Windows
Analysis Report
https://atpscan.global.hornetsecurity.com?d=CSvj-8b3fpwAumC6AbFMfEVmIT5ENJWTqrZHusAeFnU&f=Mzo1PUwZQd3evqHstuwR_5FCozrkJ9Jd1jGDrnrvcdluTk54zR-Gop3tgMHHrGpX90Gv7ZppU4ALGygldB7J0A&i=&k=bz9r&m=KuGpJb7F8ZjkKBdLnbtsoBlIPcr_V2YvhrjDwSG7wjDkh9t68btueC3me_khplS04Y1vkmcz2DALFAdsCPnXV9Y0e_KkoBmquE5hQxvQRCkIOVA
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64_ra
- chrome.exe (PID: 7020 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6340 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2216 --fi eld-trial- handle=194 8,i,788417 8855131201 589,162407 5238014947 2380,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 5672 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt ps://atpsc an.global. hornetsecu rity.com?d =CSvj-8b3f pwAumC6AbF MfEVmIT5EN JWTqrZHusA eFnU&f=Mzo 1PUwZQd3ev qHstuwR_5F CozrkJ9Jd1 jGDrnrvcdl uTk54zR-Go p3tgMHHrGp X90Gv7ZppU 4ALGygldB7 J0A&i=&k=b z9r&m=KuGp Jb7F8ZjkKB dLnbtsoBlI Pcr_V2Yvhr jDwSG7wjDk h9t68btueC 3me_khplS0 4Y1vkmcz2D ALFAdsCPnX V9Y0e_KkoB mquE5hQxvQ RCkIOVAxUS YrmBcZKNoh 8NCT&n=3jw 3xk5HrrJRp v5jkTsPtIA 8SNg8pPkNV IChy5v4uio LwV8t1Qhw8 Jl0rPecYr_ z&r=Mi1JW6 WUX7aRK4la w3uJhl9L7A wt-TwJX20O R-eyQiCnji N--PaFEdBZ XBvOt4br&s =9e20e3b94 1956d70210 1ff1a86d29 524b24c4f8 158208c10c fbca279a87 2d30e&u=ht tps%3A%2F% 2Fwww.goog le.ca%2Fur l%3Fn89vrc %3Dhttps%3 A%2F%2Fwww .cookejack son.com%26 bg%3DAJ%26 SQ%3DPQ%26 TA%3DR6%26 SQ%3DPW%26 TA%3D6O%26 q%3D%25256 1%25256d%2 52570%252F %252573%25 2561%25256 E%252564%2 52562%2525 6F%252578% 25252E%252 575%252573 %25252E%25 2570%25257 2%25256F%2 52564%2525 2E%252561% 252570%252 569%25252E %252575%25 2570%25256 6%25256F%2 52572%2525 74%25252E% 252563%252 56F%25256D %25252F%25 256C%25256 9%25256E%2 5256B%2525 2F%252565% 252579%252 54A%252573 %252549%25 256A%25256 F%252569aH R0cHM6Ly9x M3oycDUuZG VrY2hvYnRp ZXcuY29tL2 Jvbm5pZS5w ZXRlcnNlbk BnZWxpdGEu Y29tIiwidS I6InVzZXIt MGIzMzM5NW ItZDE0OS00 NzVkLTljMD MtZmExMGIx Mjg1YTVmIi wiciI6ImFu bmEudmFuY2 VAbWFzb25v d2VuYW5kaG FsZS5jaCIs InYiOjF9%2 6opdg%3DSm o%26Uk4%3D RXM%26QTU% 3DN3I%20Ca tegory%20S tatus%20Pr iority%20Q uickAction s" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Classification label: |
Source: | File created: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Window detected: |
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
securelinks.cloud-security.net | 94.100.133.74 | true | false | high | |
atpscan.global.hornetsecurity.com | 94.100.136.44 | true | false | high | |
www.google.com | 216.58.206.36 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
94.100.136.44 | atpscan.global.hornetsecurity.com | Germany | 24679 | SSERV-ASDE | false | |
142.250.185.67 | unknown | United States | 15169 | GOOGLEUS | false | |
142.251.168.84 | unknown | United States | 15169 | GOOGLEUS | false | |
94.100.133.74 | securelinks.cloud-security.net | Germany | 25394 | MK-NETZDIENSTE-ASDE | false | |
