IOC Report
https://klickskydd.skolverket.org/?url=https%3A%2F%2Fonedrive.live.com%2Fredir%3Fresid%3DA2C259BD24DEB977%25211517%26authkey%3D%2521AMV6sdjMIZf95vs%26page%3DView%26wd%3Dtarget%2528Quick%2520Notes.one%257C8266a05f-045a-4cc0-bddc-4debc90069bb%252FNotera%2520H6TYD9J4rDFDFECZC-HUYW%257Ca949d04d-b4e2-450

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 07:18:01 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 07:18:01 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 07:18:01 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 07:18:01 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 07:18:01 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 218
ASCII text, with very long lines (65476)
dropped
Chrome Cache Entry: 219
PNG image data, 22 x 69, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 220
ASCII text, with very long lines (5949), with no line terminators
downloaded
Chrome Cache Entry: 221
ASCII text, with very long lines (38617), with no line terminators
dropped
Chrome Cache Entry: 222
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 223
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 224
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 225
ASCII text, with very long lines (14666), with no line terminators
downloaded
Chrome Cache Entry: 226
ASCII text, with very long lines (1922), with no line terminators
downloaded
Chrome Cache Entry: 227
ASCII text, with very long lines (41569), with no line terminators
dropped
Chrome Cache Entry: 228
ASCII text, with very long lines (20946), with CRLF line terminators
dropped
Chrome Cache Entry: 229
ASCII text, with very long lines (57788)
dropped
Chrome Cache Entry: 230
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 231
ASCII text, with very long lines (20082), with no line terminators
dropped
Chrome Cache Entry: 232
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 233
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
Chrome Cache Entry: 234
ASCII text, with very long lines (627)
downloaded
Chrome Cache Entry: 235
GIF image data, version 89a, 24 x 24
downloaded
Chrome Cache Entry: 236
ASCII text, with very long lines (5650)
downloaded
Chrome Cache Entry: 237
ASCII text, with very long lines (60197)
dropped
Chrome Cache Entry: 238
JSON data
downloaded
Chrome Cache Entry: 239
ASCII text, with very long lines (32011), with CRLF line terminators
downloaded
Chrome Cache Entry: 240
PNG image data, 222 x 204, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 241
JSON data
downloaded
Chrome Cache Entry: 242
ASCII text, with very long lines (47671)
dropped
Chrome Cache Entry: 243
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 244
ASCII text, with very long lines (351)
dropped
Chrome Cache Entry: 245
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 246
PNG image data, 102 x 102, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 247
ASCII text, with very long lines (32038)
dropped
Chrome Cache Entry: 248
Unicode text, UTF-8 text, with very long lines (56385)
downloaded
Chrome Cache Entry: 249
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 250
Unicode text, UTF-8 text, with very long lines (12695)
downloaded
Chrome Cache Entry: 251
Unicode text, UTF-8 text, with very long lines (28488)
downloaded
Chrome Cache Entry: 252
ASCII text, with very long lines (27024), with CRLF line terminators
downloaded
Chrome Cache Entry: 253
XML 1.0 document, ASCII text
dropped
Chrome Cache Entry: 254
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 255
PNG image data, 222 x 204, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 256
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 257
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 258
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 259
JSON data
dropped
Chrome Cache Entry: 260
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 261
