Windows Analysis Report
https://1drv.ms/f/c/4cc2c3970781876c/Emubibgy1S9CjBV3sD2cI4EBCsEw6xIoHLgTyUgbzesCkw?e=Tt2kD9

Overview

General Information

Sample URL: https://1drv.ms/f/c/4cc2c3970781876c/Emubibgy1S9CjBV3sD2cI4EBCsEw6xIoHLgTyUgbzesCkw?e=Tt2kD9
Analysis ID: 1592374
Infos:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Drops files with a non-matching file extension (content does not match file extension)

Classification

Source: https://signup.live.com/signup?wreply=https%3A%2F%2Fonedrive.live.com%2F%3Fid%3Droot&lw=1&fl=easi2&lic=1 HTTP Parser: No favicon
Source: https://signup.live.com/signup?wreply=https%3A%2F%2Fonedrive.live.com%2F%3Fid%3Droot&lw=1&fl=easi2&lic=1 HTTP Parser: No favicon
Source: https://signup.live.com/signup?wreply=https%3A%2F%2Fonedrive.live.com%2F%3Fid%3Droot&lw=1&fl=easi2&lic=1 HTTP Parser: No favicon
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /redir?cid=4cc2c3970781876c&resid=4CC2C3970781876C!sb8899b6bd532422f8c1577b03d9c2381&ithint=folder&e=Tt2kD9&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL2YvYy80Y2MyYzM5NzA3ODE4NzZjL0VtdWJpYmd5MVM5Q2pCVjNzRDJjSTRFQkNzRXc2eElvSExnVHlVZ2J6ZXNDa3c_ZT1UdDJrRDk HTTP/1.1Host: onedrive.live.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /?id=4CC2C3970781876C!sb8899b6bd532422f8c1577b03d9c2381&resid=4CC2C3970781876C!sb8899b6bd532422f8c1577b03d9c2381&cid=4cc2c3970781876c&ithint=folder&redeem=aHR0cHM6Ly8xZHJ2Lm1zL2YvYy80Y2MyYzM5NzA3ODE4NzZjL0VtdWJpYmd5MVM5Q2pCVjNzRDJjSTRFQkNzRXc2eElvSExnVHlVZ2J6ZXNDa3c_ZT1UdDJrRDk&migratedtospo=true HTTP/1.1Host: onedrive.live.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: E=P:4YshT8k13Yg=:yffeS95WdIWvhjg6d3/jOtQQ8JACmfwiBvm4VPXn9E8=:F; xid=809e4879-9080-4bfc-9dad-d47e16fc8c31&&ODSP-ODWEB-ODCF&48; xidseq=1
Source: global traffic HTTP traffic detected: GET /_layouts/15/spwebworkerproxy.ashx HTTP/1.1Host: onedrive.live.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: E=P:4YshT8k13Yg=:yffeS95WdIWvhjg6d3/jOtQQ8JACmfwiBvm4VPXn9E8=:F; xid=809e4879-9080-4bfc-9dad-d47e16fc8c31&&ODSP-ODWEB-ODCF&48; xidseq=1
Source: global traffic HTTP traffic detected: GET /_layouts/15/spwebworkerproxy.ashx HTTP/1.1Host: onedrive.live.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: E=P:4YshT8k13Yg=:yffeS95WdIWvhjg6d3/jOtQQ8JACmfwiBvm4VPXn9E8=:F; xid=809e4879-9080-4bfc-9dad-d47e16fc8c31&&ODSP-ODWEB-ODCF&48; xidseq=1
Source: global traffic HTTP traffic detected: GET /_layouts/15/images/BLANK.gif HTTP/1.1Host: onedrive.live.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://onedrive.live.com/?id=4CC2C3970781876C%21sb8899b6bd532422f8c1577b03d9c2381&resid=4CC2C3970781876C%21sb8899b6bd532422f8c1577b03d9c2381&cid=4cc2c3970781876c&ithint=folder&redeem=aHR0cHM6Ly8xZHJ2Lm1zL2YvYy80Y2MyYzM5NzA3ODE4NzZjL0VtdWJpYmd5MVM5Q2pCVjNzRDJjSTRFQkNzRXc2eElvSExnVHlVZ2J6ZXNDa3c%5FZT1UdDJrRDk&migratedtospo=true&v=validatepermissionAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: E=P:4YshT8k13Yg=:yffeS95WdIWvhjg6d3/jOtQQ8JACmfwiBvm4VPXn9E8=:F; xid=809e4879-9080-4bfc-9dad-d47e16fc8c31&&ODSP-ODWEB-ODCF&48; xidseq=1