1.1.1.1 | unknown | Australia | 13335 | CLOUDFLARENETUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.186.142 | unknown | United States | 15169 | GOOGLEUS | false | |
216.58.206.36 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1592048 |
Start date and time: | 2025-01-15 17:45:59 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://atpscan.global.hornetsecurity.com?d=CSvj-8b3fpwAumC6AbFMfEVmIT5ENJWTqrZHusAeFnU&f=Mzo1PUwZQd3evqHstuwR_5FCozrkJ9Jd1jGDrnrvcdluTk54zR-Gop3tgMHHrGpX90Gv7ZppU4ALGygldB7J0A&i=&k=bz9r&m=KuGpJb7F8ZjkKBdLnbtsoBlIPcr_V2YvhrjDwSG7wjDkh9t68btueC3me_khplS04Y1vkmcz2DALFAdsCPnXV9Y0e_KkoBmquE5hQxvQRCkIOVAxUSYrmBcZKNoh8NCT&n=3jw3xk5HrrJRpv5jkTsPtIA8SNg8pPkNVIChy5v4uioLwV8t1Qhw8Jl0rPecYr_z&r=Mi1JW6WUX7aRK4law3uJhl9L7Awt-TwJX20OR-eyQiCnjiN--PaFEdBZXBvOt4br&s=9e20e3b941956d702101ff1a86d29524b24c4f8158208c10cfbca279a872d30e&u=https%3A%2F%2Fwww.google.ca%2Furl%3Fn89vrc%3Dhttps%3A%2F%2Fwww.cookejackson.com%26bg%3DAJ%26SQ%3DPQ%26TA%3DR6%26SQ%3DPW%26TA%3D6O%26q%3D%252561%25256d%252570%252F%252573%252561%25256E%252564%252562%25256F%252578%25252E%252575%252573%25252E%252570%252572%25256F%252564%25252E%252561%252570%252569%25252E%252575%252570%252566%25256F%252572%252574%25252E%252563%25256F%25256D%25252F%25256C%252569%25256E%25256B%25252F%252565%252579%25254A%252573%252549%25256A%25256F%252569aHR0cHM6Ly9xM3oycDUuZGVrY2hvYnRpZXcuY29tL2Jvbm5pZS5wZXRlcnNlbkBnZWxpdGEuY29tIiwidSI6InVzZXItMGIzMzM5NWItZDE0OS00NzVkLTljMDMtZmExMGIxMjg1YTVmIiwiciI6ImFubmEudmFuY2VAbWFzb25vd2VuYW5kaGFsZS5jaCIsInYiOjF9%26opdg%3DSmo%26Uk4%3DRXM%26QTU%3DN3I%20Category%20Status%20Priority%20QuickActions |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | stream |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean0.win@17/27@8/38 |
- Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.67, 142.250.186.142, 142.251.168.84, 216.58.212.142, 142.250.185.238, 216.58.212.174
- Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, clientservices.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: https://atpscan.global.hornetsecurity.com?d=CSvj-8b3fpwAumC6AbFMfEVmIT5ENJWTqrZHusAeFnU&f=Mzo1PUwZQd3evqHstuwR_5FCozrkJ9Jd1jGDrnrvcdluTk54zR-Gop3tgMHHrGpX90Gv7ZppU4ALGygldB7J0A&i=&k=bz9r&m=KuGpJb7F8ZjkKBdLnbtsoBlIPcr_V2YvhrjDwSG7wjDkh9t68btueC3me_khplS04Y1vkmcz2DALFAdsCPnXV9Y0e_KkoBmquE5hQxvQRCkIOVAxUSYrmBcZKNoh8NCT&n=3jw3xk5HrrJRpv5jkTsPtIA8SNg8pPkNVIChy5v4uioLwV8t1Qhw8Jl0rPecYr_z&r=Mi1JW6WUX7aRK4law3uJhl9L7Awt-TwJX20OR-eyQiCnjiN--PaFEdBZXBvOt4br&s=9e20e3b941956d702101ff1a86d29524b24c4f8158208c10cfbca279a872d30e&u=https%3A%2F%2Fwww.google.ca%2Furl%3Fn89vrc%3Dhttps%3A%2F%2Fwww.cookejackson.com%26bg%3DAJ%26SQ%3DPQ%26TA%3DR6%26SQ%3DPW%26TA%3D6O%26q%3D%252561%25256d%252570%252F%252573%252561%25256E%252564%252562%25256F%252578%25252E%252575%252573%25252E%252570%252572%25256F%252564%25252E%252561%252570%252569%25252E%252575%252570%252566%25256F%252572%252574%25252E%252563%25256F%25256D%25252F%25256C%252569%25256E%25256B%25252F%252565%252579%25254A%252573%252549%25256A%25256F%252569aHR0cHM6L
