876HTTP Parser: No favicon
Source: file:///C:/Users/user/Downloads/INDUSTRIAL%20CONNECTORS%20-%20COUPLINGS%20-%20DATA%20SHEET.pdfHTTP Parser: No favicon
Source: file:///C:/Users/user/Downloads/INDUSTRIAL%20CONNECTORS%20-%20COUPLINGS%20-%20DATA%20SHEET.pdfHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:49782 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:57132 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.16:57127 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:57127 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:57127 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:57127 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63758 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:57127 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63758 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:57127 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63758 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:57127 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:63758 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.16:57127 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: we.tl
Source: global trafficDNS traffic detected: DNS query: wetransfer.com
Source: global trafficDNS traffic detected: DNS query: cdn.wetransfer.com
Source: global trafficDNS traffic detected: DNS query: cdn.jsdelivr.net
Source: global trafficDNS traffic detected: DNS query: tagging.wetransfer.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: ekstrom.wetransfer.net
Source: global trafficDNS traffic detected: DNS query: auth-session-caching.wetransfer.net
Source: global trafficDNS traffic detected: DNS query: privacy.wetransfer.com
Source: global trafficDNS traffic detected: DNS query: bsp-proxy.wetransfer.net
Source: global trafficDNS traffic detected: DNS query: experiments.wetransfer.com
Source: global trafficDNS traffic detected: DNS query: analytics-v2.wetransfer.com
Source: global trafficDNS traffic detected: DNS query: connect.facebook.net
Source: global trafficDNS traffic detected: DNS query: s.pinimg.com
Source: global trafficDNS traffic detected: DNS query: js.adsrvr.org
Source: global trafficDNS traffic detected: DNS query: c.amazon-adsystem.com
Source: global trafficDNS traffic detected: DNS query: snowplow.wetransfer.com
Source: global trafficDNS traffic detected: DNS query: s.amazon-adsystem.com
Source: global trafficDNS traffic detected: DNS query: api.pico.bendingspoonsapps.com
Source: global trafficDNS traffic detected: DNS query: googleads.g.doubleclick.net
Source: global trafficDNS traffic detected: DNS query: e-10220.adzerk.net
Source: global trafficDNS traffic detected: DNS query: ara.paa-reporting-advertising.amazon
Source: global trafficDNS traffic detected: DNS query: insight.adsrvr.org
Source: global trafficDNS traffic detected: DNS query: nolan.wetransfer.net
Source: global trafficDNS traffic detected: DNS query: match.adsrvr.org
Source: global trafficDNS traffic detected: DNS query: di.rlcdn.com
Source: global trafficDNS traffic detected: DNS query: public.profitwell.com
Source: global trafficDNS traffic detected: DNS query: ct.pinterest.com
Source: global trafficDNS traffic detected: DNS query: cm.g.doubleclick.net
Source: global trafficDNS traffic detected: DNS query: pixel.rubiconproject.com
Source: global trafficDNS traffic detected: DNS query: ib.adnxs.com
Source: global trafficDNS traffic detected: DNS query: www.facebook.com
Source: global trafficDNS traffic detected: DNS query: download.wetransfer.com
Source: global trafficDNS traffic detected: DNS query: doc-datafiles2891673526uayte6453-pubdoc.pages.dev
Source: global trafficDNS traffic detected: DNS query: www.w3schools.com
Source: global trafficDNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
Source: unknownNetwork traffic detected: HTTP traffic on port 57141 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49862
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49861
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
Source: unknownNetwork traffic detected: HTTP traffic on port 49932 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49898 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57129
Source: unknownNetwork traffic detected: HTTP traffic on port 57129 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57133
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57134
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57135
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57136
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57130
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57131
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57132
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49859
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57137
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57138
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57139
Source: unknownNetwork traffic detected: HTTP traffic on port 49909 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57141
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57142
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49943 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
Source: unknownNetwork traffic detected: HTTP traffic on port 49886 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49960
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 57130 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49933 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49959
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49958
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
Source: unknownNetwork traffic detected: HTTP traffic on port 49921 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49957
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49956
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49955
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
Source: unknownNetwork traffic detected: HTTP traffic on port 49887 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49954
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49953
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49952
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49951
Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49950
Source: unknownNetwork traffic detected: HTTP traffic on port 49944 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49910 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49955 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49949