Source: global traffic HTTP traffic detected: GET /_layouts/15/images/BLANK.gif HTTP/1.1Host: onedrive.live.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: E=P:4YshT8k13Yg=:yffeS95WdIWvhjg6d3/jOtQQ8JACmfwiBvm4VPXn9E8=:F; xid=809e4879-9080-4bfc-9dad-d47e16fc8c31&&ODSP-ODWEB-ODCF&48; xidseq=1; FeatureOverrides_experiments=[]
Source: global traffic HTTP traffic detected: GET /_layouts/15/images/odbfavicon.ico?rev=47 HTTP/1.1Host: onedrive.live.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://onedrive.live.com/?id=4CC2C3970781876C%21sb8899b6bd532422f8c1577b03d9c2381&resid=4CC2C3970781876C%21sb8899b6bd532422f8c1577b03d9c2381&cid=4cc2c3970781876c&ithint=folder&redeem=aHR0cHM6Ly8xZHJ2Lm1zL2YvYy80Y2MyYzM5NzA3ODE4NzZjL0VtdWJpYmd5MVM5Q2pCVjNzRDJjSTRFQkNzRXc2eElvSExnVHlVZ2J6ZXNDa3c%5FZT1UdDJrRDk&migratedtospo=true&v=validatepermissionAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: E=P:4YshT8k13Yg=:yffeS95WdIWvhjg6d3/jOtQQ8JACmfwiBvm4VPXn9E8=:F; xid=809e4879-9080-4bfc-9dad-d47e16fc8c31&&ODSP-ODWEB-ODCF&48; xidseq=1; FeatureOverrides_experiments=[]
Source: global traffic HTTP traffic detected: GET /_layouts/15/images/odbfavicon.ico?rev=47 HTTP/1.1Host: onedrive.live.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: E=P:4YshT8k13Yg=:yffeS95WdIWvhjg6d3/jOtQQ8JACmfwiBvm4VPXn9E8=:F; xid=809e4879-9080-4bfc-9dad-d47e16fc8c31&&ODSP-ODWEB-ODCF&48; xidseq=1; FeatureOverrides_experiments=[]
Source: global traffic HTTP traffic detected: GET /webappmanifest.json HTTP/1.1Host: onedrive.live.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: manifestReferer: https://onedrive.live.com/?id=4CC2C3970781876C%21sb8899b6bd532422f8c1577b03d9c2381&resid=4CC2C3970781876C%21sb8899b6bd532422f8c1577b03d9c2381&cid=4cc2c3970781876c&ithint=folder&redeem=aHR0cHM6Ly8xZHJ2Lm1zL2YvYy80Y2MyYzM5NzA3ODE4NzZjL0VtdWJpYmd5MVM5Q2pCVjNzRDJjSTRFQkNzRXc2eElvSExnVHlVZ2J6ZXNDa3c%5FZT1UdDJrRDk&migratedtospo=true&v=validatepermissionAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: E=P:4YshT8k13Yg=:yffeS95WdIWvhjg6d3/jOtQQ8JACmfwiBvm4VPXn9E8=:F; xid=809e4879-9080-4bfc-9dad-d47e16fc8c31&&ODSP-ODWEB-ODCF&48; xidseq=1; FeatureOverrides_experiments=[]
Source: global traffic HTTP traffic detected: GET /v1.0/token HTTP/1.1Host: api-badgerp.svc.msConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_api/v2.0/shares/u!aHR0cHM6Ly8xZHJ2Lm1zL2YvYy80Y2MyYzM5NzA3ODE4NzZjL0VtdWJpYmd5MVM5Q2pCVjNzRDJjSTRFQkNzRXc2eElvSExnVHlVZ2J6ZXNDa3c_ZT1UdDJrRDk/driveitem?%24select=id%2CparentReference HTTP/1.1Host: my.microsoftpersonalcontent.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_api/v2.0/drives/4cc2c3970781876c/items/4CC2C3970781876C!sb8899b6bd532422f8c1577b03d9c2381?%24expand=thumbnails&%24select=*%2CcontainingDrivePolicyScenarioViewpoint%2Cocr%2CwebDavUrl&ump=1 HTTP/1.1Host: my.microsoftpersonalcontent.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_api/v2.0/drives/4cc2c3970781876c/items/4CC2C3970781876C!sb8899b6bd532422f8c1577b03d9c2381/children?%24top=100&orderby=folder%2Cname&%24expand=tags&select=*%2Cocr%2CwebDavUrl%2CsharepointIds%2CisRestricted%2CcommentSettings%2CspecialFolder%2CcontainingDrivePolicyScenarioViewpoint&ump=1 HTTP/1.1Host: my.microsoftpersonalcontent.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_api/v2.0/drives/4cc2c3970781876c/items/4CC2C3970781876C!sb8899b6bd532422f8c1577b03d9c2381?