Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Chrome Cache Entry: 128
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 406986
|
dropped
|
||
Chrome Cache Entry: 129
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 141866
|
dropped
|
||
Chrome Cache Entry: 130
|
HTML document, ASCII text, with very long lines (3450), with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 131
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 200x95, components
3
|
downloaded
|
||
Chrome Cache Entry: 132
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113401
|
downloaded
|
||
Chrome Cache Entry: 133
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 119648
|
dropped
|
||
Chrome Cache Entry: 134
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 406986
|
downloaded
|
||
Chrome Cache Entry: 135
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 57443
|
dropped
|
||
Chrome Cache Entry: 136
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113769
|
dropped
|
||
Chrome Cache Entry: 137
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 119648
|
downloaded
|
||
Chrome Cache Entry: 138
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 11970
|
downloaded
|
||
Chrome Cache Entry: 139
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1592
|
downloaded
|
||
Chrome Cache Entry: 140
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 11970
|
dropped
|
||
Chrome Cache Entry: 141
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1310, components
3
|
dropped
|
||
Chrome Cache Entry: 142
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1310, components
3
|
downloaded
|
||
Chrome Cache Entry: 143
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113769
|
downloaded
|
||
Chrome Cache Entry: 144
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 9285
|
downloaded
|
||
Chrome Cache Entry: 145
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 15755
|
dropped
|
||
Chrome Cache Entry: 146
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 57443
|
downloaded
|
||
Chrome Cache Entry: 147
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 9285
|
dropped
|
||
Chrome Cache Entry: 148
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 141866
|
downloaded
|
||
Chrome Cache Entry: 149
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 15755
|
downloaded
|
||
Chrome Cache Entry: 150
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1592
|
dropped
|
||
Chrome Cache Entry: 151
|
GIF image data, version 89a, 352 x 3
|
dropped
|
||
Chrome Cache Entry: 152
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 449844
|
dropped
|
||
Chrome Cache Entry: 153
|
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
|
downloaded
|
||
Chrome Cache Entry: 154
|
GIF image data, version 89a, 352 x 3
|
dropped
|
||
Chrome Cache Entry: 155
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 156
|
GIF image data, version 89a, 352 x 3
|
downloaded
|
||
Chrome Cache Entry: 157
|
GIF image data, version 89a, 352 x 3
|
downloaded
|
||
Chrome Cache Entry: 158
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1310, components
3
|
downloaded
|
||
Chrome Cache Entry: 159
|
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
|
dropped
|
||
Chrome Cache Entry: 160
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 449844
|
downloaded
|
||
Chrome Cache Entry: 161
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 200x95, components
3
|
dropped
|
There are 25 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=1656 --field-trial-handle=1936,i,5408255694739210393,11818520442255201119,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://eu.knowbe4.com/auth/saml/c33d8069242e"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://eu.knowbe4.com/auth/saml/c33d8069242e
|
|||
https://aadcdn.msauthimages.net/c1c6b6c8-obob6uz3nidzuuv1qwz2jtykzbgxef3vz5oy-e2m4f4/logintenantbranding/0/illustration?ts=636374910507629828
|
152.199.21.175
|
||
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D&sso_reload=true
|
|||
https://aadcdn.msftauthimages.net/c1c6b6c8-obob6uz3nidzuuv1qwz2jtykzbgxef3vz5oy-e2m4f4/logintenantbranding/0/illustration?ts=636374910507629828
|
13.107.246.60
|
||
https://login.microsoftonline.com
|
unknown
|
||
https://eu.knowbe4.com/auth/saml/c33d8069242e
|
52.222.236.7
|
||
https://aadcdn.msauthimages.net/c1c6b6c8-obob6uz3nidzuuv1qwz2jtykzbgxef3vz5oy-e2m4f4/logintenantbranding/0/bannerlogo?ts=636374909487213813
|
152.199.21.175
|
||
https://login.windows-ppe.net
|
unknown
|
||
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D
|
|||
https://autologon.microsoftazuread-sso.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/winauth/ssoprobe?client-request-id=86f3327a-513a-4b17-80a7-f8671ca05158&_=1728655788321
|
20.190.159.75
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
eu.knowbe4.com
|
52.222.236.7
|
||
bg.microsoft.map.fastly.net
|
199.232.214.172
|
||
s-part-0023.t-0009.t-msedge.net
|
13.107.246.51
|
||
sni1gl.wpc.upsiloncdn.net
|
152.199.21.175
|
||
s-part-0017.t-0009.fb-t-msedge.net
|
13.107.253.45
|
||
sni1gl.wpc.omegacdn.net
|
152.199.21.175
|
||
www.google.com
|
142.250.186.36
|
||
s-part-0032.t-0009.t-msedge.net
|
13.107.246.60
|
||
fp2e7a.wpc.phicdn.net
|
192.229.221.95
|
||
autologon.microsoftazuread-sso.com
|
20.190.159.75
|
||
aadcdn.msauthimages.net
|
unknown
|
||
identity.nel.measure.office.net
|
unknown
|
||
aadcdn.msftauth.net
|
unknown
|
||
login.microsoftonline.com
|
unknown
|
||
aadcdn.msftauthimages.net
|
unknown
|
There are 5 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
13.107.246.51
|
s-part-0023.t-0009.t-msedge.net
|
United States
|
||
142.250.186.36
|
www.google.com
|
United States
|
||
13.107.253.45
|
s-part-0017.t-0009.fb-t-msedge.net
|
United States
|
||
13.107.246.60
|
s-part-0032.t-0009.t-msedge.net
|
United States
|
||
192.168.2.6
|
unknown
|
unknown
|
||
20.190.159.75
|
autologon.microsoftazuread-sso.com
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
152.199.21.175
|
sni1gl.wpc.upsiloncdn.net
|
United States
|
||
52.222.236.7
|
eu.knowbe4.com
|
United States
|
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D
|
||
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D&sso_reload=true
|
||
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D&sso_reload=true
|
||
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D&sso_reload=true
|
||
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D&sso_reload=true
|