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.993796317342278 |
Encrypted: | false |
SSDEEP: | |
MD5: | 508FC1386EE27172AE8CA2460E89EEEC |
SHA1: | 9224755E259BCA9CDB7B65DD191EE9A540B9B0B6 |
SHA-256: | E02CAF0FF32E477A7A8945CCEF488BE8A21D1E3716C254A22794008A8D848C76 |
SHA-512: | 60BEF119076BA497193969B0B5713AA76272AE0520E876BB19ACA28CF480CA10FC82D43B85A64E44C1EB3392F1EF3E28D69CD810A81B01A88663AF36D89D0756 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 4.009086773222255 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0DF643660D65BAD2D475897462ED52D4 |
SHA1: | F21386A8BCD9FEF4D76E83D5B60D1EB9FA339957 |
SHA-256: | 5FA9C279494C911DDE04291795ED001BE8DB1061B1A9771CA50D6BBA460421FC |
SHA-512: | E9AB8749D835D2D91061133F79B7021EFBEAD36F7A92EB7CC69FD8B805D1B35416A3B4492C6F4F3F9DC6782FDA37A00E5BC2162BF9A35F914A8DE707579A6392 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.018007554754152 |
Encrypted: | false |
SSDEEP: | |
MD5: | 97408F3E71D4BE1C72556E4C1B5B515E |
SHA1: | 7C4AA4862A505F9431635C5ED91F7457C7979955 |
SHA-256: | D53C1BF443D31227D38010FB2EE99AF33BFB17117DE0CFD4A66E7826BEC83D89 |
SHA-512: | C889631882D6076B3B316D1497A276FADAD47946FCC3C7CCFCAE66C0E89628FD18D28FED2C9ABBAFC317078C6CCA690082674008028D56F2663C0ECF8C08AED9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 4.006698131009491 |
Encrypted: | false |
SSDEEP: | |
MD5: | 31A11CEBC6E87E023221D0D25A1A52B2 |
SHA1: | 418DF4B4C060CBEE479A5C4892CEC27FFAE18EAC |
SHA-256: | 46D469E5ED5B1F903959E087AB2B8F953F5F3712268C2391F7BAF263DF8B604C |
SHA-512: | 45C42682BB709EAB2271D7EF65AD1F3BFA7A9C5C3998BC7B9AF4A7FFD20F3B2C340DA9A880747DEB8E3CF63D05BE3256F03EA31B5274DF9BC731A95A956FA966 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.995632782020756 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9BE3D00C0F95FCD6B48190097147B2FC |
SHA1: | 7238AFD274AE4E97F2885E65770C29DAFFE1F416 |
SHA-256: | 6CF3FF5F8EE4B48E7491375F892750EF710E26B805945768ABED9C3CF8D51DE3 |
SHA-512: | 8028FD248C7F207D5A3E1A6D8C7EAFD875E9A0400EC1D2268954941CC47455BA9A5D9E0A17FE5DECD9A253F72CDB04F273064ECA025F4FD430670B86F19EA064 |
Malicious: | false |
Reputation: | unknown |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 4.001259982293753 |
Encrypted: | false |
SSDEEP: | |
MD5: | B0A1430A084E027A95AB13BB8D679734 |
SHA1: | 1AA917FB3C46F9177274E78555A1C337746ABE6B |
SHA-256: | 3FCBAB3A90431609D87FA058CFCB8905B835CC27F3CBE2265A941D03AE0A6621 |
SHA-512: | 112EAF825918B0FA9009B0401304F9D1CAD784111137648AF49ACA0A4AF6B6883E70C14186F660A9B57349E8DE9F9F86D9BE5EFB05983F46B919C9E9157D28AB |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2700 |
Entropy (8bit): | 5.404498031676358 |
Encrypted: | false |
SSDEEP: | |
MD5: | CA1283E0450D2543AB1896C928DDDA40 |
SHA1: | 449A5A0382F4D7CAE5FEBC1E8737E3F42CB62278 |
