Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://smarsh.my.site.com/messagingsandbox

Overview

General Information

Sample URL:https://smarsh.my.site.com/messagingsandbox
Analysis ID:1428833
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

Stores files to the Windows start menu directory

Classification

Analysis Advice

Uses HTTPS for network communication, use the 'Proxy HTTPS (port 443) to read its encrypted data' cookbook for further analysis
Some HTTP requests failed (404). It is likely that the sample will exhibit less behavior.
  • System is w10x64_ra
  • chrome.exe (PID: 6972 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://smarsh.my.site.com/messagingsandbox MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 7156 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1948,i,7036498522755533032,13766852167547442370,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://smarsh.my.site.com/messagingsandbox/s/HTTP Parser: No favicon
Source: http://smarsh.mysite.com/HTTP Parser: No favicon
Source: http://smarsh.mysite.com/cgi-bin/show_meHTTP Parser: No favicon
Source: http://signup.mysite.com/cgi-bin/path/signup?verify=1713540177HTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.16:49721 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.16:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49776 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 184.31.62.93
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: smarsh.mysite.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cgi-bin/css/new_style.css?partner=mysite.com HTTP/1.1Host: smarsh.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://smarsh.mysite.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cgi-bin/image/logo_small.gif?partner=mysite.com HTTP/1.1Host: smarsh.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://smarsh.mysite.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs_img/cgi/html_parser.gif HTTP/1.1Host: smarsh.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://smarsh.mysite.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs_img/js/pt.js HTTP/1.1Host: smarsh.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://smarsh.mysite.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cgi-bin/image/logo_small.gif HTTP/1.1Host: members.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://smarsh.mysite.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cgi-bin/image/logo_small.gif?partner=mysite.com HTTP/1.1Host: smarsh.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /fs_img/cgi/html_parser.gif HTTP/1.1Host: smarsh.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cgi-bin/image/logo_small.gif HTTP/1.1Host: members.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: smarsh.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://smarsh.mysite.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: __utma=1.63387539.1713540150.1713540150.1713540150.1; __utmc=1; __utmz=1.1713540150.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; __utmb=1.1.10.1713540150
Source: global trafficHTTP traffic detected: GET /cgi-bin/path/signup HTTP/1.1Host: signup.mysite.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://smarsh.mysite.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: refcd=WSUOWS030708NB01
Source: global trafficHTTP traffic detected: GET /cgi-bin/path/signup?verify=1713540177 HTTP/1.1Host: signup.mysite.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://smarsh.mysite.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: refcd=WSUOWS030708NB01; NIGOL=799d5809c997793058dbb3bd8ca493fe/signup.mysite.com/1713540177/120/sss.7.15914/1713540177.318853821
Source: global trafficHTTP traffic detected: GET /cgi-bin/css/new_style.css?partner=mysite.com HTTP/1.1Host: signup.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://signup.mysite.com/cgi-bin/path/signup?verify=1713540177Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: refcd=WSUOWS030708NB01; NIGOL=ae7cc74f0fe5318cc134da0f9c9c2c5c/signup.mysite.com/1713540177/120/sss.4.54339/1713540177.318853821
Source: global trafficHTTP traffic detected: GET /cgi-bin/image/logo_small.gif?partner=mysite.com HTTP/1.1Host: signup.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://signup.mysite.com/cgi-bin/path/signup?verify=1713540177Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: refcd=WSUOWS030708NB01; NIGOL=ae7cc74f0fe5318cc134da0f9c9c2c5c/signup.mysite.com/1713540177/120/sss.4.54339/1713540177.318853821
Source: global trafficHTTP traffic detected: GET /fs_img/cgi/signup.gif HTTP/1.1Host: signup.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://signup.mysite.com/cgi-bin/path/signup?verify=1713540177Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: refcd=WSUOWS030708NB01; NIGOL=ae7cc74f0fe5318cc134da0f9c9c2c5c/signup.mysite.com/1713540177/120/sss.4.54339/1713540177.318853821
Source: global trafficHTTP traffic detected: GET /fs_img/js/CGI/Ex/validate.js HTTP/1.1Host: signup.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://signup.mysite.com/cgi-bin/path/signup?verify=1713540177Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: refcd=WSUOWS030708NB01; NIGOL=ae7cc74f0fe5318cc134da0f9c9c2c5c/signup.mysite.com/1713540177/120/sss.4.54339/1713540177.318853821
Source: global trafficHTTP traffic detected: GET /fs_img/js/pt.js HTTP/1.1Host: signup.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://signup.mysite.com/cgi-bin/path/signup?verify=1713540177Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: refcd=WSUOWS030708NB01; NIGOL=ae7cc74f0fe5318cc134da0f9c9c2c5c/signup.mysite.com/1713540177/120/sss.4.54339/1713540177.318853821
Source: global trafficHTTP traffic detected: GET /fs_img/spacer.gif HTTP/1.1Host: signup.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://signup.mysite.com/cgi-bin/path/signup?verify=1713540177Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: refcd=WSUOWS030708NB01; NIGOL=ae7cc74f0fe5318cc134da0f9c9c2c5c/signup.mysite.com/1713540177/120/sss.4.54339/1713540177.318853821
Source: global trafficHTTP traffic detected: GET /cgi-bin/image/logo_small.gif?partner=mysite.com HTTP/1.1Host: signup.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: refcd=WSUOWS030708NB01; NIGOL=ae7cc74f0fe5318cc134da0f9c9c2c5c/signup.mysite.com/1713540177/120/sss.4.54339/1713540177.318853821
Source: global trafficHTTP traffic detected: GET /fs_img/cgi/signup.gif HTTP/1.1Host: signup.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: refcd=WSUOWS030708NB01; NIGOL=ae7cc74f0fe5318cc134da0f9c9c2c5c/signup.mysite.com/1713540177/120/sss.4.54339/1713540177.318853821