ASCII text, with very long lines (7708)
dropped
Chrome Cache Entry: 262
Unicode text, UTF-8 text, with very long lines (28488)
dropped
Chrome Cache Entry: 263
ASCII text, with very long lines (65437)
dropped
Chrome Cache Entry: 264
JSON data
dropped
Chrome Cache Entry: 265
ASCII text, with very long lines (616)
downloaded
Chrome Cache Entry: 266
ASCII text, with very long lines (41569), with no line terminators
downloaded
Chrome Cache Entry: 267
ASCII text, with very long lines (47671)
downloaded
Chrome Cache Entry: 268
Unicode text, UTF-8 text, with very long lines (65526), with no line terminators
downloaded
Chrome Cache Entry: 269
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 270
ASCII text, with very long lines (35936), with CRLF line terminators
downloaded
Chrome Cache Entry: 271
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 272
Unicode text, UTF-8 text, with very long lines (65340), with no line terminators
dropped
Chrome Cache Entry: 273
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 274
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 275
XML 1.0 document, ASCII text
downloaded
Chrome Cache Entry: 276
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
downloaded
Chrome Cache Entry: 277
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 278
ASCII text, with very long lines (3527), with no line terminators
downloaded
Chrome Cache Entry: 279
ASCII text, with very long lines (627)
dropped
Chrome Cache Entry: 280
ASCII text, with very long lines (8369), with no line terminators
dropped
Chrome Cache Entry: 281
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 282
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 283
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
dropped
Chrome Cache Entry: 284
ASCII text, with very long lines (64817)
downloaded
Chrome Cache Entry: 285
HTML document, ASCII text, with very long lines (337), with CRLF line terminators
downloaded
Chrome Cache Entry: 286
ASCII text, with very long lines (1922), with no line terminators
dropped
Chrome Cache Entry: 287
JSON data
downloaded
Chrome Cache Entry: 288
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 289
ASCII text, with very long lines (61584), with CRLF line terminators
dropped
Chrome Cache Entry: 290
Unicode text, UTF-8 (with BOM) text, with very long lines (18992), with CRLF line terminators
downloaded
Chrome Cache Entry: 291
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 292
Unicode text, UTF-8 text, with very long lines (58392)
downloaded
Chrome Cache Entry: 293
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 294
ASCII text, with very long lines (672)
dropped
Chrome Cache Entry: 295
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 296
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 297
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 298
ASCII text, with very long lines (2224), with no line terminators
downloaded
Chrome Cache Entry: 299
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
dropped
Chrome Cache Entry: 300
ASCII text, with very long lines (64817)
dropped
Chrome Cache Entry: 301
ASCII text, with very long lines (65443)
downloaded
Chrome Cache Entry: 302
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 303
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 304
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 305
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 306
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 307
ASCII text, with very long lines (35936), with CRLF line terminators
dropped
Chrome Cache Entry: 308
Unicode text, UTF-8 (with BOM) text, with very long lines (18992), with CRLF line terminators
dropped
Chrome Cache Entry: 309
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 310
ASCII text, with very long lines (38617), with no line terminators
downloaded
Chrome Cache Entry: 311