SHA-256: | E63F99F80FA6498669406B28DACE22088A93BF6DE20680BC887C6172A381211A |
SHA-512: | 1EBFF3E4F45A8136A68D20B0615B2F86881795AE7659343BF22CB2F7E6C64F712B60F47A477E205D838E1289C845A228B7AEB385615288CF28C7C9FAE36BE625 |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/404 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 648 |
Entropy (8bit): | 6.9444680008496515 |
Encrypted: | false |
SSDEEP: | |
MD5: | 3DE33DFA1B245F7553171CE3833B354D |
SHA1: | F4438771EB078C7A522DBC3993716216788FE613 |
SHA-256: | 811539B2DF228C281BACF0E9D94EABD239F9EFE1F97716F27071424A5F32A149 |
SHA-512: | 2805C3FB1EFF1919CA6DFD983EF714E1C9D5638BA63F35F087FE6681FD1710FB45B2ECC0E65BE230B3B23D002A29EFC235CC353E3DA2CD1069D82EDFB284E58D |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/images/shield-check-solid.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 549193 |
Entropy (8bit): | 5.440799036817487 |
Encrypted: | false |
SSDEEP: | |
MD5: | 6E65A57136F66F1A805A84D88C73EFB0 |
SHA1: | A2F504264EA295C294F2DF1CA1B906BB41E23EAA |
SHA-256: | 800EF65BCCBFC293578C2F91838AD7D275D23510CA7EE9550253D8386433D5A2 |
SHA-512: | A022717E6C7DECFA6C0ABD6A6AAB2049BF45C15815BC9C8B1028418AD8A95531018F2D1C824201B556A7046865D843F0A4DFD25FEA2BF2D2BBE2B32328368AB0 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8982 |
Entropy (8bit): | 7.9057836818765335 |
Encrypted: | false |
SSDEEP: | |
MD5: | AC1F68DFFF4C95D6173D3DF275C3C3C5 |
SHA1: | ECCD110D000BD792433131BA2085F2BE31DA98F0 |
SHA-256: | 7D286D640E6703FC4B2B1BCF474EDE14C215669F226F4A26C0281C183BD06FC1 |
SHA-512: | FB08053DC1E235720C3EC651E234CB8E42C3E3E2FDC59E71F95D1EE177A1EB0D24ACD2EDC32B256FFF05791D9910AD4E92E2E9888D3C5BC6F0012F5C2784576F |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 608 |
Entropy (8bit): | 6.976364509574518 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8556D7FB1D9C540E7019A123120F2EA7 |
SHA1: | F87AFB09A0F888F51EF230B843525260002B45BA |
SHA-256: | 7B3D59CC41CEC1E0B16DFB20140E18FA45553097959C630D5AE20A12935E5125 |
SHA-512: | 4008008B0ED7F1092C8EE2E7A06B590858A3163CD028FA71D3CFEE3D55DCEA6A56F0E47FE45408360BE46677771D4FC2B95AFCB0BB8AD4EE95843C258B7C79B5 |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/images/circle-blocked-solid.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 50 |
Entropy (8bit): | 4.21287868934203 |
Encrypted: | false |
SSDEEP: | |
MD5: | 48CEF5284EEBCF3B1380D6710357990C |
SHA1: | B381F3445730FEFD66485A85E761CF6323D59AD9 |
SHA-256: | CDFC8444656AA534028FB59331119A15CE73E5129435B877ED8AA11A65C91FA7 |
SHA-512: | 419F94B95EE23EE0AD5DEB4C1580C6A0C3E39C04D81E21DD9BCB6BC68823788F6A5D80B4BBB8ECBB52349010418D1F5910791C6C091299BD6D8432782DA224DA |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/app/config/config.json |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5371 |
Entropy (8bit): | 5.123544901248162 |
Encrypted: | false |
SSDEEP: | |
MD5: | 02EFC42E535F3957B39856795900CB0B |