Source: unknownNetwork traffic detected: HTTP traffic on port 63761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49948
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49947
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49946
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49945
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49944
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49943
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 49922 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49945 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 57139 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 49885 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49899
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49898
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49897
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49896
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49895
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49894
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49893
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49892
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49891
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49890
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49897 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49911 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49957 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49889
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49888
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49887
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49886
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49885
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49884
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49883
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49882
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49881
Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49880
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49956 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49879
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49878
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49877
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49876
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49875
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49874
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49873
Source: unknownNetwork traffic detected: HTTP traffic on port 49923 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49872
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49871
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49870
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49934 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49869
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49868
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49867
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 63764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63760
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63762
Source: unknownNetwork traffic detected: HTTP traffic on port 49906 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63761
Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63763
Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 57138 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49929 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49861 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49918 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49873 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49930 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 49952 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 49895 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49907 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49941 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49871 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49894 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49942 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 57136 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49919 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49954 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49882 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49953 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49908 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49883 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49931 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49920 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 57137 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49926 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49949 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49881 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49950 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49893 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49915 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 57135 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49904 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49927 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49938 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49951 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49916 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49939 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49905 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49940 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 57134 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49891 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49917 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49890 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49878 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49912 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49935 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49958 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 57132 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49889 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49866 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49946 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49901 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49924 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49947 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49856 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49913 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49867 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 57133 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49942