ASCII text, with very long lines (24306), with CRLF line terminators
dropped
Chrome Cache Entry: 312
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 313
PNG image data, 452 x 444, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 314
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 315
MS Windows cursor resource - 1 icon, 32x32, hotspot @16x16
dropped
Chrome Cache Entry: 316
ASCII text, with very long lines (30497), with no line terminators
dropped
Chrome Cache Entry: 317
Unicode text, UTF-8 text, with very long lines (65526), with no line terminators
dropped
Chrome Cache Entry: 318
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
dropped
Chrome Cache Entry: 319
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 320
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
Chrome Cache Entry: 321
ASCII text, with very long lines (32038)
downloaded
Chrome Cache Entry: 322
ASCII text, with very long lines (1917), with no line terminators
downloaded
Chrome Cache Entry: 323
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 324
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 325
Unicode text, UTF-8 text, with very long lines (65340), with no line terminators
downloaded
Chrome Cache Entry: 326
PNG image data, 102 x 102, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 327
Unicode text, UTF-8 text, with very long lines (56385)
dropped
Chrome Cache Entry: 328
ASCII text, with very long lines (64762), with CRLF line terminators
downloaded
Chrome Cache Entry: 329
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 330
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 331
ASCII text, with very long lines (3527), with no line terminators
dropped
Chrome Cache Entry: 332
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 333
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 334
ASCII text, with very long lines (1917), with no line terminators
dropped
Chrome Cache Entry: 335
PNG image data, 82 x 258, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 336
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 337
ASCII text, with very long lines (1837)
downloaded
Chrome Cache Entry: 338
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 339
JSON data
downloaded
Chrome Cache Entry: 340
ASCII text, with very long lines (49535)
dropped
Chrome Cache Entry: 341
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 342
ASCII text, with very long lines (61584), with CRLF line terminators
downloaded
Chrome Cache Entry: 343
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 344
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
dropped
Chrome Cache Entry: 345
Web Open Font Format, TrueType, length 3052, version 4.-22282
downloaded
Chrome Cache Entry: 346
ASCII text, with very long lines (65443)
dropped
Chrome Cache Entry: 347
Web Open Font Format, TrueType, length 151924, version 0.0
downloaded
Chrome Cache Entry: 348
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 349
ASCII text, with very long lines (672)
downloaded
Chrome Cache Entry: 350
HTML document, Unicode text, UTF-8 (with BOM) text, with very long lines (4207), with CRLF line terminators
downloaded
Chrome Cache Entry: 351
ASCII text, with very long lines (49535)
downloaded
Chrome Cache Entry: 352
PNG image data, 82 x 258, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 353
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 354
ASCII text, with very long lines (1837)
dropped
Chrome Cache Entry: 355
ASCII text, with very long lines (351)
downloaded
Chrome Cache Entry: 356
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 357
ASCII text, with very long lines (64762), with CRLF line terminators
dropped
Chrome Cache Entry: 358
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 359
JSON data
dropped
Chrome Cache Entry: 360
JSON data
dropped
Chrome Cache Entry: 361
ASCII text, with very long lines (5650)
dropped
