Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Chrome Cache Entry: 100
|
ASCII text, with very long lines (8146), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 101
|
PNG image data, 89 x 18, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 102
|
HTML document, Unicode text, UTF-8 text, with very long lines (1049), with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 103
|
ASCII text, with very long lines (1361), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 104
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 105
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1592
|
downloaded
|
||
Chrome Cache Entry: 106
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 107
|
PNG image data, 89 x 18, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 108
|
ASCII text, with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 109
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 110
|
ASCII text, with very long lines (61363)
|
downloaded
|
||
Chrome Cache Entry: 111
|
PNG image data, 338 x 72, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 112
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 444227
|
downloaded
|
||
Chrome Cache Entry: 113
|
ASCII text, with very long lines (65371)
|
downloaded
|
||
Chrome Cache Entry: 114
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 115
|
ASCII text, with very long lines (65291)
|
downloaded
|
||
Chrome Cache Entry: 116
|
PNG image data, 17 x 25, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 117
|
ASCII text, with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 118
|
PNG image data, 16 x 25, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 119
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 120
|
MS Windows icon resource - 4 icons, 64x64, 32 bits/pixel, 32x32, 32 bits/pixel
|
dropped
|
||
Chrome Cache Entry: 121
|
ASCII text, with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 122
|
ASCII text, with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 123
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1592
|
dropped
|
||
Chrome Cache Entry: 124
|
GIF image data, version 89a, 352 x 3
|
dropped
|
||
Chrome Cache Entry: 125
|
ASCII text, with very long lines (39257), with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 126
|
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
|
downloaded
|
||
Chrome Cache Entry: 127
|
PNG image data, 60 x 60, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 128
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 223759
|
downloaded
|
||
Chrome Cache Entry: 129
|
PNG image data, 16 x 25, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 130
|
ASCII text, with very long lines (32044), with escape sequences
|
downloaded
|
||
Chrome Cache Entry: 131
|
ASCII text, with very long lines (32003)
|
downloaded
|
||
Chrome Cache Entry: 132
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
|
downloaded
|
||
Chrome Cache Entry: 133
|
GIF image data, version 89a, 352 x 3
|
dropped
|
||
Chrome Cache Entry: 134
|
PNG image data, 89 x 18, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 135
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 136
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 137
|
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 138
|
GIF image data, version 89a, 352 x 3
|
downloaded
|
||
Chrome Cache Entry: 139
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 140
|
Unicode text, UTF-8 (with BOM) text
|
downloaded
|
||
Chrome Cache Entry: 141
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 142
|
ASCII text, with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 143
|
GIF image data, version 89a, 22 x 22
|
downloaded
|
||
Chrome Cache Entry: 144
|
MS Windows icon resource - 8 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel,
256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
|
dropped
|
||
Chrome Cache Entry: 145
|
PNG image data, 89 x 18, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 146
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 55071
|
downloaded
|
||
Chrome Cache Entry: 147
|
GIF image data, version 89a, 22 x 22
|
dropped
|