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
Source: unknownNetwork traffic detected: HTTP traffic on port 49842 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49941
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49940
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49939
Source: unknownNetwork traffic detected: HTTP traffic on port 63760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49938
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49937
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49936
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49935
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 49902 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49934
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49933
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49932
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49931
Source: unknownNetwork traffic detected: HTTP traffic on port 57142 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49930
Source: unknownNetwork traffic detected: HTTP traffic on port 49925 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49936 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49876 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49960 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49929
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49928
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49927
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49926
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49925
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49924
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49923
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49922
Source: unknownNetwork traffic detected: HTTP traffic on port 57131 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49921
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49920
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49877 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49914 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49919
Source: unknownNetwork traffic detected: HTTP traffic on port 49937 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49918
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49917
Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49916
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49915
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49914
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49913
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49912
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49911
Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:49782 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.16:57132 version: TLS 1.2
Source: classification engineClassification label: mal52.phis.win@37/8@128/492
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1924,i,6867516786048380989,2074778571567150778,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://we.tl/t-BVtGtb0HLz"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1924,i,6867516786048380989,2074778571567150778,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5660 --field-trial-handle=1924,i,6867516786048380989,2074778571567150778,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5660 --field-trial-handle=1924,i,6867516786048380989,2074778571567150778,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected

Persistence and Installation Behavior

barindex
Source: file:///C:/Users/user/Downloads/INDUSTRIAL%20CONNECTORS%20-%20COUPLINGS%20-%20DATA%20SHEET.pdfLLM: Page contains button: 'DOWNLOAD SHARED DOCUMENT' Source: '0.8.pages.csv'
Source: file:///C:/Users/user/Downloads/INDUSTRIAL%20CONNECTORS%20-%20COUPLINGS%20-%20DATA%20SHEET.pdfLLM: Page contains button: 'DOWNLOAD SHARED DOCUMENT' Source: '0.9.pages.csv'
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Registry Run Keys / Startup Folder
1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
www.google.com0%VirustotalBrowse
wetransfer.com0%VirustotalBrowse
tagging.wetransfer.com0%VirustotalBrowse
cdn.wetransfer.com0%VirustotalBrowse
we.tl0%VirustotalBrowse
cdn.jsdelivr.net0%VirustotalBrowse
ekstrom.wetransfer.net0%VirustotalBrowse
auth-session-caching.wetransfer.net0%VirustotalBrowse
sp-20200324121949090600000008-54648268.eu-west-1.elb.amazonaws.com0%VirustotalBrowse
cm.g.doubleclick.net0%VirustotalBrowse
wetransfer.fides-cdn.ethyca.com0%VirustotalBrowse
bsp-proxy.wetransfer.net0%VirustotalBrowse
dg2iu7dxxehbo.cloudfront.net0%VirustotalBrowse
star-mini.c10r.facebook.com0%VirustotalBrowse
insight.adsrvr.org0%VirustotalBrowse
scontent.xx.fbcdn.net0%VirustotalBrowse
ara.paa-reporting-advertising.amazon0%VirustotalBrowse
match.adsrvr.org0%VirustotalBrowse
ax-0001.ax-dc-msedge.net0%VirustotalBrowse
s.amazon-adsystem.com0%VirustotalBrowse
api.pico.bendingspoonsapps.com0%VirustotalBrowse
prod.pinterest.global.map.fastly.net0%VirustotalBrowse
dna8twue3dlxq.cloudfront.net0%VirustotalBrowse
ax-0001.ax-msedge.net1%VirustotalBrowse
googleads.g.doubleclick.net0%VirustotalBrowse
d1ykf07e75w7ss.cloudfront.net0%VirustotalBrowse
analytics-v2.wetransfer.com0%VirustotalBrowse
ib.anycast.adnxs.com1%VirustotalBrowse
nolan.wetransfer.net0%VirustotalBrowse
snowplow.wetransfer.com0%VirustotalBrowse
experiments.wetransfer.com0%VirustotalBrowse
e-prod-alb-s105-us-east-1-01.adzerk.net0%VirustotalBrowse
ct.pinterest.com0%VirustotalBrowse
dualstack.pinterest.map.fastly.net0%VirustotalBrowse
www.facebook.com0%VirustotalBrowse
di.rlcdn.com0%VirustotalBrowse
c.amazon-adsystem.com0%VirustotalBrowse
connect.facebook.net0%VirustotalBrowse
js.adsrvr.org0%VirustotalBrowse
privacy.wetransfer.com0%VirustotalBrowse
s.pinimg.com0%VirustotalBrowse
pixel.rubiconproject.com0%VirustotalBrowse
ib.adnxs.com0%VirustotalBrowse
e-10220.adzerk.net0%VirustotalBrowse
public.profitwell.com0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
sp-20200324121949090600000008-54648268.eu-west-1.elb.amazonaws.com
52.30.139.70
truefalseunknown
cs837.wac.edgecastcdn.net
192.229.133.221
truefalse
    unknown
    dg2iu7dxxehbo.cloudfront.net
    18.239.67.100