SHA1: | C87B16C080AEE832CA6086AE4FAD27EB98C60780 |
SHA-256: | C02B9B424716C0BAF1BE2CB183899C6AE0252AB2DEBA23071FBD61DB4303338C |
SHA-512: | D1F6FC33A19881460AA8CCEA7F4007B5DCB8D6A2C628FAE9199B622C60D74A89815609F44F3CB581ECDF9B0AD44953FAE967F9136B024E35EC614F4323B18599 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 574 |
Entropy (8bit): | 7.003749898821409 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2FD4F7E868BDFC2783336BFF3023B54D |
SHA1: | 34B74C34C949FECFD9EF4D306461979E2B27FFE5 |
SHA-256: | 4D1957F26FD121F764E588060F2B27C97700D0E917F9102D57FB2FC3F281E5B7 |
SHA-512: | 60D38C7B09A42244E9576EEB98A856D5AC1C4654DB1491AF0A72BD0B7BD83AA377BE2F055C7A1309252996EBB9D95EC2D93A2EFFC110BBDFE1235C557BF5F55B |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/images/shield-loop-solid.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2181 |
Entropy (8bit): | 5.3095990683805665 |
Encrypted: | false |
SSDEEP: | |
MD5: | A403E98E25AC68FA90C5737E59F7587F |
SHA1: | FFA564511AF63DF85D75929EDA4CA027D2692130 |
SHA-256: | 6FF0F6C2CE32B910C69C182DD3BE48757F3022CB5CBCC06F0FCDB5C92A1F8974 |
SHA-512: | 9E279278C2F8DCFBB17F187981BF7C80555F38FD5BED88B6AA0ADC6A9E5A65770EC7905F36118F2EB32CE44DFF15B8E8A3C222BA7EC1E4F0E9D1E2957182E011 |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/218.0809266569f41ece.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 7568 |
Entropy (8bit): | 4.28627422479574 |
Encrypted: | false |
SSDEEP: | |
MD5: | E70A7FEA65196A80D6893563C6320B17 |
SHA1: | 391FBF6210CE6C3B0D4B47AADAB1B0D72F498CC0 |
SHA-256: | D3FED4BCC05BF65575D05CD3E7E90BA6200B13BD1B4FE0EDC3A20971BA08684B |
SHA-512: | 02C173F6AA606C525EE7280200004CAB99D8E9D014274717DDF5CED86286FC04E45033237EC3EBD7116626986AC80D601F43EF8369882125E2FA7DBEF99A49C5 |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/translations/en.json |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5861 |
Entropy (8bit): | 7.683707650541321 |
Encrypted: | false |
SSDEEP: | |
MD5: | E34F3DA43B467D6929B0BD59759517DE |
SHA1: | 374DFD60029B884AE5ACAA2A1B20E4D774D9FA83 |
SHA-256: | A97CC7904F4522EB52B27E13DB3E33A49F23B1C6AAB3CBD75C9B42B94D3EC84A |
SHA-512: | 23D6025F8025A7E098867D678BA0387718640949F3BEB74D0215577AB62452AE27E58918B1C95715729AD4F79B23CB99FA387C89936766A2125B92826B31D0F8 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5808 |
Entropy (8bit): | 7.899339536396948 |
Encrypted: | false |
SSDEEP: | |
MD5: | D53A85BF4EC9FCCB0D4D211B8D76DBAD |
SHA1: | ADEC794DB162E17B34C90BCEB69A2E5847496AD0 |
SHA-256: | 3747D2D6D30FD7EB538C98C936ED43912A4636B3F4D2C6FAB5F2FB144133D79C |
SHA-512: | 501BD8553402D69E33E37DD5FF31753B02CDCB49CD797BE8A67AF0B43531AD4FC95FA5A054A0BD7B5116F7FE7E4DF779DEB5647788496684830C40D782A450DA |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/images/completed.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 49920 |
Entropy (8bit): | 7.996426918774006 |