||
Chrome Cache Entry: 148
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 149
|
GIF image data, version 89a, 24 x 24
|
downloaded
|
||
Chrome Cache Entry: 150
|
HTML document, ASCII text, with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 151
|
ASCII text, with very long lines (65447)
|
downloaded
|
||
Chrome Cache Entry: 152
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
|
dropped
|
||
Chrome Cache Entry: 153
|
GIF image data, version 89a, 352 x 3
|
downloaded
|
||
Chrome Cache Entry: 154
|
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
|
dropped
|
||
Chrome Cache Entry: 155
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 156
|
ASCII text, with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 157
|
MS Windows icon resource - 8 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel,
256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
|
downloaded
|
||
Chrome Cache Entry: 158
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113084
|
downloaded
|
||
Chrome Cache Entry: 159
|
ASCII text, with very long lines (65291)
|
downloaded
|
||
Chrome Cache Entry: 160
|
GIF image data, version 89a, 24 x 24
|
dropped
|
||
Chrome Cache Entry: 161
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113657
|
downloaded
|
||
Chrome Cache Entry: 162
|
PNG image data, 338 x 72, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 163
|
ASCII text, with very long lines (28900)
|
downloaded
|
||
Chrome Cache Entry: 87
|
ASCII text, with very long lines (65329), with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 88
|
HTML document, ASCII text, with very long lines (2345), with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 89
|
HTML document, Unicode text, UTF-8 text, with very long lines (941), with CRLF line terminators
|
dropped
|
||
Chrome Cache Entry: 90
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
|
downloaded
|
||
Chrome Cache Entry: 91
|
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 92
|
PNG image data, 60 x 60, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 93
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
|
dropped
|
||
Chrome Cache Entry: 94
|
MS Windows icon resource - 4 icons, 64x64, 32 bits/pixel, 32x32, 32 bits/pixel
|
downloaded
|
||
Chrome Cache Entry: 95
|
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 141320
|
downloaded
|
||
Chrome Cache Entry: 96
|
Unicode text, UTF-8 text, with very long lines (65500)
|
downloaded
|
||
Chrome Cache Entry: 97
|
PNG image data, 17 x 25, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 98
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 99
|
ASCII text
|
downloaded
|
There are 68 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2164 --field-trial-handle=1988,i,9110740969243465056,422628057034115576,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://aka.ms/vmsettings"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://aka.ms/vmsettings
|
|||
http://fontawesome.io
|
unknown
|
||
https://login.microsoftonline.com/
|
unknown
|
||
https://login.microsoftonline.com
|
unknown
|
||
https://github.com/AzureAD/microsoft-authentication-library-for-js/blob/dev/lib/msal-browser/docs/ac
|
unknown
|
||
http://getbootstrap.com)
|
unknown
|
||
https://github.com/twbs/bootstrap/blob/master/LICENSE)
|
unknown
|
||
https://github.com/AzureAD/microsoft-authentication-library-for-js/blob/dev/lib/msal-common/docs/Acc
|
unknown
|
||
https://github.com/AzureAD/microsoft-authentication-library-for-js/blob/dev/lib/msal-browser/docs/re
|
unknown
|
||
https://login.windows-ppe.net
|
unknown
|
||
https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration
|
unknown
|
||
https://account.live.com/resetpassword.aspx
|
unknown
|
||
https://aka.ms/vmsettings
|
23.54.202.151
|
||
https://login.microsoftonline.com/common/discovery/v2.0/keys
|
unknown
|
||
https://login.microsoftonline.com/common/oauth2/v2.0/token
|
unknown
|
||
https://github.com/AzureAD/microsoft-authentication-library-for-js/blob/dev/lib/msal-browser/docs/co
|
unknown
|
||
https://login.microsoftonline.com/common
|
unknown
|
||
http://fontawesome.io/license
|
unknown
|