Chrome Cache Entry: 362
ASCII text, with very long lines (20116), with no line terminators
downloaded
Chrome Cache Entry: 363
JSON data
dropped
Chrome Cache Entry: 364
PNG image data, 452 x 444, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 365
ASCII text, with very long lines (2936)
downloaded
Chrome Cache Entry: 366
ASCII text, with very long lines (33654)
downloaded
Chrome Cache Entry: 367
ASCII text, with very long lines (20082), with no line terminators
downloaded
Chrome Cache Entry: 368
PNG image data, 24 x 51, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 369
JSON data
dropped
Chrome Cache Entry: 370
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 371
JSON data
dropped
Chrome Cache Entry: 372
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 373
GIF image data, version 89a, 24 x 24
dropped
Chrome Cache Entry: 374
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
downloaded
Chrome Cache Entry: 375
JSON data
dropped
Chrome Cache Entry: 376
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 377
Unicode text, UTF-8 text, with very long lines (58392)
dropped
Chrome Cache Entry: 378
ASCII text, with very long lines (20946), with CRLF line terminators
downloaded
Chrome Cache Entry: 379
ASCII text, with very long lines (65476)
downloaded
Chrome Cache Entry: 380
ASCII text, with very long lines (24306), with CRLF line terminators
downloaded
Chrome Cache Entry: 381
ASCII text, with very long lines (2936)
dropped
Chrome Cache Entry: 382
ASCII text, with very long lines (3379)
downloaded
Chrome Cache Entry: 383
ASCII text, with very long lines (33654)
dropped
Chrome Cache Entry: 384
ASCII text, with very long lines (14666), with no line terminators
dropped
Chrome Cache Entry: 385
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 386
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 387
ASCII text, with very long lines (65437)
downloaded
Chrome Cache Entry: 388
ASCII text, with very long lines (11667), with no line terminators
dropped
Chrome Cache Entry: 389
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 390
ASCII text, with very long lines (8369), with no line terminators
downloaded
Chrome Cache Entry: 391
ASCII text, with very long lines (22010)
dropped
Chrome Cache Entry: 392
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
downloaded
Chrome Cache Entry: 393
ASCII text, with very long lines (60197)
downloaded
Chrome Cache Entry: 394
ASCII text, with very long lines (616)
dropped
Chrome Cache Entry: 395
PNG image data, 22 x 69, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 396
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 397
ASCII text, with very long lines (11667), with no line terminators
downloaded
Chrome Cache Entry: 398
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 399
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 400
Unicode text, UTF-8 text, with very long lines (12695)
dropped
Chrome Cache Entry: 401
ASCII text, with very long lines (22010)
downloaded
Chrome Cache Entry: 402
JSON data
dropped
Chrome Cache Entry: 403
ASCII text, with very long lines (20116), with no line terminators
dropped
Chrome Cache Entry: 404
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 405
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 406
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 407
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 408
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 409
PNG image data, 24 x 51, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 410
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 411
JSON data
downloaded
Chrome Cache Entry: 412
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 413
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 414
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 415
ASCII text, with very long lines (57788)
downloaded
Chrome Cache Entry: 416