Encrypted: | true |
SSDEEP: | |
MD5: | 26506E803D3D8B51270718F8A93DA7FD |
SHA1: | 6D15EA085D9835E27535892C4212EE8F56E48384 |
SHA-256: | ECFE794CBBA27DA3987A32504E6A35AB5A5A67BD70D69B89444FAC4882DC5895 |
SHA-512: | BFEC060B60DAA1D2CA4B473F06C384B943C6F75B8F3428676783FF815A414CF0E9F0D5FC65789C556FB2AC14A6900026C0C55B8DCDBDB364400E2B9301F4FF97 |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/Hornet-SemiBold.bf9154546071add8.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2713 |
Entropy (8bit): | 5.308299534055227 |
Encrypted: | false |
SSDEEP: | |
MD5: | DB5CA089D76E4480D203D98FC45E13F6 |
SHA1: | 42A62C0C7742A97C1361BBA1BF33BCDB4C54B011 |
SHA-256: | 092242A628AF1705B1734CEC65C3A12364D3BDDAD337A20D5A900358A7577847 |
SHA-512: | FE88A4CAAB386A04544C3A25813854897C4282CED6723FC956A7A38783DE389506575FD0E1921DA2014DF21692A281B35EE3CB21210712536FCF1894433EF8CA |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/runtime.d608c7ed1d9c3996.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 34317 |
Entropy (8bit): | 5.395050154373031 |
Encrypted: | false |
SSDEEP: | |
MD5: | AD0E75BA8A3ECE9A1C9B77505FEE0CED |
SHA1: | 4592F816CCF9333A7300ED0792F2F0407C00297C |
SHA-256: | 5456382D2FBCD1FB337FCB90034B05A1A1A141F5D8E38165D416BF41B76F479D |
SHA-512: | CF28A7C734EEE86633BB81F634277AA6181F7C6B63253D4D7FF583784787BE8766D710D2B62E69051C6548773CA4355F64496E88A5A4CFD6CF38B71C974AF465 |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/polyfills.607595976de3afd5.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 8207 |
Entropy (8bit): | 5.175649761615389 |
Encrypted: | false |
SSDEEP: | |
MD5: | 36CE11FA3B14B9F4C950F1DB634D3E63 |
SHA1: | D844C00B783BA7E250563C19775E884AD2A32BE7 |
SHA-256: | 90EF5F750A447710E60902B4E4CD51BA95B38E2C6925DB2742ED5369F87017CF |
SHA-512: | A932B64849EF0CA20918C2B68868DBFFB5B7DCB587DC1342534F149473ECA3A8B4F6B5779C08A00C60F4B23D6916BF43CC2E3D9633C730D347EB92E6CF25D2EA |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/styles.291c02806014e652.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 48108 |
Entropy (8bit): | 7.995882110476692 |
Encrypted: | true |
SSDEEP: | |
MD5: | 5619FCCB91BD4D8B2847CD88A22BB8D7 |
SHA1: | 47C1A0C78B4FD45746FF3FCB1041BF96F5F45C27 |
SHA-256: | FB275F3A183E4552E77ED48A1BF545066596CE929F40CB72979C559D173F3795 |
SHA-512: | C61FDBBD1243C1C1B37A9737949A485DE4765A45EC3DE1CFED6992B90126E3B28B66FC22224B85232D084172AE9382F83FC5226E0B43D15CCF5EBD33A1CCEFAE |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/Hornet-Regular.021743c5464be55c.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2697 |
Entropy (8bit): | 5.4054827459209704 |
Encrypted: | false |
SSDEEP: | |
MD5: | 08738FBCE04A054614C61300403756C2 |
SHA1: | CF3A91B63BC1ED779A028CA64F32FB31F2782C64 |
SHA-256: | E203879546D1341B467FA935956F07FB9588F1CA2C48867D19109CE4CC01266F |