    truefalseunknown
    insight.adsrvr.org
    3.33.220.150
    truefalseunknown
    scontent.xx.fbcdn.net
    157.240.253.1
    truefalseunknown
    cdnjs.cloudflare.com
    104.17.25.14
    truefalse
      unknown
      cm.g.doubleclick.net
      172.217.16.194
      truefalseunknown
      www.google.com
      172.217.23.100
      truefalseunknown
      ara.paa-reporting-advertising.amazon
      108.138.192.119
      truefalseunknown
      wetransfer.fides-cdn.ethyca.com
      18.245.86.79
      truefalseunknown
      bsp-proxy.wetransfer.net
      52.17.56.161
      truefalseunknown
      match.adsrvr.org
      52.223.40.198
      truefalseunknown
      doc-datafiles2891673526uayte6453-pubdoc.pages.dev
      188.114.97.3
      truefalse
        unknown
        star-mini.c10r.facebook.com
        157.240.253.35
        truefalseunknown
        a.nel.cloudflare.com
        35.190.80.1
        truefalse
          unknown
          we.tl
          18.66.147.15
          truefalseunknown
          ax-0001.ax-dc-msedge.net
          150.171.29.10
          truefalseunknown
          s.amazon-adsystem.com
          98.82.156.207
          truefalseunknown
          e-prod-alb-s105-us-east-1-01.adzerk.net
          52.203.206.228
          truefalseunknown
          dna8twue3dlxq.cloudfront.net
          18.66.196.119
          truefalseunknown
          api.pico.bendingspoonsapps.com
          34.102.204.67
          truefalseunknown
          ax-0001.ax-msedge.net
          150.171.27.10
          truefalseunknown
          d1ykf07e75w7ss.cloudfront.net
          108.138.190.150
          truefalseunknown
          download.wetransfer.com
          18.245.60.93
          truefalse
            unknown
            analytics-v2.wetransfer.com
            13.32.27.54
            truefalseunknown
            prod.pinterest.global.map.fastly.net
            151.101.192.84
            truefalseunknown
            di.rlcdn.com
            35.244.174.68
            truefalseunknown
            googleads.g.doubleclick.net
            142.250.186.162
            truefalseunknown
            dualstack.pinterest.map.fastly.net
            151.101.0.84
            truefalseunknown
            cdn.wetransfer.com
            143.204.98.97
            truefalseunknown
            ekstrom.wetransfer.net
            34.247.65.7
            truefalseunknown
            wetransfer.com
            143.204.98.51
            truefalseunknown
            auth-session-caching.wetransfer.net
            34.247.65.7
            truefalseunknown
            experiments.wetransfer.com
            13.33.187.87
            truefalseunknown
            tagging.wetransfer.com
            18.245.46.95
            truefalseunknown
            ib.anycast.adnxs.com
            185.89.210.122
            truefalseunknown
            nolan.wetransfer.net
            13.224.189.11
            truefalseunknown
            cdn.jsdelivr.net
            unknown
            unknownfalseunknown
            snowplow.wetransfer.com
            unknown
            unknownfalseunknown
            ct.pinterest.com
            unknown
            unknownfalseunknown
            www.w3schools.com
            unknown
            unknownfalse
              unknown
              www.facebook.com
              unknown
              unknownfalseunknown
              js.adsrvr.org
              unknown
              unknownfalseunknown
              c.amazon-adsystem.com
              unknown
              unknownfalseunknown
              privacy.wetransfer.com
              unknown
              unknownfalseunknown
              pixel.rubiconproject.com
              unknown
              unknownfalseunknown
              connect.facebook.net
              unknown
              unknownfalseunknown
              public.profitwell.com
              unknown
              unknownfalseunknown
              s.pinimg.com
              unknown
              unknownfalseunknown
              ib.adnxs.com
              unknown
              unknownfalseunknown
              e-10220.adzerk.net
              unknown
              unknownfalseunknown
              NameMaliciousAntivirus DetectionReputation
              file:///C:/Users/user/Downloads/INDUSTRIAL%20CONNECTORS%20-%20COUPLINGS%20-%20DATA%20SHEET.pdftrue
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                151.101.0.84
                dualstack.pinterest.map.fastly.netUnited States
                54113FASTLYUSfalse
                108.138.192.119
                ara.paa-reporting-advertising.amazonUnited States
                16509AMAZON-02USfalse
                104.18.187.31
                unknownUnited States
                13335CLOUDFLARENETUSfalse
                13.32.27.54
                analytics-v2.wetransfer.comUnited States
                7018ATT-INTERNET4USfalse
                18.245.86.118
                unknownUnited States
                16509AMAZON-02USfalse
                108.138.190.150
                d1ykf07e75w7ss.cloudfront.netUnited States
                16509AMAZON-02USfalse
                13.224.189.11
                nolan.wetransfer.netUnited States
                16509AMAZON-02USfalse
                98.82.156.207
                s.amazon-adsystem.comUnited States
                11351TWC-11351-NORTHEASTUSfalse
                151.101.128.84
                unknownUnited States
                54113FASTLYUSfalse
                142.251.168.84
                unknownUnited States
                15169GOOGLEUSfalse
                34.102.204.67
                api.pico.bendingspoonsapps.comUnited States
                15169GOOGLEUSfalse
                52.30.139.70
                sp-20200324121949090600000008-54648268.eu-west-1.elb.amazonaws.comUnited States
                16509AMAZON-02USfalse
                18.204.39.54
                unknownUnited States
                14618AMAZON-AESUSfalse
                143.204.98.97
                cdn.wetransfer.comUnited States
                16509AMAZON-02USfalse
                143.204.98.51
                wetransfer.comUnited States
                16509AMAZON-02USfalse
                35.190.80.1
                a.nel.cloudflare.comUnited States
                15169GOOGLEUSfalse
                13.32.27.128
                unknownUnited States
                7018ATT-INTERNET4USfalse
                69.173.144.165
                unknownUnited States