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 417
ASCII text, with very long lines (41116)
dropped
Chrome Cache Entry: 418
JSON data
downloaded
Chrome Cache Entry: 419
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 420
ASCII text, with very long lines (41116)
downloaded
Chrome Cache Entry: 421
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 422
ASCII text, with very long lines (30497), with no line terminators
downloaded
Chrome Cache Entry: 423
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
dropped
Chrome Cache Entry: 424
MS Windows cursor resource - 1 icon, 32x32, hotspot @16x16
downloaded
Chrome Cache Entry: 425
ASCII text, with very long lines (65451)
dropped
Chrome Cache Entry: 426
HTML document, Unicode text, UTF-8 (with BOM) text, with very long lines (4207), with CRLF line terminators
dropped
Chrome Cache Entry: 427
ASCII text, with very long lines (2224), with no line terminators
dropped
Chrome Cache Entry: 428
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
downloaded
Chrome Cache Entry: 429
ASCII text, with very long lines (32011), with CRLF line terminators
dropped
Chrome Cache Entry: 430
ASCII text, with very long lines (5949), with no line terminators
dropped
Chrome Cache Entry: 431
ASCII text, with very long lines (7708)
downloaded
There are 211 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2196,i,9191752182764225536,16471943110662272050,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://klickskydd.skolverket.org/?url=https%3A%2F%2Fonedrive.live.com%2Fredir%3Fresid%3DA2C259BD24DEB977%25211517%26authkey%3D%2521AMV6sdjMIZf95vs%26page%3DView%26wd%3Dtarget%2528Quick%2520Notes.one%257C8266a05f-045a-4cc0-bddc-4debc90069bb%252FNotera%2520H6TYD9J4rDFDFECZC-HUYW%257Ca949d04d-b4e2-4509-b99f-d04546199b7b%252F%2529%26wdorigin%3DNavigationUrl&id=71de&rcpt=johan.brandt@skolverket.se&tss=1729830791&msgid=2d0ccdeb-928a-11ef-8a2e-0050569b0508&html=1&h=008c08c0"

URLs

Name
IP
Malicious
https://klickskydd.skolverket.org/?url=https%3A%2F%2Fonedrive.live.com%2Fredir%3Fresid%3DA2C259BD24DEB977%25211517%26authkey%3D%2521AMV6sdjMIZf95vs%26page%3DView%26wd%3Dtarget%2528Quick%2520Notes.one%257C8266a05f-045a-4cc0-bddc-4debc90069bb%252FNotera%2520H6TYD9J4rDFDFECZC-HUYW%257Ca949d04d-b4e2-4509-b99f-d04546199b7b%252F%2529%26wdorigin%3DNavigationUrl&id=71de&rcpt=johan.brandt@skolverket.se&tss=1729830791&msgid=2d0ccdeb-928a-11ef-8a2e-0050569b0508&html=1&h=008c08c0
malicious
https://klickskydd.skolverket.org/?url=https%3A%2F%2Fonedrive.live.com%2Fredir%3Fresid%3DA2C259BD24DEB977%25211517%26authkey%3D%2521AMV6sdjMIZf95vs%26page%3DView%26wd%3Dtarget%2528Quick%2520Notes.one%257C8266a05f-045a-4cc0-bddc-4debc90069bb%252FNotera%2520H6TYD9J4rDFDFECZC-HUYW%257Ca949d04d-b4e2-4509-b99f-d04546199b7b%252F%2529%26wdorigin%3DNavigationUrl&id=71de&rcpt=johan.brandt@skolverket.se&tss=1729830791&msgid=2d0ccdeb-928a-11ef-8a2e-0050569b0508&html=1&h=008c08c0
193.235.52.43
malicious
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/8d80c75699b24770/1729844337720/5e9895ee7bcc56b5e3d2218924c4b6a743fff2104160fd3b3386fd98d96833a2/e-QeoT4_tpk3zlh
104.18.95.41
https://roaming.officeapps.partner.office365.cn/rs/v1/settings
unknown
https://www.onenote.com/officeaddins/meetings?ui=fil-PH&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=az-Latn-AZ&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=hy-AM&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=is-IS&temporaryLocalization=true
unknown
https://support.office.com/f1/home?isAgave=true&helpid=161255
unknown
https://www.onenote.com/officeaddins/meetings?ui=mi-NZ&temporaryLocalization=true
unknown
https://ffksdtexbdsdtexbdsdtexbsdtexbdsdtexbdsdtexb.thedagrouppseervicesdfrtycbgt.top/captcha/style.css
104.21.16.104
https://login.microsoftonline-int.com
unknown