%24select=*%2CsharepointIds%2CwebDavUrl%2CcontainingDrivePolicyScenarioViewpoint&%24expand=thumbnails&ump=1 HTTP/1.1Host: my.microsoftpersonalcontent.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /_api/v2.0/drives/4cc2c3970781876c/items/root?%24expand=thumbnails&%24select=*%2CcontainingDrivePolicyScenarioViewpoint%2Cocr%2CwebDavUrl&ump=1 HTTP/1.1Host: my.microsoftpersonalcontent.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /mydata/myprofile/expressionprofile/profilephoto:UserTileStatic,UserTileSmall/MeControlMediumUserTile?ck=1&ex=24&fofoff=1&sc=1736989316718 HTTP/1.1Host: storage.live.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://onedrive.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: xid=809e4879-9080-4bfc-9dad-d47e16fc8c31&&ODSP-ODWEB-ODCF&48; E=P:0s5MV8k13Yg=:7iDuDhoYIanV1FB0KDMky7yjcLwppS6Q/HIWiDEP7Do=:F; xidseq=2; wla42=
Source: global traffic HTTP traffic detected: GET /_api/v2.0/drives/4CC2C3970781876C/items/4CC2C3970781876C!s2b4b6d4d10b543008f808d3979749a5b?select=id%2C%40content.downloadUrl HTTP/1.1Host: my.microsoftpersonalcontent.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Accept: application/jsonAccept-Language: en-USsec-ch-ua-mobile: ?0Authorization: Badger eyJhbGciOiJSUzI1NiIsImtpZCI6IjEzQTAwRkQ1MEEzMEM1MTVDQjYzMDNFREI3NEE2MTlBNzQ0NUQzRkEiLCJ4NXQiOiJFNkFQMVFvd3hSWExZd1B0dDBwaG1uUkYwX28iLCJ0eXAiOiJKV1QifQ.eyJhdWQiOiJodHRwczovL29uZWRyaXZlLmNvbS8iLCJpc3MiOiJodHRwczovL2JhZGdlci5zdmMubXMvdjEuMC9hdXRoIiwiZXhwIjoxNzM3NTk0MTA1LCJuYmYiOjE3MzY5ODkzMDUsImdpdmVuX25hbWUiOiI2NyIsImZhbWlseV9uYW1lIjoiU3dhbGxvdyIsImh0dHA6Ly9zY2hlbWFzLnhtbHNvYXAub3JnL3dzLzIwMDUvMDUvaWRlbnRpdHkvY2xhaW1zL3NpZCI6ImI1NTE4MDU2N2UzYTkwOTc0Yzk3YzNkODM1MDU5NzBhIiwiYXBwaWQiOiI1Y2JlZDZhYy1hMDgzLTRlMTQtYjE5MS1iNGJhMDc2NTNkZTIiLCJpYXQiOjE3MzY5ODkzMDV9.g0zHMfOIuNNVq76EeURSpKoSHzHnVefeZcMoQAdiMtp9VbdRyzzDTQVIATiQsute66KjnbtJqFExAKcpHjGM3v0spMWdJJCdNyGe5p3pZTP8yM93c06JItRsKkqUktWiERcIJGE2A7a1JXbz6P2a5m-4vXjF5xA3jD3t6GdmnKn3x7BMFgEtkpr_UAE5f1s3auOjRJ85VtRt0OSu5-j4k_fAZRDzMQoYTSmbeK8FfXsp1VWA08rGR10wWpGUDSg_QBYCyPb9jG044gv1WouXWa0_Yf-PQPCrsClq_tet7DkwRybmYjCjNeVdBatqrepyc7C1JXvT6OCyGWaPYvC77QUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Origin: https://onedrive.live.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://onedrive.live.com/Accept-Encoding: gzip, deflate, br
Source: global traffic HTTP traffic detected: GET /_api/v2.0/drives/4CC2C3970781876C/items/4CC2C3970781876C!s2b4b6d4d10b543008f808d3979749a5b?select=id%2C%40content.downloadUrl HTTP/1.1Host: my.microsoftpersonalcontent.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /personal/4cc2c3970781876c/_layouts/15/download.aspx?UniqueId=2b4b6d4d-10b5-4300-8f80-8d3979749a5b&Translate=false&tempauth=v1e.eyJzaXRlaWQiOiI2YzY4NGQ1YS1lODc5LTQ3ZjctOWVlZS1kYjhkMjMyMmU3MTUiLCJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvbXkubWljcm9zb2Z0cGVyc29uYWxjb250ZW50LmNvbUA5MTg4MDQwZC02YzY3LTRjNWItYjExMi0zNmEzMDRiNjZkYWQiLCJleHAiOiIxNzM2OTkyOTM0In0.Iw4bORjBbSKQmYbO2v1r27hlv4EdHsercMppHuTQssZ77mX1j85HIB-Oh7HkCJu5p2MtHvpV38gvu2k-qjD8DCrxSOy23vKtc9zMwAXe72UHmEl21PJ8kGzSRvAX4FflYFIJSk-K24JeSLK8DxcDQEOdugEc6zM62UxBoEiJwARaugAWZ58TXEKPYP_Wdz7o229ixSLdp-DqqOPtFRyLRq2LQIo2igXP4haYIskqe3v2DUookFAv_CQ5ZTVO6eKRvLj7kFdlJUTA56upLy5RuxF1YTdGvzNr-5OOFiYiE5IDhpFXaELYNqNPlJroThxvdNT0suLGCLNl9PWL1IFxYJfWrVvORMRrgsolNG6LdfsO8iPK5K4ugqtuqJAH6zjFp-SnSQp7xI61Q1i3rEJcPzPR1fB5WW0sZ3zCjmZMqd6G_2sQQ0a6S7ZcwcjSxynFtQhRDkJ48CEPFAOkrdTvz0IZPmHvZolBn4Py_87ttOIbOLBSqkOXduCzZ0YPCQKFLK-Hlidj02bzyEL-ESmjyg.CkVa1fhkLBEc06EGQozZwKF5vQwz6hJAnf5OxAImX08&ApiVersion=2.0 HTTP/1.1Host: my.microsoftpersonalcontent.