                26667RUBICONPROJECTUSfalse
                142.250.185.67
                unknownUnited States
                15169GOOGLEUSfalse
                3.33.220.150
                insight.adsrvr.orgUnited States
                8987AMAZONEXPANSIONGBfalse
                34.104.35.123
                unknownUnited States
                15169GOOGLEUSfalse
                1.1.1.1
                unknownAustralia
                13335CLOUDFLARENETUSfalse
                104.18.186.31
                unknownUnited States
                13335CLOUDFLARENETUSfalse
                185.89.210.122
                ib.anycast.adnxs.comGermany
                29990ASN-APPNEXUSfalse
                108.138.192.103
                unknownUnited States
                16509AMAZON-02USfalse
                54.155.48.237
                unknownUnited States
                16509AMAZON-02USfalse
                239.255.255.250
                unknownReserved
                unknownunknownfalse
                188.114.97.3
                doc-datafiles2891673526uayte6453-pubdoc.pages.devEuropean Union
                13335CLOUDFLARENETUSfalse
                150.171.29.10
                ax-0001.ax-dc-msedge.netUnited States
                8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                172.217.23.100
                www.google.comUnited States
                15169GOOGLEUSfalse
                35.244.174.68
                di.rlcdn.comUnited States
                15169GOOGLEUSfalse
                172.217.16.194
                cm.g.doubleclick.netUnited States
                15169GOOGLEUSfalse
                157.240.253.35
                star-mini.c10r.facebook.comUnited States
                32934FACEBOOKUSfalse
                108.157.188.91
                unknownUnited States
                16509AMAZON-02USfalse
                52.223.40.198
                match.adsrvr.orgUnited States
                8987AMAZONEXPANSIONGBfalse
                18.245.46.38
                unknownUnited States
                16509AMAZON-02USfalse
                151.101.192.84
                prod.pinterest.global.map.fastly.netUnited States
                54113FASTLYUSfalse
                104.17.25.14
                cdnjs.cloudflare.comUnited States
                13335CLOUDFLARENETUSfalse
                18.245.60.93
                download.wetransfer.comUnited States
                16509AMAZON-02USfalse
                18.239.67.100
                dg2iu7dxxehbo.cloudfront.netUnited States
                16509AMAZON-02USfalse
                18.172.103.101
                unknownUnited States
                3MIT-GATEWAYSUSfalse
                34.247.65.7
                ekstrom.wetransfer.netUnited States
                16509AMAZON-02USfalse
                52.48.170.216
                unknownUnited States
                16509AMAZON-02USfalse
                13.33.187.87
                experiments.wetransfer.comUnited States
                16509AMAZON-02USfalse
                98.82.157.231
                unknownUnited States
                11351TWC-11351-NORTHEASTUSfalse
                18.244.140.9
                unknownUnited States
                16509AMAZON-02USfalse
                142.250.186.131
                unknownUnited States
                15169GOOGLEUSfalse
                142.250.184.206
                unknownUnited States
                15169GOOGLEUSfalse
                172.217.18.10
                unknownUnited States
                15169GOOGLEUSfalse
                52.203.206.228
                e-prod-alb-s105-us-east-1-01.adzerk.netUnited States
                14618AMAZON-AESUSfalse
                157.240.252.35
                unknownUnited States
                32934FACEBOOKUSfalse
                18.66.147.15
                we.tlUnited States
                3MIT-GATEWAYSUSfalse
                142.250.184.202
                unknownUnited States
                15169GOOGLEUSfalse
                13.224.186.120
                unknownUnited States
                16509AMAZON-02USfalse
                18.66.196.119
                dna8twue3dlxq.cloudfront.netUnited States
                3MIT-GATEWAYSUSfalse
                142.250.186.162
                googleads.g.doubleclick.netUnited States
                15169GOOGLEUSfalse
                52.17.56.161
                bsp-proxy.wetransfer.netUnited States
                16509AMAZON-02USfalse
                108.159.227.117
                unknownUnited States
                16509AMAZON-02USfalse
                192.229.133.221
                cs837.wac.edgecastcdn.netUnited States
                15133EDGECASTUSfalse
                150.171.27.10
                ax-0001.ax-msedge.netUnited States
                8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                157.240.251.9
                unknownUnited States
                32934FACEBOOKUSfalse
                142.250.181.226
                unknownUnited States
                15169GOOGLEUSfalse
                18.245.46.95
                tagging.wetransfer.comUnited States
                16509AMAZON-02USfalse
                18.245.46.51
                unknownUnited States
                16509AMAZON-02USfalse
                143.204.98.85
                unknownUnited States
                16509AMAZON-02USfalse
                157.240.253.1
                scontent.xx.fbcdn.netUnited States
                32934FACEBOOKUSfalse
                142.250.181.228
                unknownUnited States
                15169GOOGLEUSfalse
                13.32.121.58
                unknownUnited States
                16509AMAZON-02USfalse
                18.245.86.79
                wetransfer.fides-cdn.ethyca.comUnited States
                16509AMAZON-02USfalse
                18.245.46.98
                unknownUnited States
                16509AMAZON-02USfalse
                142.250.186.66
                unknownUnited States
                15169GOOGLEUSfalse
                IP
                192.168.2.16
                Joe Sandbox version:41.0.0 Charoite
                Analysis ID:1528874
                Start date and time:2024-10-08 11:14:58 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:defaultwindowsinteractivecookbook.jbs
                Sample URL:https://we.tl/t-BVtGtb0HLz
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:15
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • EGA enabled