https://www.onenote.com/officeaddins/meetings?ui=kok-IN&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ky-KG&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=sk-SK&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ca-ES-valencia&temporaryLocalization=true
unknown
https://fa000000128.resources.office.net:3000/index.html
unknown
https://www.onenote.com/officeaddins/meetings?ui=ka-GE&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=tk-TM&temporaryLocalization=true
unknown
https://ffksdtexbdsdtexbdsdtexbsdtexbdsdtexbdsdtexb.thedagrouppseervicesdfrtycbgt.top/
https://augloop.office.com/v2;394866fc-eedb-4f01-8536-3ff84b16be2a;liveprofilecard.access;https://sh
unknown
https://www.onenote.com/officeaddins/meetings?ui=et-EE&temporaryLocalization=true
unknown
https://cdn.fluidpreview.office.net/fluid/prod
unknown
https://my.microsoftpersonalcontent.com
unknown
https://www.onenote.com/officeaddins/meetings?ui=mt-MT&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=sr-Latn-RS&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ne-NP&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ru-RU&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=sl-SI&temporaryLocalization=true
unknown
https://forms.office.com
unknown
https://www.onenote.com/officeaddins/meetings?ui=bn-BD&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=vi-VN&temporaryLocalization=true
unknown
https://common.online.office.com/suite/RemoteUls.ashx?usid=c468fa01-be7e-4a57-96d2-7f5d2065121a&officeserverversion=
52.108.8.12
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/908940638:1729840494:mx0_n_SCeJLqaphdsFJLTpBaXTQuzYz38JlXbDQGU70/8d80c75699b24770/pprSxAgs1NFE27Sj2kyjeQKSK803c6AORgW9duV_jd8-1729844335-1.1.1.1-Aj_ryDg4Eoxhecc7UJY64vITmZFw_PBd9uXflBdq1DJ3J5nO12Nu_VliOv9Gg5vQ
104.18.95.41
https://www.onenote.com/officeaddins/meetings?ui=af-ZA&temporaryLocalization=true
unknown
https://whiteboard.microsoft.scloud
unknown
https://augloop-int.officeppe.com/v2
unknown
https://aka.ms/Officeaddins
unknown
https://www.onenote.com/officeaddins/meetings?ui=mn-MN&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ro-RO&temporaryLocalization=true
unknown
https://consent.config.office.com/consentcheckin/v1.0/consents
unknown
https://www.onenote.com/officeaddins/meetings?ui=cs-CZ&temporaryLocalization=true
unknown
https://fa000000096.resources.office.net
unknown
https://www.onenote.com/officeaddins/meetings?ui=pl-PL&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=prs-AF&temporaryLocalization=true
unknown
https://support.office.com/f1/home?isAgave=true&helpid=126385
unknown
https://whiteboard.office.com/root/index.fluid.js
unknown
https://www.onenote.com/officeaddins/meetings?ui=sv-SE&temporaryLocalization=true
unknown
https://github.com/js-cookie/js-cookie
unknown
https://www.onenote.com/officeaddins/meetings?ui=uk-UA&temporaryLocalization=true
unknown
https://support.office.com/article/7afcb4f3-4aa2-443a-9b08-125a5d692576
unknown
https://support.office.com/article/ec43ed03-eb3c-4a10-8d9d-e9e5433c9ed2
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/8d80c75699b24770/1729844337721/eU1Oj_y52zVDRbp
104.18.95.41
https://common.online.office.com/suite/RemoteTelemetry.ashx?usid=c468fa01-be7e-4a57-96d2-7f5d2065121a
52.108.8.12
http://support.office.com
unknown
https://support.office.com/images/inapp-help-icon-80.png
unknown
https://www.onenote.com/officeaddins/meetings?ui=ar-SA&temporaryLocalization=true
unknown
https://roaming.osi.office.de/rs/v1/settings
unknown
https://www.onenote.com/officeaddins/meetings?ui=he-IL&temporaryLocalization=true
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/76oc6/0x4AAAAAAAyWJLKajdsL6TRH/auto/fbE/normal/auto/
104.18.95.41
https://www.onenote.com/officeaddins/meetings?ui=nso-ZA&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=mk-MK&temporaryLocalization=true
unknown
https://login.windows-ppe.net
unknown
https://www.onenote.com/officeaddins/meetings?ui=zu-ZA&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=lt-LT&temporaryLocalization=true