There are 7 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
bg.microsoft.map.fastly.net
|
199.232.214.172
|
||
part-0013.t-0009.t-msedge.net
|
13.107.213.41
|
||
cs1100.wpc.omegacdn.net
|
152.199.4.44
|
||
www.google.com
|
64.233.176.147
|
||
aka.ms
|
23.54.202.151
|
||
passwordreset.microsoftonline.com
|
unknown
|
||
identity.nel.measure.office.net
|
unknown
|
||
aadcdn.msftauth.net
|
unknown
|
||
login.microsoftonline.com
|
unknown
|
||
ajax.aspnetcdn.com
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
13.107.246.41
|
unknown
|
United States
|
||
192.168.2.17
|
unknown
|
unknown
|
||
23.54.202.151
|
aka.ms
|
United States
|
||
192.168.2.4
|
unknown
|
unknown
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
13.107.213.41
|
part-0013.t-0009.t-msedge.net
|
United States
|
||
64.233.176.147
|
www.google.com
|
United States
|
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://dialin.teams.microsoft.com/usp/voicemail
|
||
https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=e1f7a25e-4159-4245-938f-8d1515b64998&scope=openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fdialin.teams.microsoft.com%2Fusp&client-request-id=902ba2b9-7be9-4899-ab31-1e726ff49dac&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=2.14.1&x-client-OS=&x-client-CPU=&client_info=1&code_challenge=BOWP_prUUMODE2ivwnYWTrw58N4SCN2Qf8LCw2QLnBU&code_challenge_method=S256&nonce=911b8969-077a-4090-b31e-6b31a841862d&state=eyJpZCI6IjA2MmY4MTgzLWJiZjQtNDVhNy1iZTY1LWFjNGViZGNlMmJkZSIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoicmVkaXJlY3QifX0%3D&sso_reload=true
|
||
https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=e1f7a25e-4159-4245-938f-8d1515b64998&scope=openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fdialin.teams.microsoft.com%2Fusp&client-request-id=902ba2b9-7be9-4899-ab31-1e726ff49dac&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=2.14.1&x-client-OS=&x-client-CPU=&client_info=1&code_challenge=BOWP_prUUMODE2ivwnYWTrw58N4SCN2Qf8LCw2QLnBU&code_challenge_method=S256&nonce=911b8969-077a-4090-b31e-6b31a841862d&state=eyJpZCI6IjA2MmY4MTgzLWJiZjQtNDVhNy1iZTY1LWFjNGViZGNlMmJkZSIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoicmVkaXJlY3QifX0%3D&sso_reload=true
|
||
https://passwordreset.microsoftonline.com/?ru=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2freprocess%3fctx%3drQQIARAAjZG7btNQAEDtpA1ppLYBJNSFKkNVIYIdX8dO7Egd0jYPp0nclua5VHZyHd_EznV9XaKEiY0F0Y2HxNKxMFRVB0BCYmLIFDHx2JHogBBi6MBA-AOWs59zQgGeBQILbvt5lkutQGAkNV6EjABEmRF4QWTkuGQwUhuIQNQTgixL7rVQ-M1x9Oj7_Wf5l2DZxb9fvDqhV03Pc0gqFmsjzUJ91oOaTVgbtVxMsOGxLWzHDonzmqYnNH3iW5EB0CU5ITNcMqkxAidzjB4HkElMqUkCkBJ8-4tvUU0feib_D9hFI_jLFzRcrWPDvvfc78BhwWluKAmlm-ZLdkMo7XVGxVoBNbs7XnmzapaHADX3GqBYy3bLuSpq5spWyS70mncVotjAaucySO0TpNVErlkvmI34rqPzYgXW1y2li1HLrva0esFqxHeQUefWzvyBqYaN-2P_TezAPmpHHBcbyIIRbBhTa7ivtVqQkE9-ejJDX8zcCPrCC0t0hLq1yvlTwWAoTC1REepyhj6enVa8-iB6_mF-ufzo3dnXxx_nqPFsLM2rqtJcb8tJVDvgepDI1WKtyEMzN8i4OLmlWpLXjWL1QOysySlwFKCPAtfHgUWbaBbbJazu4gGB7s8A_fAK9XbuP688DdEnoehBCQ7iIysvc7rD665cLmWqjXv7FdIx1V6cye4Oc71saUDQRuY0RL-fpy4XPk_O_3wbP_mRv1i8U_GIrQ82K0Mza-qxXAcWR842bkXrFa-A00p_Z5AXt_c2tordzNppmPoL0&mkt=en-US&hosted=0&device_platform=Windows+10
|
||
https://passwordreset.microsoftonline.com/?ru=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2freprocess%3fctx%3drQQIARAAjZG7btNQAEDtpA1ppLYBJNSFKkNVIYIdX8dO7Egd0jYPp0nclua5VHZyHd_EznV9XaKEiY0F0Y2HxNKxMFRVB0BCYmLIFDHx2JHogBBi6MBA-AOWs59zQgGeBQILbvt5lkutQGAkNV6EjABEmRF4QWTkuGQwUhuIQNQTgixL7rVQ-M1x9Oj7_Wf5l2DZxb9fvDqhV03Pc0gqFmsjzUJ91oOaTVgbtVxMsOGxLWzHDonzmqYnNH3iW5EB0CU5ITNcMqkxAidzjB4HkElMqUkCkBJ8-4tvUU0feib_D9hFI_jLFzRcrWPDvvfc78BhwWluKAmlm-ZLdkMo7XVGxVoBNbs7XnmzapaHADX3GqBYy3bLuSpq5spWyS70mncVotjAaucySO0TpNVErlkvmI34rqPzYgXW1y2li1HLrva0esFqxHeQUefWzvyBqYaN-2P_TezAPmpHHBcbyIIRbBhTa7ivtVqQkE9-ejJDX8zcCPrCC0t0hLq1yvlTwWAoTC1REepyhj6enVa8-iB6_mF-ufzo3dnXxx_nqPFsLM2rqtJcb8tJVDvgepDI1WKtyEMzN8i4OLmlWpLXjWL1QOysySlwFKCPAtfHgUWbaBbbJazu4gGB7s8A_fAK9XbuP688DdEnoehBCQ7iIysvc7rD665cLmWqjXv7FdIx1V6cye4Oc71saUDQRuY0RL-fpy4XPk_O_3wbP_mRv1i8U_GIrQ82K0Mza-qxXAcWR842bkXrFa-A00p_Z5AXt_c2tordzNppmPoL0&mkt=en-US&hosted=0&device_platform=Windows+10
|