                Analysis Mode:stream
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal52.phis.win@37/8@128/492
                • Exclude process from analysis (whitelisted): svchost.exe
                • Excluded IPs from analysis (whitelisted): 142.250.186.131, 142.250.184.206, 142.251.168.84, 34.104.35.123, 88.221.110.91, 104.18.186.31, 104.18.187.31, 184.28.90.27
                • Excluded domains from analysis (whitelisted): cdn.jsdelivr.net.cdn.cloudflare.net, clients2.google.com, fs.microsoft.com, accounts.google.com, edgedl.me.gvt1.com, e16604.g.akamaiedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net
                • Not all processes where analyzed, report is missing behavior information
                InputOutput
                URL: https://wetransfer.com/downloads/f683cf602bf7ad0cbbb1d17af304e6e720241007131436/6732a7?t_exp=1728566076&t_lsid=63f04c2c-67b9-487a-8e60-0689842b0750&t_s=download_link&t_ts=1728306876 Model: jbxai
                {
                "brand":["WeTransfer"],
                "contains_trigger_text":true,
                "trigger_text":"Ready when you are",
                "prominent_button_name":"Download",
                "text_input_field_labels":"unknown",
                "pdf_icon_visible":false,
                "has_visible_captcha":false,
                "has_urgent_text":false,
                "text":"Transfer expires in 2 days",
                "has_visible_qrcode":false}
                URL: https://wetransfer.com/downloads/f683cf602bf7ad0cbbb1d17af304e6e720241007131436/6732a7?t_exp=1728566076&t_lsid=63f04c2c-67b9-487a-8e60-0689842b0750&t_s=download_link&t_ts=1728306876 Model: jbxai
                {
                "brand":["We"],
                "contains_trigger_text":false,
                "trigger_text":"",
                "prominent_button_name":"I agree",
                "text_input_field_labels":"unknown",
                "pdf_icon_visible":false,
                "has_visible_captcha":false,
                "has_urgent_text":false,
                "text":"You're almost there To continue,
                 please agree to our Terms of Service,
                 and acknowledge our Privacy Policy. I agree",
                "has_visible_qrcode":false}
                URL: https://wetransfer.com/downloads/f683cf602bf7ad0cbbb1d17af304e6e720241007131436/6732a7?t_exp=1728566076&t_lsid=63f04c2c-67b9-487a-8e60-0689842b0750&t_s=download_link&t_ts=1728306876 Model: jbxai
                {
                "brand":["Wepresent"],
                "contains_trigger_text":false,
                "trigger_text":"",
                "prominent_button_name":"Download",
                "text_input_field_labels":"unknown",
                "pdf_icon_visible":false,
                "has_visible_captcha":false,
                "has_urgent_text":false,
                "text":"Ready when you are Transfer expires in 2 days INDUSTRIAL CONNECTORS - COUPLINGS - DATA SHEET.pdf INDUSTRIAL CONNECTORS - C Download We use cookies and similar methods to recognize visitors and remember their preferences. We may also use them to measure ad campaign effectiveness,
                 target ads,
                 and analyze site traffic. Depending on your location,
                 you may opt-in or opt out of the use of these technologies.Manage preferences",
                "has_visible_qrcode":false}
                URL: https://wetransfer.com/downloads/f683cf602bf7ad0cbbb1d17af304e6e720241007131436/6732a7?t_exp=1728566076&t_lsid=63f04c2c-67b9-487a-8e60-0689842b0750&t_s=download_link&t_ts=1728306876 Model: jbxai
                {
                "brand":["Wepresent"],
                "contains_trigger_text":false,
                "trigger_text":"",
                "prominent_button_name":"Download",
                "text_input_field_labels":"unknown",
                "pdf_icon_visible":false,
                "has_visible_captcha":false,
                "has_urgent_text":false,
                "text":"Ready when you are Transfer expires in 2 days INDUSTRIAL CONNECTORS - COUPLINGS - DATA SHEET.pdf INDUSTRIAL CONNECTORS - C Download We use cookies and similar methods to recognize visitors and remember their preferences. We may also use them to measure ad campaign effectiveness,
                 target ads,
                 and analyze site traffic. Depending on your location,
                 you may opt-in or opt out of the use of these technologies.Manage preferences",
                "has_visible_qrcode":false}
                URL: file:///C:/Users/user/Downloads/INDUSTRIAL%20CONNECTORS%20-%20COUPLINGS%20-%20DATA%20SHEET.pdf Model: jbxai
                {
                "brand":["Microsoft"],
                "contains_trigger_text":true,
                "trigger_text":"Welcome to Microsoft privacy share point verification",
                "prominent_button_name":"DOWNLOAD SHARED DOCUMENT",
                "text_input_field_labels":"unknown",
                "pdf_icon_visible":false,
                "has_visible_captcha":false,
                "has_urgent_text":false,
                "text":"Save your files and photos to OneDrive and get them from any device,
                 anywhere",
                "has_visible_qrcode":false}
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 8 08:15:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2673
                Entropy (8bit):3.984873547156934
                Encrypted:false
                SSDEEP:
                MD5:B058B076A747FEA6138A6E9C6EEB3CA0
                SHA1:614B7A4735040EC46D7E74CA5E401E076C3047EA
                SHA-256:184F4AC09F31DCA806ED496EB3A8953C678294F6FEA79E9396D3E205E2FDB432
                SHA-512:3996DC54076D8696706C288882B147C35EF42F6C4D4B21D8E118277F27D71883A2A58079ACBA38863C89BA29959B5860B5FFD6CE93BE780C4BD85DC346DBB6E5
                Malicious:false
                Reputation:unknown
                Preview:L..................F.@.. ...$+.,.....XW.b...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IHY.I....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHY.I....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHY.I....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHY.I..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHY.I...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 8 08:15:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2675
                Entropy (8bit):4.001885967365184
                Encrypted:false