unknown
https://reactjs.org/link/react-polyfills
unknown
https://www.onenote.com/officeaddins/meetings?ui=sq-AL&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=pt-PT&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/learningtools/?et=
13.107.253.67
https://login.microsoftonline.com
unknown
https://www.onenote.com/officeaddins/meetings?ui=tg-Cyrl-TJ&temporaryLocalization=true
unknown
https://cdn.fluidpreview.office.net/fluid/gcc
unknown
https://www.onenote.com/officeaddins/meetings?ui=nb-NO&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=zh-TW&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=tr-TR&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=fr-FR&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=wo-SN&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=de-DE&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=kn-IN&temporaryLocalization=true
unknown
https://fa000000096.resources.office.net/f7024bdc-7caf-4ca8-807d-2908f09640d6/1.0.2210.23001/en-us_w
unknown
https://www.onenote.com/officeaddins/mathassistant
unknown
https://challenges.cloudflare.com/turnstile/v0/b/e1a56f38220d/api.js
104.18.95.41
https://onedrive.live.com/view?id=A2C259BD24DEB977!1517&resid=A2C259BD24DEB977!1517&authkey=!AMV6sdjMIZf95vs&wd=target(Quick%20Notes.one|8266a05f-045a-4cc0-bddc-4debc90069bb/Notera%20H6TYD9J4rDFDFECZC-HUYW|a949d04d-b4e2-4509-b99f-d04546199b7b/)&wdorigin=NavigationUrl&wdo=2&cid=a2c259bd24deb977
https://forms.officeppe.com
unknown
https://www.onenote.com/officeaddins/meetings?ui=bn-IN&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=fi-FI&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ms-MY&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=te-IN&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ml-IN&temporaryLocalization=true
unknown
http://hammerjs.github.io/
unknown
https://whiteboard.office365.us
unknown
https://www.onenote.com/officeaddins/meetings?ui=id-ID&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=ca-ES&temporaryLocalization=true
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/8d80c7963fe14683/1729844348550/4d62caf019efa1cd8f433bc086f48a0e1aa346e85350d41b7471bfe06d872b3b/rfUlUEaDb_z1-vS
104.18.95.41
https://edog.onenote.com
unknown
https://support.office.com/f1/home?isAgave=true
unknown
https://whiteboard.eaglex.ic.gov
unknown
https://www.onenote.com/officeaddins/meetings?ui=tt-RU&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=am-ET&temporaryLocalization=true
unknown
https://www.onenote.com/officeaddins/meetings?ui=es-ES&temporaryLocalization=true
unknown
https://roaming.osi.apps.mil/rs/v1/settings
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
s-part-0017.t-0009.t-msedge.net
13.107.246.45
ffksdtexbdsdtexbdsdtexbsdtexbdsdtexbdsdtexb.thedagrouppseervicesdfrtycbgt.top
104.21.16.104
wac-0003.wac-dc-msedge.net
52.108.10.12
s-part-0039.t-0009.fb-t-msedge.net
13.107.253.67
clickprotection.skolverket.se
193.235.52.43
fp2e7a.wpc.phicdn.net
192.229.221.95
dual-spov-0006.spov-msedge.net
13.107.139.11
wac-0003.wac-msedge.net
52.108.8.12
bg.microsoft.map.fastly.net
199.232.210.172
code.jquery.com
151.101.130.137
www.cloudflare.com
104.16.123.96
challenges.cloudflare.com
104.18.95.41
www.google.com
142.250.186.132
s-part-0032.t-0009.t-msedge.net
13.107.246.60
sni1gl.wpc.sigmacdn.net
152.199.21.175
fa000000012.resources.office.net
unknown
fa000000111.resources.office.net
unknown
fa000000128.resources.office.net
unknown
augloop.office.com
unknown
ajax.aspnetcdn.com
unknown
fa000000110.resources.office.net
unknown
onenoteonline.nel.measure.office.net
unknown
common.online.office.com
unknown
klickskydd.skolverket.org
unknown
fa000000138.resources.office.net
unknown
onedrive.live.com
unknown
westeurope-pd03.augloop.office.com
unknown
www.onenote.com
unknown
spoprod-a.akamaihd.net
unknown