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://onedrive.live.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://onedrive.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /personal/4cc2c3970781876c/_layouts/15/download.aspx?UniqueId=2b4b6d4d-10b5-4300-8f80-8d3979749a5b&Translate=false&tempauth=v1e.eyJzaXRlaWQiOiI2YzY4NGQ1YS1lODc5LTQ3ZjctOWVlZS1kYjhkMjMyMmU3MTUiLCJhdWQiOiIwMDAwMDAwMy0wMDAwLTBmZjEtY2UwMC0wMDAwMDAwMDAwMDAvbXkubWljcm9zb2Z0cGVyc29uYWxjb250ZW50LmNvbUA5MTg4MDQwZC02YzY3LTRjNWItYjExMi0zNmEzMDRiNjZkYWQiLCJleHAiOiIxNzM2OTkyOTM0In0.Iw4bORjBbSKQmYbO2v1r27hlv4EdHsercMppHuTQssZ77mX1j85HIB-Oh7HkCJu5p2MtHvpV38gvu2k-qjD8DCrxSOy23vKtc9zMwAXe72UHmEl21PJ8kGzSRvAX4FflYFIJSk-K24JeSLK8DxcDQEOdugEc6zM62UxBoEiJwARaugAWZ58TXEKPYP_Wdz7o229ixSLdp-DqqOPtFRyLRq2LQIo2igXP4haYIskqe3v2DUookFAv_CQ5ZTVO6eKRvLj7kFdlJUTA56upLy5RuxF1YTdGvzNr-5OOFiYiE5IDhpFXaELYNqNPlJroThxvdNT0suLGCLNl9PWL1IFxYJfWrVvORMRrgsolNG6LdfsO8iPK5K4ugqtuqJAH6zjFp-SnSQp7xI61Q1i3rEJcPzPR1fB5WW0sZ3zCjmZMqd6G_2sQQ0a6S7ZcwcjSxynFtQhRDkJ48CEPFAOkrdTvz0IZPmHvZolBn4Py_87ttOIbOLBSqkOXduCzZ0YPCQKFLK-Hlidj02bzyEL-ESmjyg.CkVa1fhkLBEc06EGQozZwKF5vQwz6hJAnf5OxAImX08&ApiVersion=2.0 HTTP/1.1Host: my.microsoftpersonalcontent.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ns?c=900e8530-d3a5-11ef-befa-8f06733f016a HTTP/1.1Host: stk.hsprotect.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://msft.hsprotect.netSec-Fetch-Site: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://msft.hsprotect.net/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /api/v2/msft HTTP/1.1Host: collector-pxzc5j78di.hsprotect.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ns?c=900e8530-d3a5-11ef-befa-8f06733f016a HTTP/1.1Host: stk.hsprotect.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /api/v2/msft HTTP/1.1Host: collector-pxzc5j78di.hsprotect.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /api/v2/msft HTTP/1.1Host: collector-pxzc5j78di.hsprotect.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: 1drv.ms
Source: global traffic DNS traffic detected: DNS query: onedrive.live.com
Source: global traffic DNS traffic detected: DNS query: m365cdn.nel.measure.office.net
Source: global traffic DNS traffic detected: DNS query: api.onedrive.com
Source: global traffic DNS traffic detected: DNS query: p.sfx.ms
Source: global traffic DNS traffic detected: DNS query: api-badgerp.svc.ms
Source: global traffic DNS traffic detected: DNS query: my.microsoftpersonalcontent.com
Source: global traffic DNS traffic detected: DNS query: storage.live.com
Source: global traffic DNS traffic detected: DNS query: signup.live.com
Source: global traffic DNS traffic detected: DNS query: logincdn.msftauth.net
Source: global traffic DNS traffic detected: DNS query: fpt.live.com
Source: global traffic DNS traffic detected: DNS query: msft.hsprotect.net