                SSDEEP:
                MD5:F9F6F53AAA1C2485BA412B804F0A505A
                SHA1:D9683764865889076441565F8B70AF86076DD2F7
                SHA-256:3398A083515FB6E472CB5AB7958DD2339D977B050A345A2A2CDF9C7DD4669596
                SHA-512:2AE2FB8B42C4D0AD4DA3096278A624D81DF090DF1DA1F2AAEB00147E0932B49FB975B09BD2D9E4A25286DBB000AF2204B9EA9C02BD4A630E6EA9F6825F8EB64E
                Malicious:false
                Reputation:unknown
                Preview:L..................F.@.. ...$+.,......C.b...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IHY.I....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHY.I....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHY.I....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHY.I..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHY.I...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2689
                Entropy (8bit):4.010080528414421
                Encrypted:false
                SSDEEP:
                MD5:B50439208F6552C858F78F3A8749E893
                SHA1:C4C32A27E822A336DC67B1021F7813C39972E53C
                SHA-256:5B2AC1D6C43591FD01F506CB076042828A9A42DA1903A0845E43AED3685D2221
                SHA-512:4BBA520638BC1B1DC178EC5B9F9DA36D68B9F5271A73FFBCEF185030B0095BFF854F0BB2C18535B0285768246ED54A39D1BFA4ED374DF5300DA75AED0E6DC6AC
                Malicious:false
                Reputation:unknown
                Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IHY.I....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHY.I....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHY.I....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHY.I..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 8 08:15:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2677
                Entropy (8bit):3.9986794921074456
                Encrypted:false
                SSDEEP:
                MD5:1C491F8B2BEE65ED302737A0D918598E
                SHA1:5B00A75451A397E93C671FA71053148BCCD5EE7F
                SHA-256:F192692D8C189815B3B75E13ABF9984AFC0F3A576A1DC84F9650785586D38472
                SHA-512:9B09E3375F043C0762D86946A18F3167450BD4289EF56F9FF5DA3B3C4481B46CEC66E935EF3512E2012198C6005C163E7441A18813F86C87F5735A8E0D6A59B3
                Malicious:false
                Reputation:unknown
                Preview:L..................F.@.. ...$+.,.....%7.b...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IHY.I....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHY.I....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHY.I....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHY.I..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHY.I...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 8 08:15:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2677
                Entropy (8bit):3.9876918144320186
                Encrypted:false
                SSDEEP:
                MD5:64ACCB0FA521BFD1379D8374AD57D9FF
                SHA1:1AF1D1E765B9F21FEF0045D9B9888E583BB8F122
                SHA-256:F4A8C3AA57BC4CDFA32F38F1A7442E8BDCA441BF20BFDA45050C01708BCFAFB8
                SHA-512:D18B776C7A8D3D1A6034B01BDFEAC1EF22FC23108F3F9BF77D806DB3DBEE32B4292732FEE9AC04FF9FDCF7711CFD9334D503928295E035E217262F0F13E9EDC5
                Malicious:false
                Reputation:unknown
                Preview:L..................F.@.. ...$+.,.....zP.b...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IHY.I....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHY.I....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHY.I....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHY.I..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHY.I...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 8 08:15:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                Category:dropped
                Size (bytes):2679
                Entropy (8bit):3.996964269854148
                Encrypted:false
                SSDEEP:
                MD5:FA0D38C91E3613B21019160F5E4E518A
                SHA1:CE5161624DFCD1A710BDB9FFFAFB9AB0E382700F
                SHA-256:FAA38F3A25FA67AC10BC98EE5F37A4F2168F88C8D688BEDC8FA8D91BFB6C2BD9
                SHA-512:C2934F560F418A83F98C126C7EC98C0D90825436680BB08006E29B52CBCF90A623FFDD5B58CA223501349A47BB50B2721A99E899C89F1718FF7FD379A3A20D8D
                Malicious:false
                Reputation:unknown
                Preview:L..................F.@.. ...$+.,......,.b...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.IHY.I....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VHY.I....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.VHY.I....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.VHY.I..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VHY.I...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PDF document, version 2.0 (zip deflate encoded)
                Category:dropped
                Size (bytes):15664
                Entropy (8bit):7.946845529354188
                Encrypted:false
                SSDEEP:
                MD5:B052D0C13CB76B04BA9BCB45B48273F6
                SHA1:48885FF34BF57BC388F5656934105CECAB406745
                SHA-256:E44ED528121287651ADC741FF1398AA05E638318D493B8903A7DCC0595B80A4E
                SHA-512:44340E14E6F776C71DFDB01780B6A8A51851AA7C7BD06B995CE5BBDA921914FEFCF052FAAE75AD242C64B6FEBD7926556D4763020A892B5FC9571F6E9BE7616B
                Malicious:false
                Reputation:unknown
                Preview:%PDF-2.0.%.....1 0 obj<</Type/Catalog/Pages 3 0 R/Lang(en-US)/StructTreeRoot 4 0 R/MarkInfo 5 0 R>>.endobj.2 0 obj<</Type/ObjStm/N 39/First 293/Filter/FlateDecode/Length 1412>>stream.x..Wmo.6..+.......T...;n.4Y.gk.4.d.u.8......{(:..8A]..-.....<.)I.QDj...11..m...DDkKb.-z9..sA"....g@p(1.).B..-D....;^CG....TDp.....o.ZA..EP.^...{...{q.9.L...Fp.&8^..Z.-L..P.r.RQ...*F?..pNZ...#..r..SD..@....i.P...Q...!o.........tP.EC8=...`......!.j..r.,.zQ..i2..........;N..N.Mr....@xg.4.n]F`...n,4...\..l...|.u.K...3/?<....]#...._.N.......x....5"-..R#):.wU....{.2..t..8xS.F.EQ6.... .....aB s....l.\".IyO.p..wI...:....,/..&...;...&/.._5......TV......2m..].S.8...k0.iU......a....Z.x.gn....lZ%wt.O.*..Y{Wc&.]..N....Z.......Ga...;.#<....D..fX.@l ...Vd."..)6r.......3.H...,.....v...4.....$.|R.X....bJ?.E...%..CW.U>o..o....n.ta|.1Y.?.YsS...%..8%.s..r.}.g....K..]...+xY%E=...>.....<u..V..5.a|.[....d.D..V...V..VR+.C.5..E..Py...vd..==...Iv^..eWQ...0q.....e..<.....9....5w..=....Ew...5o..