messaging.engagement.office.com
unknown
fa000000096.resources.office.net
unknown
There are 21 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.107.246.45
s-part-0017.t-0009.t-msedge.net
United States
104.21.16.104
ffksdtexbdsdtexbdsdtexbsdtexbdsdtexbdsdtexb.thedagrouppseervicesdfrtycbgt.top
United States
13.107.246.60
s-part-0032.t-0009.t-msedge.net
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
52.108.9.12
unknown
United States
151.101.130.137
code.jquery.com
United States
52.108.10.12
wac-0003.wac-dc-msedge.net
United States
142.250.186.132
www.google.com
United States
13.107.139.11
dual-spov-0006.spov-msedge.net
United States
13.107.253.67
s-part-0039.t-0009.fb-t-msedge.net
United States
104.18.95.41
challenges.cloudflare.com
United States
52.108.8.12
wac-0003.wac-msedge.net
United States
52.108.11.12
unknown
United States
239.255.255.250
unknown
Reserved
152.199.21.175
sni1gl.wpc.sigmacdn.net
United States
193.235.52.43
clickprotection.skolverket.se
Sweden
104.16.123.96
www.cloudflare.com
United States
There are 8 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://onedrive.live.com/view?id=A2C259BD24DEB977!1517&resid=A2C259BD24DEB977!1517&authkey=!AMV6sdjMIZf95vs&wd=target(Quick%20Notes.one|8266a05f-045a-4cc0-bddc-4debc90069bb/Notera%20H6TYD9J4rDFDFECZC-HUYW|a949d04d-b4e2-4509-b99f-d04546199b7b/)&wdorigin=NavigationUrl&wdo=2&cid=a2c259bd24deb977
https://onedrive.live.com/view?id=A2C259BD24DEB977!1517&resid=A2C259BD24DEB977!1517&authkey=!AMV6sdjMIZf95vs&wd=target(Quick%20Notes.one|8266a05f-045a-4cc0-bddc-4debc90069bb/Notera%20H6TYD9J4rDFDFECZC-HUYW|a949d04d-b4e2-4509-b99f-d04546199b7b/)&wdorigin=NavigationUrl&wdo=2&cid=a2c259bd24deb977
https://onedrive.live.com/redir?resid=A2C259BD24DEB977%211517&authkey=%21AMV6sdjMIZf95vs&page=View&wd=target%28Quick%20Notes.one%7C8266a05f-045a-4cc0-bddc-4debc90069bb%2FNotera%20H6TYD9J4rDFDFECZC-HUYW%7Ca949d04d-b4e2-4509-b99f-d04546199b7b%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/redir?resid=A2C259BD24DEB977%211517&authkey=%21AMV6sdjMIZf95vs&page=View&wd=target%28Quick%20Notes.one%7C8266a05f-045a-4cc0-bddc-4debc90069bb%2FNotera%20H6TYD9J4rDFDFECZC-HUYW%7Ca949d04d-b4e2-4509-b99f-d04546199b7b%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/redir?resid=A2C259BD24DEB977%211517&authkey=%21AMV6sdjMIZf95vs&page=View&wd=target%28Quick%20Notes.one%7C8266a05f-045a-4cc0-bddc-4debc90069bb%2FNotera%20H6TYD9J4rDFDFECZC-HUYW%7Ca949d04d-b4e2-4509-b99f-d04546199b7b%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/redir?resid=A2C259BD24DEB977%211517&authkey=%21AMV6sdjMIZf95vs&page=View&wd=target%28Quick%20Notes.one%7C8266a05f-045a-4cc0-bddc-4debc90069bb%2FNotera%20H6TYD9J4rDFDFECZC-HUYW%7Ca949d04d-b4e2-4509-b99f-d04546199b7b%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/redir?resid=A2C259BD24DEB977%211517&authkey=%21AMV6sdjMIZf95vs&page=View&wd=target%28Quick%20Notes.one%7C8266a05f-045a-4cc0-bddc-4debc90069bb%2FNotera%20H6TYD9J4rDFDFECZC-HUYW%7Ca949d04d-b4e2-4509-b99f-d04546199b7b%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/redir?resid=A2C259BD24DEB977%211517&authkey=%21AMV6sdjMIZf95vs&page=View&wd=target%28Quick%20Notes.one%7C8266a05f-045a-4cc0-bddc-4debc90069bb%2FNotera%20H6TYD9J4rDFDFECZC-HUYW%7Ca949d04d-b4e2-4509-b99f-d04546199b7b%2F%29&wdorigin=NavigationUrl
https://onedrive.live.com/redir?resid=A2C259BD24DEB977%211517&authkey=%21AMV6sdjMIZf95vs&page=View&wd=target%28Quick%20Notes.one%7C8266a05f-045a-4cc0-bddc-4debc90069bb%2FNotera%20H6TYD9J4rDFDFECZC-HUYW%7Ca949d04d-b4e2-4509-b99f-d04546199b7b%2F%29&wdorigin=NavigationUrl
https://ffksdtexbdsdtexbdsdtexbsdtexbdsdtexbdsdtexb.thedagrouppseervicesdfrtycbgt.top/
https://ffksdtexbdsdtexbdsdtexbsdtexbdsdtexbdsdtexb.thedagrouppseervicesdfrtycbgt.top/
https://ffksdtexbdsdtexbdsdtexbsdtexbdsdtexbdsdtexb.thedagrouppseervicesdfrtycbgt.top/
There are 2 hidden doms, click here to show them.