Source: global trafficHTTP traffic detected: GET /fs_img/spacer.gif HTTP/1.1Host: signup.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: refcd=WSUOWS030708NB01; NIGOL=ae7cc74f0fe5318cc134da0f9c9c2c5c/signup.mysite.com/1713540177/120/sss.4.54339/1713540177.318853821
Source: global trafficHTTP traffic detected: GET /fs_img/footer/spacer.gif HTTP/1.1Host: www.communityarchitect.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://signup.mysite.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: signup.mysite.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://signup.mysite.com/cgi-bin/path/signup?verify=1713540177Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: refcd=WSUOWS030708NB01; NIGOL=ae7cc74f0fe5318cc134da0f9c9c2c5c/signup.mysite.com/1713540177/120/sss.4.54339/1713540177.318853821; __utma=1.988642818.1713540178.1713540178.1713540178.1; __utmc=1; __utmz=1.1713540178.1.1.utmcsr=smarsh.mysite.com|utmccn=(referral)|utmcmd=referral|utmcct=/; __utmt=1; __utmb=1.1.10.1713540178
Source: global trafficHTTP traffic detected: GET /fs_img/footer/spacer.gif HTTP/1.1Host: www.communityarchitect.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: smarsh.my.site.com
Source: unknownHTTP traffic detected: POST /cgi-bin/show_me HTTP/1.1Host: smarsh.mysite.comConnection: keep-aliveContent-Length: 119Cache-Control: max-age=0Upgrade-Insecure-Requests: 1Origin: http://smarsh.mysite.comContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://smarsh.mysite.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: __utma=1.63387539.1713540150.1713540150.1713540150.1; __utmc=1; __utmz=1.1713540150.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utmt=1; __utmb=1.1.10.1713540150Data Raw: 70 61 67 65 3d 62 6f 75 6e 63 65 5f 69 6e 26 72 65 66 63 64 3d 57 53 55 4f 57 53 30 33 30 37 30 38 4e 42 30 31 26 6d 79 75 72 6c 3d 68 74 74 70 25 33 41 25 32 46 25 32 46 73 69 67 6e 75 70 2e 6d 79 73 69 74 65 2e 63 6f 6d 25 32 46 63 67 69 2d 62 69 6e 25 32 46 70 61 74 68 25 32 46 73 69 67 6e 75 70 26 73 69 67 6e 75 70 3d 53 49 47 4e 2b 55 50 2b 4e 4f 57 Data Ascii: page=bounce_in&refcd=WSUOWS030708NB01&myurl=http%3A%2F%2Fsignup.mysite.com%2Fcgi-bin%2Fpath%2Fsignup&signup=SIGN+UP+NOW
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 19 Apr 2024 15:22:59 GMTServer: .V16 ApacheContent-Length: 0Keep-Alive: timeout=5, max=999994Connection: Keep-AliveContent-Type: text/x-invalid
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.16:49721 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.31.62.93:443 -> 192.168.2.16:49722 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:49776 version: TLS 1.2
Source: classification engineClassification label: clean0.win@20/21@24/138
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://smarsh.my.site.com/messagingsandbox
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1948,i,7036498522755533032,13766852167547442370,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1948,i,7036498522755533032,13766852167547442370,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media4
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive5
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
signup.mysite.com
64.136.20.55
truefalse
    high
    www.google.com
    108.177.122.103
    truefalse
      high
      members.mysite.com
      64.136.20.37
      truefalse
        high
        www.communityarchitect.com
        64.136.20.68
        truefalse
          unknown
          smarsh.mysite.com
          64.136.20.37
          truefalse
            high
            smarsh.my.site.com
            unknown
            unknownfalse
              high
              NameMaliciousAntivirus DetectionReputation
              http://smarsh.mysite.com/cgi-bin/css/new_style.css?partner=mysite.comfalse
                high
                http://smarsh.mysite.com/favicon.icofalse
                  high
                  https://smarsh.my.site.com/messagingsandbox/s/false
                    high
                    http://www.communityarchitect.com/fs_img/footer/spacer.giffalse
                      unknown
                      http://signup.mysite.com/cgi-bin/path/signup?verify=1713540177false
                        high
                        http://signup.mysite.com/fs_img/js/CGI/Ex/validate.jsfalse
                          high
                          http://signup.mysite.com/fs_img/js/pt.jsfalse
                            high
                            http://smarsh.mysite.com/false
                              high
                              http://signup.mysite.com/fs_img/spacer.giffalse
                                high
                                http://signup.mysite.com/fs_img/cgi/signup.giffalse
                                  high
                                  http://smarsh.mysite.com/cgi-bin/show_mefalse
                                    high
                                    http://signup.mysite.com/favicon.icofalse
                                      high
                                      http://smarsh.mysite.com/fs_img/cgi/html_parser.giffalse
                                        high
                                        http://smarsh.mysite.com/cgi-bin/image/logo_small.gif?partner=mysite.comfalse
                                          high
                                          http://signup.mysite.com/cgi-bin/image/logo_small.gif?partner=mysite.comfalse
                                            high
                                            http://signup.mysite.com/cgi-bin/css/new_style.css?partner=mysite.comfalse
                                              high
                                              http://members.mysite.com/cgi-bin/image/logo_small.giffalse
                                                high
                                                http://smarsh.mysite.com/fs_img/js/pt.jsfalse
                                                  high
                                                  http://signup.mysite.com/cgi-bin/path/signupfalse
                                                    high
                                                    • No. of IPs < 25%
                                                    • 25% < No. of IPs < 50%
                                                    • 50% < No. of IPs < 75%
                                                    • 75% < No. of IPs