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PDF document, version 2.0 (zip deflate encoded)
                Category:dropped
                Size (bytes):0
                Entropy (8bit):0.0
                Encrypted:false
                SSDEEP:
                MD5:2D1715A4F314AD1BBCD3BC4765A14972
                SHA1:02F5A5CC2DBBAB1998C3D31B98004E1E697C303B
                SHA-256:6C2637CACEC2346FDFFA2280F755AE726327BFF291D8FD586327DCF44F62EDF7
                SHA-512:5117BB76C96A182D4AEA844DE62EFC374737FA31DC65E0310C684436AD0A83A3555EE3F1639C2B1621F3DB929A36DCC1AEE53F0C0690A99C7004F0DA657FC548
                Malicious:false
                Reputation:unknown
                Preview:%PDF-2.0.%.....1 0 obj<</Type/Catalog/Pages 3 0 R/Lang(en-US)/StructTreeRoot 4 0 R/MarkInfo 5 0 R>>.endobj.2 0 obj<</Type/ObjStm/N 39/First 293/Filter/FlateDecode/Length 1412>>stream.x..Wmo.6..+.......T...;n.4Y.gk.4.d.u.8......{(:..8A]..-.....<.)I.QDj...11..m...DDkKb.-z9..sA"....g@p(1.).B..-D....;^CG....TDp.....o.ZA..EP.^...{...{q.9.L...Fp.&8^..Z.-L..P.r.RQ...*F?..pNZ...#..r..SD..@....i.P...Q...!o.........tP.EC8=...`......!.j..r.,.zQ..i2..........;N..N.Mr....@xg.4.n]F`...n,4...\..l...|.u.K...3/?<....]#...._.N.......x....5"-..R#):.wU....{.2..t..8xS.F.EQ6.... .....aB s....l.\".IyO.p..wI...:....,/..&...;...&/.._5......TV......2m..].S.8...k0.iU......a....Z.x.gn....lZ%wt.O.*..Y{Wc&.]..N....Z.......Ga...;.#<....D..fX.@l ...Vd."..)6r.......3.H...,.....v...4.....$.|R.X....bJ?.E...%..CW.U>o..o....n.ta|.1Y.?.YsS...%..8%.s..r.}.g....K..]...+xY%E=...>.....<u..V..5.a|.[....d.D..V...V..VR+.C.5..E..Py...vd..==...Iv^..eWQ...0q.....e..<.....9....5w..=....Ew...5o..
                Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                File Type:PDF document, version 2.0 (zip deflate encoded)
                Category:dropped
                Size (bytes):376028
                Entropy (8bit):7.990869163970242
                Encrypted:true
                SSDEEP:
                MD5:2D1715A4F314AD1BBCD3BC4765A14972
                SHA1:02F5A5CC2DBBAB1998C3D31B98004E1E697C303B
                SHA-256:6C2637CACEC2346FDFFA2280F755AE726327BFF291D8FD586327DCF44F62EDF7
                SHA-512:5117BB76C96A182D4AEA844DE62EFC374737FA31DC65E0310C684436AD0A83A3555EE3F1639C2B1621F3DB929A36DCC1AEE53F0C0690A99C7004F0DA657FC548
                Malicious:false
                Reputation:unknown
                Preview:%PDF-2.0.%.....1 0 obj<</Type/Catalog/Pages 3 0 R/Lang(en-US)/StructTreeRoot 4 0 R/MarkInfo 5 0 R>>.endobj.2 0 obj<</Type/ObjStm/N 39/First 293/Filter/FlateDecode/Length 1412>>stream.x..Wmo.6..+.......T...;n.4Y.gk.4.d.u.8......{(:..8A]..-.....<.)I.QDj...11..m...DDkKb.-z9..sA"....g@p(1.).B..-D....;^CG....TDp.....o.ZA..EP.^...{...{q.9.L...Fp.&8^..Z.-L..P.r.RQ...*F?..pNZ...#..r..SD..@....i.P...Q...!o.........tP.EC8=...`......!.j..r.,.zQ..i2..........;N..N.Mr....@xg.4.n]F`...n,4...\..l...|.u.K...3/?<....]#...._.N.......x....5"-..R#):.wU....{.2..t..8xS.F.EQ6.... .....aB s....l.\".IyO.p..wI...:....,/..&...;...&/.._5......TV......2m..].S.8...k0.iU......a....Z.x.gn....lZ%wt.O.*..Y{Wc&.]..N....Z.......Ga...;.#<....D..fX.@l ...Vd."..)6r.......3.H...,.....v...4.....$.|R.X....bJ?.E...%..CW.U>o..o....n.ta|.1Y.?.YsS...%..8%.s..r.}.g....K..]...+xY%E=...>.....<u..V..5.a|.[....d.D..V...V..VR+.C.5..E..Py...vd..==...Iv^..eWQ...0q.....e..<.....9....5w..=....Ew...5o..
                No static file info