SHA-512: | 46E94CE918B5B8BFAD0B222960B6C72139C9F6F904F15B09B7693EDDDA153500A30807AD9A782C30AB97E378C9C20598462FEDD0BB5BC5B3E32EB1F75B2851CE |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/v4?d=CSvj-8b3fpwAumC6AbFMfEVmIT5ENJWTqrZHusAeFnU&f=Mzo1PUwZQd3evqHstuwR_5FCozrkJ9Jd1jGDrnrvcdluTk54zR-Gop3tgMHHrGpX90Gv7ZppU4ALGygldB7J0A&i=&k=bz9r&m=KuGpJb7F8ZjkKBdLnbtsoBlIPcr_V2YvhrjDwSG7wjDkh9t68btueC3me_khplS04Y1vkmcz2DALFAdsCPnXV9Y0e_KkoBmquE5hQxvQRCkIOVAxUSYrmBcZKNoh8NCT&n=3jw3xk5HrrJRpv5jkTsPtIA8SNg8pPkNVIChy5v4uioLwV8t1Qhw8Jl0rPecYr_z&r=Mi1JW6WUX7aRK4law3uJhl9L7Awt-TwJX20OR-eyQiCnjiN--PaFEdBZXBvOt4br&s=9e20e3b941956d702101ff1a86d29524b24c4f8158208c10cfbca279a872d30e&u=https%3A%2F%2Fwww.google.ca%2Furl%3Fn89vrc%3Dhttps%3A%2F%2Fwww.cookejackson.com%26bg%3DAJ%26SQ%3DPQ%26TA%3DR6%26SQ%3DPW%26TA%3D6O%26q%3D%252561%25256d%252570%252F%252573%252561%25256E%252564%252562%25256F%252578%25252E%252575%252573%25252E%252570%252572%25256F%252564%25252E%252561%252570%252569%25252E%252575%252570%252566%25256F%252572%252574%25252E%252563%25256F%25256D%25252F%25256C%252569%25256E%25256B%25252F%252565%252579%25254A%252573%252549%25256A%25256F%252569aHR0cHM6Ly9xM3oycDUuZGVrY2hvYnRpZXcuY29tL2Jvbm5pZS5wZXRlcnNlbkBnZWxpdGEuY29tIiwidSI6InVzZXItMGIzMzM5NWItZDE0OS00NzVkLTljMDMtZmExMGIxMjg1YTVmIiwiciI6ImFubmEudmFuY2VAbWFzb25vd2VuYW5kaGFsZS5jaCIsInYiOjF9%26opdg%3DSmo%26Uk4%3DRXM%26QTU%3DN3I%20Category%20Status%20Priority%20QuickActions |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5885 |
Entropy (8bit): | 7.633626076350842 |
Encrypted: | false |
SSDEEP: | |
MD5: | 49FFE68D82D0C1A1A75C081422CB67A7 |
SHA1: | BA7A91D0AEFAF9A1B9341DDF9C6DA7487B636389 |
SHA-256: | 44068129BD4515CD320B5BAFAE65BE2763C0FFC9080BFE8147D613146546DA67 |
SHA-512: | 598C6978F6D188FCCE61B4B3B506996362AEABA86835300226AD47BCE8F577614CE5F8B61A06EFB7B5786BDF727221B6D3A9F8F3537DCF28747CDFB688D8C7A4 |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/images/logo.png |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 67646 |
Entropy (8bit): | 2.212959767992868 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0B2B04040BC6EE5E6F123D5316A8407A |
SHA1: | 17AED11945C5EF8021A97F13162F06D5F7E65CEC |
SHA-256: | 3862DB4922F99149C6E1CA3EAC9743A9980CB60546E7E76269717C4CDC5236FE |
SHA-512: | E069431349CCB8403603BAE40B641DBB21DCB5461295B6E9AD8F08A03894F9DBD3E49B270D980926C7009BF45118C4CC0A990534D10F572DB4BCEC7C872A1919 |
Malicious: | false |
Reputation: | unknown |
URL: | https://securelinks.cloud-security.net/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 18047 |
Entropy (8bit): | 5.424910363050938 |
Encrypted: | false |
SSDEEP: | |
MD5: | 74A115C2AB3173B22F7D3D392B047946 |
SHA1: | 44B6B66DDA2B934EA8F8C0996CC860F17A639C25 |
SHA-256: | CC3E0F33193785EA654E0C48C5AB249D6016BBA7E7F750A13A451867DFC87F62 |
SHA-512: | B561E297985F9573E3E1762048C1F888F5E46E0F73FA7CDE7E334B0DE361A698D43AC07A194183C400F53EE5CCBA42A903E87244639E27DE52AEFD2D8916EBD3 |
Malicious: | false |
Reputation: | unknown |
Preview: |