Source: global traffic DNS traffic detected: DNS query: client.hsprotect.net
Source: global traffic DNS traffic detected: DNS query: stk.hsprotect.net
Source: global traffic DNS traffic detected: DNS query: collector-pxzc5j78di.hsprotect.net
Source: global traffic DNS traffic detected: DNS query: spo.nel.measure.office.net
Source: unknown HTTP traffic detected: POST /v1.0/token HTTP/1.1Host: api-badgerp.svc.msConnection: keep-aliveContent-Length: 48sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/json;odata=verboseAccept: application/jsonCache-Control: privateAppId: 1141147648X-ForceCache: 1sec-ch-ua-platform: "Windows"Origin: https://onedrive.live.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://onedrive.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: chromecache_318.1.dr, chromecache_388.1.dr, chromecache_504.1.dr, chromecache_512.1.dr String found in binary or memory: http://fb.me/use-check-prop-types
Source: chromecache_298.1.dr String found in binary or memory: http://www.opensource.org/licenses/mit-license.php
Source: chromecache_336.1.dr String found in binary or memory: http://www.unicode.org/copyright.html
Source: chromecache_357.1.dr, chromecache_248.1.dr String found in binary or memory: https://1drv.com/
Source: chromecache_254.1.dr, chromecache_487.1.dr String found in binary or memory: https://api.onedrive.com/inappmessaging/v1/messages
Source: chromecache_486.1.dr String found in binary or memory: https://client.hsprotect.net/PXzC5j78di/main.min.js
Source: chromecache_458.1.dr, chromecache_312.1.dr String found in binary or memory: https://feross.org
Source: chromecache_458.1.dr, chromecache_312.1.dr String found in binary or memory: https://feross.org/opensource
Source: chromecache_483.1.dr, chromecache_311.1.dr String found in binary or memory: https://floodgatesurveyschema.svc.cloud.microsoft/be998278-ae33-41a3-a032-f8020d1a9379/0777467b-557e
Source: chromecache_502.1.dr String found in binary or memory: https://fpt.live.com/
Source: chromecache_276.1.dr, chromecache_526.1.dr String found in binary or memory: https://g.live.com/8SESkyDrive/SkyDriveApps?biciid=lhnlink
Source: chromecache_249.1.dr, chromecache_440.1.dr String found in binary or memory: https://github.com/uuidjs/uuid#getrandomvalues-not-supported
Source: chromecache_357.1.dr, chromecache_248.1.dr String found in binary or memory: https://livefilestore.com/
Source: chromecache_458.1.dr, chromecache_312.1.dr String found in binary or memory: https://localcdn.centro-dev.com:5555/floodgate.bundle.js.map
Source: chromecache_254.1.dr, chromecache_487.1.dr String found in binary or memory: https://my.microsoftpersonalcontent.com
Source: chromecache_447.1.dr, chromecache_250.1.dr String found in binary or memory: https://onedrive.live.com/?id=
Source: chromecache_383.1.dr String found in binary or memory: https://onedrive.live.com/_forms/default.aspx
Source: chromecache_383.1.dr String found in binary or memory: https://onedrive.live.com/_forms/default.aspx?ReturnUrl=%2F%3Fview%3D1%26id%3D4CC2C3970781876C%21sb8
Source: chromecache_447.1.dr, chromecache_250.1.dr String found in binary or memory: https://onedrive.live.com/edit.aspx?resid=