                                                    IPDomainCountryFlagASNASN NameMalicious
                                                    64.233.177.94
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    1.1.1.1
                                                    unknownAustralia
                                                    13335CLOUDFLARENETUSfalse
                                                    23.48.105.206
                                                    unknownUnited States
                                                    20940AKAMAI-ASN1EUfalse
                                                    142.250.105.102
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    173.194.219.138
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    64.136.20.37
                                                    members.mysite.comUnited States
                                                    13446AS-NETZEROUSfalse
                                                    64.136.20.68
                                                    www.communityarchitect.comUnited States
                                                    13446AS-NETZEROUSfalse
                                                    239.255.255.250
                                                    unknownReserved
                                                    unknownunknownfalse
                                                    173.194.219.139
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    64.233.177.101
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    142.250.9.94
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    64.233.185.84
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    23.48.105.198
                                                    unknownUnited States
                                                    20940AKAMAI-ASN1EUfalse
                                                    74.125.138.95
                                                    unknownUnited States
                                                    15169GOOGLEUSfalse
                                                    64.136.20.55
                                                    signup.mysite.comUnited States
                                                    13446AS-NETZEROUSfalse
                                                    108.177.122.103
                                                    www.google.comUnited States
                                                    15169GOOGLEUSfalse
                                                    IP
                                                    192.168.2.16
                                                    Joe Sandbox version:40.0.0 Tourmaline
                                                    Analysis ID:1428833
                                                    Start date and time:2024-04-19 17:21:28 +02:00
                                                    Joe Sandbox product:CloudBasic
                                                    Overall analysis duration:
                                                    Hypervisor based Inspection enabled:false
                                                    Report type:full
                                                    Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                    Sample URL:https://smarsh.my.site.com/messagingsandbox
                                                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                    Number of analysed new started processes analysed:14
                                                    Number of new started drivers analysed:0
                                                    Number of existing processes analysed:0
                                                    Number of existing drivers analysed:0
                                                    Number of injected processes analysed:0
                                                    Technologies:
                                                    • EGA enabled
                                                    Analysis Mode:stream
                                                    Analysis stop reason:Timeout
                                                    Detection:CLEAN
                                                    Classification:clean0.win@20/21@24/138
                                                    • Exclude process from analysis (whitelisted): SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, svchost.exe
                                                    • Excluded IPs from analysis (whitelisted): 142.250.9.94, 23.48.105.198, 23.48.105.208, 23.48.105.215, 142.250.105.102, 142.250.105.138, 142.250.105.100, 142.250.105.139, 142.250.105.101, 142.250.105.113, 64.233.185.84, 34.104.35.123
                                                    • Excluded domains from analysis (whitelisted): default.cdn.prod.communities.salesforce.edgekey.net, fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, e89622.dsca.akamaiedge.net, clientservices.googleapis.com, clients.l.google.com
                                                    • HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                    • Not all processes where analyzed, report is missing behavior information
                                                    • VT rate limit hit for: https://smarsh.my.site.com/messagingsandbox
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 14:21:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                    Category:dropped
                                                    Size (bytes):2673
                                                    Entropy (8bit):3.992535133118586
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:129126037DBD6BBEB9BB50BABEB59304
                                                    SHA1:C277CCCADF2C0EE5B75F82505F0BE1F6DF47534F
                                                    SHA-256:6B95A3021C3BC2BEE7243B89A7F41279D6C4F0E747C2DFE23C9B5F2195F4C0D7
                                                    SHA-512:783A0CB12E7E35DCAB4813EE0A24D0DDB71DC341F47E39DDA852DE82B65437BF635CE2C1D8E6E05E7A4A4C12F432068DE905028DF82674CFC1947B58E7E4E4A0
                                                    Malicious:false
                                                    Reputation:unknown