Source: chromecache_254.1.dr, chromecache_487.1.dr String found in binary or memory: https://portal.office.com/
Source: chromecache_290.1.dr, chromecache_424.1.dr String found in binary or memory: https://pub-d140030cf41742a0819817717ecea2d0.r2.dev/xxc.html)
Source: chromecache_457.1.dr String found in binary or memory: https://reactjs.org/link/react-polyfills
Source: chromecache_361.1.dr, chromecache_383.1.dr, chromecache_413.1.dr String found in binary or memory: https://res-1.cdn.office.net
Source: chromecache_268.1.dr, chromecache_457.1.dr String found in binary or memory: https://res-1.cdn.office.net/files/fabric-cdn-prod_20230815.002/assets
Source: chromecache_247.1.dr, chromecache_344.1.dr, chromecache_383.1.dr String found in binary or memory: https://res-1.cdn.office.net/files/odsp-web-prod_2025-01-03.002/
Source: chromecache_247.1.dr, chromecache_344.1.dr String found in binary or memory: https://res-1.cdn.office.net/files/odsp-web-prod_2025-01-03.002/spwebworker.js
Source: chromecache_383.1.dr String found in binary or memory: https://res-1.cdn.office.net/files/sp-client/odsp-media-08c82b19
Source: chromecache_383.1.dr String found in binary or memory: https://res-2.cdn.office.net/files/odsp-web-prod_2025-01-03.002/
Source: chromecache_272.1.dr String found in binary or memory: https://res.cdn.office.net/admincenter/admin-main/2025.1.6.4/
Source: chromecache_272.1.dr String found in binary or memory: https://res.cdn.office.net/admincenter/admin-main/2025.1.6.4/floodgate.en.bundle.js
Source: chromecache_383.1.dr String found in binary or memory: https://skyapi.onedrive.live.com
Source: chromecache_383.1.dr String found in binary or memory: https://spoprod-a.akamaihd.net/files/odsp-common-library-prod_2019-02-15_20190219.002/require.js
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/leelawadeeui-thai/leelawadeeui-bold.w
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/leelawadeeui-thai/leelawadeeui-regula
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/leelawadeeui-thai/leelawadeeui-semili
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-bold.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-bold.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-light.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-light.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-regular.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-regular.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-semibold.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-semibold.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-arabic/segoeui-semilight.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-bold.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-bold.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-light.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-light.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-regular.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-semibold.wof
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-cyrillic/segoeui-semilight.wo
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-bold.wof
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-light.wo
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-regular.