                                                    Preview:L..................F.@.. ...$+.,....!.FQm...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.z....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.z....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.z....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.z..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.z...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............4.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 14:21:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                    Category:dropped
                                                    Size (bytes):2675
                                                    Entropy (8bit):4.008186018310427
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:1E997A3ACA9E94B050B7B802FD223F58
                                                    SHA1:370937F621B72181859D29117BC09046396A5881
                                                    SHA-256:E3F4D1895FA0F7945E3815FE70B2C419C51235DDFDE03A5AF065823365831D39
                                                    SHA-512:C9F27363C91FF4048EEE991855BC2AECBF98FB115969E0D13DC6203DCD764AB8FC55466B5EBFD5816D732DAE175FD0BCDB150ED5806E665A417999CBC217D527
                                                    Malicious:false
                                                    Reputation:unknown
                                                    Preview:L..................F.@.. ...$+.,....>.;Qm...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.z....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.z....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.z....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.z..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.z...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............4.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                    Category:dropped
                                                    Size (bytes):2689
                                                    Entropy (8bit):4.014647412661949
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:F403ABCD3D34BFF5B133B79F317CCD68
                                                    SHA1:FCF6C6FC3208D61A7A00CC8B15DC0317A36837A0
                                                    SHA-256:FAE4B48763A32E29215969B3F76A5BA76B6871D6645E882661E736839881234E
                                                    SHA-512:FF33390A352E1E5F22DD6D973755EF9D6740E6268B469DB811550E4BBE3A02884DD40D5E0A9D01CBFCF6D18E31A488E1F9FDCBDE31D77BDDE314BB2AF6BAD79D
                                                    Malicious:false
                                                    Reputation:unknown
                                                    Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.z....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.z....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.z....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.z..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............4.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 14:21:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                    Category:dropped
                                                    Size (bytes):2677
                                                    Entropy (8bit):4.005088603275653
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:FDB5FE83FEC80D210ACA9B46672CD34F
                                                    SHA1:89BDAD38287496DE1A7595FF016B33E2A0C3EEC0
                                                    SHA-256:A98E82DD229A123D2E31ECAE6C2B667FBE241434993FF02CC5ABB493B3928E85
                                                    SHA-512:FBE0B7B8D453BBE5772569B701D482C1FF6BFB71E178D39C8B785BB267C1F11B089817188A1E71179F351A97B9C07DC5C69734053C7357ACC20D70ACE7ADA23C
                                                    Malicious:false
                                                    Reputation:unknown
                                                    Preview:L..................F.@.. ...$+.,.....95Qm...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.z....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.z....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.z....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.z..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.z...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............4.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 14:21:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                    Category:dropped
                                                    Size (bytes):2677
                                                    Entropy (8bit):3.9960838687525464
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:FE58702E5EE44539BE1065EEF1BF4FB5
                                                    SHA1:B56BBFCDB378F11F18AA7483DD3E97D373BCDEFD
                                                    SHA-256:83588D1A52D0055307B7EE49684964DA2978902A1BCE29EC716601DE6CB36BD8
                                                    SHA-512:1C2814A316F14188D5929A9B5F41B3526ED37254D95DF7125675129C297549A21054FEF20C7CF6BF0F37C123F25C67506C224136E6B0CAF48BEAB6A28DBF65D9
                                                    Malicious:false
                                                    Reputation:unknown
                                                    Preview:L..................F.@.. ...$+.,......@Qm...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.z....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.z....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.z....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.z..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.z...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............4.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 14:21:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                    Category:dropped
                                                    Size (bytes):2679
                                                    Entropy (8bit):4.000890866507332
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:66EEE976C22EC1121B2DB84031C516A0
                                                    SHA1:F68C1E300127367DF5A600758AC2B88707A471EA
                                                    SHA-256:BEF350E8ACA4EEC56F1A00421DEBD24BBFB689EA8F15F2B8D470E22A8D9760C2
                                                    SHA-512:E4E18DD4DB4A4FB23F857D28DA85FCAAE091D7245A39DE679CA011A9B0EA6BB19ACE8C1FDA31D8F401B98CCF96E88496BC7B16C529C27C4466397042602FD81C
                                                    Malicious:false
                                                    Reputation:unknown
                                                    Preview:L..................F.@.. ...$+.,......+Qm...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.z....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.z....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.z....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X.z..........................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.z...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............4.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:PNG image data, 16 x 17, 8-bit/color RGBA, non-interlaced
                                                    Category:downloaded
                                                    Size (bytes):305
                                                    Entropy (8bit):6.920524772861289
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:380E7641151E631A29F16DDA352995A3
                                                    SHA1:AD0BF8292E2562B2889343C9C0F2E849EDF7A10F
                                                    SHA-256:EFA02E9A94FA33101AE3AF345171D1D4D087F7551BC9B0BC958CF482440B0958
                                                    SHA-512:0096306A8A8860F75DF31B0CC8D7C6937151884DA571065AAF7FD24AF943012FF6A83080B01FDDAFACB799AF6D529B42F602FAD674ED9697CC6C995AE6988961
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://smarsh.my.site.com/favicon.ico
                                                    Preview:.PNG........IHDR..............,.....pHYs...)...).........IDAT8.....@....qW..@.f. :.a.:..g.P.:........|.[a"..N.....{.......&J.`....%.._.3.... ....I....@...5..I ...I..G!...#....7,.(_?.L,...-e.. ''....lM.D.X.9`%M....Tpq)f.|...<{).....m....sh.^....5...b].^.b].*20.#;.......f9.u.[...?FA.........IEND.B`.
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:GIF image data, version 89a, 48 x 48
                                                    Category:downloaded
                                                    Size (bytes):1922
                                                    Entropy (8bit):7.767077628121498
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:EE79D215F4DEEDD7156433D72DEF0BDE
                                                    SHA1:4D94BC0F38CE7CEFF3AFABD1E75D48B1EF927815
                                                    SHA-256:D70D60467DE0857AFD3C34723DC41A6EFAA58AAA2660CC205E7CA876A2CE6BE3
                                                    SHA-512:070E5F76606B256CA839BBF57B3129510C44CD1FE34C999541C35CD36744AB428879F472DDA8086ED5751396EE4F4FD2602545BB3862233066B10A3FA756AADF
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:http://smarsh.mysite.com/fs_img/cgi/html_parser.gif
                                                    Preview:GIF89a0.0....e.....fff.......\a.$'...U4..B9.kg.......#....a..VB>....DA....................KHj...QI.mg./".. r!........v{q...f]....0,...z2%....qMG..z....HQ...uts.)$...33q/$... ..... !..........WN.@4.Y*"....sj....bbXQP.OO...sih.......ie....zy.YR.-(....AB.48.............a].;6r&.....xu.:6{:1.SP....l^[j......C9Y!.W=8.bi....ws.......pu.ZU. ...........4-z...PU......."..().RJ.KD.<0.hm.65.WLs7-..........NK.G>......zzz..YKI.IK.afb* ...xq.9;...........x.fb...j .....2.....&$.xvm1'|(........}......|...).....B:.)..C:...XQ._[.TYj..kkk.+%][Z.rn....|y....so.<?}YS.CD.ke.....t...34|NF....de.LA......{A9.=4.=?.F:."..43...c...ty.........S94.3(.ts|3(...ej....KD..........+&......b[.T[....cZ.lr_OL.?=.MHZHE.so.*!...}OH.zw.ol.QJ..........t+.s<2j...,-....ll.]W.J:.\S.QHm,".....`XW,....0.0........H......*\....#J.H.......uA_.V>.\2X.[.=.Df.v,...2dt.7r..i/;...n.E?/.";....$5.....2ujN."&(......sc..FJ.^92.(u6xL.....&j....dT.yV...h...`H.F..gV..%.....XF.j..i....Y2....R....".1.t..Q.|.....:L.7..m
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:gzip compressed data, max compression, original size modulo 2^32 46274
                                                    Category:downloaded
                                                    Size (bytes):17168
                                                    Entropy (8bit):7.989364903563379
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:01D5892E6E243B52998310C2925B9F3A
                                                    SHA1:58180151B6A6EE4AF73583A214B68EFB9E8844D4
                                                    SHA-256:7E90EFB4620A78E8869796D256BCDDBDE90B853C8C15C5CC116CB11D3D17BC4D
                                                    SHA-512:DE6CA9D539326C1D63A79E90A87D6A69676FC77A2955050B4C5299FAB12B87AF63C3D7F0789D10F4BE214E5C58D6271106A82944D276D5CA361B6D01F7A9F319
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:http://www.google-analytics.com/ga.js
                                                    Preview:...........}k{........m..i...`.@.....-.G..4$MB.........b.qYk.s.w...#it..."..t ..p.....xq.....;..7l..C1.....B....Q.}....9>..d..&~.....~...=_Z...0.{...w'<..e../..L..A..J.w.R.Jy......XZ..<.......<."....K?.~.xx~..AM.....MF.n.{-/h.p...._[.G.O...........h....>.&...YT..A'.l.........vEY..%..xm4.\..q..0}.i.g.. -T.{txt...... .b....v.W........E.5.~i.O~.._.-.A.I{...kc9.s!....J.y.Z}..@..zA.........Z.....Wh.v..s......,h?Za.p..v......U.....6..n..xq...E...M........zSU..."HCC...i..T*..f....g...lf.<k .@.....&n..'...../.+!....3.C...t<..p\...`F..C...t..t. C.RU/.)............_.4/(s........4.[. .........C...x+..A..x.k.i4.2.....5#s.1....m..[.].......6.N....X...dms.._...\...P.2.|....a~..v...@`....t.-F.(.Fl....k..-...>...2....2T.......[...e....eB.s)...IP..~.q0.}...M.Y.p....\g..,...x..^...I*.r.....R.a..x.rqI.H..O..Q...............kb,y*w...N.;J...p>.^..z....:....n B `.6....m...Q....L5.......W2.z^.h.).c...-...H|.-aPK_0n.L..|..b..uKv...6=/..6[.x.Dk.R.X..A.h.A.0. ...
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:HTML document, ASCII text, with CRLF, LF line terminators
                                                    Category:downloaded
                                                    Size (bytes):1638
                                                    Entropy (8bit):5.285324172916636
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:893414CF35C0D9F1F0F182B41FA1731B
                                                    SHA1:D93922C13071ED1E0F02C8D11C75181235767FE5
                                                    SHA-256:2E4D771E7FF8D5A66CB27812432082C48C1282FBE6BFA5F1A63B3B571B5A2382
                                                    SHA-512:2D8DC100DB3FBF514F9BF4820692D97400C94E6671434C4DDF332DFABD22ADC3DAB4B61F4A221B97BDDAC4C7A9AB23305BD7E27F5B6142DEF3F3454350128D7B
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:http://smarsh.mysite.com/cgi-bin/show_me
                                                    Preview: |16|1713540177|81.181.57.52|http://smarsh.mysite.com/|-->. content - Partner "default.partner" - File "show_me/bounce_in.htm" -->.... <SCRIPT type="text/javascript" language="javascript"> . ..if (!document.refcd) { // If refcd has already been set, don't bother.. ...document.refcd="WSUOWS030708NB01";........document.cookie="refcd=WSUOWS030708NB01;path=/;domain=mysite.com;";.......}..//--></SCRIPT>. . Google Analytics Insertion Begin -->.<script type="text/javascript">. . var _gaq = _gaq || [];. _gaq.push(['_setAccount', "UA-4601892-1"]);. _gaq.push(['_setDomainName', 'none']);. _gaq.push(['_setAllowLinker', true]);. _gaq.push(['_trackPageview']);. . (function() {. var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true;. ga.src = ('https:' == document.location.protocol ? 'https://ssl' : 'http://www') + '.google-analytics.com/ga.js';. var s =
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:GIF image data, version 89a, 1 x 49
                                                    Category:downloaded
                                                    Size (bytes):49
                                                    Entropy (8bit):3.8800844705318878
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:8652B802B48D66A42E6B4B37208ADE58
                                                    SHA1:401C6B5FE3BD213C48428D1A64C8FACBCF8AFA45
                                                    SHA-256:28474AEE50F7220AAEE68A61417078E4A3394E0063A209925CBB67CE8EFD8398
                                                    SHA-512:0554C59F1CC04BB88211F1C766F8D5282E1B7D750A4A874F2AE0C2264BA9B1AEB9BE37CD57D9EEAAE68A456BE7769A75D274D962E421E2F9D72BFD0601D642E8
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:http://www.communityarchitect.com/fs_img/footer/spacer.gif
                                                    Preview:GIF89a..1..........!.......,......1.........,.;
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text
                                                    Category:downloaded
                                                    Size (bytes):4924
                                                    Entropy (8bit):5.198702174256519
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:5A579305A5ED446E5D235FDF055AF4DF
                                                    SHA1:460970478D97E27013664CCA14B24B312DB5E837
                                                    SHA-256:B7869A1AD7F1EEC802FDBD1018FA315B26B3C92A13DB66C9044DAD80A8FC5B2F
                                                    SHA-512:F4F16089075A583C87B99E17A3E250B9728A2BE977ABC1D8E5A359393EC19F027317B76B67A284AF6626E48EDAD54CFDEBE20886BC525A3B54E66066953EF128
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:http://smarsh.mysite.com/fs_img/js/pt.js
                                                    Preview:function FDCPClient(){.this.cpHost="unitedonline.cleanprint.net";.this.divid="2412";.this.refid="2361";.this.rt="i;";.this.cpstatus=false;.this.ptstatus="y";.this.printSpecId=0;.this.fdDebug=false;.this.cpc=null;.this.blkwidth=0;.this.xpathLib="";.this.shost="secure-unitedonline.cleanprint.net";.this.hosted="fd";.this.templateTest=false;.this.insType="c";.this.escCom=function(st){.st=new st.constructor(st);.st=st.replace(/:/g,"::");.st=st.replace(/,/g,":,");.return st;.};.this.getSegment=function(){.var wh=window.location.hostname;.var re=new RegExp("[^.]+.[^.]+$");.var _4=wh.search(re);.if(_4>0){.wh=wh.substring(_4);.}.return this.escCom(wh);.};.this.getPFF=function(){.return "0";.};.this.getVR=function(){.return {};.};.this.onPrint=function(){.};.this.getBlockThreshold=function(){.return 500;.};.this.getCfg=function(_5,_6){.if(this.cpc!=null&&typeof this.cpc[_5]!="undefined"){.return this.cpc[_5];.}.return _6;.};.this.getTHost=function(){.if(this.shost.length>0&&document.location.pro
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:GIF image data, version 89a, 48 x 48
                                                    Category:downloaded
                                                    Size (bytes):2068
                                                    Entropy (8bit):7.803444303796298
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:09ACF76F9735B3724AC69571D278EBD1
                                                    SHA1:2D87B917AFE78CE89224D75D1F73D43E40CA1A20
                                                    SHA-256:36EF09B5E0AD7B042406266B19FBFF9821AD92E1D6E97A29DFE84BE6CD6D74D4
                                                    SHA-512:8659981DC77704EB588408888BA88BD185AAB3748976B4F7203698805ACDFF35A0309CC7F9AA44B51040221F06DC037D4EE0FE7BFBE6A047340CEFA8F3C633FE
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:http://signup.mysite.com/fs_img/cgi/signup.gif
                                                    Preview:GIF89a0.0.......H.....{.~..\.....@..MRH......y{D/....>1...7}z}............EUa.j.....xS....c.c...38..a83*...fff{...........}\......sR..4........tu..d.c.P..;...]^............k..........h5+N,'F..z`.a..#./.F]l.{..n9.f.....3....?..P...q......L~..s.q\4...e@...R.'........u...TTS....f.sss.zJNH>.....f...................3..........._.XK.G...z*...N%......4o.,BH"$.pJ..lh.O..t.......3.k:....xD..\.r....}\....`Q4cB..xh.RF..i.....l.........c..NsLF..Z.............u[)......l....ljdscN.%..v...........}K.@....`$..J..c][X.....U....Y..tf..;%.....x..Tq.........n......I..A.......sc..&va 5%.fG...........R..E.o..\....].......l..N]|...Q......t..,.m_.?>U...Sl|z......<<e\J..5..r......h....<<<<IF..........WUD.......nmj...."&..=...._.....P,....0.0.....W..H......*T.....Q."..-....qG..6.Q$..M.T..........I.....F4..a.UN..l|$hI.?.h..1....*`...C.r..QK...b....@.l.U...x..M,080...G_.3..-.a.._L..YS.bG......Q..3...JXc.......a.U.4!.......N(.8......5^0r.nKf.
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:HTML document, ASCII text
                                                    Category:downloaded
                                                    Size (bytes):6153
                                                    Entropy (8bit):5.287526339990681
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:3CEE938CD7ED24C4D4B997EFA831E00D
                                                    SHA1:BA38EE481485C040659ADCDD20D80C53CAB6312E
                                                    SHA-256:B087DCFC0B805474B2954F2BB76362A9CB1E1D184E7442F5631097FF1EF753C7
                                                    SHA-512:10B8572EC50365FB8F051A445A8B783A5D6A867B979AAA5C877E1F2FB4C10F7E796AD69AAB769097070B0EFB525AB91409834DAF94D7F757988D112C976C1F50
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:http://smarsh.mysite.com/
                                                    Preview: |16|1713540150|81.181.57.52|NONE|-->. content - Partner "default.partner" - File "html_parser/available.htm" -->..... .. <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head>. <title>AVAILABLE - MySite</title>. . . <META http-equiv="X-UA-Compatible" content="IE=Edge"> . env.cgi: html_parser -->. <link rel="stylesheet" href="/cgi-bin/css/new_style.css?partner=mysite.com" type="text/css">. . </head><body>. . . . . . . <div id="insidebanners">. <div id="shellouterdiv">. . <DIV id="logocontainer"><a href="http://www.mysite.com"><img NAME=logo SRC=/cgi-bin/image/logo_small.gif?partner=mysite.com border=0></a></DIV> . <div id="shellinnerdiv">. . <div class="areaborder">. <div id="maintable">.. . . <div class=spot><table class="spottable"><tr valign=top><td>. <DIV ID="spotimage" class="spotimage">.....<IMG src="/fs_img/cgi/html_parser.gif"></DIV></td><TD width="100%">. . <DIV class=spotheading>
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text
                                                    Category:downloaded
                                                    Size (bytes):10135
                                                    Entropy (8bit):5.191883559465481
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:7F09B1917375812B1A63453AE56A3B9D
                                                    SHA1:AD913FF33955FA4D8D5DD407FB939535E97F8396
                                                    SHA-256:EED6960EF646044756FA4933973D13A6D3CA1563BD8BEE39670329279FDD253B
                                                    SHA-512:8998EC340DC6773D05D8CA0E1C0719428227A4357842BF895D063437F0455A39CE8A88A81D4054AFB8BAD785D214DCFC569DE1B5A39C6B22D3BC09A979EB7AF7
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:http://signup.mysite.com/cgi-bin/css/new_style.css?partner=mysite.com
                                                    Preview:/* Defaults for page */..........body {..background-color:#1682CC;..margin:0px;..font-size:12px;.}.#insidebanners {..background-color:#FFFFFF;..font-family:Arial, Helvetica, sans-serif;..color:#333333;..padding-left:20px;..padding-right:20px;..padding-bottom:30px;..padding-top:20px;.}.table {..font-family:Arial, Helvetica, sans-serif;..font-size:12px;.}.a, a:link{..color:#000000;.}.a:visited {..color:#999999;.}.a:active,a:hover {..color:#555555;.}.form {..margin:0px;.}.#titlebar1{..background-image:url(/fs_img/white_TR.gif);..background-position:top right;..background-repeat:no-repeat;..background-color:#CEE5F7;..float:left;.}.#titlebar2{..background-image:url(/fs_img/white_TL.gif);..background-position:top left;..background-repeat:no-repeat;.}.#titlebar3{..border-top:1px solid #000000;.}.#pagetitle {..font-family:Arial, Helvetica, sans-serif,sans-serif;..color:#1682CC;..font-size:12px;..font-weight:bold;..padding:10px;..padding-top:5px;..padding-bottom:5px;.}.#pagetitle a:link{...colo
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text, with no line terminators
                                                    Category:downloaded
                                                    Size (bytes):40
                                                    Entropy (8bit):4.315311532225102
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:1922FE4F59B9A26B01AB11EA35692DE6
                                                    SHA1:368DB1799F547C96AF3E85F6DB30CF010830E5DF
                                                    SHA-256:3FFB8AE278AF5452F1408449A7FEDAADB6BB58F50EA631FBC98020A39127855B
                                                    SHA-512:C101641B7CC60B689217E712F6FFBAD972A4DC2B0E21987088E5BEBB5F425F68A139C0ABA58A2398DBB10978E0F42E6B3B8003C298B7958532EFFA4F4C4039BA
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISHgmEb2YkR4WNixIFDVYo6CMSBQ2c3A8PEgUNBVC73A==?alt=proto
                                                    Preview:ChsKBw1WKOgjGgAKBw2c3A8PGgAKBw0FULvcGgA=
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:GIF image data, version 89a, 159 x 49
                                                    Category:dropped
                                                    Size (bytes):1599
                                                    Entropy (8bit):7.685443548782895
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:3C115F04C2030E6DD92FF9D0EAF1980F
                                                    SHA1:38C7343E61EAF4A37BFD5789529C98B57A7E59DB
                                                    SHA-256:09CEF2831269CA7FC076B6D644168DDE5E4430020E83AC008ABEF03E63984A4D
                                                    SHA-512:A11D633DC16FE5C8AA00C714A91BCC9D95786BA4AF3EDD49B56D77E2B039F0C9CE6CDC0F1AC2D44A9A9C4197E9130ECF94E1A975F474C6CB42912C0FF30B471F
                                                    Malicious:false
                                                    Reputation:unknown
                                                    Preview:GIF89a..1....v.!.....g.....P......../.........K....3........[.......X.........m................%..B...={..........f........u.............._......Z............................................!.......,......1......pH,...r.l:.PH...X#-R...z..0."..h.!........M$.~...&X$...Tu.*}....h...K).hy...a&g..P..h....K....^).g....#.g.a..f....g.n.....}t.&b)...g...p.`.+B.f...`*go.......]....#...r...C....r..p...z..x..p....4.y.M......Y.P.C...k.&..P#5*...b.8g&}1.K..a*.|....N.....#....l9.....<,A...vR.%.#^...u+&..>....."...P...]..=.!....=P..C..E6h.........D...(....6.V$.E$......x....."...zm...`.....l.F\.......K4...@a..Q..P.y..H..."...+.-;&..l.bg.-0..Z.l..F..H....t@N..q...3.......ASiC..@.V$.EP.P.LT......I.V...p.w.....o(.....@d.....B?..7...1D.......,eDSm8..(gd....Ih....q.iH.Q@k2....E0...#...HH8.Q.E4.#...A.IBL...R.r.@F..Z.[-9..0.y..r.%B.$.....)q.KZ...K......Q9.U.P.I..e.Y...5B..y..i2..Z|D.....9.D....%..%q..D.S.v...G.9.E.9..C.P.Zx.w.:C.p*...P#...X.c....o..P.....h.b......-.
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:HTML document, ASCII text
                                                    Category:downloaded
                                                    Size (bytes):22734
                                                    Entropy (8bit):5.2121408913205345
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:247E9546C8DB6B9CCBC0CC841B870A18
                                                    SHA1:17A95D2B111FE385B8E53F06E7D5736749A901D0
                                                    SHA-256:702026C9CC57C22971A9E0268AE77B77D02ED4DF9633B96E24C02F22F766E0DA
                                                    SHA-512:3EFA11893E23D7451FB9D63591E40DB63505EF0586D28D9C4DD7AB962A2CF6AFE0CFEEB8F078D20405D9E68D1BD1DD7482CA376E32F1BDFAE677FF2D9929FAC1
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:http://signup.mysite.com/cgi-bin/path/signup?verify=1713540177
                                                    Preview: |16|1713540178|81.181.57.52|http://smarsh.mysite.com/|-->. content - Partner "default.partner" - File "path/signup/choose_domain.htm" -->........ <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head>. <title>Sign Up - MySite</title>. . . <META http-equiv="X-UA-Compatible" content="IE=Edge"> . env.cgi: signup -->. <link rel="stylesheet" href="/cgi-bin/css/new_style.css?partner=mysite.com" type="text/css">. . </head><body>. . . . . . . <div id="insidebanners">. <div id="shellouterdiv">. . <DIV id="logocontainer"><a href="http://www.mysite.com"><img NAME=logo SRC=/cgi-bin/image/logo_small.gif?partner=mysite.com border=0></a></DIV> . <div id="shellinnerdiv">. . <div class="areaborder">. <div id="maintable">...<SCRIPT> . //when opened from the left chunk of the banner bar, window.opener yields the iframe (the WxH are not accomodating). //5/04 this also can happen from my.netzero.com..if (self!=
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:ASCII text
                                                    Category:downloaded
                                                    Size (bytes):35679
                                                    Entropy (8bit):4.911558264407295
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:91844E4DD7429DDA1405F81976996A48
                                                    SHA1:C4EFABAB08FFECD20CCA8F9E6C965DC4048F2FC2
                                                    SHA-256:CA8144E63905A60A7A7FCF417CC1C936A84060FAA741ECA80CE3BA0FC86B828F
                                                    SHA-512:5F26FC81E40625757647D6312E89A1774B4EB656760DA074136E5C283CE6A901CEF369BE5F032E761377C3F7C857E481C88A5E7A0F1903AA2BF6E3F03D027B20
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:http://signup.mysite.com/fs_img/js/CGI/Ex/validate.js
                                                    Preview:/**----------------------------------------------------------------***.* Copyright 2004 - Paul Seamons *.* Distributed under the Perl Artistic License without warranty *.* Based upon CGI/Ex/Validate.pm v1.14 from Perl *.* For instructions on usage, see perldoc of CGI::Ex::Validate *.***----------------------------------------------------------------**/.// $Revision: 1.14 $..function Validate () {. this.error = vob_error;. this.validate = vob_validate;. this.check_conditional = vob_check_conditional;. this.filter_types = vob_filter_types;. this.add_error = vob_add_error;. this.validate_buddy = vob_validate_buddy;. this.check_type = vob_check_type;. this.get_form_value = vob_get_form_value;.}..function ValidateError (errors, extra) {. this.errors = errors;. this.extra = extra;.. this.as_string = eob_as_string;. this.as_array = eob_as_array;. this.as_hash = eob_as_hash
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:HTML document, ASCII text
                                                    Category:downloaded
                                                    Size (bytes):6174
                                                    Entropy (8bit):5.286793334732655
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:D229A57272953426288C57FCC349F143
                                                    SHA1:707E1E04713DFF77EFBBE4A60DAAFB62C3DF3D2A
                                                    SHA-256:537B40B5B514149326A81689581BAE132CDF05EDEF4B54595CE84927934A20F3
                                                    SHA-512:D4B440AEE31C080DC5BD056E083653DFF4823AF7FCB53F31DD89631C2E48D2A1CE74E70445F590CE6937310E967B38D6276E5E628D37C34BF504F294565BB0F2
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:http://smarsh.mysite.com/favicon.ico
                                                    Preview: |16|1713540151|81.181.57.52|http://smarsh.mysite.com/|-->. content - Partner "default.partner" - File "html_parser/available.htm" -->..... .. <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head>. <title>AVAILABLE - MySite</title>. . . <META http-equiv="X-UA-Compatible" content="IE=Edge"> . env.cgi: html_parser -->. <link rel="stylesheet" href="/cgi-bin/css/new_style.css?partner=mysite.com" type="text/css">. . </head><body>. . . . . . . <div id="insidebanners">. <div id="shellouterdiv">. . <DIV id="logocontainer"><a href="http://www.mysite.com"><img NAME=logo SRC=/cgi-bin/image/logo_small.gif?partner=mysite.com border=0></a></DIV> . <div id="shellinnerdiv">. . <div class="areaborder">. <div id="maintable">.. . . <div class=spot><table class="spottable"><tr valign=top><td>. <DIV ID="spotimage" class="spotimage">.....<IMG src="/fs_img/cgi/html_parser.gif"></DIV></td><TD width="100%">. . <D
                                                    Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                    File Type:GIF image data, version 89a, 1 x 1
                                                    Category:downloaded
                                                    Size (bytes):42
                                                    Entropy (8bit):3.0241026136709444
                                                    Encrypted:false
                                                    SSDEEP:
                                                    MD5:32023BB33CFB2A1990A4EF2D85B6AC16
                                                    SHA1:23DCC6D4B5BFE00357FD0248BB5955B8E36BB8F1
                                                    SHA-256:99C2917EE5B2A01459A923BDD1C676F15EE73B62B87F696E6735312D26F51E12
                                                    SHA-512:D052ECEC2839340876EB57247CFC2E777DD7F2E868DC37CD3F3F740C8DEB94917A0C9F2A4FC8229987A0B91B04726DE2D1E9F6BCBE3F9BEF0E4B7E0D7F65EA12
                                                    Malicious:false
                                                    Reputation:unknown
                                                    URL:http://signup.mysite.com/fs_img/spacer.gif
                                                    Preview:GIF89a.............!.......,...........L.;
                                                    No static file info