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-semibold
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-easteuropean/segoeui-semiligh
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-bold.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-bold.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-light.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-light.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-regular.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-regular.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semibold.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semibold.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semilight.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-greek/segoeui-semilight.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-bold.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-bold.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-light.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-light.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-regular.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-regular.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-semibold.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-semibold.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-hebrew/segoeui-semilight.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-bold.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-bold.woff2
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-light.woff
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-regular.wo
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-semibold.w
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-vietnamese/segoeui-semilight.
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-bold.wof
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-light.wo
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-regular.
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-semibold
Source: chromecache_496.1.dr String found in binary or memory: https://static2.sharepointonline.com/files/fabric/assets/fonts/segoeui-westeuropean/segoeui-semiligh
Source: chromecache_361.1.dr, chromecache_413.1.dr String found in binary or memory: https://www.onedrive-tst.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49985
Source: unknown Network traffic detected: HTTP traffic on port 49926 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49949 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49916 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49898 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50221 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49819
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49938
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49936
Source: unknown Network traffic detected: HTTP traffic on port 49902 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49934
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49933
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49898
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49925 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50064 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50274 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50064
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50221
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50066
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50220
Source: unknown Network traffic detected: HTTP traffic on port 50240 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50268
Source: unknown Network traffic detected: HTTP traffic on port 49936 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49985 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49876 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49911 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50072
Source: unknown Network traffic detected: HTTP traffic on port 50268 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49926
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49925
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49924
Source: unknown Network traffic detected: HTTP traffic on port 50250 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50084 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50233 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49920
Source: unknown Network traffic detected: HTTP traffic on port 49924 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49884
Source: unknown Network traffic detected: HTTP traffic on port 49819 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50076
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50274
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50232
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50076 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50233
Source: unknown Network traffic detected: HTTP traffic on port 49828 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49933 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50084
Source: unknown Network traffic detected: HTTP traffic on port 50163 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49916
Source: unknown Network traffic detected: HTTP traffic on port 50066 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50232 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49911
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49910
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49876
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49874
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50163
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50240
Source: unknown Network traffic detected: HTTP traffic on port 49874 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50220 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49910 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50072 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49934 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50250
Source: unknown Network traffic detected: HTTP traffic on port 49938 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49828
Source: unknown Network traffic detected: HTTP traffic on port 49884 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49949
Source: unknown Network traffic detected: HTTP traffic on port 49920 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49902
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: classification engine Classification label: clean0.win@20/451@56/9
Source: chromecache_290.1.dr Initial sample: https://pub-d140030cf41742a0819817717ecea2d0.r2.dev/xxc.html
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1916 --field-trial-handle=1984,i,11941159772521316494,18071558179849026029,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://1drv.ms/f/c/4cc2c3970781876c/Emubibgy1S9CjBV3sD2cI4EBCsEw6xIoHLgTyUgbzesCkw?e=Tt2kD9"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1916 --field-trial-handle=1984,i,11941159772521316494,18071558179849026029,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 424 Jump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 290
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 290 Jump to dropped file
Source: chromecache_447.1.dr, chromecache_458.1.dr, chromecache_250.1.dr, chromecache_312.1.dr Binary or memory string: ",ConnectVirtualMachine:"
Source: chromecache_447.1.dr, chromecache_458.1.dr, chromecache_250.1.dr, chromecache_312.1.dr Binary or memory string: ",DisconnectVirtualMachine:"
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs