Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe

Overview

General Information

Sample name:GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
Analysis ID:1430937
MD5:fd2c102f6b2dac90179d7981dc7299e1
SHA1:36b30f7173dae7c450e24204cd432b122121ebb3
SHA256:4627b4f84258eede9176028143c17f0ef56d649b4ff4ba4d218a2609bf0193f5
Infos:

Detection

Score:27
Range:0 - 100
Whitelisted:false
Confidence:0%

Compliance

Score:19
Range:0 - 100

Signatures

Installs a global event hook (focus changed)
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
DLL planting / hijacking vulnerabilities found
Drops PE files
EXE planting / hijacking vulnerabilities found
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Sigma detected: CurrentVersion Autorun Keys Modification
Uses 32bit PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
Uses HTTPS for network communication, use the 'Proxy HTTPS (port 443) to read its encrypted data' cookbook for further analysis
Sample monitors window changes (e.g. starting applications), analyze the sample with the 'Simulates keyboard and window changes' cookbook
Sample searches for specific file, try point organization specific fake files to the analysis machine
  • System is w10x64_ra
  • GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe (PID: 7032 cmdline: "C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe" MD5: FD2C102F6B2DAC90179D7981DC7299E1)
    • Grammarly.Desktop.exe (PID: 7104 cmdline: "C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe" new-version-v2 onboarding MD5: 091A781339910425916ACC6BE9750128)
      • explorer.exe (PID: 4380 cmdline: C:\Windows\Explorer.EXE MD5: 662F4F92FDE3557E86D110526BB578D5)
        • msedge.exe (PID: 6264 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=A0ej0vpdcBiI-yz3QBpBBJwbh5pbNmPvz1dsC4zUlqs&verify=j4bHc&showSuccessState=true MD5: 69222B8101B0601CC6663F8381E7E00F)
          • msedge.exe (PID: 2524 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2612 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:3 MD5: 69222B8101B0601CC6663F8381E7E00F)
          • msedge.exe (PID: 7356 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=7364 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
          • msedge.exe (PID: 7396 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=7468 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
          • msedge.exe (PID: 7780 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6796 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
      • msedgewebview2.exe (PID: 4732 cmdline: "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --embedded-browser-webview=1 --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --noerrdialogs --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --enable-features=MojoIpcz --mojo-named-platform-channel-pipe=7104.3668.17407409699958160167 MD5: 9909D978B39FB7369F511D8506C17CA0)
        • msedgewebview2.exe (PID: 2216 cmdline: "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=117.0.5938.132 "--annotation=exe=C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=117.0.2045.47 --initial-client-data=0x15c,0x160,0x164,0x138,0x170,0x7fff1e618e88,0x7fff1e618e98,0x7fff1e618ea8 MD5: 9909D978B39FB7369F511D8506C17CA0)
        • msedgewebview2.exe (PID: 1596 cmdline: "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:2 MD5: 9909D978B39FB7369F511D8506C17CA0)
        • msedgewebview2.exe (PID: 5980 cmdline: "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=1980 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:3 MD5: 9909D978B39FB7369F511D8506C17CA0)
        • msedgewebview2.exe (PID: 7064 cmdline: "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-GB --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=2440 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:8 MD5: 9909D978B39FB7369F511D8506C17CA0)
        • msedgewebview2.exe (PID: 3924 cmdline: "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --disable-nacl --first-renderer-process --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=en_CH" --time-ticks-at-unix-epoch=-1713946862127608 --launch-time-ticks=5472465795 --mojo-platform-channel-handle=3312 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:1 MD5: 9909D978B39FB7369F511D8506C17CA0)
      • msedge.exe (PID: 2268 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=A0ej0vpdcBiI-yz3QBpBBJwbh5pbNmPvz1dsC4zUlqs&verify=j4bHc&showSuccessState=true MD5: 69222B8101B0601CC6663F8381E7E00F)
        • msedge.exe (PID: 3560 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=2028,i,1723528232903650596,3920355234927745539,262144 /prefetch:3 MD5: 69222B8101B0601CC6663F8381E7E00F)
      • msedge.exe (PID: 2920 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=6qrxDAzOWbV4ISaXbaeblzbqt1-zHDJKTAsNkxFACRE&verify=j4bHc&showSuccessState=true MD5: 69222B8101B0601CC6663F8381E7E00F)
      • msedge.exe (PID: 7948 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=YMT3ROP5autsdjZ_tsNOQAOfNJfh5L4UPzMB0_suXcA&verify=j4bHc&showSuccessState=true MD5: 69222B8101B0601CC6663F8381E7E00F)
      • msedge.exe (PID: 4864 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=DedXj_1j5KNl-qml7Yln6Y4k7TpJCcoTkY4W331meKk&verify=j4bHc&showSuccessState=true MD5: 69222B8101B0601CC6663F8381E7E00F)
    • tasklist.exe (PID: 7084 cmdline: tasklist /NH /FI "IMAGENAME eq Grammarly.Desktop.exe" MD5: 0A4448B31CE7F83CB7691A2657F330F1)
      • conhost.exe (PID: 7072 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No yara matches
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe, ProcessId: 7032, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Grammarly
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: MSVCP140_CLR0400.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: LINKINFO.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: ncrypt.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: WINMM.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.ExperimentationSDK.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PowerPointApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.WebView.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Dependencies.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Memory.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.CheetahClient.Protocol.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Batteries.FSharp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\WebView2Loader.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\WebView2Loader.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Dapper.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LanguageExt.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Main.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\SQLitePCLRaw.batteries_v2.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\TestableIO.System.IO.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Threading.Tasks.Extensions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.UI.Onboarding.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Data.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\SQLitePCLRaw.provider.dynamic_cdecl.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm\native\e_sqlite3.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.StorageClient.Protocol.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Text.Encodings.Web.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: d3d10warp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.FSharp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.MsOffice.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Serialization.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Resources.Extensions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\SQLitePCLRaw.core.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: RichEd20.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Reactive.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Gos.Sdk.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\NLog.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: Wldp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.TextChecking.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\TestableIO.System.IO.Abstractions.Wrappers.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: D3DCOMPILER_47.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Premium.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.Wpf.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Text.Json.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Core.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: USERENV.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Buffers.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Linq.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\FSharp.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: msvcp110_win.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.SDUI.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Toolkit.Uwp.Notifications.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.CoreApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Gnar.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\OfficeApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Application.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: d3d9.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.WinEvents.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\VBIDEApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.UIAutomation.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.SHCore.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.SDUI.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Windows.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Http.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Experimentation.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: msls31.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Keyboard.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: USP10.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\DynamicData.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Data.Sqlite.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Iterable.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm64\native\WebView2Loader.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Services.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Auth.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.PInvoke.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Security.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: WinTypes.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.WinForms.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Interfaces.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: CRYPTSP.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Bcl.AsyncInterfaces.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.IAccessible2Lib.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Logging.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.LegacyCheetahProtocol.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Tracking.GnarClient.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grace.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Diagnostics.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\stdole.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.QuillDelta.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.ConfigurationApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Xaml.Behaviors.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: BROWCLI.Dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: CRYPTBASE.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Mouse.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Kernel32.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.User32.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\websocket-sharp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.GrammarlyBusinessApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Parallel.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.SDUI.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Json.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Collections.Immutable.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\WordApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Validation.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: profapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.Accessible2.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.AdvApi32.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Numerics.Vectors.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.DesignSystem.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Storage.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LZStringCSharp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: cscapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.SDUI.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Batteries.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\e_sqlite3.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.OAuth2.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: edputil.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Windows.ShellSuserngApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Logging.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.BusinessMetric.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\e_sqlite3.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Transforms.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Felog.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.UIAutomationClient.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Suggestions.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: twinapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Runtime.CompilerServices.Unsafe.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\NetOffice.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.ValueTuple.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Newtonsoft.Json.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.IO.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeEXE: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeEXE: tasklist.exe
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeEXE: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Uninstall.exe

Compliance

barindex
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: MSVCP140_CLR0400.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: LINKINFO.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: ncrypt.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: WINMM.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.ExperimentationSDK.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PowerPointApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.WebView.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Dependencies.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Memory.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.CheetahClient.Protocol.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Batteries.FSharp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\WebView2Loader.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\WebView2Loader.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Dapper.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LanguageExt.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Main.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\SQLitePCLRaw.batteries_v2.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\TestableIO.System.IO.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Threading.Tasks.Extensions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.UI.Onboarding.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Data.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\SQLitePCLRaw.provider.dynamic_cdecl.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm\native\e_sqlite3.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.StorageClient.Protocol.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Text.Encodings.Web.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: d3d10warp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.FSharp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.MsOffice.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Serialization.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Resources.Extensions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\SQLitePCLRaw.core.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: RichEd20.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Reactive.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Gos.Sdk.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\NLog.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: Wldp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.TextChecking.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\TestableIO.System.IO.Abstractions.Wrappers.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: D3DCOMPILER_47.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Premium.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.Wpf.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Text.Json.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Core.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: USERENV.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Buffers.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Linq.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\FSharp.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: msvcp110_win.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.SDUI.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Toolkit.Uwp.Notifications.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.CoreApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Gnar.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\OfficeApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Application.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: d3d9.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.WinEvents.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\VBIDEApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.UIAutomation.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.SHCore.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.SDUI.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Windows.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Http.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Experimentation.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: msls31.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Keyboard.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: USP10.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\DynamicData.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Data.Sqlite.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Iterable.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm64\native\WebView2Loader.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Services.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Auth.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.PInvoke.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Security.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: WinTypes.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.WinForms.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Interfaces.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: CRYPTSP.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Bcl.AsyncInterfaces.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.IAccessible2Lib.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Logging.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.LegacyCheetahProtocol.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Tracking.GnarClient.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grace.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Diagnostics.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\stdole.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.QuillDelta.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.ConfigurationApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Xaml.Behaviors.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: BROWCLI.Dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: CRYPTBASE.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Mouse.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Kernel32.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.User32.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\websocket-sharp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.GrammarlyBusinessApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Parallel.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.SDUI.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Json.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Collections.Immutable.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\WordApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Validation.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: profapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.Accessible2.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.AdvApi32.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Numerics.Vectors.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.DesignSystem.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Core.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Storage.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LZStringCSharp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: cscapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.SDUI.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Batteries.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\e_sqlite3.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.OAuth2.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: edputil.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Windows.ShellSuserngApi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Common.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Logging.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.BusinessMetric.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\e_sqlite3.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Transforms.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Felog.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.UIAutomationClient.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Suggestions.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeDLL: twinapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Runtime.CompilerServices.Unsafe.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\NetOffice.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.ValueTuple.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Newtonsoft.Json.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDLL: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.IO.Abstractions.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeEXE: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeEXE: tasklist.exe
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeEXE: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Uninstall.exe
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Grammarly Desktop Integrations
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-DiffMatchPatch.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-NHotkey.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-NLog.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-NewtonsoftJson.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-Validation.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-dotnet.txt
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeStatic PE information: certificate valid
Source: unknownHTTPS traffic detected: 34.197.163.13:443 -> 192.168.2.16:49728 version: TLS 1.2
Source: unknownHTTPS traffic detected: 3.231.17.194:443 -> 192.168.2.16:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 3.231.17.194:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.21.223.151:443 -> 192.168.2.16:49731 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.208.47.8:443 -> 192.168.2.16:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 107.22.173.72:443 -> 192.168.2.16:49734 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.197.163.13:443 -> 192.168.2.16:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 44.205.78.241:443 -> 192.168.2.16:49738 version: TLS 1.2
Source: unknownHTTPS traffic detected: 3.211.23.45:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.73.100.250:443 -> 192.168.2.16:50127 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.235.239.81:443 -> 192.168.2.16:50175 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.235.239.81:443 -> 192.168.2.16:50184 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.154.132.81:443 -> 192.168.2.16:50198 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.235.76.136:443 -> 192.168.2.16:50200 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.3.124.253:443 -> 192.168.2.16:50201 version: TLS 1.2
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile opened: C:\Users\user
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile opened: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile opened: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile opened: C:\Users\user\AppData
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile opened: C:\Users\user\AppData\Local
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile opened: C:\Users\user\AppData\Local\Grammarly
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownTCP traffic detected without corresponding DNS query: 172.183.192.109
Source: unknownDNS traffic detected: queries for: win-extension.femetrics.grammarly.io
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49986
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49985
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49984
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49983
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49982
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49981
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49980
Source: unknownNetwork traffic detected: HTTP traffic on port 49932 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49898 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50131 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50211 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 50177 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49979
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49978
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49977
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49976
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49975
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49974
Source: unknownNetwork traffic detected: HTTP traffic on port 50085 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49973
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49972
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49971
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49970
Source: unknownNetwork traffic detected: HTTP traffic on port 50165 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50004 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49909 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49969
Source: unknownNetwork traffic detected: HTTP traffic on port 49978 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49886 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49968
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49967
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49966
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49965
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49964
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49963
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49962
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49961
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49960
Source: unknownNetwork traffic detected: HTTP traffic on port 49966 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50189 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50108 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50073 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49959
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49958
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49957
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49956
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49955
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49954
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49953
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49952
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49951
Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49950
Source: unknownNetwork traffic detected: HTTP traffic on port 49944 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49910 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50051 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50153 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49949
Source: unknownNetwork traffic detected: HTTP traffic on port 50235 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49948
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49947
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49946
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49945
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49944
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49943
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 50061 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 49922 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49968 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50187 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50221 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 50095 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50155 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49991 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 50038 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 50143 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50208 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49956 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 50083 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49999
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49998
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49997
Source: unknownNetwork traffic detected: HTTP traffic on port 50121 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49996
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49995
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49994
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49993
Source: unknownNetwork traffic detected: HTTP traffic on port 50016 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49992
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49991
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49990
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49874 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49934 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50199 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49989
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49988
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49987
Source: unknownNetwork traffic detected: HTTP traffic on port 50151 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50116 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50225 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50071 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50106
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50108
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50107
Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50109
Source: unknownNetwork traffic detected: HTTP traffic on port 49929 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50100
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50102
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50101
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50104
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50103
Source: unknownNetwork traffic detected: HTTP traffic on port 49964 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50128 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50197 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50117
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50116
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50119
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50118
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50111
Source: unknownNetwork traffic detected: HTTP traffic on port 49930 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50110
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50113
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50112
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50115
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50114
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49986 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50175 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50213 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50128
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 50012 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50127
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50129
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 49952 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50120
Source: unknownNetwork traffic detected: HTTP traffic on port 50093 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50122
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50121
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50124
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50123
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50126
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50125
Source: unknownNetwork traffic detected: HTTP traffic on port 50048 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49907 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49894 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50106 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49942 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50081 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50173 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49919 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49954 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50014 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49988 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50201 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50046 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49882 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50141 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50233 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49976 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50118 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50223 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50024 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50163 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49998 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50058 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50002 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50185 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49920 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49926 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50054
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50053
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50056
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50055
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50058
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50057
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50059
Source: unknownNetwork traffic detected: HTTP traffic on port 49961 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50061
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50060
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50063
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50062
Source: unknownNetwork traffic detected: HTTP traffic on port 50102 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50045 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50148 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50064
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50067
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50066
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50069
Source: unknownNetwork traffic detected: HTTP traffic on port 50205 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50183 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50070
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50072
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50071
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50074
Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50073
Source: unknownNetwork traffic detected: HTTP traffic on port 50080 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50227 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50195 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50076
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50075
Source: unknownNetwork traffic detected: HTTP traffic on port 50057 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50078
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50077
Source: unknownNetwork traffic detected: HTTP traffic on port 50114 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50079
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50081
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50080
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50083
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50082
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50085
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50084
Source: unknownNetwork traffic detected: HTTP traffic on port 49904 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50087
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50086
Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50089
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50088
Source: unknownNetwork traffic detected: HTTP traffic on port 50079 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50090
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50092
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50091
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50094
Source: unknownNetwork traffic detected: HTTP traffic on port 50136 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49983 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50093
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50096
Source: unknownNetwork traffic detected: HTTP traffic on port 49938 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50095
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50018
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50017
Source: unknownNetwork traffic detected: HTTP traffic on port 50193 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50019
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49951 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50010
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50012
Source: unknownNetwork traffic detected: HTTP traffic on port 49916 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50055 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50011
Source: unknownNetwork traffic detected: HTTP traffic on port 50090 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50014
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50013
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50016
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50015
Source: unknownNetwork traffic detected: HTTP traffic on port 50161 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50215 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50230 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50029
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50020
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50022
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50024
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50027
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49879 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49985 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50030
Source: unknownNetwork traffic detected: HTTP traffic on port 50067 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50039
Source: unknownNetwork traffic detected: HTTP traffic on port 49995 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50011 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50032
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50031
Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50034
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50033
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50035
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50038
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50037
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50041
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50040
Source: unknownNetwork traffic detected: HTTP traffic on port 50104 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50089 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49973 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50203 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50033 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50171 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50043
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50042
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50045
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50044
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50047
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50046
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50049
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50048
Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50050
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50052
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50051
Source: unknownNetwork traffic detected: HTTP traffic on port 50126 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50168 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50122 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49912 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49958 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50219 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49946 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50018 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50077 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50134 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50053 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49981 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49924 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50099 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50031 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50156 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50043 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50100 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50207 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50006 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50181 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49867 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49942
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49941
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49940
Source: unknownNetwork traffic detected: HTTP traffic on port 50229 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50098
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50097
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50099
Source: unknownNetwork traffic detected: HTTP traffic on port 50112 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50075 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50158 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49939
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49938
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49937
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49936
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49935
Source: unknownNetwork traffic detected: HTTP traffic on port 49902 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49934
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49933
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49932
Source: unknownNetwork traffic detected: HTTP traffic on port 50087 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49931
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49930
Source: unknownNetwork traffic detected: HTTP traffic on port 50008 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49971 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49936 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49929
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49928
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49927
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49926
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49925
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49924
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49923
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49922
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49921
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49920
Source: unknownNetwork traffic detected: HTTP traffic on port 50063 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50124 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50191 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49877 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50217 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49914 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49919
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49918
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49917
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49916
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49915
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49914
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49913
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49912
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49910
Source: unknownNetwork traffic detected: HTTP traffic on port 49948 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50041 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50146 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50097 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49909
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49908
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49907
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49906
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49905
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49904
Source: unknownHTTPS traffic detected: 34.197.163.13:443 -> 192.168.2.16:49728 version: TLS 1.2
Source: unknownHTTPS traffic detected: 3.231.17.194:443 -> 192.168.2.16:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 3.231.17.194:443 -> 192.168.2.16:49730 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.21.223.151:443 -> 192.168.2.16:49731 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.208.47.8:443 -> 192.168.2.16:49733 version: TLS 1.2
Source: unknownHTTPS traffic detected: 107.22.173.72:443 -> 192.168.2.16:49734 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.197.163.13:443 -> 192.168.2.16:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 44.205.78.241:443 -> 192.168.2.16:49738 version: TLS 1.2
Source: unknownHTTPS traffic detected: 3.211.23.45:443 -> 192.168.2.16:49742 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.73.100.250:443 -> 192.168.2.16:50127 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.235.239.81:443 -> 192.168.2.16:50175 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.235.239.81:443 -> 192.168.2.16:50184 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.154.132.81:443 -> 192.168.2.16:50198 version: TLS 1.2
Source: unknownHTTPS traffic detected: 34.235.76.136:443 -> 192.168.2.16:50200 version: TLS 1.2
Source: unknownHTTPS traffic detected: 52.3.124.253:443 -> 192.168.2.16:50201 version: TLS 1.2

Key, Mouse, Clipboard, Microphone and Screen Capturing

barindex
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeWindows user hook set: Path: unknown Event Start:focus Event End: focus Module: NULL
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeWindows user hook set: Path: unknown Event Start:focus Event End: focus Module: NULL
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engineClassification label: sus27.winEXE@76/502@39/251
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeMutant created: \Sessions\1\BaseNamedObjects\com.grammarly.ProjectLlama.SingleInstance
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeMutant created: NULL
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeMutant created: \Sessions\1\BaseNamedObjects\grammarly.desktop.installer-6e9b97a3-dfe7-4a91-afbe-8e51f7be6d6c
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Temp\nsm152A.tmp
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile read: C:\Users\desktop.ini
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeFile read: C:\Windows\System32\drivers\etc\hosts
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile read: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
Source: unknownProcess created: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe "C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe"
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe "C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe" new-version-v2 onboarding
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist /NH /FI "IMAGENAME eq Grammarly.Desktop.exe"
Source: C:\Windows\SysWOW64\tasklist.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --embedded-browser-webview=1 --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --noerrdialogs --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --enable-features=MojoIpcz --mojo-named-platform-channel-pipe=7104.3668.17407409699958160167
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=117.0.5938.132 "--annotation=exe=C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=117.0.2045.47 --initial-client-data=0x15c,0x160,0x164,0x138,0x170,0x7fff1e618e88,0x7fff1e618e98,0x7fff1e618ea8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:2
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=1980 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:3
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-GB --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=2440 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --disable-nacl --first-renderer-process --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=en_CH" --time-ticks-at-unix-epoch=-1713946862127608 --launch-time-ticks=5472465795 --mojo-platform-channel-handle=3312 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:1
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=A0ej0vpdcBiI-yz3QBpBBJwbh5pbNmPvz1dsC4zUlqs&verify=j4bHc&showSuccessState=true
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=2028,i,1723528232903650596,3920355234927745539,262144 /prefetch:3
Source: C:\Windows\explorer.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=A0ej0vpdcBiI-yz3QBpBBJwbh5pbNmPvz1dsC4zUlqs&verify=j4bHc&showSuccessState=true
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2612 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:3
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=6qrxDAzOWbV4ISaXbaeblzbqt1-zHDJKTAsNkxFACRE&verify=j4bHc&showSuccessState=true
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe "C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe" new-version-v2 onboarding
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist /NH /FI "IMAGENAME eq Grammarly.Desktop.exe"
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=7364 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=7468 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=A0ej0vpdcBiI-yz3QBpBBJwbh5pbNmPvz1dsC4zUlqs&verify=j4bHc&showSuccessState=true
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=6qrxDAzOWbV4ISaXbaeblzbqt1-zHDJKTAsNkxFACRE&verify=j4bHc&showSuccessState=true
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: unknown unknown
Source: C:\Windows\explorer.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=A0ej0vpdcBiI-yz3QBpBBJwbh5pbNmPvz1dsC4zUlqs&verify=j4bHc&showSuccessState=true
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=117.0.5938.132 "--annotation=exe=C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=117.0.2045.47 --initial-client-data=0x15c,0x160,0x164,0x138,0x170,0x7fff1e618e88,0x7fff1e618e98,0x7fff1e618ea8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:2
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=1980 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:3
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-GB --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=2440 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --disable-nacl --first-renderer-process --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=en_CH" --time-ticks-at-unix-epoch=-1713946862127608 --launch-time-ticks=5472465795 --mojo-platform-channel-handle=3312 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:1
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=YMT3ROP5autsdjZ_tsNOQAOfNJfh5L4UPzMB0_suXcA&verify=j4bHc&showSuccessState=true
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6796 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=DedXj_1j5KNl-qml7Yln6Y4k7TpJCcoTkY4W331meKk&verify=j4bHc&showSuccessState=true
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2612 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:3
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=7364 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=7468 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6796 --field-trial-handle=2044,i,6870177471301933371,15639429936319785931,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: userenv.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: apphelp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: propsys.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: dwmapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: cryptbase.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: oleacc.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: ntmarta.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: version.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: shfolder.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: windows.storage.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: wldp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: riched20.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: usp10.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: msls31.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: textshaping.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: textinputframework.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: coremessaging.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: mswsock.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: dnsapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: rasadhlp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: fwpuclnt.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: cryptsp.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: rsaenh.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: profapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: linkinfo.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: ntshrui.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: sspicli.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: srvcli.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: cscapi.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: edputil.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: urlmon.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: iertutil.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: netutils.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: windows.staterepositoryps.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: appresolver.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: bcp47langs.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: slc.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: sppc.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeSection loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: mscoree.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: version.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: vcruntime140_clr0400.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: cryptsp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: rsaenh.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: cryptbase.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: windows.applicationmodel.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: twinapi.appcore.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: propsys.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: msasn1.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: riched20.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: usp10.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: msls31.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: gpapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: dnsapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: dhcpcsvc6.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: dhcpcsvc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: winnsi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: rasapi32.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: rasman.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: rtutils.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: winhttp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: rasadhlp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: fwpuclnt.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: secur32.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: schannel.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: mskeyprotect.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: ncryptsslp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: windows.ui.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: windowmanagementapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: inputhost.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: dwrite.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: msvcp140_clr0400.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: uiautomationcore.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: netfxperf.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: pdh.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: wtsapi32.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: bitsperf.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: bitsproxy.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: esentprf.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: perfts.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: winsta.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: utildll.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: tdh.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: msdtcuiu.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: atl.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: msdtcprx.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: mtxclu.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: clusapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: resutils.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: ktmw32.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: wkscli.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: cscapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: msscntrs.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: perfdisk.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: wmiclnt.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: perfnet.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: browcli.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: perfos.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: perfproc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: sysmain.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: umpdc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: powrprof.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: rasctrs.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: tapiperf.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: perfctrs.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: usbperf.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: wbemcomn.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: tquery.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: cryptdll.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: appresolver.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: bcp47langs.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: slc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: sppc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: windowscodecs.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: linkinfo.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: thumbcache.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: dpapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: policymanager.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: msvcp110_win.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: perfproc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: d3d9.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: d3d10warp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: sxs.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: oleacc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: uiamanager.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: wtsapi32.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: winsta.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: powrprof.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: umpdc.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: dataexchange.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: d3d11.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: dcomp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: dxgi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: resourcepolicyclient.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: dxcore.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: edputil.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: msctfui.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: d3dcompiler_47.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: dbghelp.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: actxprxy.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: twinapi.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: edputil.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: windows.staterepositoryps.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: ia2comproxy.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: version.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: ntmarta.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: uxtheme.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: windows.system.profile.platformdiagnosticsandusagedatasettings.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: policymanager.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: winmm.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: kbdus.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: windows.system.profile.platformdiagnosticsandusagedatasettings.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: policymanager.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: userenv.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: gpapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: wkscli.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: netutils.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: mdmregistration.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: mdmregistration.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: omadmapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: powrprof.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dmcmnutils.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: iri.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: umpdc.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: netapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: netapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dsreg.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: msvcp110_win.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: profapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: powrprof.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: umpdc.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dwrite.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dpapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: nlaapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: iphlpapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dhcpcsvc6.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dhcpcsvc.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dnsapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: textinputframework.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: coremessaging.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: windows.storage.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: wldp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: windows.ui.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: windowmanagementapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: inputhost.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: twinapi.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: twinapi.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: propsys.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: profapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: wtsapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: mscms.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: coloradapterclient.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: winsta.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: winhttp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: windows.security.authentication.web.core.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: iertutil.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: devobj.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: rsaenh.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dataexchange.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: d3d11.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dcomp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dxgi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: uxtheme.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dxgi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: resourcepolicyclient.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: mf.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: mfplat.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: rtworkq.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: hevcdecoder.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dolbydecmft.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: mfperfhelper.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dwmapi.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: netapi32.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: uiautomationcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: atlthunk.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: oleacc.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: directmanipulation.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: d3d11.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: d3d10warp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dbghelp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dxcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dcomp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: dwrite.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: wldp.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: windows.security.authentication.onlineid.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: onecoreuapcommonproxystub.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: policymanager.dll
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeSection loaded: msvcp110_win.dll
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeSection loaded: windows.shell.servicehostbuilder.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist /NH /FI "IMAGENAME eq Grammarly.Desktop.exe"
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Grammarly Desktop Integrations
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeStatic PE information: certificate valid
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeStatic file information: File size 18314104 > 1048576
Source: GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Keyboard.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\DynamicData.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Iterable.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.ExperimentationSDK.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm64\native\WebView2Loader.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Services.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.WebView.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Auth.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.PInvoke.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Dependencies.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Security.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Temp\nsw156A.tmp\NScurl.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.CheetahClient.Protocol.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.IAccessible2Lib.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Batteries.FSharp.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\WebView2Loader.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Logging.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.LegacyCheetahProtocol.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\WebView2Loader.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Dapper.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LanguageExt.Core.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Common.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Abstractions.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Main.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Tracking.GnarClient.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grace.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.Common.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Temp\nsw156A.tmp\nsExec.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.UI.Onboarding.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Diagnostics.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Data.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm\native\e_sqlite3.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.StorageClient.Protocol.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.FSharp.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.ConfigurationApi.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.QuillDelta.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.MsOffice.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Serialization.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Mouse.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.GrammarlyBusinessApi.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Parallel.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Reactive.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Gos.Sdk.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.SDUI.Core.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.TextChecking.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Json.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Premium.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.Accessible2.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Temp\nsw156A.tmp\System.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.DesignSystem.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Core.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Common.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Storage.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LZStringCSharp.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.SDUI.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\FSharp.Core.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Batteries.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.SDUI.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\e_sqlite3.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.OAuth2.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.CoreApi.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Gnar.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Common.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Logging.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.BusinessMetric.Abstractions.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Application.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.WinEvents.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\e_sqlite3.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Uninstall.exeJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.UIAutomation.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.SDUI.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Transforms.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Felog.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.UIAutomationClient.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Suggestions.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Http.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Experimentation.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-DiffMatchPatch.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-NHotkey.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-NLog.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-NewtonsoftJson.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-Validation.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Legal\License-dotnet.txt
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Grammarly
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Grammarly
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\explorer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeMemory allocated: 27D3A450000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeMemory allocated: 27D52550000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeThread delayed: delay time: 922337203685477
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeWindow / User API: threadDelayed 8585
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeWindow / User API: threadDelayed 1242
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Keyboard.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\DynamicData.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Iterable.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.ExperimentationSDK.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm64\native\WebView2Loader.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Services.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.WebView.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Auth.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.PInvoke.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Dependencies.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsw156A.tmp\NScurl.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Security.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.CheetahClient.Protocol.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Batteries.FSharp.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.IAccessible2Lib.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\WebView2Loader.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Logging.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.LegacyCheetahProtocol.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\WebView2Loader.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Dapper.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LanguageExt.Core.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Common.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Abstractions.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Main.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Tracking.GnarClient.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.Common.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grace.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsw156A.tmp\nsExec.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.UI.Onboarding.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Diagnostics.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Data.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-arm\native\e_sqlite3.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.StorageClient.Protocol.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.FSharp.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.QuillDelta.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.ConfigurationApi.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.MsOffice.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Serialization.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Mouse.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.GrammarlyBusinessApi.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Parallel.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Reactive.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Gos.Sdk.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.SDUI.Core.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.TextChecking.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Json.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Premium.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.Accessible2.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsw156A.tmp\System.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Core.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.DesignSystem.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Common.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Storage.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LZStringCSharp.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.SDUI.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\FSharp.Core.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Batteries.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.SDUI.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x86\native\e_sqlite3.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.OAuth2.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.CoreApi.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Gnar.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Common.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Logging.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Application.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.BusinessMetric.Abstractions.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.WinEvents.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\runtimes\win-x64\native\e_sqlite3.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Uninstall.exeJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.UIAutomation.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.SDUI.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Transforms.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Felog.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.UIAutomationClient.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Suggestions.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Http.dllJump to dropped file
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Experimentation.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe TID: 5504Thread sleep time: -7378697629483816s >= -30000s
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe TID: 4872Thread sleep count: 8585 > 30
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe TID: 4872Thread sleep count: 1242 > 30
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\d0010809
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeFile Volume queried: C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Code Cache\js FullSizeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeFile Volume queried: C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Code Cache\wasm FullSizeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeThread delayed: delay time: 922337203685477
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile opened: C:\Users\user
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile opened: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile opened: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile opened: C:\Users\user\AppData
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile opened: C:\Users\user\AppData\Local
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeFile opened: C:\Users\user\AppData\Local\Grammarly
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess information queried: ProcessInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess token adjusted: Debug
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeMemory allocated: page read and write | page guard
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess created: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe "C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe" new-version-v2 onboarding
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist /NH /FI "IMAGENAME eq Grammarly.Desktop.exe"
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=A0ej0vpdcBiI-yz3QBpBBJwbh5pbNmPvz1dsC4zUlqs&verify=j4bHc&showSuccessState=true
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://www.grammarly.com/signin/app?client_id=windowsExtension&code_challenge=6qrxDAzOWbV4ISaXbaeblzbqt1-zHDJKTAsNkxFACRE&verify=j4bHc&showSuccessState=true
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Crashpad --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=117.0.5938.132 "--annotation=exe=C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --annotation=plat=Win64 "--annotation=prod=Edge WebView2" --annotation=ver=117.0.2045.47 --initial-client-data=0x15c,0x160,0x164,0x138,0x170,0x7fff1e618e88,0x7fff1e618e98,0x7fff1e618ea8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:2
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=1980 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:3
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-GB --service-sandbox-type=service --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=2440 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView" --webview-exe-name=Grammarly.Desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --disable-nacl --first-renderer-process --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=en_CH" --time-ticks-at-unix-epoch=-1713946862127608 --launch-time-ticks=5472465795 --mojo-platform-channel-handle=3312 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=MojoIpcz /prefetch:1
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --embedded-browser-webview=1 --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --noerrdialogs --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --enable-features=mojoipcz --mojo-named-platform-channel-pipe=7104.3668.17407409699958160167
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview\crashpad --annotation=isofficialbuild=1 --annotation=channel= --annotation=chromium-version=117.0.5938.132 "--annotation=exe=c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --annotation=plat=win64 "--annotation=prod=edge webview2" --annotation=ver=117.0.2045.47 --initial-client-data=0x15c,0x160,0x164,0x138,0x170,0x7fff1e618e88,0x7fff1e618e98,0x7fff1e618ea8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --gpu-preferences=waaaaaaaaadgaaamaaaaaaaaaaaaaaaaaabgaaaaaaa4aaaaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaagaaaaaaaaaayaaaaaaaaaagaaaaaaaaacaaaaaaaaaaiaaaaaaaaaa== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:2
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.networkservice --lang=en-gb --service-sandbox-type=none --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=1980 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:3
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.storageservice --lang=en-gb --service-sandbox-type=service --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=2440 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --disable-nacl --first-renderer-process --lang=en-gb --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=en_ch" --time-ticks-at-unix-epoch=-1713946862127608 --launch-time-ticks=5472465795 --mojo-platform-channel-handle=3312 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:1
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=crashpad-handler --user-data-dir=c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler --database=c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview\crashpad --annotation=isofficialbuild=1 --annotation=channel= --annotation=chromium-version=117.0.5938.132 "--annotation=exe=c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --annotation=plat=win64 "--annotation=prod=edge webview2" --annotation=ver=117.0.2045.47 --initial-client-data=0x15c,0x160,0x164,0x138,0x170,0x7fff1e618e88,0x7fff1e618e98,0x7fff1e618ea8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=gpu-process --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --gpu-preferences=waaaaaaaaadgaaamaaaaaaaaaaaaaaaaaabgaaaaaaa4aaaaaaaaaaaaaaaeaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaagaaaaaaaaaayaaaaaaaaaagaaaaaaaaacaaaaaaaaaaiaaaaaaaaaa== --mojo-platform-channel-handle=1772 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:2
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=network.mojom.networkservice --lang=en-gb --service-sandbox-type=none --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=1980 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:3
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=utility --utility-sub-type=storage.mojom.storageservice --lang=en-gb --service-sandbox-type=service --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --mojo-platform-channel-handle=2440 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:8
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeProcess created: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe "c:\program files (x86)\microsoft\edgewebview\application\117.0.2045.47\msedgewebview2.exe" --type=renderer --noerrdialogs --user-data-dir="c:\users\user\appdata\roaming\grammarly\desktopintegrations\webviewuserdatafolder\ebwebview" --webview-exe-name=grammarly.desktop.exe --webview-exe-version=1.2.73.1374 --embedded-browser-webview=1 --embedded-browser-webview-dpi-awareness=2 --edge-webview-custom-scheme --disable-nacl --first-renderer-process --lang=en-gb --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --js-flags="--harmony-weak-refs-with-cleanup-some --expose-gc --ms-user-locale=en_ch" --time-ticks-at-unix-epoch=-1713946862127608 --launch-time-ticks=5472465795 --mojo-platform-channel-handle=3312 --field-trial-handle=1776,i,2049788337709370666,9571100101711157599,262144 --enable-features=mojoipcz /prefetch:1
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Services.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Common.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\LanguageExt.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\netstandard\v4.0_2.0.0.0__cc7b13ffcd2ddd51\netstandard.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Reactive.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.UI.winmd VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.Foundation.winmd VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.WindowsRuntime\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.WindowsRuntime.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.InteropServices.WindowsRuntime\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.InteropServices.WindowsRuntime.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Storage.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Gnar.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.TextChecking.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Parallel.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Collections.Immutable.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Keyboard.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Main.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Auth.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Premium.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.GrammarlyBusinessApi.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.ConfigurationApi.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Iterable.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.WebView.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.CoreApi.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Felog.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Logging.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Abstractions.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.BusinessMetric.Abstractions.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\NLog.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Bcl.AsyncInterfaces.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Newtonsoft.Json.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Tracking.GnarClient.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\FSharp.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Json.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Http.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Interfaces.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Logging.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Batteries.FSharp.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Reactive.Linq.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Text.Json.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Batteries.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.ExperimentationSDK.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Experimentation.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Diagnostics.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Application.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Common.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Data.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.SDUI.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Utils.PInvoke.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.User32.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Interop.UIAutomationClient.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Dependencies.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.FSharp.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Common.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.OAuth2.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.SDUI.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.ValueTuple.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Threading.Tasks.Extensions.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Gos.Sdk.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.SDUI.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\DynamicData.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Suggestions.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.LegacyCheetahProtocol.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\websocket-sharp.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Transforms.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.QuillDelta.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.Services.winmd VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.SDUI.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.UI.Xaml.winmd VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.WinEvents.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Mouse.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.Accessible2.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.UI.Classic.Common.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Web.WebView2.Wpf.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Windows.Core.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Kernel32.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Security.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Toolkit.Uwp.Notifications.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.ApplicationModel.winmd VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.Storage.winmd VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\PInvoke.Windows.ShellSuserngApi.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.MsOffice.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.DesignSystem.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Resources.Extensions.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Memory.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Runtime.CompilerServices.Unsafe.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\System.Numerics.Vectors.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ariali.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ARIALN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ariblk.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ARIALNI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ARIALNB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ARIALNBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\userbrii.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\userbrili.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\userbrib.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\consola.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\consolai.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\consolab.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\consolaz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOD_I.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\userFR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\userFI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\userFB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\userST.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\userSTI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\userSTB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\userSTBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\CURLZ___.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\DUBAI-REGULAR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\DUBAI-MEDIUM.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\DUBAI-BOLD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\FELIXTI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GILBI___.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GILC____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GLSNECB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GLECB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\HTOWERT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LBRITE.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LCALLIG.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LFAXD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LHANDW.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LSANSDI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\LTYPEBO.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\MATURASC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\MISTRAL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\MOD20.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\OUTLOOK.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\PAPYRUS.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\PERI____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\PERB____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\PERTIBD.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\PLAYBILL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\PRISTINA.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\RAGE.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\ROCCB___.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\STENCIL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\TCM_____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\TCB_____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\TCCM____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\VIVALDII.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\VLADIMIR.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\WINGDNG3.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\flat_officeFontsPreview.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\OFFSYM.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\OFFSYMSL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\OFFSYMSB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\OFFSYMXL.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\OFFSYML.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\OFFSYMB.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\WordApi.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\NetOffice.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Microsoft.Xaml.Behaviors.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Windows\System32\drivers\etc\hosts VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\Trust Protection Lists\manifest.json VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\WidevineCdm\manifest.json VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Windows\Fonts\arial.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Windows\Fonts\ARIALN.TTF VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Windows\Fonts\ARIALNI.TTF VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Windows\Fonts\arialbi.ttf VolumeInformation
Source: C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exeQueries volume information: C:\Windows\Fonts\ARIALNBI.TTF VolumeInformation
Source: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
Command and Scripting Interpreter
1
Windows Service
1
Windows Service
1
Masquerading
1
Credential API Hooking
2
Process Discovery
Remote Services1
Credential API Hooking
2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Registry Run Keys / Startup Folder
11
Process Injection
1
Disable or Modify Tools
LSASS Memory31
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
DLL Side-Loading
1
Registry Run Keys / Startup Folder
31
Virtualization/Sandbox Evasion
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCron2
DLL Search Order Hijacking
1
DLL Side-Loading
11
Process Injection
NTDS1
Remote System Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script2
DLL Search Order Hijacking
1
DLL Side-Loading
LSA Secrets2
File and Directory Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts2
DLL Search Order Hijacking
Cached Domain Credentials23
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe0%ReversingLabs
GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe0%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Dapper.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Dapper.dll0%VirustotalBrowse
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\DynamicData.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\DynamicData.dll0%VirustotalBrowse
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\FSharp.Core.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\FSharp.Core.dll0%VirustotalBrowse
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grace.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grace.dll0%VirustotalBrowse
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.FSharp.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.FSharp.dll0%VirustotalBrowse
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Batteries.FSharp.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.CheetahClient.Protocol.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Abstractions.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Batteries.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Data.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Diagnostics.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Logging.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Parallel.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Reactive.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Security.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Common.Serialization.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.DesignSystem.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.Accessible2.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.MsOffice.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.UIAutomation.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Attachment.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.BusinessMetric.Abstractions.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Core.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Dependencies.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Experimentation.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Gnar.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Main.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.Services.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.UI.Onboarding.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.WebView.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Application.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Common.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.SDUI.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Suggestions.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.Models.Transforms.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.QuillDelta.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.SDUI.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Domain.TextChecking.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Keyboard.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Mouse.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.Storage.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Env.WinEvents.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.ExperimentationSDK.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Gos.Sdk.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Http.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Json.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.LegacyCheetahProtocol.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Logging.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.SDUI.Core.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Auth.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.Common.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.ConfigurationApi.dll0%ReversingLabs
C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Services.CoreApi.dll0%ReversingLabs
No Antivirus matches
SourceDetectionScannerLabelLink
win-extension.femetrics.grammarly.io0%VirustotalBrowse
f-log-win-extension.grammarly.io0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
chrome.cloudflare-dns.com
162.159.61.3
truefalse
    unknown
    auth.grammarly.com
    23.21.223.151
    truefalse
      high
      properties.grammarly.com
      3.211.23.45
      truefalse
        high
        public-treatment.prod-experimentation.grammarlyaws.com
        107.22.173.72
        truefalse
          unknown
          f-log-win-extension.grammarly.io
          3.231.17.194
          truefalseunknown
          gates.grammarly.com
          44.205.78.241
          truefalse
            high
            us-cds.taboola.com
            141.226.224.32
            truefalse
              high
              www.grammarly.com
              44.212.184.83
              truefalse
                high
                win-extension.femetrics.grammarly.io
                34.197.163.13
                truefalseunknown
                update-windows.grammarly.com
                18.154.132.81
                truefalse
                  high
                  app.grammarly.com
                  44.209.120.59
                  truefalse
                    high
                    gnar.grammarly.com
                    18.208.47.8
                    truefalse
                      high
                      denali-static.grammarly.com
                      18.164.174.95
                      truefalse
                        high
                        treatment.grammarly.com
                        unknown
                        unknownfalse
                          high
                          cds.taboola.com
                          unknown
                          unknownfalse
                            high
                            • No. of IPs < 25%
                            • 25% < No. of IPs < 50%
                            • 50% < No. of IPs < 75%
                            • 75% < No. of IPs
                            IPDomainCountryFlagASNASN NameMalicious
                            184.73.100.250
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            20.25.227.174
                            unknownUnited States
                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            13.107.6.158
                            unknownUnited States
                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            204.79.197.200
                            unknownUnited States
                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            34.202.153.49
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            216.137.39.47
                            unknownUnited States
                            16509AMAZON-02USfalse
                            104.16.117.43
                            unknownUnited States
                            13335CLOUDFLARENETUSfalse
                            18.154.142.121
                            unknownUnited States
                            16509AMAZON-02USfalse
                            142.250.101.154
                            unknownUnited States
                            15169GOOGLEUSfalse
                            162.159.61.3
                            chrome.cloudflare-dns.comUnited States
                            13335CLOUDFLARENETUSfalse
                            3.92.120.28
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            151.101.65.140
                            unknownUnited States
                            54113FASTLYUSfalse
                            23.219.38.72
                            unknownUnited States
                            20940AKAMAI-ASN1EUfalse
                            3.211.23.45
                            properties.grammarly.comUnited States
                            14618AMAZON-AESUSfalse
                            23.21.223.151
                            auth.grammarly.comUnited States
                            14618AMAZON-AESUSfalse
                            204.79.197.239
                            unknownUnited States
                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            18.164.174.31
                            unknownUnited States
                            3MIT-GATEWAYSUSfalse
                            142.250.141.104
                            unknownUnited States
                            15169GOOGLEUSfalse
                            44.205.78.241
                            gates.grammarly.comUnited States
                            14618AMAZON-AESUSfalse
                            23.3.84.234
                            unknownUnited States
                            16625AKAMAI-ASUSfalse
                            52.41.227.71
                            unknownUnited States
                            16509AMAZON-02USfalse
                            204.79.197.237
                            unknownUnited States
                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            142.251.2.155
                            unknownUnited States
                            15169GOOGLEUSfalse
                            34.224.77.76
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            151.101.193.44
                            unknownUnited States
                            54113FASTLYUSfalse
                            31.13.70.36
                            unknownIreland
                            32934FACEBOOKUSfalse
                            1.1.1.1
                            unknownAustralia
                            13335CLOUDFLARENETUSfalse
                            34.235.76.136
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            13.107.21.237
                            unknownUnited States
                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            44.212.184.83
                            www.grammarly.comUnited States
                            14618AMAZON-AESUSfalse
                            34.197.11.42
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            40.76.174.66
                            unknownUnited States
                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            13.107.21.239
                            unknownUnited States
                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            44.235.175.241
                            unknownUnited States
                            16509AMAZON-02USfalse
                            34.235.239.81
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            20.99.186.246
                            unknownUnited States
                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            13.107.42.16
                            unknownUnited States
                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            104.16.118.43
                            unknownUnited States
                            13335CLOUDFLARENETUSfalse
                            13.107.42.14
                            unknownUnited States
                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            172.183.192.109
                            unknownUnited States
                            7018ATT-INTERNET4USfalse
                            23.219.38.40
                            unknownUnited States
                            20940AKAMAI-ASN1EUfalse
                            142.251.2.148
                            unknownUnited States
                            15169GOOGLEUSfalse
                            239.255.255.250
                            unknownReserved
                            unknownunknownfalse
                            151.101.65.44
                            unknownUnited States
                            54113FASTLYUSfalse
                            216.239.36.54
                            unknownUnited States
                            15169GOOGLEUSfalse
                            18.219.60.11
                            unknownUnited States
                            16509AMAZON-02USfalse
                            52.223.40.198
                            unknownUnited States
                            8987AMAZONEXPANSIONGBfalse
                            18.208.125.13
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            142.250.141.113
                            unknownUnited States
                            15169GOOGLEUSfalse
                            34.200.169.99
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            107.22.173.72
                            public-treatment.prod-experimentation.grammarlyaws.comUnited States
                            14618AMAZON-AESUSfalse
                            142.251.2.100
                            unknownUnited States
                            15169GOOGLEUSfalse
                            216.137.39.100
                            unknownUnited States
                            16509AMAZON-02USfalse
                            23.23.170.89
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            13.107.246.69
                            unknownUnited States
                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            23.204.249.220
                            unknownUnited States
                            16625AKAMAI-ASUSfalse
                            20.125.62.241
                            unknownUnited States
                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            18.154.132.45
                            unknownUnited States
                            16509AMAZON-02USfalse
                            152.195.19.97
                            unknownUnited States
                            15133EDGECASTUSfalse
                            13.107.21.200
                            unknownUnited States
                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                            34.197.163.13
                            win-extension.femetrics.grammarly.ioUnited States
                            14618AMAZON-AESUSfalse
                            18.208.47.8
                            gnar.grammarly.comUnited States
                            14618AMAZON-AESUSfalse
                            104.18.37.212
                            unknownUnited States
                            13335CLOUDFLARENETUSfalse
                            3.231.17.194
                            f-log-win-extension.grammarly.ioUnited States
                            14618AMAZON-AESUSfalse
                            52.3.124.253
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            142.251.2.132
                            unknownUnited States
                            15169GOOGLEUSfalse
                            162.159.152.17
                            unknownUnited States
                            13335CLOUDFLARENETUSfalse
                            18.164.174.95
                            denali-static.grammarly.comUnited States
                            3MIT-GATEWAYSUSfalse
                            23.56.109.200
                            unknownUnited States
                            20940AKAMAI-ASN1EUfalse
                            3.248.143.215
                            unknownUnited States
                            16509AMAZON-02USfalse
                            142.251.2.97
                            unknownUnited States
                            15169GOOGLEUSfalse
                            54.88.125.176
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            44.209.120.59
                            app.grammarly.comUnited States
                            14618AMAZON-AESUSfalse
                            104.244.42.197
                            unknownUnited States
                            13414TWITTERUSfalse
                            52.200.166.19
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            104.244.42.3
                            unknownUnited States
                            13414TWITTERUSfalse
                            142.251.2.94
                            unknownUnited States
                            15169GOOGLEUSfalse
                            151.101.1.140
                            unknownUnited States
                            54113FASTLYUSfalse
                            34.111.113.62
                            unknownUnited States
                            15169GOOGLEUSfalse
                            52.22.38.2
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            31.13.70.7
                            unknownIreland
                            32934FACEBOOKUSfalse
                            146.75.92.157
                            unknownSweden
                            30051SCCGOVUSfalse
                            52.49.83.48
                            unknownUnited States
                            16509AMAZON-02USfalse
                            34.198.116.68
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            141.226.224.32
                            us-cds.taboola.comIsrael
                            200478TABOOLA-ASILfalse
                            34.226.161.161
                            unknownUnited States
                            14618AMAZON-AESUSfalse
                            35.244.142.80
                            unknownUnited States
                            15169GOOGLEUSfalse
                            34.120.195.249
                            unknownUnited States
                            15169GOOGLEUSfalse
                            18.154.132.81
                            update-windows.grammarly.comUnited States
                            16509AMAZON-02USfalse
                            146.75.92.84
                            unknownSweden
                            30051SCCGOVUSfalse
                            IP
                            127.0.0.1
                            192.168.2.16
                            Joe Sandbox version:40.0.0 Tourmaline
                            Analysis ID:1430937
                            Start date and time:2024-04-24 11:51:18 +02:00
                            Joe Sandbox product:CloudBasic
                            Overall analysis duration:
                            Hypervisor based Inspection enabled:false
                            Report type:full
                            Cookbook file name:defaultwindowsinteractivecookbook.jbs
                            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                            Number of analysed new started processes analysed:40
                            Number of new started drivers analysed:0
                            Number of existing processes analysed:0
                            Number of existing drivers analysed:0
                            Number of injected processes analysed:1
                            Technologies:
                            • EGA enabled
                            Analysis Mode:stream
                            Sample name:GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            Detection:SUS
                            Classification:sus27.winEXE@76/502@39/251
                            Cookbook Comments:
                            • Found application associated with file extension: .exe
                            • Exclude process from analysis (whitelisted): dllhost.exe, svchost.exe
                            • Excluded IPs from analysis (whitelisted): 13.107.42.16, 20.190.151.133, 20.190.151.70, 20.190.151.68, 20.190.151.134, 20.190.151.7, 20.190.151.132, 20.190.151.69, 20.190.151.6, 20.25.227.174
                            • Excluded domains from analysis (whitelisted): ctldl.windowsupdate.com
                            • Not all processes where analyzed, report is missing behavior information
                            • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                            • Report size getting too big, too many NtCreateFile calls found.
                            • Report size getting too big, too many NtEnumerateKey calls found.
                            • Report size getting too big, too many NtOpenFile calls found.
                            • Report size getting too big, too many NtOpenKey calls found.
                            • Report size getting too big, too many NtOpenKeyEx calls found.
                            • Report size getting too big, too many NtProtectVirtualMemory calls found.
                            • Report size getting too big, too many NtQueryValueKey calls found.
                            • Report size getting too big, too many NtReadVirtualMemory calls found.
                            • Report size getting too big, too many NtSetInformationFile calls found.
                            • Report size getting too big, too many NtWriteVirtualMemory calls found.
                            • Timeout during stream target processing, analysis might miss dynamic analysis data
                            • VT rate limit hit for: C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Auth.dll
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):225888
                            Entropy (8bit):6.623785835894481
                            Encrypted:false
                            SSDEEP:
                            MD5:73769A3CA63428E06C50D7EAFDD6FF1F
                            SHA1:09C3443395F960082586541BD396F6C24FA1F3FA
                            SHA-256:79E28A836F6D024C70FEBD0DBF2347B26B11E9B233FE6693B474938679503C43
                            SHA-512:8CDC2C19AB905B766691247CA3EE168F1EC85FCEC82924CD77B25F5E45FD0DFB4EBF6C96665055B5BD524A07EDBB9FCEFF0349798030413E2E27942BDBEDB283
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            • Antivirus: Virustotal, Detection: 0%, Browse
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...|.j..........." ..0..@..........2^... ...`....... ....................................`..................................]..O....`..d............J..`(..........x...p............................................ ............... ..H............text...8>... ...@.................. ..`.rsrc...d....`.......B..............@..@.reloc...............H..............@..B.................^......H........&................................................................(R...*..(R...*^.(R..........%...}....*:.(R.....}....*:.(R.....}....*:.(R.....}....*V!.........sS........*..(R...*:.(R.....}....*..{....*..(R...*..(R...*...0...........u....,..s....*.........*Z.(....uA...%-.&*o....*..{....*..{....*..{....*..{....*2.{....sT...*2.(....._...*2.(....._...*..{....*2.(....._...*.0..O.........}......}......}.......}..........(U...-..(....+...(V...}.......}.......}....*R.,.(#...
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):744032
                            Entropy (8bit):6.346363511455326
                            Encrypted:false
                            SSDEEP:
                            MD5:5331B33FCD83F3A69C842F62EDDC4D55
                            SHA1:7E18BD5B14F3071862527032BEDF5A5CBADA5466
                            SHA-256:F066E1124E668A969CB53E067E12A6F04943E3AA231FEC12E207B2704DC74F03
                            SHA-512:E27F7E315D42A68ECC13A861F72DF9799442878C4403610B72C5DCFF2A7C595DE511D60A10D823FD495FDCEB764549FF2A0F468368AC7B81940F63415DC99668
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            • Antivirus: Virustotal, Detection: 0%, Browse
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....p..........." ..0..&...........D... ...`....... ...............................J....`..................................D..O....`...............2..`(..............p............................................ ............... ..H............text....%... ...&.................. ..`.rsrc........`.......(..............@..@.reloc...............0..............@..B.................D......H.........................................................................{=...*..{>...*V.(?.....}=.....}>...*...0..A........u........4.,/(@....{=....{=...oA...,.(B....{>....{>...oC...*.*.*. .... )UU.Z(@....{=...oD...X )UU.Z(B....{>...oE...X*...0..b........r...p......%..{=......%q.........-.&.+.......oF....%..{>......%q.........-.&.+.......oF....(G...*..{H...*..{I...*V.(?.....}H.....}I...*.0..A........u........4.,/(@....{H....{H...oA...,.(B....{I....{I...oC...*.*.*. 6v.. )UU.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):2930784
                            Entropy (8bit):6.098548488740082
                            Encrypted:false
                            SSDEEP:
                            MD5:F4CE479D7CDCD25BD5F2BD33C232CC63
                            SHA1:939EC0B04FCB3284374A0E3885FA77DB4D7A3C81
                            SHA-256:A64A74241D19BDFE5FC73F97CE379B75EE315FEB4DCEDF3FB18CE8720111AD03
                            SHA-512:28B2696315E100C96AD9656A522DB5FD2753B7E1740B3FE27AFA284B7760F2B95745A0C77BD326C7C5F3959FA3FAC0AB4F00DE8717E86326897B07FFCFBBB91E
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            • Antivirus: Virustotal, Detection: 0%, Browse
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...E.;............!......,..........t*.. ....,...@.. ........................-.....X.,...`.................................]t*.^.....,...............,.`(....,......t*.p............................................ ............... ..H............text....,.. ....,................. ..`.rsrc.........,.......,.............@..@.reloc........,.......,.............@..B.................t*.....H........z...*..........`..............................................&.o.....&*....*.F.,..(...+-..*.*.*....*.B.o.....&..}....*.....{....*"..o....*...&.o.....&*..&.o.....&*..&.o.....&*..B.o.....&..}....*.....{....*"..o....*...&.o.....&*..B.o.....&..}....*.....{....*&.o.....&*..&.o.....&*..B.o.....&..}....*.....{....*B.o.....&..}....*.....{....*"..o....*...&.o.....&*..&.o.....&*..&.o.....&*..&.o.....&*..&.o.....&*..&.o.....&*..&.o.....&*..&.o.....&*..B.o.....&..}....*..."..o
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with very long lines (315), with CRLF line terminators
                            Category:dropped
                            Size (bytes):875706
                            Entropy (8bit):5.0393925642187485
                            Encrypted:false
                            SSDEEP:
                            MD5:4502A879BDDAF43A0E81FB595FDD01BA
                            SHA1:4E2F59B896C30C627E00FAAE162467A84C4FF3C0
                            SHA-256:787105F005A35EDB5B053BB69BA777B6FEAA9926B8578E16FF3BAD4F905A3816
                            SHA-512:70DCE12356A1DA48A64BFEF1EA9F7FE6F9EFF3AFD2852CC8424124B41DA525DCD2EC3E0CBCDFC27B82D9112CF7BC4644BB4D4F6190200CCEAB55DC2387A14668
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<doc>..<assembly><name>FSharp.Core</name></assembly>..<members>..<member name="T:Microsoft.FSharp.Collections.seq`1">.. <summary>An abbreviation for the CLI type <see cref="T:System.Collections.Generic.IEnumerable`1"/></summary>.... <remarks>.. See the <see cref="T:Microsoft.FSharp.Collections.SeqModule"/> module for further operations related to sequences..... See also <a href="https://docs.microsoft.com/dotnet/fsharp/language-reference/sequences">F# Language Guide - Sequences</a>...</remarks>..</member>..<member name="T:Microsoft.FSharp.Collections.ResizeArray`1">.. <summary>An abbreviation for the CLI type <see cref="T:System.Collections.Generic.List`1"/></summary>..</member>..<member name="T:Microsoft.FSharp.Collections.list`1">.. <summary>The type of immutable singly-linked lists. </summary>.... <remarks>See the <see cref="T:Microsoft.FSharp.Collections.ListModule"/> module for further operations related to lists..... Use the constructors
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):332896
                            Entropy (8bit):6.209805363898298
                            Encrypted:false
                            SSDEEP:
                            MD5:D6F4D063AFE557441EB360B8F46FDB4B
                            SHA1:AEC65DD55A1E74BD6FE7B9E878C3C7EF697A5F24
                            SHA-256:2AF600F0CD40FD681A6BE94BD4A13B2BFDE73F2FA09DB6AEA5B04492F2B4F057
                            SHA-512:C806FBD3DE8E470E278EA326F66D714FA74AFB7510A7B014327570E068699F842ABF5924C2C2C9FD84D967EDA2C33D33A9C11831E766D9CDC4B2B60C83874158
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            • Antivirus: Virustotal, Detection: 0%, Browse
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0.............r.... ... ....... .......................`.......C....`................................. ...O.... ..................`(...@..........8............................................ ............... ..H............text...x.... ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B................T.......H.......................................................................:.(7.....}8...*..0..&.......s9......}:....(7.......;...s<...}8...*:.{8.....o=...*..(7....-.r...ps>...z...,..(...++.~?...}@...*..{A...*"..}A...*N..{@....oB...}@...*:.%..C...sD...*...0...........(E...,B.{@...oF....+..oG....oH...,....X.o....-....,..o......{@...~?.....*.{@...oF....+..oG....oH...-......o....-....,..o......*.*...........2........V..t.......0..n..........(I...oJ......8N...s.........}.....{....(I
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):220768
                            Entropy (8bit):5.9598688295954085
                            Encrypted:false
                            SSDEEP:
                            MD5:3E9E4955EB519A2531039792D867496A
                            SHA1:47545CA375819711BB5A183DA1778AF522718105
                            SHA-256:5C9F6C363A85C8BEF2953E53B5B5076A18D051451C8D78C9F88900D9BBB258D7
                            SHA-512:CAA5BABBE517EB3C889960829BC547296A7DAB9E6E5AFC9BA08613679432901DEE3BA3FCCBC59D8CF60A7FB470AD46FF9298ABC0C937241E58B01CD2F6E097AB
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            • Antivirus: Virustotal, Detection: 0%, Browse
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......f...........!.................L... ...`....@.. ..............................$.....`..................................K..X....`..X............6..`(..........4L..8............................................ ............... ..H............text....-... ...................... ..`.rsrc...X....`.......0..............@..@.reloc...............4..............@..B.................L......H.......D...L............X..C.............................................{....*..{....*V.(......}......}....*..Zr...ps....(...+.o....*..0..K........,A.,<(.....{.....{....(...+.../..*..1..*(.....{.....{......(...+*.*.,..*.*.>.........o....*.0..T...............,>......,4..{.....{....(...+.../..*..1..*..{.....{......(...+*.*......,..*.*.0..?........,:.. .y7...{....(...+..b..cXXX. .y7...{....(...+..b..cXXX..*.*.2.(....o....*....0..B........,7.u......,+..{.....{....(...+,...{....
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):21600
                            Entropy (8bit):6.761088975179339
                            Encrypted:false
                            SSDEEP:
                            MD5:84E19C00532F36132B1958A004C7470E
                            SHA1:A0F6748415267B101DA778235197A071E07A3B1F
                            SHA-256:5EA92DF8F8F0ED4BD97EC61D9335B957AFE4BA3FCBCC839996DFEBD8B8FC0C4F
                            SHA-512:6D94A5B4C508A7A89CB2AE4D4D9524791C60C9EE61BBFBE0FE501BC55B7E12744C461B9FDCFB698751B0D0EEE642571C99BA78723C27DAD5DC557D7F6C4826CC
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....s............" ..0..$...........C... ...`....... ....................................`.................................XC..O....`...............,..`(...........B..8............................................ ............... ..H............text....#... ...$.................. ..`.rsrc........`.......&..............@..@.reloc...............*..............@..B.................C......H........(................................................................(....*..(....*v.(.....s....}.....s....}....*...0..!........`.-.....{.....o......(....(....*....0..$........{....(.....o....o.......(....(....*^.{....o.....{....o....*..(....,..*.r...pr...po....r...pr...po....r...pr...po....*>..}......}....*2r...p.( ...*..0..^.........(!...,..........*.o"....(#...,..........*.o$...r?..p(#...,..........*.-..+..(%.....(....,..........*...2...%..?.o&.....2...%..&.o'...~....
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):295520
                            Entropy (8bit):5.7149215430054365
                            Encrypted:false
                            SSDEEP:
                            MD5:B0FDD89E9B6A1CFE94555B2C26BB8DCC
                            SHA1:72CA0BDE2ED2F59BB3AE52613E6DDD6947C33E83
                            SHA-256:B97FEE69CEAACB5F396DDCB859737AC652E96CDA029ED062B565EDA6BAB7EF33
                            SHA-512:310CCEBC15368E9AF40F6C47E838FE0F0BCD6D17FA573D33486062FFA593DAE3D271E748179873700912A3CE5269D3E53867C21671BFDDC1CC5DF50FC9AF99D8
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....qa...........!.....R...........o... ........@.. ..............................(e....`..................................o..`.......l............Z..`(...........p..8............................................ ............... ..H............text....Q... ...R.................. ..`.rsrc...l............T..............@..@.reloc...............X..............@..B.................o......H........r...2..........(...s..........................................."..(....*...:.(......o....*.6..(....(....*..6..(....(....*..6..(....(....*....(....*..s....**.uK......*...s....**.uL......*.6.uL...,..+..*..Zr...ps....(...+.o....*.Zr...ps....(...+.o....*..0..............9........9.......uL...,..+......uL...,..+.....3v.uK...,7.tK......tK.....(........{........{..............(...+*.tL......tL.....(........{ .......{ .............(...+*..Y*.*....,..*.*..>.........o!...*.0..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):58464
                            Entropy (8bit):6.206826108971572
                            Encrypted:false
                            SSDEEP:
                            MD5:ADBFA77D2A6BFC2542DA420359ECB92B
                            SHA1:0A28AC038DDD9C93BF523CECB0D07B0E2A1AB63B
                            SHA-256:674AECDE0B89E277B35EB01E517ABADCCE494C2497D69A1F4D529DE32AAF90AB
                            SHA-512:0908275C0FBCF97588EF3BACD24A1A5CE1708E2FD49A478C1E42D18B795D6954A33821308FF41952D92E67A48E18969A7DA84D9CABD3CD401AFD8B733D1FD5D1
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...7ue..........." ..0.................. ........... ....................... ...........`.....................................O.......................`(........................................................... ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......`:..0.............................................................{....*"..}....*..{....*"..}....*..(....*..(....*...0..g........q......(....o.......r...p(.......(......r...p(....-..r#..p(....-.+....(...+*...(...+*rE..p.(....s....z>...o.....(....*..(....*.r#..p*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..(....*.r...p*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):16992
                            Entropy (8bit):6.794298616493806
                            Encrypted:false
                            SSDEEP:
                            MD5:50C45ED2918C33C3C2D0159FF2D5EB7B
                            SHA1:E6B41DFCB90993DD7E16CE449D6BC2B44A92DC2B
                            SHA-256:7455AA9716EBBF7E0285CCF0C17B85F52648EA690B4CD6C39973FA83C3AC72CE
                            SHA-512:87C7BEB016416F4CEDDDDE99F000E5086F60E3EDF25DBE6B83A3022F04CD0E4D3208541479C13B417970F43743DA0393F3D4221D8CD8B1D164B69ABAAEDAFD71
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[............." ..0............../... ...@....... ....................................`................................../..O....@..X...............`(...`..........8............................................ ............... ..H............text........ ...................... ..`.rsrc...X....@......................@..@.reloc.......`......................@..B................./......H.......<!...............................................................(....*.~....o....*.(.........*..(....*..0..<.......s.......}.....(....}.....{.....{.....o...........s....s....*J.s....}.....(....*..(....*"..(....*..(....*:.(......}....*6.{....o....&*..(....*....0...........{....{.....{......o....*...BSJB............v4.0.30319......l...X...#~..........#Strings....P.......#US.T.......#GUID...d...4...#Blob...........W..........3............................................
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):426
                            Entropy (8bit):4.992188598898432
                            Encrypted:false
                            SSDEEP:
                            MD5:C6854ADB8BB84DAEEFE3CEAB487968B1
                            SHA1:A862A779CFE55CF88EDF3DB7CBA90BF670DEB7F7
                            SHA-256:C3C2F06FC6206E5A1A9BF6068D79126BE59FCCBA689E771A3384F789B5F8FC22
                            SHA-512:9BB0FA9920E863BB93070B808C16E68274B0EBC751547FB9B20015F5A088294A268579CA47C299D2DADC4C27A7DC19A5AF004C313A9D6E452FEB72C0CD910A21
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Buffers" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.3.0" newVersion="4.0.3.0" />.. </dependentAssembly>.. </assemblyBinding>.. </runtime>..</configuration>
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):37472
                            Entropy (8bit):6.351556673404384
                            Encrypted:false
                            SSDEEP:
                            MD5:B782A120EE6F2A4D5E3E2CB381297E75
                            SHA1:3B6B8E76734376D939A105757A7598A85461C6D1
                            SHA-256:F2EE51A5A02A7F2CBCAC6728BA21905EAC11D2C755D3B0A1A963E7F0BAEBF2CA
                            SHA-512:DFD047A62D97FA215979286E321AD6C0744E5339FD04FEDC6447AA5202F4AF4876B1C79BA89FBBA3A9EDE7D0697124EEDE672BFC8132738F970E960A17345333
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....P..........." ..0..`............... ........... ....................................`..................................~..O.......L............j..`(...........}..8............................................ ............... ..H............text... _... ...`.................. ..`.rsrc...L............b..............@..@.reloc...............h..............@..B.................~......H.......t2...K............................................................(.......dr...p(....}.....s....}....*r.{......eo....j.{....n.....*bs....%.}...... ...s!...*B......-..s"...z*F......-..s"...z.*r../.r%..p.r;..p(#...s$...z.*v../.r...p...@...(%...s$...z.*v..1.r...p...@...(%...s$...z.*v..6.r...p...A...(%...s$...z.**.........*..*..{&...*..{'...*"..s(...*....0..%........()...-.....(*...,..(...+*(,...(-...*..()...,..*...o....o/.....o0...(1...*..()...,..*.o2....0..*...o....rK..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):19040
                            Entropy (8bit):6.687216529230128
                            Encrypted:false
                            SSDEEP:
                            MD5:C2C7F22A8A46730A254909B774D0D3A7
                            SHA1:FCD0695EE6E6E02863690214F883B0B6A84ED560
                            SHA-256:B87ADD7F15B6C01132A81D0239F997EB83D6ABF706389058815DD769D38C0FEB
                            SHA-512:43547B2DE551BC56CB5C8C9B674FB8DD57A11DB96F3479852FC3B645CF7907F96043BFBF552CB250AF2ED04371995628505E695FACDE320FD7621E7E36166473
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....u............" ..0..............7... ...@....... ..............................X.....`..................................7..O....@..(............"..`(...`.......6..8............................................ ............... ..H............text........ ...................... ..`.rsrc...(....@......................@..@.reloc.......`....... ..............@..B.................7......H........#..............................................................>..}......}....*..{....*..{....*:.(.....(....Y*6..(....s....*6.(.....s....*..0..B........(......(....(......(......(....(.......2...s....(....*(....(....*...0..(........(......(....(.....(......(....(......Y*Z.(.....X.(.....Xs....*.r...p.(..........(.........(....*..(......(....3..(......(......*.*..0...........u....,..........(....*.*R.(.... ....Z.(....a*Z..}......}......}....*..{....*..{....*..{......(.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):1442
                            Entropy (8bit):4.985799511977245
                            Encrypted:false
                            SSDEEP:
                            MD5:AF65BB064CEA741F998EC76BA12EF699
                            SHA1:DFABE9024491AC8DBB550F7B74BF139BF8A928EB
                            SHA-256:46F710BE635EB86209D9A3272F416B5ED490A5FA7341590EFE90B2C0E6C7F168
                            SHA-512:6E6E79608174A2D3DC23EC28A63AFEFE0195C08A6BAA962D1F7A864460E7C45C5B8E945F0C429321BF325A2D6C6F849FA7911B81ABCFB23E8A1F199723FD4C26
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.0.0" newVersion="7.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Buffers" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.3.0" newVersion="4.0.3.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Memory" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.1.2" newVersion="4.0
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):25184
                            Entropy (8bit):6.524431013446919
                            Encrypted:false
                            SSDEEP:
                            MD5:66E8E848873974FD499CE106648B454B
                            SHA1:DD98057964A84E84A60EF11BC90D9B40C9855F60
                            SHA-256:13BB64A8AF97495AF7B04B582400BB1911158CCCFA0FFCEFD7BB18C61DAFB3B0
                            SHA-512:D0F195C149EFA6000420C3F1C83D663B279A778B56B23D5EF59BEF17664126EACB3490427FBFFFB9347124FDFE0CDE8B788E885B2EC11A83C10B02F1E27FC139
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....G............" ..0..0..........vO... ...`....... ..............................Nf....`................................."O..O....`.. ............:..`(..........PN..8............................................ ............... ..H............text...|/... ...0.................. ..`.rsrc... ....`.......2..............@..@.reloc...............8..............@..B................VO......H........*...#............................................................(......}......}......}.......}....*....0..D..........{.....{......{....(.....{.....~....o...+..o........{.....o...+..*......,..5.......0..".......s:...%.}).....;...s........(...+&*...}......o....}......}.......}....*...0...........{....-.~....+..{......{.....r...p.{....(....*>..}......}....*J.{.....{....o...+*....0..m........s....}.......s....}.....s....}.....(......}......(.......s....}......}.........
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):25184
                            Entropy (8bit):6.472206702694945
                            Encrypted:false
                            SSDEEP:
                            MD5:1C8A851BAC66B1183F970FB5461AB24B
                            SHA1:61AE9A0CBB8A01B22B50A87FB3762CF40CAC26DC
                            SHA-256:7503D72D180BF902933E77AF6DD9473E1DA6393E64248423CBD7FBD2A764F410
                            SHA-512:DF800F8B9534301000DB9EB259CA31206D28B87A4285E085D81FEB01E1F78221B46F496685972FEFDCEA4A2CF779C8D0B22960EFDCC9C2A0192FF86D734BCA6C
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..0..........rO... ...`....... ..............................L.....`..................................O..O....`...............:..`(..........TN..8............................................ ............... ..H............text...x/... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B................RO......H........&...'...........................................................0..T.......s......(......(.....s.....+...(...+.....o.....o....%.-....,..o......,..o......o....*.........9..........6C......r.(......}......}......}....*..{....*..{....*..{....*..(......}......}......}.......}.......}.......}.......}....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*...0...........o.....o.....o....(/....o....(.....o.....o ...r...p(...+.....(...+(...+...~/...%-.&~......\...s$...%
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):27744
                            Entropy (8bit):6.439119541089724
                            Encrypted:false
                            SSDEEP:
                            MD5:73E7274ED80BFBC50AEA97CC3EF31C37
                            SHA1:A18B5A225F1AD5475A12944E3A8A0F8CC22075D4
                            SHA-256:D588B1AC538C37C3932CB504FC7FA51547895A9E1A39C85D11542E90B77ACC40
                            SHA-512:AAEF149ED8038CFD40A461DD97DB3F8E8E04207EFCDF78C2433393792F049FED740B4C58F38945AA6F44402D4CD7826BE4793E44031578C74E0C9F490B0434A0
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..:...........X... ...`....... ..............................iU....`.................................8X..O....`..@............D..`(..........lW..8............................................ ............... ..H............text....8... ...:.................. ..`.rsrc...@....`.......<..............@..@.reloc...............B..............@..B................lX......H.......l....)..........................................................z.(....(....}.....(......}....*..0..G.........(;...}.......}.......}.......}.......}......|......(...+..|....(:...*..|....~....%-.&~......[...s....%.....(....&*..s....}.....(....../.r...prg..ps....z..}......}......}....*&...{....*...0..?.........(;...}(......})......}*......}'.....|(.....(...+..|(...(:...*..0..?.........(;...}#......}$......}%......}".....|#.....(...+..|#...(:...*f.s....}.....(......}....
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):30304
                            Entropy (8bit):6.469410902835985
                            Encrypted:false
                            SSDEEP:
                            MD5:FBBC463533FE20673524275108CB21D8
                            SHA1:0BB684600E614A2270645E951C5A5E4E23BA0C81
                            SHA-256:96DE8C4E614E707D186454460F4B7BBF9B215E09B60A37D8279E61B53EBB4521
                            SHA-512:B78111355E490555DAB6B78155D7140A684A0B3CF8AE714F7D0E833EE3F35E23CD80DD7EB3EF8347FC52BDA439288C70FE659E3C07066CA8088BB48A033D5024
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...".^..........." ..0..D...........c... ........... ..............................<>....`..................................b..O.......@............N..`(...........a..8............................................ ............... ..H............text....C... ...D.................. ..`.rsrc...@............F..............@..@.reloc...............L..............@..B.................b......H........*..l7............................................................(....*^.(.......6...%...}....*:.(......}....*..0...........o............o.....*....0.. .......s.......}............s....o....*.0.. .......s.......}........ ...s....o....*.0..,.......s!......}".....}#....{#......$...s....o....*N.......+s%...(...+*N.......+s'...(...+*N.......+s'...(...+*.0..!.......s(......}).......*...s+....(...+*....0..!.......s-......}......../...s+....(...+*...(0...-.(1...(2...*..(3..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):1771
                            Entropy (8bit):4.981328320204323
                            Encrypted:false
                            SSDEEP:
                            MD5:A954CD8E971C56559C2EE9E754012ABA
                            SHA1:E7B41DC72B8264840707CDD986F6C96787F9084E
                            SHA-256:CA7E1A9785690927C042EC5C540AF1503AB9D60128A727983C6C3E9A764951A0
                            SHA-512:FE25115E4FDA95E04F05E4CA881CF36D76F2A8BB3F2974850E75BDEACF643A0FA63E9FBCF487DE0FCADA3EDCD2FA8434E7B03AF5D3FC240C5BFAA10B83381C40
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.0.0" newVersion="7.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Buffers" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.3.0" newVersion="4.0.3.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Memory" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.1.2" newVersion="4.0
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):24672
                            Entropy (8bit):6.599425446290985
                            Encrypted:false
                            SSDEEP:
                            MD5:191C1D5DFD0490AD41192AB4AE5E5EAA
                            SHA1:5132A6E3E4678D81701DEC898127FF294A0D5395
                            SHA-256:0ECC77331B54F56F511205AB0DBF14404F4950D576A94B8B6A73567FF9553148
                            SHA-512:E44BA59AFA04FF6F77A70B5B729487C2D5E93E0E390451BDE46B9228205C21E0FCFF12504F58C89683D4A368365243AAD6EC45F032E4A445600F83A67EC8DCD7
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...`............." ..0.............nL... ...`....... ..............................t.....`..................................L..O....`..@............8..`(..........PK..8............................................ ............... ..H............text....,... ...................... ..`.rsrc...@....`.......0..............@..@.reloc...............6..............@..B................PL......H........'..D$...........................................................0...........(....-..r...p.s.............(....%{.....{......-..-..r)..p.s...........(....-..rg..p.s...........(....%{.....{......-..-..r...p.s.......o.(....%{......{........-...o....-..r...p..s.......<..(....-..r...p.s.......#.~.....s...........r9..p..s..........*....................(....*..(......}......%-.&~....}......}....*..{....*..{....*..{....*...0....................(...+}>......}?....(...+......
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):21088
                            Entropy (8bit):6.665134449789308
                            Encrypted:false
                            SSDEEP:
                            MD5:D9B678DBA30C94ED30475BB9124DCB65
                            SHA1:C9A238C25593471984B5C65DE106970F01B90B7F
                            SHA-256:929C68000C1D3BF650A7EC6135690E296FA5C4095AAA61646D9B8B836DE25880
                            SHA-512:4EB845134DD91B43F36D6F59808ABC9F5E4141B12C1326338C38FB7F3090B45226A574322B38CBF9A5E7C5B55F574B05D24B2672C977A1EEA42C7029ED970983
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...6.+..........." ..0.. ...........?... ...@....... ..............................!"....`..................................?..O....@..d............*..`(...`.......>..8............................................ ............... ..H............text........ ... .................. ..`.rsrc...d....@......."..............@..@.reloc.......`.......(..............@..B.................?......H.......L%................................................................(....*.0.............o...+.......,..(....*~....*...0..).......s.......}......}.............s....(....&*..(....*..o....-..*.o.........(....(....,..*.*..0..-........o ...........(..........%...o!...("...t....*..(#...*..o....-..*.o..... ...(....(....,..*.*..0..-........o ...........(..........%...o!...("...t....*..(#...*..($...*"..(%...*...0..0.............(&..... &~............s'...o(...%-.......*........
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):7514720
                            Entropy (8bit):6.35315184642231
                            Encrypted:false
                            SSDEEP:
                            MD5:9A32C6744B223C118A2BF0D47F702F94
                            SHA1:46F7597EE1C54DF2F2B845CE32E12995F18CF13D
                            SHA-256:AD133C6A2336CF54743ECD5828200F3921A312FEDD83075FECC4DC2DB5D4F5C3
                            SHA-512:39D34FAB7E11B483FF10D274D81D07E17372C0F6BE32AD7EBB125F1CF9303987735FDEA23689330BADAB61B59C03CCD9188FFBC5272942135F527B2CDB274E1E
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..xr...........r.. ....r...... ........................r......5s...`.................................F.r.O.....r...............r.`(....r.......r.8............................................ ............... ..H............text....wr.. ...xr................. ..`.rsrc.........r......zr.............@..@.reloc........r.......r.............@..B................z.r.....H........h..4...........8...H.q...........................................(....*F .j@.j(f...(....*F /.|.j(e...(....*F ...*j(d...(....*R!........(c...(....*R!...3....(b...(....*R!7...#...(a...(....*R!...7-...(`...(....*R!'.@.4...(_...(....*R!.n..8...(^...(....*R!.n..8...(]...(....*R!..fn;...(\...(....*F o?~.j(G...(....*R!?.;]....(F...(....*R!. .....(E...(....*R!..J.....(D...(....*R!.I......(C...(....*R!.I......(B...(....*R!...K,...(A...(....*R!...64...(@...(....*F /.P.j(2...(
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):244209
                            Entropy (8bit):4.680903658493413
                            Encrypted:false
                            SSDEEP:
                            MD5:E12C4E8889677F400875F0F7B7902483
                            SHA1:BC808E034F863B1581279F27B7DE6C652F779A3C
                            SHA-256:202F0F22AF3B96A96C39088E6EBD06CEBE7B912C57D9E064589D217EAFA118F1
                            SHA-512:A3F54914AA80DC6F98C0777BD8AFBFB60034EF0AF268CF858DCCD15DA0C9A7F407A0596ECCFA88C9830FDABB839478EB609E27B994B1034FA9863ECD7576DAB8
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0"?>..<doc>.. <assembly>.. <name>Grammarly.DesignSystem</name>.. </assembly>.. <members>.. <member name="P:Grammarly.DesignSystem.Core.Brushes.Neutral90">.. <summary>Gets the solid fill color that has a hexadecimal value of #0E101A.</summary>.. <returns>A solid fill color.</returns>.. </member>.. <member name="P:Grammarly.DesignSystem.Core.Brushes.Neutral80">.. <summary>Gets the solid fill color that has a hexadecimal value of #1F243C.</summary>.. <returns>A solid fill color.</returns>.. </member>.. <member name="P:Grammarly.DesignSystem.Core.Brushes.Neutral70">.. <summary>Gets the solid fill color that has a hexadecimal value of #333954.</summary>.. <returns>A solid fill color.</returns>.. </member>.. <member name="P:Grammarly.DesignSystem.Core.Brushes.Neutral60">.. <summary>Gets the solid fill color that has a hexadecimal value
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):61024
                            Entropy (8bit):6.265801317957779
                            Encrypted:false
                            SSDEEP:
                            MD5:1AA4395BC0A34AF82E5FE4FF27D15FC4
                            SHA1:1F79BDB9C09A8C5CC36818ECA0AB86137FA4F89D
                            SHA-256:8795396035B13FDFF33FF12A8B1E0FEEBF3A107853CF5F0682FBBE237503DD0B
                            SHA-512:504B410207C3E544888F18CC9A7F6F385DC404B5D0C30E7881468615413AAD262BC5FC84F5E5CD2392F7FE91177104BDEB001177BA41C38B7C9B86DF51B1A3A2
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....]............" ..0.................. ........... ....................... ............`.....................................O.......................`(..............8............................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H........F...............................................................0..j.......s......(....o.....+@.o........(/...o0...-....(/.....(1...o2...+....(/.....(1...o3....o....-....,..o......*..........L^......>..s....%.}9...*.0..^........(4...,..*.r...po5....+@..;.o6....../..o7....Y....o8.....o9....r...p.(:......r...po5....../..*..(;...*...0..P........{3...o<.....{4...o<.....(=...-'.{3...o>...&.{4...o>...&...s?.........*........*2.s"...(....*:.(;.....}....*F.o....(...+(...+*2.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):69216
                            Entropy (8bit):6.1182150142288405
                            Encrypted:false
                            SSDEEP:
                            MD5:D1BF6ADF4A22860F10E50C31C4A47007
                            SHA1:A5B158FD82A2D622811F7007EA15F3EBB69064A2
                            SHA-256:250C437B0770AA77D92EAD1A9B4F0B47BC02B6F35FB9F8E89F78D529897C617B
                            SHA-512:C2607F7CD95E4342B0F4B852ADCAFB594EE3C459245D142F90A6663447062747EF87E6D550BDB70493DE4E6AB71F4CC0420813C549978C5EE3F5337FCA304D58
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.............B.... ........... .......................@.......j....`.....................................O.......@...............`(... ..........8............................................ ............... ..H............text...H.... ...................... ..`.rsrc...@...........................@..@.reloc....... ......................@..B................$.......H........`...............................................................0..0.......~.......o....,.......*.o.....~...........o.....*.s.........*.0..L........(....-..(....,6.~r...%-.&~q.....g...s....%.r...(...+..,..(....*~....*~....*..~s...%-.&~q.....h...s....%.s...(...+*2.r...p(....*2.r...p(....*V.(......}......}....*..0..<..........(..............s....~u...%-.&~t.....k...s....%.u...(...+*.0..Z.........~v...%-.&~t.....l...s....%.v...(...+..........s....~w...%-.&~t.....m...s .
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):333920
                            Entropy (8bit):5.695361651635239
                            Encrypted:false
                            SSDEEP:
                            MD5:37EB10E9AA8824BC20C4789F215D07FC
                            SHA1:4301D263F924B97FBB641EE9C0BBE94B6A4E9B7F
                            SHA-256:F481A4300DA8307287885473A1FDAF89B1576ACC84E2B1E3546CF27EDE06C967
                            SHA-512:4C5CAB3D351D528F8663533C5DEAEA20A0914B2B5CC882D0935F4EB3D3F56AA3877CE3319D55DAD9028D74CF78145EC0F93A8691062518364033AA06E28265CF
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..............." ..0.................. ... ....... .......................`......^P....`.................................h...O.... ..................`(...@......|...8............................................ ............... ..H............text........ ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................H.......$...X)...........................................................0..........r...p.s!........s"...%.x...(#... .'..o$...%.{...(#... ('..o$...%.h...(#... .'..o$...%.]...(#... "'..o$...%....(#... .'..o$...%....(#... .'..o$........~....~<.........s%....o...+.....*..('...*B~....~....s....*...0..5.......~.....o(.....,..-.~.....o)...&*....._,.~......o$...**V.('.....}......}....*..{....*..{....*..0.._.......s"...%.x...(#... .'..o$...%.{...(#... ('..o$...%.h...(#... .'..o$...
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):704096
                            Entropy (8bit):5.958774239055958
                            Encrypted:false
                            SSDEEP:
                            MD5:E2296B50A52D4C753B74E52F39F688D0
                            SHA1:62FCADD2973BED6659031D87049C29FC9F3786A9
                            SHA-256:9036E347B2A866526B9207C2EF3668AF1BF5A5ACBF1CBD4168040FF3429CAE13
                            SHA-512:A910032EDF03FC1AA8EDE033DB0F51C4AC96902E19B64AC12FF70DC700D2CB177FFB7FB9E4832358560DBA90865A4A90E8AD6F4A68971909E290A062512D1A02
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...3q............" ..0.............".... ........... ..............................K.....`....................................O.......X...............`(..............8............................................ ............... ..H............text...@.... ...................... ..`.rsrc...X...........................@..@.reloc..............................@..B........................H........a...F............................................................{=...*..{>...*..{?...*..{@...*..{A...*..{B...*..{C...*..{D...*..{E...*..{F...*..{G...*..{H...*..{I...*..{J...*..{K...*..{L...*..{M...*..{N...*..{O...*..{P...*..{Q...*..{R...*..{S...*..{T...*..{U...*..{V...*..{W...*..{X...*..{Y...*..{Z...*..{[...*..{\...*..{]...*..{^...*..{_...*.0...........(`.....}=.....}>.....}?......}@......}A......}B......}C......}D......}E......}F......}G......}H......}I......}J....
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):3325
                            Entropy (8bit):5.007318612655374
                            Encrypted:false
                            SSDEEP:
                            MD5:65A68FF04D2D1E9502D864EB186E583A
                            SHA1:F94E4B2D6B7A17AADD12C1E949955A4DDC9A66F6
                            SHA-256:242E41F8752E3379DEC415675A02647F3B97D2DF15A5322FB7C8A1454D13BFF2
                            SHA-512:771188007D1BBE89C2F1FFB9A59B2A4EB0F3E82B75968D082FEE3C472605E974624185B415D813B047BD48FFE74BB616D22885FFE112572170ABC7C3DC086BB1
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Newtonsoft.Json" publicKeyToken="30ad4fe6b2a6aeed" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-13.0.0.0" newVersion="13.0.0.0" />.. </dependentAssembly>.. <dependentAssembly>.. <assemblyIdentity name="System.Net.Http" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.1.1.2" newVersion="4.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="FSharp.Core" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-5.0.0.0" newVersion="5.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):15456
                            Entropy (8bit):6.833574808340965
                            Encrypted:false
                            SSDEEP:
                            MD5:2F6ED2B59B080CB9DC99BDDC8D7542B1
                            SHA1:30904CA8ABF478230D3997FD5A26E457F9EEE2A1
                            SHA-256:EA7A8318E9467DEBAF55550E532C64876EBF5A944C7CE029AD0FB23A9B3DFCC4
                            SHA-512:C023ECE7846C125EDA84B003A99B85CE821AF600939E069D921BC4318DD4B2BE5E05BB32643E9D7B05523C3E70AE978D152B8432C5632EBD8E3200648A77AE06
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...:............." ..0..............(... ...@....... ..............................3/....`..................................(..O....@..................`(...`.......'..8............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P ..L...........................................................BSJB............v4.0.30319......l.......#~..t...P...#Strings............#US.........#GUID.......t...#Blob...........G..........3....................................................9...........G.............U...Y.U.....U.....U...r.U.....U.....U.....U...o.U...[.....9...........................g...............................'.#.........................?...........................=.........'...............z.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):57952
                            Entropy (8bit):6.295507959338889
                            Encrypted:false
                            SSDEEP:
                            MD5:F0E64AC80018B802B673716F1479DB82
                            SHA1:53CE260D8F91624DF71D723D616B78316159CC97
                            SHA-256:EC83A57FF675A9D0BD3FA542AF5D4A84B3A7994AF3FA194ACDB44F9C386A4C69
                            SHA-512:1C7B7213B05DD0EFCFE578883CCFBBD1860A7F79A4D52ADD4A900CDFAC9A2078B9E4AB78E17AC2AFC2D76CE2D4E4398D0A38514A122B7371E855A33B081B38D2
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...c.5..........." ..0.............~.... ........... ....................... .......N....`.................................*...O.......4...............`(..........d...8............................................ ............... ..H............text........ ...................... ..`.rsrc...4...........................@..@.reloc..............................@..B................^.......H........4..\...........................................................~.(......}......{....o....}....*..{....o.....{.......o......{.......}.....*.*..(....*....0..E........(......(....}......(....}......(....}.......(....}.......(....}....*..{....*..{....*..{....*..{....*..{....*....0..8.........~V...%-.&~U.........s....%.V...(...+............(....*^..&...%.T...(....(...+*V.(......}......}/...*..{....*..{/...*...0...........(......}0......~^...%-.&~].........s!...%.^...(...+
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):2990
                            Entropy (8bit):4.984114451941571
                            Encrypted:false
                            SSDEEP:
                            MD5:5F19A06A96C5658F636FBC36BC12235C
                            SHA1:EF4545D32F6AA34BFE070CADB2D4BF6FD464E6C6
                            SHA-256:10961EE33E640B8F43DE5BC9EFF0E13AD54B1EB3A704DB8BA084F13184DF7EA5
                            SHA-512:C6B0472BA789AA051A905CAC6D2A61D56E297C732CFE68C9912DC542CF9A5B5D277B423BBDD850B1C08A51A183C66F540358374AC9D604BB9EEA23B425E97628
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Newtonsoft.Json" publicKeyToken="30ad4fe6b2a6aeed" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-13.0.0.0" newVersion="13.0.0.0" />.. </dependentAssembly>.. <dependentAssembly>.. <assemblyIdentity name="System.Net.Http" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.1.1.2" newVersion="4.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="FSharp.Core" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-5.0.0.0" newVersion="5.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):26720
                            Entropy (8bit):6.683565807903274
                            Encrypted:false
                            SSDEEP:
                            MD5:30E0F9A588D8C68DF96E2FB6F643F6FE
                            SHA1:CA89CBBE5E815279E61C02B1CEA577B2B73BA82F
                            SHA-256:10BC92EADC53ED5B24344386122EEE3477BEDD0A5C3709E2515E46BC8DE9EB0B
                            SHA-512:93128EB6B5259F4D6A4EA1562858A0F62A15525CB0AD3E18EA53943509723C217927F854AF12EDBDDFDAA681CA8D76AD348DE51007DA39F46B416B947318C518
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...(............." ..0..6...........T... ...`....... ..............................u.....`.................................rT..O....`..d............@..`(...........S..8............................................ ............... ..H............text....4... ...6.................. ..`.rsrc...d....`.......8..............@..@.reloc...............>..............@..B.................T......H.......<)..`*...........................................................0..........s.......}......}......}.......}......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......}.......} ......}!......}"....s....%.......s....o....*.s.........*..(....*..*..*..(....*....0...........o...+o...+&.o...+o...+&..@...(....o.....?...(....o....&.o...+o...+&.o..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):4417
                            Entropy (8bit):5.00523793486626
                            Encrypted:false
                            SSDEEP:
                            MD5:9DFED2DD3B6ACAA0456EEA66C37FC991
                            SHA1:31A8ECB7F3DE6D8780F9DB5A3363B0D9E8E97004
                            SHA-256:D05D462978498121450DBFF1041EFF63026AAEE438EB0C740010485F3508AED9
                            SHA-512:7635C6E21E71A2FC54D75C8AC05B0C2E69130C2A7B9CC8250DD86E56DB7F868BC01D41E12A30D7401706468E5F710A06D1C749969777D518C84E0B759DA00BC6
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Resources.Extensions" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-6.0.0.0" newVersion="6.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="FSharp.Core" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-5.0.0.0" newVersion="5.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.0.0" newV
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):76384
                            Entropy (8bit):5.877515441418693
                            Encrypted:false
                            SSDEEP:
                            MD5:C8B967A4FBA11DDF8CC24F96D2AB28ED
                            SHA1:278869234243AD16EF9F5775D64257B0A367D3AB
                            SHA-256:B7CC248289FE36D3D26B9E8D9137B0222CCE4D3AA0268E9D8862E66192F9925E
                            SHA-512:CA4D73B2B81F59ED835F2FAE7FCF63A7B2C0F59AE306268647821D1536353D76BD92F3894AB9FF3DD28831AFD9F87C80DF0DFCA4D82E265900A09C27F31FF07F
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....o]..........." ..0.................. ... ....... .......................`.......p....`.....................................O.... ..p...............`(...@..........8............................................ ............... ..H............text........ ...................... ..`.rsrc...p.... ......................@..@.reloc.......@......................@..B........................H........K................................................................{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{ ...*..{!...*..{"...*..{#...*..{$...*..{%...*..{&...*..{'...*..{(...*..{)...*.0...........).....%..(.....%..(.....%..(.....%..(.....%..(.....%..(.....%..(...
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):219232
                            Entropy (8bit):5.815798829121086
                            Encrypted:false
                            SSDEEP:
                            MD5:B6B66F317D578D30687753E32BF57C66
                            SHA1:695F617FAE19AF0C41C15A16DA816E6AAD8F91FB
                            SHA-256:1CF09214660B74FA46CA04C94D9C79A01D663E0810BC292110FE0D2B3A737F21
                            SHA-512:8FBB850E5BF8E859DD9199521A2DF701FBA53326ADA2D50BEF5300969CE5C0F9E3E391E2357E323BD3218076E6FD04529F8E446BC63F219582866DD9BFEEABF0
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0..&..........nD... ...`....... ..............................IC....`..................................D..O....`..0............0..`(..........TC..8............................................ ............... ..H............text....$... ...&.................. ..`.rsrc...0....`.......(..............@..@.reloc..............................@..B................ND......H........................................................................{....*..{....*..{....*..{....*..{....*..{....*R....o.........s....*...}......}......}.......}.......}.......}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{ ...*"..} ...*..{!...*"..}!...*..{"...*..{#...*"..}#...*..{....*..{....*..{....*..{$...*"..}$...*..0...........s....}.....s....}.....s....}.....s....}.....s....}.....s0...}"....(.......}......,=..(.......(....r...ps......(......r?..p.(...
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):3189
                            Entropy (8bit):5.02616217003795
                            Encrypted:false
                            SSDEEP:
                            MD5:2618E8425D33266D34EF56F4DD757367
                            SHA1:C69E3DEE9B15918688B343CBC8A3306E459D4DF1
                            SHA-256:F48514C7AC5C496BB6D9FF96FC2F3F02513421DEACCE657634807AFFEA24BE6C
                            SHA-512:55E0CF102752D66EF177F9319727617D9A23515F5609F3A89676FE1A2B2B6DDC5772C6A0DF5C04DC05E0AA6FCFF2F2D92849FC3D48B8C69AD482F91CB8C18AB1
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.7.2" />.. </startup>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="FSharp.Core" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-5.0.0.0" newVersion="5.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.0.0" newVersion="7.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Newtonsoft.Json" publicKeyToken="30ad4fe
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):1053792
                            Entropy (8bit):6.20363782020849
                            Encrypted:false
                            SSDEEP:
                            MD5:84DF77A780F3BBA81CE987AA1AD04C9F
                            SHA1:C245FC71423A9F8E7A770178AB151AA08EB5C4FB
                            SHA-256:6EDEC42E59D362FF315489B82FF19E3EEA92B49BF8446621AB8D9989B1C30E6A
                            SHA-512:114C9CDC297C631E012377A09CD98701CF02D53A870B7016F5619CB41807E269EA8CAEF7B79DE1AE39BB9F873607F4198D9AC1189532CB4C35B4612E6F2B6177
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....p............" ..0.................. ... ....... .......................`......0.....`.....................................O.... ..4...............`(...@..........8............................................ ............... ..H............text........ ...................... ..`.rsrc...4.... ......................@..@.reloc.......@......................@..B........................H...........................K............................................{....*..{/...*..{0...*..{1...*..{2...*..(3.....}......}/.....}0......}1......}2...*....0...........uB.......|.,w(4....{.....{....o5...,_(6....{/....{/...o7...,G(8....{0....{0...o9...,/(:....{1....{1...o;...,.(<....{2....{2...o=...*.*.*....0..y....... Oa1. )UU.Z(4....{....o>...X )UU.Z(6....{/...o?...X )UU.Z(8....{0...o@...X )UU.Z(:....{1...oA...X )UU.Z(<....{2...oB...X*....0...........r...p......%..{....
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):153696
                            Entropy (8bit):6.255903901693951
                            Encrypted:false
                            SSDEEP:
                            MD5:E549BC282A6F169266C3E8036ACFF2B3
                            SHA1:B26852807282E9332757E963CF00725A6DE9F040
                            SHA-256:9B4AA5DA0C08196B7FF6CC76E9C2C24D77DCE959D6723CE90B64F5781D903355
                            SHA-512:6FD597B5CDD777873D021329825750124779427BAEBEF48F03556B9B92BB3DE54F59714FF967740FF01CEFAC1CD95DDAE936C25EEDA72B9F4BD96685F2E95D3A
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...#m6..........." ..0..&...........E... ...`....... ..............................f.....`..................................E..O....`..L............0..`(...........D..8............................................ ............... ..H............text....%... ...&.................. ..`.rsrc...L....`.......(..............@..@.reloc..............................@..B.................E......H.........................................................................{....*..{ ...*V.(!.....}......} ...*...0..A........u........4.,/("....{.....{....o#...,.($....{ ....{ ...o%...*.*.*. .... )UU.Z("....{....o&...X )UU.Z($....{ ...o'...X*...0..b........r...p......%..{.......%q.........-.&.+.......o(....%..{ ......%q.........-.&.+.......o(....()...*V.(!.....}......}....*Z.{....o*...ri..p(+...*..0..7.........(,...}.......}.......}......|......(...+..|....(....*..0..G.......
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):3756
                            Entropy (8bit):5.012589405539922
                            Encrypted:false
                            SSDEEP:
                            MD5:F828A9221E2AA12A0F2FED87688227AD
                            SHA1:DAD02B8851A1F5C2CD498F253FBECE81722C4B92
                            SHA-256:ACA269BA82288941AFBD920E78A5DA3BE14E7F7CB742C8A852E3B70B0065742C
                            SHA-512:906ADD7F0219F451ADA712D1C1EA7BA117D1C0040F3AD3C7DBFC60091260B4401EDD2F40427914A1246992BB5F44CA8C2A565AD2A080DBAF60F2FFB79258E5CC
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="FSharp.Core" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-5.0.0.0" newVersion="5.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.0.0" newVersion="7.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Data.Sqlite" publicKeyToken="adb9793829ddae60" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.17.0" newVersio
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):674400
                            Entropy (8bit):7.75967302601783
                            Encrypted:false
                            SSDEEP:
                            MD5:93619442D91E1C56E898453933AFB9BD
                            SHA1:2E5AA1000F9F1E22566E440323C887CBF502E998
                            SHA-256:89A085D646FF8A6DDB19A12469551C9D068F0FDD33792B653A345963DF00CBB9
                            SHA-512:41264D9D9BAB755BAFA3E963278ED74DD49E59C8A9199E93EFAE2E5A175FD7327702C7EBD28B94DAFC1E28418C363684FED91FD83FA89B4D3D6EB06C8CEBC413
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....{............" ..0.............b6... ...@....... ....................................`..................................6..O....@..d............"..`(...`......85..8............................................ ............... ..H............text...h.... ...................... ..`.rsrc...d....@......................@..@.reloc.......`....... ..............@..B................D6......H........}................................................................{....*..{....*V.(......}......}....*...0..A........u........4.,/(.....{.....{....o ...,.(!....{.....{....o"...*.*.*. y..' )UU.Z(.....{....o#...X )UU.Z(!....{....o$...X*...0..b........r...p......%..{.......%q.........-.&.+.......o%....%..{.......%q.........-.&.+.......o%....(&...*..{'...*:.(......}'...*....0..)........u..........,.(.....{'....{'...o ...*.*.*v ...x )UU.Z(.....{'...o#...X*..0..:........r..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):4078
                            Entropy (8bit):5.009184713673463
                            Encrypted:false
                            SSDEEP:
                            MD5:77D85C741F02B9657B384FF16D8A3D85
                            SHA1:EA315C09DC59031A7AEC39CB2D9C128362EEFF2E
                            SHA-256:3F69B6930F23621714D8E8A7E8755066BE912D34B5D5105377BB34937B9D6E4A
                            SHA-512:A26A33798CA3EEA6AE981132FB0D8FD0277BDB6D13B00E06D92654F38E96D34583B2F68F6B28E9108CE21CC77B3845D8CC050FEE9F7545BBD9A09A6A24B547A3
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="FSharp.Core" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-5.0.0.0" newVersion="5.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.0.0" newVersion="7.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Data.Sqlite" publicKeyToken="adb9793829ddae60" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.17.0" newVersio
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):205408
                            Entropy (8bit):6.125516280391582
                            Encrypted:false
                            SSDEEP:
                            MD5:F073FD1A76081B7E2580BB1A935CCE2D
                            SHA1:6729F1153F53A74D1A733B76C71338302A2DDE1D
                            SHA-256:90F9B88EC09CC9CD5938E80D82E129ACB40DE4D00A6F2311CC894AC19B6624A6
                            SHA-512:EE6BB6B42CBB0CC04553A9995E6B88C51C8BE365A6611B6F7C5E69D4A8E9EC15C52F116FB99277B34F77A5152040A47F3FC71A057BC94D64A6BAF8281C083130
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....g............" ..0.................. ... ....... .......................`............`.................................@...O.... ..@...............`(...@......t...8............................................ ............... ..H............text........ ...................... ..`.rsrc...@.... ......................@..@.reloc.......@......................@..B................t.......H.......$...P.............................................................{....*..{....*..{....*r.( .....}......}......}....*....0..Y........u........L.,G(!....{.....{....o"...,/(#....{.....{....o$...,.(%....{.....{....o&...*.*.*....0..K....... &._. )UU.Z(!....{....o'...X )UU.Z(#....{....o(...X )UU.Z(%....{....o)...X*..0...........r...p......%..{.......%q!....!...-.&.+...!...o*....%..{.......%q"...."...-.&.+..."...o*....%..{.......%q#....#...-.&.+...#...o*....(+...*..{,...*:.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):235104
                            Entropy (8bit):6.020871961965504
                            Encrypted:false
                            SSDEEP:
                            MD5:091A781339910425916ACC6BE9750128
                            SHA1:EA05A92895558D29583B73525C7067869F2CDF63
                            SHA-256:6FA214E34776A5C889298390B6B18E1D17428C1843E0C4D0256E06EDCA6A4012
                            SHA-512:F62C09E68B1A207BA8C3F2BE1BBC47AE3044E5E9812BE356CFDA4CBCBF293C8E5F84A73A0FC186AD491E251F5B8B6841AF4C22567DA3B4E673DE6CA76D0083D2
                            Malicious:true
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=............"...0.............v.... ... ....@.. ..............................X.....`.................................$...O.... ...............n..`(..........h...8............................................ ............... ..H............text...|.... ...................... ..`.rsrc........ ......................@..@.reloc...............l..............@..B................X.......H.......`...x.............................................................{....*..{....*..{ ...*r.(!.....}......}......} ...*....0..Y........u........L.,G("....{.....{....o#...,/($....{.....{....o%...,.(&....{ ....{ ...o'...*.*.*....0..K....... .Hv. )UU.Z("....{....o(...X )UU.Z($....{....o)...X )UU.Z(&....{ ...o*...X*..0...........r...p......%..{.......%q.........-.&.+.......o+....%..{.......%q.........-.&.+.......o+....%..{ ......%q.........-.&.+.......o+....(,...*..{-...*:.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):6382
                            Entropy (8bit):5.072968215202752
                            Encrypted:false
                            SSDEEP:
                            MD5:9481A42135E69B508D316992FAFB17F2
                            SHA1:22F42D90E158B1E32DD48D161A18DD17C8A6E250
                            SHA-256:0AD6B7C44395824FF4CB7AADC2FFE80618354857963292B6120DE98A2DF27202
                            SHA-512:79C2C3F35A854DE5F8E5EA6127D167F6A4BB80A6A472379B3FCD185911CF361ED974A98222C4AE569A02D7330605723DEE77C0BF8F99EE37FB0F8F8EDA36E5FD
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <configSections>.. <sectionGroup name="userSettings" type="System.Configuration.UserSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089">.. <section name="Grammarly.Desktop.Properties.Settings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" allowExeDefinition="MachineToLocalUser" requirePermission="false" />.. </sectionGroup>.. </configSections>.. <appSettings>.. <add key="Debug.ShowEditControlFrame" value="false" />.. <add key="Debug.SelectSleepInterval" value="100" />.. <add key="Debug.PasteSleepInterval" value="150" />.. <add key="Debug.PasteSleepIntervalLong" value="500" />.. <add key="Debug.OpenCallbackWebPages" value="true" />.. <add key="Debug.ForceNewUpgradeCards" value="false" />.. <add key="Debug.EnableRestartAfterException" value="false" />.. <add key="Debug.ForceEnab
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):43616
                            Entropy (8bit):6.383579840923247
                            Encrypted:false
                            SSDEEP:
                            MD5:2E0BCA7046CDEA4AB20015A9C7F24C1E
                            SHA1:E001117D1BE23068D5928F18960CE2B604E00AA9
                            SHA-256:88D876BE857D4EB685E01581120BE7358AAE260E5B1FDAAFB690CA126DD85541
                            SHA-512:C61CDFF9A4610DDF7B29C6207C9967E16FB6E76D38A352B06C3435F7FDBCFABBD869671D5213A86FFE9BDE58E8E1574E7C91893AC7AD752F651B4C6C87AEDEB4
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....]..........." ..0..x..........:.... ........... ....................................`....................................O.......X...............`(..............8............................................ ............... ..H............text...@v... ...x.................. ..`.rsrc...X............z..............@..@.reloc..............................@..B........................H........7...]............................................................(....*^.(.......i...%...}....*:.(......}....*..s....}.....s....}.....(......}......}......}....*...0..].............%..{....o...........s....(...+.%..{....oC..........s....(...+..{....%......s....(...+&*N..(.....{....o!...*....0..3.........("...}?......}A......}@......}>.....|?.....(...+*..0..?.........($...}D......}E......}F......}C.....|D.....(...+..|D...(&...*..0..X.........($...}I......}J......}M...
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):15456
                            Entropy (8bit):6.826886853578562
                            Encrypted:false
                            SSDEEP:
                            MD5:DBA90B0DFB10CF5B90F3DDEDDA5E5E33
                            SHA1:7BB3F40C6B5B224E784F166EF99141D5A8506B24
                            SHA-256:8AB8ED2DDA154247F0F876966F80C10C252B5AECE8921A1B49967B59C963F445
                            SHA-512:32D5629E9A5AB2C33C6679FEB7573C75BAFB336C6905257042C803053690E6B0039581ACFB7FB3D346F5970B9EFE2B153E7EE2DAA18D70FF3C0247B57E583023
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..............." ..0..............)... ...@....... ....................................`.................................<)..O....@..................`(...`......t(..8............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p)......H.......P ..$...........................................................BSJB............v4.0.30319......l.......#~..8...d...#Strings............#US.........#GUID.......t...#Blob...........G..........3..................................................!.........x.......................<.W.....W...[.W.....W.....W.....W.....W.....W....................... .....E...................S.,.............,...............j.#...........L.'...........=./.............#...........0.'...........
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):751
                            Entropy (8bit):4.986100091969351
                            Encrypted:false
                            SSDEEP:
                            MD5:BA665254841A60CD2571A54B16244045
                            SHA1:E8D03E8FDDD94F5ADD25287E7EE3924005D614E8
                            SHA-256:C348CE76D927160C413CDC1F0EEC5A89920F9AC1492E65A6DD18C07E60F84D28
                            SHA-512:FB52E982FDDC28BA7153E8CD941A66E0362362F7A84649051AEC5F5971BC423FEE618EBA5B7879BD41569EBA94DF4BB697BFAE2CF7D35E65CE6493E836FB9455
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Buffers" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.3.0" newVersion="4.0.3.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Memory" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.1.2" newVersion="4.0.1.2" />.. </dependentAssembly>.. </assemblyBinding>.. </runtime>..</configuration>
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):19040
                            Entropy (8bit):6.649097615227252
                            Encrypted:false
                            SSDEEP:
                            MD5:98E972E14E7371BFA7E2B422DEF8F258
                            SHA1:6662CB722117FBB41C20971B084E9C4290EA40BB
                            SHA-256:15E20DB526C7BB23AA269CB0F17E4EF2E84CB2C7083AF12B616880B99316BF08
                            SHA-512:3561B2E1D87AC4DAC2A5CD4EB4D61ABC54E004D91219F9684654353EBBBDA69A2606F38140015698DC354754706CD1CC9CA87B37CE38178A1F211538BB1F854B
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....!............" ..0.............Z6... ...@....... ..............................|.....`..................................6..O....@..X............"..`(...`......45..8............................................ ............... ..H............text...`.... ...................... ..`.rsrc...X....@......................@..@.reloc.......`....... ..............@..B................:6......H........"..(...........................................................^r...p.{.....{....(....*..(....*r.(......}......}......}....*..{....*..{....*..{....*..(......}......}......}.......}....*..{....*..{....*..{....*..{....*"..(....*r.(......}......}......}....*..{....*..{....*..{....*.0...........u......,..o.......*.*r.(......}......}......}....*..{....*..{....*..{....*..0..E........o....o......u .....-..u......-.+..o....(...+*.o....(...+*(....(....*Fr#..p.{....(....*..(..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):56928
                            Entropy (8bit):6.289938738230881
                            Encrypted:false
                            SSDEEP:
                            MD5:E6289D681FC66CA559DC4484BA1A123A
                            SHA1:A85FB7559553FCD26A532AFC15F0BE9560BABCA0
                            SHA-256:D7E6DC44E7C3B015CE9BA3DE52E1CAEF5F9B33B305B84D58C5E778C05DF5FBCB
                            SHA-512:F3F29FA227AC0798A92012AB17A465406B0221B5CFBA075FD47B148C0B0CA80F3B912D5F33AB02D1E1353FA76F5A65782BA627EA301D80A0F39EC4B60164A826
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...V#g..........." ..0.............V.... ........... ....................... .......`....`.....................................O.......|...............`(..........$...8............................................ ............... ..H............text...\.... ...................... ..`.rsrc...|...........................@..@.reloc..............................@..B................8.......H.......lH...............................................................0...........(......oc...}......ob...}......o]......~....%-.&~......4...s....%.....(...+}......o^...}......oq...}......or...}......oa...}......oh...%-.&.+.(....%-.&~....}......oi...%-.&.+.(....%-.&~....}......oj...%-.&~....}......ok...%-.&~....}......ol...%-.&~.....om...%-.&~.....on...%-.&~....s7...}......op...%-.&~....}......o]......~....%-.&~......5...s....%.....(...+....(....}......o....(*.....os...}..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):1770
                            Entropy (8bit):4.988482521190633
                            Encrypted:false
                            SSDEEP:
                            MD5:4E1C69227B13CB1497ADDC946E30F7B6
                            SHA1:B34F51491084B02800C7122567C8AE4D289A6303
                            SHA-256:CA490D74B8F52ECDDABBFD81CDCB771CC1CFD5A95FA0F2EF45F58D1EF08C8EE4
                            SHA-512:F5C83012BECF530EF0AC63A25D5252AB49520A88847179BB19F2A13F247F0EEB54D2E313B4F6BB9F8E9F5DC814449984E5F04518506895BAE6213E2F03204CDA
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.0.0" newVersion="7.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Buffers" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.3.0" newVersion="4.0.3.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Memory" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.1.2" newVersion="4.0
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):27744
                            Entropy (8bit):6.511733390917744
                            Encrypted:false
                            SSDEEP:
                            MD5:5D54C2B0FC79901C85A52A1970BE6505
                            SHA1:0014BFB18D001A3FAD6A992B6CD616CEE4460F66
                            SHA-256:C69271DB6EDDF7AF7ECD1824FD3C1562899EFA42FF3AEE6EDA693548A14A6509
                            SHA-512:45BCB8AFDA5A5D0245E2A0A37147F4F201A565D7C8196FFE0A85FF9223304ED8282AF28895C50741E444F6967B77C3A218D599226C0A813B5756510D4EED4F15
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..:..........*X... ...`....... ...............................=....`..................................W..O....`..x............D..`(...........V..8............................................ ............... ..H............text...08... ...:.................. ..`.rsrc...x....`.......<..............@..@.reloc...............B..............@..B.................X......H........)...-............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*:.(......}....*..{....*:.(......}....*..{....*:.(......}....*..{....*J.(.....s....}....*N.(......(...+}....*..{....*J.(.....s....}....*..{....*R.(......s-...o.....*:..s.....(....*:..s.....(....*:..s.....(....*R.(......s5...o.....*R.(......s;...o..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):47712
                            Entropy (8bit):6.267954816371457
                            Encrypted:false
                            SSDEEP:
                            MD5:33DF195517AD01A63816461184634887
                            SHA1:B4FE0D61BF8B89692246F0C3DCAABED3279BD275
                            SHA-256:4614884D5D1EDCBC29ADCA51E3CB42E68D8F224C7401C47029F759CDB24011BF
                            SHA-512:DE520A2987AE1CEEDA2DEBC9F1BBE2FAF38290AFDE80B512C85C3608F0056F1054C2108CD3A68B285A382F6A6351F5DC320E7DA46BD8C9F6E409D17986B7A297
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....U..........." ..0.................. ........... ...............................*....`.................................l...O.......L...............`(..............8............................................ ............... ..H............text....... ...................... ..`.rsrc...L...........................@..@.reloc..............................@..B........................H.......@e..\@...........................................................sW......o-...~....%-.&~......Z...s....%.....(...+(...+*:.(......(....*:.(......(....*...0..9.......sc......}%.....s....}&........d...s....(....&.{&...o....*...~....%-.&~......[...s....%.....(...+*....0..O.......s........s....(.....~......s ...~....%-.&~......\...s!...%.....(...+{#...(...+*..(.........~....%-.&~......]...s%...%.....(...+(...+*....0..........se.....s'...}'.....~......{'...s(......f...s)...
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):1545
                            Entropy (8bit):5.02166139887601
                            Encrypted:false
                            SSDEEP:
                            MD5:B575FE5DF8CE506EFBB0AE5F6B43E269
                            SHA1:25C482D493B8E6CF400C82F068B0186303F5A58A
                            SHA-256:944972E0823974AB4E5240351B8BA328028AAB8FA51D1229D6D8F0461ABA7CCA
                            SHA-512:126A8B6EE7057308B03AAF87C01FCD5681715C1A0A1DC5DFD7B7F3256A04E697D1453BE8F72E1EB4CCD3B0C8E064BAB43FA83D73F3C6D1714353351E211DAD3D
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.7.2" />.. </startup>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.0.0" newVersion="7.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Buffers" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.3.0" newVersion="4.0.3.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Memory" publicKeyToken="cc7b13
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):51296
                            Entropy (8bit):6.417588921103122
                            Encrypted:false
                            SSDEEP:
                            MD5:6121D613D9006C5E3670F622F2675958
                            SHA1:3C56C8282628E85E1A6D06AA784931D9620A2AFC
                            SHA-256:F87E41C5DC73467475DFC32E8708FFAE7CE715ADB59B3A46E74480620BB677B0
                            SHA-512:5B1946550F2F27C2DA13A3D789A5DED655629F33C43DD5E388A1A95D61479C4C6CB8FED23BBDB4E733B1FDE72A73E4B5650220AFD5C90FB5F80C7EDD1A015427
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....r............" ..0.............f.... ........... ....................................`.....................................O.......(...............`(..........P...8............................................ ............... ..H............text...l.... ...................... ..`.rsrc...(...........................@..@.reloc..............................@..B................H.......H........D..pn............................................................(....*^.(.......Y...%...}....*:.(......}....*..0...........s....}............s....s....}.....s....}.....s....}.....~-...%-.&~,.....^...s....%.-...s....}.....~....}.....~....}.....(......}............s....s....}.....{.....{....o......."...s....(...+o ....{.....{....o......o!......%...s"...(...+o ...*2.{....o#...*..0..e.........~....%-.&~,....._...s$...%.....~0...%-.&~,.....`...s%...%.0...~1...%-.&~,.....
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):2099
                            Entropy (8bit):4.984577559479307
                            Encrypted:false
                            SSDEEP:
                            MD5:BAEB732BC240D53F2E857DA2BAC453CA
                            SHA1:EAE0A1D08440B5AAFCC848AB9B8F674978D37BB4
                            SHA-256:8A40AFA3BC4EEC184AC2D3273CB846A00D309932A3DD034E00C07B00F673AA73
                            SHA-512:0ACE9697B7682553CCDA01051FE7E229D7DA05F64FEF95F3E2609E358A6A9CF32E733EB9F62D83EE9D09A3B53D919774AA8F7C8E2512A8DC8A08C092F77B1123
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.0.0" newVersion="7.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Buffers" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.3.0" newVersion="4.0.3.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Memory" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.1.2" newVersion="4.0
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):120416
                            Entropy (8bit):6.348047350574887
                            Encrypted:false
                            SSDEEP:
                            MD5:75FC19B47AE42B82B299A89878E50CA0
                            SHA1:BD60C6CB87075E996FD340E8B027F56C1ECE44C1
                            SHA-256:D75E45D429E1DB87ED613B9BCE34BF688CC9152D69DA32548FA2F75A0FD4FD27
                            SHA-512:98C35861A3072ABD4379D61075DD1185BFBDB9079A21BDEC4890637DBB612FCC4D1C9871533E3257B670ED56CC558194CC85EA568A3622E1C9E74A0F6E8485BC
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....[..........." ..0.................. ........... ....................... ......).....`.................................D...O.......X...............`(..........p...8............................................ ............... ..H............text........ ...................... ..`.rsrc...X...........................@..@.reloc..............................@..B................x.......H........}...D............................................................(....*^.(.......~...%...}....*:.(......}....*:.(......}....*...0...........s ...}.....s!...}.....s"...}.....(".....}......}.......}.......}.......}.......}.......}.......(!...}.......("...}.......($...}.......(#...}.......(%...}.......('...}..........(.......{#...}......{$...}.......( ...}..........(..........(&...(.......s....(....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....*..{....
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):29280
                            Entropy (8bit):6.522345408232572
                            Encrypted:false
                            SSDEEP:
                            MD5:16821E49E433E7AECE259C3E9ECB8E3D
                            SHA1:52F9FFE4DBCD149843CEF1D1773FBBF9103E03C6
                            SHA-256:8A3184076D03862DBDD7AD680351AE129D0DD87494433ACDD346B004E138E50F
                            SHA-512:B251A27F1B481B8DB74BF8E2FA1A2DDA9B9A12BDD417C9320ED07EA50AF9FD8C9FDAB2A1EE10210A6268956EF8359A86ACC46EE385438D45DEA95F08F0C70166
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0..@...........^... ...`....... ...............................1....`..................................]..O....`..4............J..`(...........\..8............................................ ............... ..H............text....>... ...@.................. ..`.rsrc...4....`.......B..............@..@.reloc...............H..............@..B.................]......H........(.. 4...........................................................0..P........(....}.....s....}.....(.......s....}......%......s....r...po......{.....o....&*.0..].........{..........(.......{.......o......,....o....&.+...{.....s....%.o ...&o!.........,..(".....*...........GQ.......0..].........{..........(.......{.......o......,(...o#...&.o$..........,...{.....o%...&......,..(".....*...........GQ.......0..x...........(......,H...(.......(......(...+..,,..~....%-.&~....
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):18016
                            Entropy (8bit):6.893261127189029
                            Encrypted:false
                            SSDEEP:
                            MD5:DF0F5747E958C6ABAC6B7AA70FD681FD
                            SHA1:34C7EF4FA65CD5D5B0AEC613099CCB68DD8D7F08
                            SHA-256:EDE95920D5DB7D715C59B083B1EB30A85582456D2E2B76A16C8AEAC4DB0545B1
                            SHA-512:F795007D17513DEDA7A5CF386F1DFE9BC677096697C36F93050A7980D10D8BDE5EDBCF44EA24BAE5A64CCE03DE29DB13850DF07F44ECAED9EA333ADC152B7314
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....t............" ..0..............5... ...@....... ...............................9....`..................................5..O....@..................`(...`.......4..8............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................5......H........#..............................................................z.(........}......}......}....*..0..).........{....(....s.....{.....{......s.....+..*....0...........(....(....}....s.......}......}.....(.......}....s.......}........}.......}.......}......}............s....}.....{...........s.....o.....*...(......{...........s.....o.....*...0..i.................,I..(...+..(........{....(......{....%-.&+...{....(....o......{.....(...+..~.......( .....+...*....0..W.......
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):68704
                            Entropy (8bit):6.031174932393049
                            Encrypted:false
                            SSDEEP:
                            MD5:E6894609D392156DC903168B9F443042
                            SHA1:C7114A30E0FCE79D119C34DA391E3C2DE3E1BC52
                            SHA-256:0550F6906EA6C9294E53F45C974D562640FF3EFC8978C0118B0ACBA262841D5E
                            SHA-512:2D91ABB6B69D3B1B97DFD5FC4821EF54CCF59812C6197595D740EDB87D02CAB70B71BF2A4EC52C6174319A3A3D604702F83795F6B9F2E230C3B7EF826A2433EC
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....*..........." ..0.................. ........... .......................@.......R....`.................................p...O.......(...............`(... ..........8............................................ ............... ..H............text........ ...................... ..`.rsrc...(...........................@..@.reloc....... ......................@..B........................H........M...............................................................{....*:.(......}....*..0..)........u..........,.(.....{.....{....o....*.*.*v 7.), )UU.Z(.....{....o....X*..0..:........r...p......%..{.......%q.........-.&.+.......o.....(....*..{....*:.(......}....*....0..)........u..........,.(.....{.....{....o....*.*.*v .lf& )UU.Z(.....{....o....X*..0..:........r!..p......%..{.......%q.........-.&.+.......o.....(....*..{ ...*:.(......} ...*....0..)........u..........
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):3086
                            Entropy (8bit):5.008530674427501
                            Encrypted:false
                            SSDEEP:
                            MD5:EC76E30957E646ED22367D64181ED5ED
                            SHA1:E8132D143B378EBB5FA34E85CCB7B58C1EC7BEF3
                            SHA-256:C721A0FCDC9BD2E9374046E65AB1F20AFF383D818AFD631F17D177B07E973D1D
                            SHA-512:5A6D8043064D986938F12BB255248C0D4880E9AC590DBE4BC1726BFA0BDABF475270B724ACE754D8EFEF2836E699E80EEE4AC059D50526FB5E8DE8B2C3D8820B
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="FSharp.Core" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-5.0.0.0" newVersion="5.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.0.0" newVersion="7.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Newtonsoft.Json" publicKeyToken="30ad4fe6b2a6aeed" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-13.0.0.0" newVersion="13.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):19040
                            Entropy (8bit):6.677447931949075
                            Encrypted:false
                            SSDEEP:
                            MD5:5420229AC5ACAA71A3C50E98B8C65C96
                            SHA1:3F862F3A79F4D5CB1A2D9D498D2996054B46E12E
                            SHA-256:29A5430CB7BC0AE3945479228C8195F17B601ED4CFF9B8CC4161888A56883FC1
                            SHA-512:32B344ABB813790E845DA7104F0739B88C944D6F0698FE1040BF604896E2A3D347495311CF73C9799C3C56FFFC2D8E324749A6427F3AEC8D997F4870A34A19CA
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...N............." ..0..............6... ...@....... ...............................L....`..................................6..O....@..............."..`(...`.......5..8............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`....... ..............@..B.................6......H.......l#..T...........................................................^.(........}......}....*.0....................(.....+..*.0..%..............s.....{.....{.......s.....+..*....0..................(.....+..*...0.....................(.....+..*....0...........(....(....}....s........}......}.......}......}.......}.....(.......}....s.......}.......}.......}.......}.......}............s....}.....{...........s.....o.....*...(......{...........s.....o.....*...0..1............(..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):40544
                            Entropy (8bit):6.386904375782982
                            Encrypted:false
                            SSDEEP:
                            MD5:B029521BC09DED02290558109B3B1AA3
                            SHA1:2D005CB2EF243B0DD5F653771EE8464FA0065FB8
                            SHA-256:70C5ED96EA7DADBC8041BE0506D860F3E0B7A413E407051B1297841AE20525DB
                            SHA-512:181505A5DBEB4397E5231BFEF81C45363369704F52651D6F11B2B550AA954537443A8383BC3BEF2D8A9DBF7727D09CCA3D6F075E7D4C11658CFC6C70B1FAC42F
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...=%............" ..0..n..........n.... ........... ....................................`.....................................O....................v..`(..............T............................................ ............... ..H............text...tl... ...n.................. ..`.rsrc................p..............@..@.reloc...............t..............@..B................M.......H........C...G..........................................................V.(......}......}....*..{....*..{....*...0...........#.......?(....}.....s....}.....(...+}.....(...+}......}.....(......%-.&......}......%-.&..9...}......}.......}.......~....(....-....{....(....-..{....+...}......{....om...}......{....on...}......&..*........$........0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*....0..7.........(....}=......}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):207456
                            Entropy (8bit):6.199655536697793
                            Encrypted:false
                            SSDEEP:
                            MD5:893E4F0CC10F07386A0F0FB6923FB0FE
                            SHA1:8FE84A30F0781BE60C6AAC36114358FB8B2AC4D7
                            SHA-256:6023C6682100FEDA7569BBFA69BC99A64E05F324AE8C223EBFBCDD7A95BA6EDB
                            SHA-512:0F1AF1763F8FAAE8FE01515458E60D31BD20604F266F278A831CB27A2AFC0B4CE309436D94382B092D9FF2F20CFC0EAE7852172AF8AE6737AE257FDF1A11ED61
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.............Z.... ... ....... .......................`............`.....................................O.... ..................`(...@..........T............................................ ............... ..H............text...`.... ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B................<.......H...........L%............................................................{....*:.(......}....*..0..)........u..........,.(.....{.....{....o....*.*.*v ..lt )UU.Z(.....{....o....X*..0..:........r...p......%..{.......%q .... ...-.&.+... ...o.....(....*:.(......}....*..{....*....0..c.......s ......}!.....}"....{.....{"....."......#...s$...o!....)..{!...r!..p.{"...(%....s&...('...o(.....*.........%9.)....:.(......})...*.r...ps*...z..0..h.......s+......},....t ...~....(...+...{)..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):94304
                            Entropy (8bit):6.044410820991603
                            Encrypted:false
                            SSDEEP:
                            MD5:FA1C2ED80C609C639A8D1BF62A8352EB
                            SHA1:4B6024E8ADF0611E76742BB03DE4BA88769DAC84
                            SHA-256:49B124FD88FBD0C36EF6E2BEAB34352B7E7A86ECA48EB4BD23E256A3EDB82BB7
                            SHA-512:03F8888789C180056E22624F62D389F10BB1A10B772A7EFF2E9ABE1A09F004DE35D420E4D9910A6FF90368402BE7A8DFAD30AE39EF9D1C1CBFA1038FB1E90F61
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....qa...........!.....@...........]... ...`....@.. ....................................`..................................\..]....`..T............H..`(...........]..8............................................ ............... ..H............text...|>... ...@.................. ..`.rsrc...T....`.......B..............@..@.reloc...............F..............@..B.................\......H.......\W..............x...6[............................................{....*..{....*..{....*r.(......}......}......}....*...Zr...ps....(...+.o....*..0..`...........,X.. .y7...{....(...+..b..cXXX. .y7..{......b..cXXX. .y7..{......,..o.....+.....b..cXXX..*.*2.(....o....*....0..T...........,F.u......,:.{.....{....(....,%.{.....{....3...{.....{......(...+*.*.*.*.......*:.{.... ......*.:.{.... ......*..0..O...........,A....,9.{.....{....(....,$.{.....{....3..{.....{......(...+
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):138336
                            Entropy (8bit):5.722411886273528
                            Encrypted:false
                            SSDEEP:
                            MD5:04DB14FCFCD017D10F2A1660ADEE113A
                            SHA1:786457AABA9E4D55B9899529BA9060D1D16BC3D9
                            SHA-256:A5EBE101C53CA0DEE0AFF9BD92B6A0AD74ACEF700C6998A58CE9289D414A2343
                            SHA-512:EEFA05307C8E6B97AB3AD0F588B0AA7CFD34832929D8B10CF1402E7BE2B81FEC4B6F751E5E0337E2074E9110D73EF23CCE3689F1B66B5E2FE896F6B3B0DC6C98
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....qa...........!..................... ... ....@.. .......................`............`.................................Y...b.... ..T...............`(...@..........8............................................ ............... ..H............text...,.... ...................... ..`.rsrc...T.... ......................@..@.reloc.......@......................@..B........................H........i.............................................................2.s.........*...:.(......}....*..~....*.*.(.......*...sB...**.(.......*...sD...**.(.......*...sF...**.(.......*...sH...**.(.......*...sJ...**.(.......*...sL...**.(.......*...{....*Zr...ps....(...+.o....*.Zr...ps....(...+.o....*..0..9...........,)....,!.{......{.......3......(....*..Y*.*....,..*.*...>.........o....*.0..K..................,/.........,".{......{.......3.......(....*..Y*.*.........,..*.*.F...
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):48224
                            Entropy (8bit):6.284583758347468
                            Encrypted:false
                            SSDEEP:
                            MD5:69CA79C5B8D31B372F8A9F57CAB33FA9
                            SHA1:9C987EEFDE3E7B8274FB1C63D3EF91E7631F8440
                            SHA-256:26D9359A720CAD2449511B4A59554B00A2B6230BF9137215F1A2C072DE8BE071
                            SHA-512:ED096BB6D32BBD35FF1CA22FF583226655F8B3941D75E0CE3A060450131608454E4FC8025619669ADF77327956185E99E7E268573CA15B895994D565B2D250C5
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0.............~.... ........... ...................................`.................................*...O.......d...............`(..........T...8............................................ ............... ..H............text........ ...................... ..`.rsrc...d...........................@..@.reloc..............................@..B................^.......H........3..ht............................................................{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*".(.....*..{....*"..}....*..{....*"..}....*".(.....*".(.....*....0..^.........q......(....o.......r...p(.......(............r...p(....-.+....(...+..+.r#..p.(....s....z..*F....o.....( ....*".(!....*.r...p*..{....*"..}....*..{....*"..}....*..{....*"..}....*".(.....*..{....*"..}....*..{....*"..}....*".(.....*..{....*"..}....*..{....*"..}....
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):1355
                            Entropy (8bit):4.993338249776485
                            Encrypted:false
                            SSDEEP:
                            MD5:D0674DB22B8BF76539D01FD508D1089F
                            SHA1:9E863EC9CD61A245128D8630A5770679501EC74B
                            SHA-256:AB1551A3B2773B9EB3411DCFC57B402DB0E8462E4E39D43EFDCA1E036918B6FA
                            SHA-512:609BEAC295D2F5643F82AE79A5B42DE5BEFC16F788E354E1A10684E220B6D04B27D3F7D75C2CB0A508B16CB942BF09F14790836B6368C1B3D0AC47075214CD1F
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Runtime.CompilerServices.Unsafe" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-6.0.0.0" newVersion="6.0.0.0" />.. </dependentAssembly>.. <dependentAssembly>.. <assemblyIdentity name="System.Net.Http" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.1.1.2" newVersion="4.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.0.0" newVersion="7.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):40032
                            Entropy (8bit):6.121153714104367
                            Encrypted:false
                            SSDEEP:
                            MD5:0F89F1BE7420DF5F80A43FB3AAADA5DC
                            SHA1:29E5BA9B0100A1862EFA070E051F6699B8E64C3B
                            SHA-256:091128DAFEE800DFFD30ED7C798753C51DC25B990CEC4BDA0D190A24782394F5
                            SHA-512:2C87D5473B2051145D409AD2FBF6C853314EF1723B3F258A50E7495840716A6ED1A180D0DF064F8622F5D817F67DF4294F40E8A55E0C37FFC18054C8E551074A
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....qa.........." ..0..l............... ........... ..............................*.....`.....................................O....................t..`(........................................................... ............... ..H............text....k... ...l.................. ..`.rsrc................n..............@..@.reloc...............r..............@..B........................H........:..hO...........................................................~5...*..0..H.......~.....(....,:......~.....o....-.~......s....o....~.....o.....o....(....*.0..........~....-.*.....#.......@(....(....(....9{...(.........(....~....(.......(.....~....o....~0...%-.&~/.........s....%.0...(...+.~....r...po...+~....r?..p..2.....2.....[.2...(....o...+~....r...pr...p~....( ...r...p(!...o...+~....o....~1...%-.&~/.........s"...%.1...(...+o$....+~.o%.......o.......(.....[....o..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):132192
                            Entropy (8bit):6.1603223445709645
                            Encrypted:false
                            SSDEEP:
                            MD5:57771404B67D9FBDFC8A294175861C3C
                            SHA1:BA5622B14A205B45012B8BE441915FFA557E4A16
                            SHA-256:C39796BCEA6056AADE1A1ADF1082905E06F7B900578438333E2D509D4D33DB6E
                            SHA-512:39CEE0CB4A2CB90F3787F2F1E2F80E7050557C35EFC0E6ECBCE239C66AD52CEB1E9049A277E38A8D6005649A81EB86E086513C94F9BFF34FA79AD672CC6E529C
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...~............." ..0.................. ........... .......................@............`.................................@...O.......................`(... ......$................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B................t.......H............]...........................................................r...p*..{....*"..}....*..(....*.r...p*..(....*.r-..p*..{....*"..}....*..(....*.rG..p*..{....*"..}....*..(....*.rg..p*..(....*.r...p*..(....*.r...p*..(....*.r...p*..(....*.r'..p*..{....*"..}....*..(....*.rM..p*..(....*.rk..p*..{....*"..}....*..(....*.r...p*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*.0..9.........(...+..r...p(....-..r...p(....-.+..*.*r...p.(....s....z..,.....*.r...p.(...+*.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):103008
                            Entropy (8bit):6.219570818808515
                            Encrypted:false
                            SSDEEP:
                            MD5:953362829F7BC88F47D346B5D04400B9
                            SHA1:AB58816936C7F8BC636255AADD5F89C273431EA1
                            SHA-256:07831CD75D58AF4367B01A9E53EE29654295F0C4ACBDDD3820D69783931E3A4B
                            SHA-512:87176863FBD7A4661AA301BF6BF6B82816D22E5648FA821734E17651ABE276139A79DB127E9B24D51BFB844DA473A4EEFC1C8CD9D569D44FFF3925F605BE615F
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....D..........." ..0..`............... ........... ..............................}q....`.................................T...O.......4............j..`(...........~..8............................................ ............... ..H............text...._... ...`.................. ..`.rsrc...4............b..............@..@.reloc...............h..............@..B........................H........................................................................{....*..{....*..{....*..{....*..(......}......}......}.......}....*....0..q........u........d.,_(.....{.....{....o ...,G(!....{.....{....o"...,/(#....{.....{....o$...,.(%....{.....{....o&...*.*.*....0..b....... F.;. )UU.Z(.....{....o'...X )UU.Z(!....{....o(...X )UU.Z(#....{....o)...X )UU.Z(%....{....o*...X*...0...........r...p......%..{.......%q.........-.&.+.......o+....%..{.......%q.........-.&.+.....
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):19552
                            Entropy (8bit):6.581912054104746
                            Encrypted:false
                            SSDEEP:
                            MD5:9AF6AB39A0544BB91D24D90F5C6F0E44
                            SHA1:2DE7A1BBB1BE24DFCE1C2536E7AA6F62F0EE1442
                            SHA-256:54BD19EDC9DD97DA8EC610A09821B343E286BA9AD72F8D9D09C21728F7B314DD
                            SHA-512:8A7DFC757048C27ED8999245006F89B54C72D98018A4E39BDC3589731BCDB159E982CD07094AC52AADDB7F2E7804231326AA6D3D0C1ABE5D019E8A7065A4E42E
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....^..........." ..0..............8... ...@....... ..............................].....`..................................7..O....@..@............$..`(...`.......6..8............................................ ............... ..H............text........ ...................... ..`.rsrc...@....@......................@..@.reloc.......`......."..............@..B.................7......H....... !................................................................(......}......}......}.......}....*..{....*..{....*..{....*..{....*...(-...Q..(....Q..(/...Q...(0...Q*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..(....*...BSJB............v4.0.30319......l...h...#~..........#Strings............#US.........#GUID...........#Blob...........W..........3....................=...............&.......%...*.......................
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):21600
                            Entropy (8bit):6.622536998605513
                            Encrypted:false
                            SSDEEP:
                            MD5:2B052A2C05BA9623B9E5D631604B77EC
                            SHA1:0B76588E54640890CDFF237C57F77E1C21074AE5
                            SHA-256:DEA53438211C50465CDDA5900C77086DF130B692314CD1B91798B3B2A577074F
                            SHA-512:2942D955B235AFB5224E2495B60219A17BC948A92E22134C87057C90B2D096BB4A2E4564370C2584244BD889D36D48C1261E38FEF42B4C0747C4136AE8E89AFA
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0.."..........jA... ...`....... ..............................8.....`..................................A..O....`..|............,..`(..........8@..8............................................ ............... ..H............text...p!... ...".................. ..`.rsrc...|....`.......$..............@..@.reloc...............*..............@..B................LA......H........&..<............................................................0..E........(...+}.....(......}......o....r...p(....}......o....r+..p(....}....*....0..7.........(....}.......}.......}......|......(...+..|....(....*..0..7.........(....}.......}.......}......|......(...+..|....(....*..0..?.........(....}.......}.......}.......}......|......(...+..|....(!...*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..(....*...0..w........{......{.......&&..,U....("....
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):204896
                            Entropy (8bit):6.326794257675216
                            Encrypted:false
                            SSDEEP:
                            MD5:79FDAE618243C3BF9ED27DB0B4D6BF68
                            SHA1:CDBF133E791EBC6C07F940A317EE1376C7BAF69D
                            SHA-256:C8D9027FD0D086BA54AC85AC182DEE3479C3A03C65F06F882E8B9203CC603144
                            SHA-512:59E640C4B576D25DC5CA5230C02C19C4AC10EA1B1A652179B73AC5FF81D4A5BB8227815FE2E62EA3AA00D513FE2256AAE5573F88102ADE80B0ECA50D5F971573
                            Malicious:false
                            Antivirus:
                            • Antivirus: ReversingLabs, Detection: 0%
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.................. ... ....... .......................`.......p....`.................................z...O.... ..L...............`(...@..........8............................................ ............... ..H............text........ ...................... ..`.rsrc...L.... ......................@..@.reloc.......@......................@..B........................H.........................................................................(-...*^.(-..........%...}....*:.(-.....}....*b.o.....o/....o0...s1...*~.,.....+..*.*r...p..Y....s2...zJ......-..*..(...+*f.s4...}5....(6.....}7...*....0..f........{7.........(8....{5......o9...,.~:...r...p......(;...o<.......#.s=.....{5.....o>.........,..(?......*..........PY.......0..j........{7.........(8....{@...-5.{5......o9...,...}@....7~:...rE..p......(;...o<.....~:...r...po<......,..(?....*......
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):60000
                            Entropy (8bit):6.215409315185123
                            Encrypted:false
                            SSDEEP:
                            MD5:551C46AE293F55F3BDB7F4C25F0DD768
                            SHA1:B7E737739C2BCD7F8D500C9CDA3C52F922801245
                            SHA-256:D9B42F48C606C54F9DA20794C5B4358834BD9A122259662EA2A3849868430FEC
                            SHA-512:C8B875AEB2A8DD0F144FEDF0548FD682FFCB987B3BFFDC3FD003903CD00BEC9F709BF8CD8A96B4A50DB4B22F3ECDFC25BB8E27A16EF20F4D6C7D818B664ECB79
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....'..........." ..0.............Z.... ........... ....................... ......q.....`.....................................O.......@...............`(..........<...8............................................ ............... ..H............text...`.... ...................... ..`.rsrc...@...........................@..@.reloc..............................@..B................:.......H........S..|.............................................................s....}.....(............s....s....} .... `...}!...*^.("...o#....{ ...o$...*....0..I........{..........(%....(&....{'........-..(...+}'......{'...o)......,..(*....*...........5>.......0..7.........(+...},......}-......}......|,.....(...+..|,...(0...*..0..8........{..........(%....(1....{'....|'.............,..(*.....*........#,........{2...,.*..}2....{ ....{!....o3...&*~.{2...-.*..}2....{ .....o3...&*...
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):45152
                            Entropy (8bit):6.287000428324375
                            Encrypted:false
                            SSDEEP:
                            MD5:C14E56308C27DEF04B27044683BCFE7C
                            SHA1:96DEFD9D9A1D7790B8C511A173D49A73406504B3
                            SHA-256:942E3EF36DFCD2DAAC25935898868F428AA1A613DF909A19E154A64EE782AD63
                            SHA-512:4BC7963EE4EAB8BB8377D1894425629CDDEF8C34E40CDA77FF99B3F3B2F6D64CAD3C5697ABC376F58E185C77A4EF3781C48642D654C5A0265ABF2F8088391BE7
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...h............." ..0..~............... ........... ...................................`....................................O.......................`(.............8............................................ ............... ..H............text....}... ...~.................. ..`.rsrc...............................@..@.reloc..............................@..B........................H........>...]............................................................{....*..{....*..{....*r.(......}......}......}....*....0..Y........u........L.,G(.....{.....{....o ...,/(!....{.....{....o"...,.(#....{.....{....o$...*.*.*....0..K....... )a.j )UU.Z(.....{....o%...X )UU.Z(!....{....o&...X )UU.Z(#....{....o'...X*..0...........r...p......%..{.......%q.........-.&.+.......o(....%..{.......%q.........-.&.+.......o(....%..{.......%q.........-.&.+.......o(....()...*..{*...*:.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):51808
                            Entropy (8bit):6.207355691744455
                            Encrypted:false
                            SSDEEP:
                            MD5:A1352E9FA67283B5D9A1FBF4CBDD2BC1
                            SHA1:618A261A9C392931B8CD92620124672D447EC55C
                            SHA-256:A9F119B74BD3E941D6EEB4BA1946A95A25FBB6CA473F25504EDDF9303C3F253B
                            SHA-512:A892B2747D5D1C8DECAAF054E236DB641F06A3939102B8D08ECA192ADFA893CBD500E8382EC46FF96EEB454B4EB831E40A12031223CB879672CA56F312569E89
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....19..........." ..0................. ........... ..............................8.....`.....................................O.......L...............`(..............8............................................ ............... ..H............text....... ...................... ..`.rsrc...L...........................@..@.reloc..............................@..B.......................H........X...]............................................................{....*..{....*..{....*r.(......}......}......}....*....0..Y........u........L.,G(.....{.....{....o....,/(.....{.....{....o ...,.(!....{.....{....o"...*.*.*....0..K....... .... )UU.Z(.....{....o#...X )UU.Z(.....{....o$...X )UU.Z(!....{....o%...X*..0...........r...p......%..{.......%q.........-.&.+.......o&....%..{.......%q.........-.&.+.......o&....%..{.......%q.........-.&.+.......o&....('...*..{(...*..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):2094
                            Entropy (8bit):4.984901041952773
                            Encrypted:false
                            SSDEEP:
                            MD5:CAAC203221C2E59EE6BD827881E0A668
                            SHA1:019FA5B8D05607C97BD2CB7CB2EFC0997ED105FD
                            SHA-256:E29170C3B98A13E5A7BF89BEB51A6989BBCC2F09C6ED51A1D974097F5A8FCBA8
                            SHA-512:FA49C1977488A7255B41B19652619E843C661C78639B53690567D18CD275C7BB610D4B735A2528752B5441285D6DA6BF6F539CB61BEFD65A231377518E2CF726
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="FSharp.Core" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-5.0.0.0" newVersion="5.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.0.0" newVersion="7.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Newtonsoft.Json" publicKeyToken="30ad4fe6b2a6aeed" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-13.0.0.0" newVersion="13.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):55392
                            Entropy (8bit):6.326915406869449
                            Encrypted:false
                            SSDEEP:
                            MD5:770DAEFB4E8C4C1A3F64D31620C5A52B
                            SHA1:8B8744DCDD4C8CFD19AF2AA0C86785FBD238A1AC
                            SHA-256:D5A4F5DFDD4235E5D35E401B04D54278E839EF4C4B048FC54408AC240EC9A5CB
                            SHA-512:9E6173072993B47330B527040E88A8347F7CA583297556416A4F30C7B8E19BA1085D384892D75E62E358691AA21DB9CF57C34681B52A3181A973E3AB679D6959
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....f..........." ..0.................. ........... ....................... ......O:....`.....................................O.......@...............`(..............8............................................ ............... ..H............text........ ...................... ..`.rsrc...@...........................@..@.reloc..............................@..B........................H........K...v............................................................{....*..{....*..{....*..{....*..(......}......}......}.......}....*....0..q........u........d.,_(.....{.....{....o....,G(.....{.....{....o ...,/(!....{.....{....o"...,.(#....{.....{....o$...*.*.*....0..b....... k.1Q )UU.Z(.....{....o%...X )UU.Z(.....{....o&...X )UU.Z(!....{....o'...X )UU.Z(#....{....o(...X*...0...........r...p......%..{.......%q.........-.&.+.......o)....%..{.......%q.........-.&.+.....
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):32864
                            Entropy (8bit):6.384737923880296
                            Encrypted:false
                            SSDEEP:
                            MD5:C81D0C4BDABEAFA5A99E53081BF7D351
                            SHA1:90FC3A1822AB49A159EFEF5151C4A4F77F825096
                            SHA-256:3C94B6CE0800F6D0CC7D55A3304505AB640605BBA6BA3B0517827758F07C8E06
                            SHA-512:22F0CB795BF89F2AC510D03E6AB958E85FFCDB8D5EE9B718AC760AA614B860FAE3FDBBF76002B81D8C88214230CB2BD6EC9756C9A643D8579A202BEC4E2BE331
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..............." ..0..N...........l... ........... ...............................'....`.................................Rl..O.......L............X..`(...........k..8............................................ ............... ..H............text....L... ...N.................. ..`.rsrc...L............P..............@..@.reloc...............V..............@..B.................l......H.......80..L;..........................................................r.(......}......(......(....*..{....*..{....*"..}....*..{....*"..}....*V.(......}......}....*....0..7.........(....}#......}$......}".....|#.....(...+..|#...(....*.(.........*..0.._........s....}.....(......}......}......o....}........o....sL...}......}.......}......o....s....}....*..0..)........{.........( ...t......|......(...+...3.*....0..)........{.........("...t......|......(...+...3.*..{....*....0..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):2751
                            Entropy (8bit):4.983944915411854
                            Encrypted:false
                            SSDEEP:
                            MD5:12DC3B415AD57288F89F9813F7362895
                            SHA1:EDFEF6CF28CF1A9B59D7D83A398E358A84FE833D
                            SHA-256:E00A9604A225A06F61F5AF62940426FBE08BE13BC639E82BCBFA2E0CF5E2D79D
                            SHA-512:6541ECFCE36ECC117CC0F966AB2E60AE6AC7ECE9889B06205E5A53D851F399AAC84D80266B72E5EA0052143E4907A3F56786E7412DCFB415D181F4E4F0AC4B11
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="FSharp.Core" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-5.0.0.0" newVersion="5.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0.0.0" newVersion="7.0.0.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Newtonsoft.Json" publicKeyToken="30ad4fe6b2a6aeed" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-13.0.0.0" newVersion="13.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):21088
                            Entropy (8bit):6.589856583414102
                            Encrypted:false
                            SSDEEP:
                            MD5:24CDF24D40B043DC4925E2F6D34E9572
                            SHA1:DE171EBC782CF0ECCC724FDC1D8F3DD43B16D734
                            SHA-256:57CA3A0ECD29695C6D49827C3A9EC79C00E2D548FCCCCF310C07AF00E4F66AA3
                            SHA-512:84DF4040E960DAE7688F845DA60555B1843AD959EA3E4BF53480FBC97F20CFEB7205BEB2581EF895F13DC06459097FDBC8F69CE1731F627A2A4E475A99B0DB7A
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....9............" ..0.. ...........?... ...@....... ..............................a.....`.................................x?..O....@...............*..`(...`......\?............................................... ............... ..H............text........ ... .................. ..`.rsrc........@......."..............@..@.reloc.......`.......(..............@..B.................?......H........$..P............................................................0..9.........(...+..r...p(....-..r...p(....-.+..*.*r+..p.(....s....z..,.....*.r...p.(...+*.r...p.(...+*..(....*..{....*"..}....*..{....*"..}....*..(....*...0..9.........(...+..r]..p(....-..ri..p(....-.+..*.*r...p.(....s....z..,.....*.r]..p.(...+*.ri..p.(...+*..(....*..{....*..(....*.0...........q......(....o.......r...p(.......(......r...p(....-).r...p(....-%.r...p(....-!.r...p(....-.+$...(...+*...(...+*
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):82528
                            Entropy (8bit):5.9930865076904585
                            Encrypted:false
                            SSDEEP:
                            MD5:E14B0DC37E9462DADEDDC049216EFCF6
                            SHA1:D3108EF1889289BA807BBEE14E8519874F20EDF2
                            SHA-256:517832F63ABDA15EF56B2FF2045B6D42717B239F2E66481EBCE934CA663D7581
                            SHA-512:F66DF564BEF81C7BB401C3B57DE799CCF7D3B52FD227175F94BECF30A0A96516DCDA6005610F9216CDDBC79702E0EF524CEE6D8AA17800810A471890369E598F
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....B.c...........!................./... ...@....@.. ..............................{.....`................................../..V....@..h...............`(...`.......0..8............................................ ............... ..H............text........ ...................... ..`.rsrc...h....@......................@..@.reloc.......`......................@..B................./......H........T..Tt..........<...if............................................s....*:.(......}....*...{....*..&.*...Zr...ps....(...+.o....*.Zr...ps....(...+.o....*..0..-........,#.,..&....(......{.....{....(....*.*.,..*.*...6.......o....*...0..8...............,"......,..&.....{.....{....(....*.*......,..*.*.0..3........,....&.... .y7..{......-...+..o.......b..cXXX..*.*.2.(....o....*....0../........,$.u......,..&.....{.....{....(....*.*.......*."..{....*...:...(....(....*..0..(...
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):430176
                            Entropy (8bit):5.903952812969663
                            Encrypted:false
                            SSDEEP:
                            MD5:E23B3877C34FEB5BC1661B61F72D2F4B
                            SHA1:077E23C2AB8AB20B189B08982A0DB6C797C2477B
                            SHA-256:1398188E3E59F827858F6599534757E006E13509C28193447BA0B069B86F8C31
                            SHA-512:40F7DDD378A114F6EF8D23092650DC3DB8FAB0EF631B50EF54856435497ADD5D20BE55ECAE7BB24872B7E98CDC37CCD0A8D062DDCFAAF32D27DBFC4B4E1580CE
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...7.B..........." ..0..^.........."|... ........... ..............................d.....`..................................{..O.......L............h..`(...........{..8............................................ ............... ..H............text...(\... ...^.................. ..`.rsrc...L............`..............@..@.reloc...............f..............@..B.................|......H........Q..h................y...........................................s....%.o ...%.o!...(...+s#...o$...%.o%...*.s....%.o ...%.o!...(...+s#...o$...%.o%...%.(...+o&...*6s'...%.o(...*.s'...%.o(...%.(...+o)...%o*....o+...%o*....o+...*.s'...%.o(...%.(...+o)...%o*....o+...%o*....o+...%o*....o+...*.0..........sA......}:....{:...o,...,.(4...r...p.{:...o-...(....*.{:...o/....3..{:...(....*.{:...o0......(1...,?.{:...o0.........B...s2...(...+....{:...o4...%-.&.+.(5...(6...*.{:...o/.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):896096
                            Entropy (8bit):6.429931366049105
                            Encrypted:false
                            SSDEEP:
                            MD5:C84548C46BD1CF776BF278614A42A51A
                            SHA1:F6FCF3F21930D602C0093A1E3851191EE051F7F5
                            SHA-256:361CFB9ED7CDFB27DFBC92568471C4886EE4E349A3FEAE748C146B9ECC17E819
                            SHA-512:33B86EA3F3A6408A605154DD8C4933EB5F1BD39E5C6B1C93A554A32E23A9435E682F268DFB3103CF647AA3E94EE693C9EB99303D8E3B72EFDABB043353EC804B
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...$i............" ..0..|............... ........... ...............................5....`.....................................O.......................`(..............8............................................ ............... ..H............text....z... ...|.................. ..`.rsrc................~..............@..@.reloc..............................@..B.......................H.......h....S..........d...............................................6.('....(....*...0..$........{....,.*..}....r...p.s(......()...*"..}....*6.('....(....*..0..A........(*...u......,1.u......,'.o+.....u....,.........o..........o,...*....0..A........(*...u......,1.u......,'.o+.....u....,.........o..........o,...*....0..$........{....,.*..}....r}..p.s(......()...*&...(-...*.........+...t....}....*..t....}....*..}....*..0...........(......}......oD...}......oK...}......oF...
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):170592
                            Entropy (8bit):6.306047046075611
                            Encrypted:false
                            SSDEEP:
                            MD5:83D0C2405AF34CF23784535469823579
                            SHA1:35CB8E93F30017BD9A746FECDAD3CA7085E77D88
                            SHA-256:A2E3FEC4C20415E8704863684755BD0F9F71193EA72E8B41A47C5BA3B9F5447C
                            SHA-512:DAE5DEFB81663F4458E6B58554F46D079AF3EC6E77E058A55C30DD6FD80008B433731C38CFA1C0A1C9A7825F38DE66DBFE2347C0903B66B84136217AF6200D46
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....)............" ..0..h............... ........... ..............................Vh....`.................................l...O....................r..`(..............8............................................ ............... ..H............text....g... ...h.................. ..`.rsrc................j..............@..@.reloc...............p..............@..B........................H.......Tb..............T%..Xa...........................................0..........(.......&.....*..................0..;.......~.......+....(%...(...+.1.......X....i2......r...p.s....z.*.........,,.............%.rG..p.%.rQ..p.%.rc..p......*&...('...*b.((.....()........(....*:.((.....(....*N.((.....o*...(....*..{....*"..}....*..{....*"..}....*^.(.....(....(....s+...*....0..T..........}f....{f...#......o@Z.. ....(......(,.....(......(-.....(......(......(....(/...*..l#......o@
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):372320
                            Entropy (8bit):6.399197327672368
                            Encrypted:false
                            SSDEEP:
                            MD5:A564450BFB26C4F324D95BDA2328890C
                            SHA1:0881BE924498AE44B28789B7D8605CB19D277293
                            SHA-256:D3E479A0F844BFA969194D4D0A581411732EB13BF8D36D69516693333209CD92
                            SHA-512:DC8D5D6C0745330AE0F4461A89323397B7EB94129B5C8469D442638F34DF0D12723E56DFAB0FEA9B7E4BA2D7DFF559D1AD13277607C3A076FAB0FF9F68986C49
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\.T..........." ..0..|..........^.... ........... ....................................`.....................................O.......................`(..........P...8............................................ ............... ..H............text....z... ...|.................. ..`.rsrc................~..............@..@.reloc..............................@..B................@.......H........<...G............................................................{....*..{....*V.(......}......}....*...0..A........u........4.,/( ....{.....{....o!...,.("....{.....{....o#...*.*.*. ... )UU.Z( ....{....o$...X )UU.Z("....{....o%...X*...0..b........r...p......%..{.......%q.........-.&.+.......o&....%..{.......%q.........-.&.+.......o&....('...*..{(...*..{)...*V.(......}(.....})...*.0..A........u........4.,/( ....{(....{(...o!...,.("....{)....{)...o#...*.*.*. .VE6 )UU.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):28256
                            Entropy (8bit):6.510651697666759
                            Encrypted:false
                            SSDEEP:
                            MD5:F5676951F7C9A832BDA839E2B6F5FAEA
                            SHA1:79695B2CD9F850941DE712C190824E9AF9E83208
                            SHA-256:0F311C1916447F0551F53B253B0410184E0F5388DE108B11E41D886FEC06A860
                            SHA-512:50F214198D7C105BA430AAF77478B2466208D62D4C3FF84ABEB60ACE73A914ED4DDB30C2BE980B669F90BAB11D069A936FD12BE1694330FAB2F15C2C21D125FE
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...3n............" ..0..<...........Y... ...`....... ...............................Y....`..................................Y..O....`..4............F..`(...........X..8............................................ ............... ..H............text....:... ...<.................. ..`.rsrc...4....`.......>..............@..@.reloc...............D..............@..B.................Y......H.......L&...2...........................................................0..O.......(....o.......s....(....,/(....o....... .:..s....(....,.."(....&*.(....&*(....&*..0..7........o.......(.....dX.o.......(.....dXs.....(.......(....&*R.{....l.{....ls....*:.{.....{....Y*:.{ ....{!...Y*..{....l.{!...l.(....l.(....ls"...*>..}......}....*.~....*..{....*..{....*.0..:...........(#...-..(....+...($.......(%...-..(....+...(&...s....*6..s.........*:.('.....}....*..0..@.......sS......}...
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):125024
                            Entropy (8bit):6.254360510892914
                            Encrypted:false
                            SSDEEP:
                            MD5:D35D88A18DC2FDF77BBEBBC5DE3E6953
                            SHA1:9C41BE3CD1A2FE0879BB73DB1424D1D821DE6C3E
                            SHA-256:84A566D1F4127B39E9A51783374BBD8B22A05CF2D3DD69C1542EA24578F6DAD5
                            SHA-512:CB99607BB0D9E550F232A1B2AA4EEB059BB7C07317A52322FA9FBAD020018FDB2E4A80F36ABFBCDA35341AD5388616495FB53A9197D97CF3E55CE1C7318A480C
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.................. ........... ....................... ............`.....................................O.......................`(..............8............................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H....... .................................................................o?...r...p(*...,..-..oD...%-.&.*(+....|.....*.*.*..(,.......*n~.....o-...-.~.....o-...*.*2~.....o-...*.0..........s....%.!o/...&%..o/...&%.?o/...&% & ..o/...&.....s....% ( ..o/...&% ) ..o/...&%..o/...&%..o/...&%..o/...&%..o/...&%..o/...&% ....o/...&.....*....0..........(0....(1.......&.....*...................0..........r...p(......r...p(....X...(....X..r...p(....X.r...pr...pr&..p......(2...(3...r4..pr&
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):42080
                            Entropy (8bit):6.299325414652226
                            Encrypted:false
                            SSDEEP:
                            MD5:A57482AAFCA6CF735F86600CBD3EB012
                            SHA1:6F3DFD28CEE5774B5DE751F35B4908EFBF292617
                            SHA-256:86C469C545EA8DE21B038B560DF723FCE8B12DA891F95F0841E7E271FED6353F
                            SHA-512:31B24EB18EC715E55E33EB6276D550F2D9CC28989FDD526D65E2476D0A3778D4F0777803CB06111D56540A954A6B370916FF4382A8BAA12561EB13D3FBC42F50
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....Pt_...........!.....t............... ........@.. ....................................@.................................<...O.......(............|..`(........................................................... ............... ..H............text....s... ...t.................. ..`.rsrc...(............v..............@..@.reloc...............z..............@..B................p.......H.......P ...r..........................................................BSJB............v4.0.30319......l....E..#~..DF..0!..#Strings....tg......#US.|g......#GUID....g..`...#Blob...........W.........%3............#.......K..........................................................!........o...............................................(.....=.....N.....e.....v.{.....{...............................................................&.............3.......=.....G...5...B.....U...5.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):161376
                            Entropy (8bit):6.02106348619019
                            Encrypted:false
                            SSDEEP:
                            MD5:3574751DFD472A5E02AEA5AB642EF518
                            SHA1:3808CEF4A2E6CF0EE45B79DAD1052172C941D681
                            SHA-256:B87F38803AC1D567F2A77DF2D8110827B09781C92D1B4B7EC084849729AB3DC9
                            SHA-512:B9E0DCB807BCBA262E7A0AC85402F5DAEF391E627B4E4985423865B8F4D6F9340768119C8B92DAA142772A0E34D211E026847FBBBEBFDC8BBE9C4A0D9C4293A2
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....#F[...........!.....F...........d... ........@.. ....................................@..................................d..S.......8............N..`(........................................................... ............... ..H............text....D... ...F.................. ..`.rsrc...8............H..............@..@.reloc...............L..............@..B.................d......H.......P ..HD..........................................................BSJB............v4.0.30319......l....i..#~..Xj.....#Strings....$#......#US.,#......#GUID...<#...!..#Blob...........W.........%3............{.......0...y..."...............3.......8...4...`.........................................................&.-...4.....L....._.....t.............-.................-.....-.................-.....................1...................................+.......8.....9.......8.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):21600
                            Entropy (8bit):6.603192536773671
                            Encrypted:false
                            SSDEEP:
                            MD5:BBAEB15EA763B6448D53DE9CE214D4AC
                            SHA1:E0E3FEA240A3FD405D0FE01A15D7164873AFDE88
                            SHA-256:900321EFED3EF86C94254F6E6C8474847965337FDDC28B3B2B099C538999D409
                            SHA-512:9FD445646CB5107D004A51B809D24B9C912CCA040D5B93C6AA465FDA660AA84CDCA14E35C4A02C0EEC3EECBD616EA54DF02B6CFB31E3D5947CF7BD51C62D1065
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.."...........@... ...`....... ....................................@.................................k@..O....`...............,..`(...........?..T............................................ ............... ..H............text.... ... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H.......X-..(............................................................0..(.......s.......+....o......o......X...o....2..*.0...........-.r...ps....z..~....%-.&~..........s....%.....(......o.....]..E................%...r...ps....z.*.r?..p(....*.rG..p(....*.rM..p(....*....0..?.......s.......}.....{....-.r...ps....z.{....o..... .......s....(....*....~....%-.&~..........s....%.....(....*.0..B.......s.......}.....{....-.r...ps....z.{....o.... .@.........s....(....*..-.rQ..p*..~.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                            Category:dropped
                            Size (bytes):6924384
                            Entropy (8bit):5.7996460525657305
                            Encrypted:false
                            SSDEEP:
                            MD5:55EEB1E92860FCBCB2F315C3CF5D92AD
                            SHA1:17413082B53D8CA1AB93925F7BD98477E527BD74
                            SHA-256:7DCDB2D7DC5051CC066881CDA3024F5F29E1FA1115FEFE02663DF32B0E86A752
                            SHA-512:4B2BD4094A52D449EB09E795B84CC27072BC36D2B6E9B3424308338668FA4E2E7D13D6E89B6067E082C55631BC5E02DD6FB39D0E2E5183BCF6279C0E2C7BAF9D
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0..vi..........i.. ....i...... ........................i......dj...`...................................i.O.....i.p.............i.`(....i.......i.T............................................ ............... ..H............text....ti.. ...vi................. ..`.rsrc...p.....i......xi.............@..@.reloc........i......~i.............@..B.................i.....H.......8O..pDP...........................................................{}...*..{~...*V.(......}}.....}~...*...0..A........u........4.,/(.....{}....{}...o....,.(.....{~....{~...o....*.*.*. .s.. )UU.Z(.....{}...o....X )UU.Z(.....{~...o....X*...0..b........r...p......%..{}......%q.........-.&.+.......o.....%..{~......%q.........-.&.+.......o.....(....*..{....*..{....*V.(......}......}....*.0..A........u........4.,/(.....{.....{....o....,.(.....{.....{....o....*.*.*. ]..( )UU.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
                            Category:dropped
                            Size (bytes):29916
                            Entropy (8bit):5.08197604502867
                            Encrypted:false
                            SSDEEP:
                            MD5:0D9CF51EEA324B45EC5D916183E9611D
                            SHA1:BE6251498212BA6405F523576A467E5ED93C4175
                            SHA-256:EAE5FB06C3FB141DFF8481C924F00BF66ED4E8B2AA47B23473CC1E2BE7D7AC6A
                            SHA-512:407E9052E7F8940EBDF8E69B62EBD94FA1F722F8EA530B92B13AFC8BFA81DBADED33A7386D49F58310F61BDC23406404800430EFD733776B25A329151E77AE5A
                            Malicious:false
                            Reputation:unknown
                            Preview:............ .h...F... .... .........@@.... .(B..V......... .^...~W..(....... ..... .........................o~..o~..o~..o~..o~..o~..o~..o~..o~..n}..n~..p..@................o~..o~..o~..o~..o~..o~..o~..o~..o~..o~..o~..o~..n|..p...........o~..o~..o~..o~..o~..o~....Q...........a.x...o~..o~..o~..p.......o~..o~..o~..o~....Q...........................a.o~..o~..n|......o~..o~..o~....Q..........1.o~..o~....A..........`.o~..o~..p.. o~..o~..x...........o~..o~..o~..o~..o~..o~...........!.o~..o...o~..o~....a.......A.o~..o~..o~..o~..o~..o~....".......`.o~..o~..o~..o~..........o~..o~..o~..o~..o~....................o~..o~..o~..o~..........o~..o~..o~..o~..o~...."............p.o~..o~..o~..o~....Q.......1.o~..o~..o~..o~..o~..o~..o~..o~..o~..o~..o~..n|..o~..o~..........o~..o~..o~..o~..o~..o~..x...o~..o~..o~..n|..px. o~..o~....Q...........A.o~..o~...."........o~..o~..o~..p|.@....o}..o~..o~....`...........................`.o~..o~..o}..........pp..o~..o~..o~..x.....a.........`...!.o~..o~..o~..pp
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):70565
                            Entropy (8bit):4.95361876797948
                            Encrypted:false
                            SSDEEP:
                            MD5:B598D2931693C4EC512019F098073132
                            SHA1:D29BB3032163FCFE4038689FC1C7EECD6DBE0025
                            SHA-256:1AD68A912C67AC983AD840A7B06B39C0A98FFACED93CE20C6E4B13C33177F2B2
                            SHA-512:3712803F61D104D774AB7E95F692BEA8F683DD988B339A1FA9C8A8693B02CF5EFC1643028A442E431597C33C0CE7E75063029119798D6B0608E9E033F6B5D84D
                            Malicious:false
                            Reputation:unknown
                            Preview:[.. {.. "ElementName": "(^(bcc|cc|find|link)\\b)|(^to:?$)",.. "IsEnabled": false,.. "Language": "English",.. "Notes": "Email reply".. },.. {.. "ElementName": "^(cco|cc|(encontrar|buscar)|enlace|para:?)\\b",.. "IsEnabled": false,.. "Language": "Spanish",.. "Notes": "Email reply".. },.. {.. "ElementName": "^((.......\\s?.....|..)|.....|(.....|.....)|......|....)\\b",.. "IsEnabled": false,.. "Language": "Russian",.. "Notes": "Email reply".. },.. {.. "ElementName": "(^(cci|cc|(trouver|rechercher)|lien)\\b)|(^.:?$)",.. "IsEnabled": false,.. "Language": "French",.. "Notes": "Email reply".. },.. {.. "ElementName": "(^(bcc|cc|(finden|suchen)|link|zu)\\b)|(^an:?$)",.. "IsEnabled": false,.. "Language": "German",.. "Notes": "Email reply".. },.. {.. "ElementName": "(^(ccn|cc|((cerca\\sin)|trova)|link|per)\\b)|(^a:?$)",.. "IsEnabled": false,.. "Language": "Italian",.. "Notes":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ISO Media, MP4 v2 [ISO 14496-14]
                            Category:dropped
                            Size (bytes):1633257
                            Entropy (8bit):6.485155644306981
                            Encrypted:false
                            SSDEEP:
                            MD5:A2BF8C212D8D8F6EFF57659293844623
                            SHA1:F7DA43E13E6BE11E546C9E0E38888EC5B8A2C9DC
                            SHA-256:463FA5B352C98E3E1DC15FCC34D249A5426A446D156E0853A91E933F979470B8
                            SHA-512:243E33C444A739E0B6B583116D848410BD953D0DB918A91E2CF69F6AA307AA2318CD7BD4ADED187E19651807B4E65E1BC79B23FBCDD5E0D655E6BD8E684F8F22
                            Malicious:false
                            Reputation:unknown
                            Preview:....ftypmp42....mp42mp41....moov...lmvhd......?..D.._.....................................................@...................................trak...\tkhd......?..?..........z.................................................@..............$edts....elst..........z............Fmdia... mdhd......?..?..]...e........@hdlr........vide.............Mainconcept Video Media Handler....minf....vmhd...............3hdlr........alis............Alias Data Handler....$dinf....dref............url .......kstbl....stsd............avc1.............................H...H.........AVC Coding............................1avcC.M@)....gM@).R.h.4.............0....h..5 ....stts........... .......@stss...................1...I...a...y...........................,sdtp..........................................................................................................................................................................................................................................................
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ISO Media, MP4 v2 [ISO 14496-14]
                            Category:dropped
                            Size (bytes):397395
                            Entropy (8bit):6.165571436281105
                            Encrypted:false
                            SSDEEP:
                            MD5:19ABCBAD2ED1A9889F59930920FC76CE
                            SHA1:3AC26E16A49F062A2D95239C5B70DA1AEB30E932
                            SHA-256:6CF485087A8BF59E3A508BD0AE0BCDE8AF057446DECAA1E139944343416F1905
                            SHA-512:43FC74CF894DB418B23E5EAE6E3CD853283D88E2C75AF257EA2AD33B59101E7F4706269AAC38109C0E1654E76BB269FEE8AC5D47002448D2DA9C843478976F39
                            Malicious:false
                            Reputation:unknown
                            Preview:....ftypmp42....mp42mp41....moov...lmvhd............_...z.................................................@...................................trak...\tkhd....................r.................................................@..............$edts....elst..........r............Amdia... mdhd............u0...........@hdlr........vide.............Mainconcept Video Media Handler....minf....vmhd...............3hdlr........alis............Alias Data Handler....$dinf....dref............url .......fstbl....stsd...........{avc1.............................H...H.........AVC Coding............................%avcC.M.)....'M.).`-..5.......(.<.....stts...........w.......(stsc....................................stsz...........w..]Y...............?.......=...............t...m...m...............k.......].......Y.......Y.......Y.......Y.......Y.......Y...*...e...........6...........\...?.......................................R...................{.......Y...................v.......'...y..............
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ISO Media, MP4 v2 [ISO 14496-14]
                            Category:dropped
                            Size (bytes):1098029
                            Entropy (8bit):6.903976586351405
                            Encrypted:false
                            SSDEEP:
                            MD5:5745431B40E778C37058E83C72DEC60C
                            SHA1:A260C4BC1D08101476926188506A8AAE5CEDD59F
                            SHA-256:9D06DCB64439F004C50159167FFAF07DEDAA9C84F91D503381BC74F4618E175E
                            SHA-512:0CB8D2DFB8C76946AC414A8A17B1A214B4C4625251487E4EF7FF5D1F6C9F46F7FCB37249BA6CBC3460468DD87C50197CB432F0B80FCEAB760B687EF59BFE9189
                            Malicious:false
                            Reputation:unknown
                            Preview:....ftypmp42....mp42mp41....moov...lmvhd............_.....................................................@..................................*trak...\tkhd......................................................................@..............$edts....elst........................mdia... mdhd............u0...........@hdlr........vide.............Mainconcept Video Media Handler...:minf....vmhd...............3hdlr........alis............Alias Data Handler....$dinf....dref............url ........stbl....stsd...........{avc1.............................H...H.........AVC Coding............................%avcC.M.)....'M.).`-..5.......(.<.....stts....................stsc.......................$stsz..............yh...[.......j...........)...l...........^...F.......z...4...!...............k...........................f.......d..E=......;.......R.......B............e...u...................r...5.......{...$...............................b.......a.......Z...........5.......................0......
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ISO Media, MP4 v2 [ISO 14496-14]
                            Category:dropped
                            Size (bytes):356882
                            Entropy (8bit):6.482888744487809
                            Encrypted:false
                            SSDEEP:
                            MD5:926F6DE4DD3348300FEE97DAAC344590
                            SHA1:8473BFB806BC149DC9DD9F36FF5A7B19759FC026
                            SHA-256:E0ECD495647C2AFD41241919B323E1949BE6EF293BD61D6D7F9D2C13FBF7B106
                            SHA-512:0B49BB977F5F76CCF0BD0C6815EA0C85DB37CA380342DF0DACC7345BFE034697ED7CEA833F65F01B9A0733C1B8C1F860947436ECA09698E922C33913C779DE42
                            Malicious:false
                            Reputation:unknown
                            Preview:....ftypmp42....mp42mp41...~moov...lmvhd............_.....................................................@...................................trak...\tkhd......................................................................@..............$edts....elst.......................6mdia... mdhd............u0...........@hdlr........vide.............Mainconcept Video Media Handler....minf....vmhd...............3hdlr........alis............Alias Data Handler....$dinf....dref............url .......[stbl....stsd...........{avc1.............................H...H.........AVC Coding............................%avcC.M.)....'M.).`-..5.......(.<.....stts...........d........stsc........................stsz...........d..rL...h...A... ...........J...........T...|...4...z... ...w.......r.......r.......r.......r.......r.......|.......................n...M...0...........V.......J...l...Y..."...L.......................................................................8.......3...............#...2...9......
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PNG image data, 1440 x 784, 8-bit/color RGB, non-interlaced
                            Category:dropped
                            Size (bytes):144950
                            Entropy (8bit):7.921858153344599
                            Encrypted:false
                            SSDEEP:
                            MD5:5D5DDBBB1ABDD3B4C4C64313750615AE
                            SHA1:77B9FEF45205AF1BDD653C479A054CF696C580CB
                            SHA-256:9CD323D8F72EF3118418AD59A1068C13750599A5C9A9043496C5B0B116710C8F
                            SHA-512:D1A05BCDF752F2D0B46BE4F6A58A60E302C1D58801DB727D71E7D40685F67AAE7AD24CE01FC9448CF10D015F84B9CBA5552A9DDB418ABB8EFF7858B2146FB6E1
                            Malicious:false
                            Reputation:unknown
                            Preview:.PNG........IHDR.............^.U.....pHYs..........e.... .IDATx....lTu..._..9.....% .E.x.u..u...kv].Q...#s5mg&3.....D..H.4..."... ...v.\..(G.9....o.NiA@..w.]Sk;...~s......Z..T....... ...@...... ..........H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ........ . ...@...... ...@....&..x........... ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PNG image data, 1440 x 784, 8-bit/color RGB, non-interlaced
                            Category:dropped
                            Size (bytes):186314
                            Entropy (8bit):7.9424090978338615
                            Encrypted:false
                            SSDEEP:
                            MD5:2F64EE43CE987C02019E015432C6CD3E
                            SHA1:4564094177409DBA61CA050F6C8B403A522D8D0B
                            SHA-256:8AE5FDF5A861F77DB020901AA864C49D4166573DAF9EF3E606FA565F6B5BF05D
                            SHA-512:CEE90D11131895752B813AFA809941110897E405B2049719BC40FDE93101469851AE22128A2B7CED4711349F0BD1E78B615636B25677DA160E27C354C5729BC3
                            Malicious:false
                            Reputation:unknown
                            Preview:.PNG........IHDR.............^.U.....pHYs..........e.... .IDATx....lTu..._..9.....% .E.x.u..u...kv].Q...#s5mg&3.....D..H.4..."... ...v.\..(G.9....o.NiA@..w.]Sk;...~s......Z..T....... ...@...... ..........H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ........ . ...@...... ...@....&..x........... ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PNG image data, 1440 x 784, 8-bit/color RGB, non-interlaced
                            Category:dropped
                            Size (bytes):186395
                            Entropy (8bit):7.957412100161246
                            Encrypted:false
                            SSDEEP:
                            MD5:54F6C84C69FAC1F6B1CA72D97BAB687E
                            SHA1:5B4F8F57A46F6AC9F0A612336F8C23C00E105AA2
                            SHA-256:F0D6F487643D7CDD899D94E8E5461FBEB1C4FEED2A227BD710BE61287F991F62
                            SHA-512:E24D8C56ACD4DAFBBA7CDA045E055246EBE6AB59F02B74FE5E83C018944D2ECAE5232D292B407A78EF2CA4A1FC2C8DAAD7CDC981C5D62CBBF44F990552AECAF0
                            Malicious:false
                            Reputation:unknown
                            Preview:.PNG........IHDR.............^.U.....pHYs..........e.... .IDATx....lTu..._..9.....% .E.x.u..u...kv].Q...#s5mg&3.....D..H.4..."... ...v.\..(G.9....o.NiA@..w.]Sk;...~s......Z..T....... ...@...... ..........H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ....(80. ...@...... ...@.......t..H.. .... ...@...... ........ . ...@...... ...@....&..x........... ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&.. ...@...... ...@................. ...@...... .....&..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ISO Media, MP4 v2 [ISO 14496-14]
                            Category:dropped
                            Size (bytes):1292732
                            Entropy (8bit):5.527046795510378
                            Encrypted:false
                            SSDEEP:
                            MD5:73CC238E282F5988B6A2CCD0E472C949
                            SHA1:4B1875610D31F7EC479B020156C6772F553D1EAA
                            SHA-256:8B7AB3D0DBB352C93AF977A777742E0601275F5E41C392317417A404FF14B3B9
                            SHA-512:494E49304C6F4B663B1B4D7024DB3CAE6B0CD6368F81E70A8A359F8295E6FE0FCA2DA246C28F6D8C9F7464F33F3A949FE243DAEF6A898FA7C43CF1B24B33E55A
                            Malicious:false
                            Reputation:unknown
                            Preview:....ftypmp42....mp42mp41.."0moov...lmvhd.....G7..G7..._.....................................................@...................................trak...\tkhd.....G7..G7.............................................................@..............$edts....elst........................mdia... mdhd.....G7..G7...]............@hdlr........vide.............Mainconcept Video Media Handler....minf....vmhd...............3hdlr........alis............Alias Data Handler....$dinf....dref............url .......!stbl....stsd............avc1.............................H...H.........AVC Coding............................2avcC.M.)....'M.)..`Z.......00.]...p^..@...(.. ....stts...........E.......,stss...............1...a...............!...Qsdtp.............................................................................................................................................................................................................................................................................
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ISO Media, MP4 v2 [ISO 14496-14]
                            Category:dropped
                            Size (bytes):665167
                            Entropy (8bit):5.932331317808176
                            Encrypted:false
                            SSDEEP:
                            MD5:BACE5381E78DADCFABA5302048AE7EB8
                            SHA1:036DAC8E77CC00116BEBAF6BE044A86216232FF1
                            SHA-256:8348A02C50FC4B65E4462058532FD3F326F9A6ADCC9E28180C45578BB8C40059
                            SHA-512:C605793458E85722CC191C088709FABEF49A61830E25558612F2E622D6E227729722250E535143144EEB194C15D851247F0FA6B244FEDC2024BCB8D341C958B2
                            Malicious:false
                            Reputation:unknown
                            Preview:....ftypmp42....mp42mp41...Fmoov...lmvhd......=..>.._...J.................................................@..................................6trak...\tkhd......=..=..........=`................................................@..............$edts....elst..........=`............mdia... mdhd......=..=..]...2........@hdlr........vide.............Mainconcept Video Media Handler...Fminf....vmhd...............3hdlr........alis............Alias Data Handler....$dinf....dref............url ........stbl....stsd............avc1.............................H...H.........AVC Coding............................1avcC.M@)....gM@).R.h.4.............0....h..5 ....stts...................(stss...................1...I...a...y....sdtp.......................................................................................................................................................(stsc...................................Tstsz..............7^.......-.../.../...p...)...)...)...+...)...)...)...+...)...)..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PNG image data, 120 x 120, 8-bit/color RGBA, non-interlaced
                            Category:dropped
                            Size (bytes):3366
                            Entropy (8bit):7.925569752224258
                            Encrypted:false
                            SSDEEP:
                            MD5:2688AFEDAA01E0030C88D15F1A624298
                            SHA1:4A058CBB2E9CCC2F0071853C5F0777C99D5FC129
                            SHA-256:4745777134E430C0186F7DCDF8639E4AF8EBE0DBEB1EA08ED0205DD52ABF60F4
                            SHA-512:B02133E5421841F12C0498F824DE2F9EF08F3A61C353BC94F5A62105E12B95E4DAC595999A309E9DDE40DE015DC85A86FE7F6B0C1D7FB5D7B522432DFB72F915
                            Malicious:false
                            Reputation:unknown
                            Preview:.PNG........IHDR...x...x.....9d6.....pHYs...%...%.IR$.....sRGB.........gAMA......a.....IDATx..MlU....kP@...H4!..$....J+...3R.@.8..*d.V...6..QY.E...aU.hM%.R*.f...%8.i.P.g.1...;q%..........;gf.}...x...=g..93S!.<|.p.?..V.)z..uPI3j.f....r..T*3d...$..0....[R.An.q.cQ.....}..[.Zi.yj..}.........:...YU.V.....o..S]Q..s..R.?.N._dq...*.uI..~.....i..K.2..An.Y.;U`...BqwP...u..`..G.{.J..;.......`Xn.....k......u.U*i..Q...E....3R.w..|.....v.....f......_..<...yj...b%m\.d...W...XG-.\.`.7...j......C..t}.n......W...m....|......mg}..(0\s/y...].:U.+Sc...b.'Y.g.g..@t...fo..#..!...!p..N.p.....%.{..M..s..Z6.wsl...c...y......v.w.Gz...W.~d.............]>...c..P.Dp.....w.ZF.F...D.....u#)q&..I.*9.}..b.O..R....8[4._..d..*.{....w..g.E.@0vn.K....(.;@.8q./K.j.8....vD..*.d...9.{..K^\pz.#.....3;..._ . .:..e~.....O....L....Mp...Y..^..gA...9..E..:...`+.spU.]\p......k`..I..k.C......Ew...6..u...Qr)n2..q.$b........l.v."Vh b.......T...}.'.q........GI0N.2..d..+>..Z+..sf...O.X...(....g..?.].
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
                            Category:dropped
                            Size (bytes):1376152
                            Entropy (8bit):7.98331327195235
                            Encrypted:false
                            SSDEEP:
                            MD5:A3932D3E28E64C25FE193D0001F16213
                            SHA1:0CB2FB7962CD0C489D5EECA53DD1C280DF330C57
                            SHA-256:CA091D0F277A2BD27941C22DCAE7DFFF66B0B46472B9D295A8019BE3D6020381
                            SHA-512:81C2981B3A0A6B15A4FD907494868A37D3BD6DDEA0EBB55414FC0ECC3BC9EA47C1280195D36F1DA9967293ED3A7E32FCCB266CAD835303E82D5BE57A57C8FC08
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1...Pf..Pf..Pf.*_9..Pf..Pg.LPf.*_;..Pf.sV..Pf..V`..Pf.Rich.Pf.........................PE..L.....Oa.................h...*......@6............@..........................`.......`....@.........................................................8...`(...........................................................................................text...vf.......h.................. ..`.rdata...............l..............@..@.data...x...........................@....ndata... ...............................rsrc...............................@..@................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:HTML document, ASCII text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):4527
                            Entropy (8bit):4.313536718256212
                            Encrypted:false
                            SSDEEP:
                            MD5:7C13D02F4198096524F84A396670636B
                            SHA1:ABDE167C468CF8254E5A687BD9CEAD74B357E643
                            SHA-256:B94BF281CC0696E23EE60737834B9AFF1C10CF96B891A8B7C6AA1D6EAC2CE38E
                            SHA-512:ACEEBAE8304AA079CE47915E58B965CB970ADC5E37102DE5FDED9E39BB1CF500CCADE5DB23669CBDCABADFAA055929EA3639E509FE30DCCEB0FA32A0DDBC8C21
                            Malicious:false
                            Reputation:unknown
                            Preview:<html>.. <head>.. <style>.. #root-body {.. margin: 0;.. }.. </style>.. <script type="text/javascript">.. // The list of anchor ids that will trigger a trackInAppClick.. const ITERABLE_TRACKINAPPCLICK_ELEMENT_IDS = ['ipm-cta', 'ipm-link'].. // The list of anchor ids that will trigger a trackInAppClose.. const ITERABLE_TRACKINAPPCLOSE_ELEMENT_IDS = ['ipm-close', 'ipm-dismiss'].... const DEFAULT_IFRAME_SIZE = {.. width: 400,.. height: 500.. } .... function handleIFrameOnLoad() {.. const iframe = document.createElement('iframe');.. iframe.setAttribute('id', 'iterable-iframe');.. iframe.setAttribute('sandbox', 'allow-same-origin allow-popups allow-top-navigation allow-scripts');.. iframe.style.visibility = 'hidden';.. iframe.srcdoc = ipm;..
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):394
                            Entropy (8bit):4.0862484789002265
                            Encrypted:false
                            SSDEEP:
                            MD5:5CA5B97899B9DD4E77EACAFD1D386729
                            SHA1:668D78F942E9E242A7EE7A9AEACB17A3860C3EF2
                            SHA-256:70365D8739273BAE885DE86D5BA672D4DB4B63F262C9A6F1FEFAED7CCF4E0114
                            SHA-512:3DA25E09E263106F4E2EBEB3E226DF5B29742AADC4E41304B05FB7A4C0E99750EC0D3CE98E5E21EAAB46579DE48C56A5F612A7D918E8CCD0EFB2B6C6BA32655D
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "strongAlertRef",. "id": "3",. "alertIds": [. "1",. "2",. "3",. "4",. "5",. "6",. "7",. "8",. "9". ],. "onEmpty": [],. "child": {. "type": "alertsCount",. "id": "2",. "meta": {},. "size": "small",. "textColor": "CoreNeutral90",. "format": [. "bold". ]. },. "name": {. "kind": "unknown",. "value": "content-ref". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):311
                            Entropy (8bit):4.272257275853467
                            Encrypted:false
                            SSDEEP:
                            MD5:3C39ECF89D8191AA3861574C5B8E01E7
                            SHA1:5574DD7B66409F13C5788E8AC548827CE25DCCD1
                            SHA-256:7BBBCB703F750E26C878FF0F005823F9BDA66F52E786FD4830AA5ABD8536B398
                            SHA-512:3CDB3B67052CB81D205E6D3B05A14076F02902BCDC86843A21E4636927D83F8B05CE70B15B12668AC075259D6DBE6672F479FA1D41874F92A304ACC3803D204A
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "strongAlertRef",. "id": "3",. "alertIds": [],. "onEmpty": [],. "child": {. "type": "alertsCount",. "id": "2",. "meta": {},. "size": "small",. "textColor": "CoreNeutral90",. "format": [. "bold". ]. },. "name": {. "kind": "unknown",. "value": "content-ref". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):135
                            Entropy (8bit):4.217924381958284
                            Encrypted:false
                            SSDEEP:
                            MD5:2E63D49EEBAA3FB6DC12126F5D4679E8
                            SHA1:035947CF3AB88C3C48234FA76A84DABE09541B82
                            SHA-256:DAA8D814A0CBE016741FD1C5FB4AAF2CF6A97499B91FF4BCC6B5CED586D4D6C0
                            SHA-512:115CA1D2C6E9BE1D0F1A512C80B8EB6AE576057960A6AA89F0F77980E9FC48D007B6AC2C925358CBED674D66977A14B18BC3DB86BBA01A5AD313B64A36765797
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "alertsCount",. "id": "2",. "meta": {},. "size": "small",. "textColor": "CoreNeutral90",. "format": [. "bold". ].}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):741
                            Entropy (8bit):4.1678496805662935
                            Encrypted:false
                            SSDEEP:
                            MD5:6C07E319A5FDF4E37910F5A8ADF13253
                            SHA1:9634326F7B879F77D469370115521FEE0D92BEA5
                            SHA-256:29FC2ED5231B6DFAC1681D842AA243C9137EEED27D7FEE33352726BDC03390D7
                            SHA-512:5B8516003C89ECD419512AB5EBFDFCEA6973D6EC14A11E58D8E6B09EA2A3AC981DBBF044379754715B5F7A97B553ED1BF9952674123FCD31F4D006B01C351A10
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "strongAlertRef",. "id": "4",. "alertIds": [],. "onEmpty": [],. "child": {. "type": "box",. "id": "3",. "child": {. "type": "alertsCount",. "id": "2",. "meta": {},. "size": "small",. "textColor": "CoreNeutral90",. "format": [. "bold". ]. },. "name": {. "kind": "unknown",. "value": "count-box". },. "padding": {. "top": "1",. "right": "1",. "bottom": "1",. "left": "1". },. "borderRadius": {. "topLeft": "Radius3",. "topRight": "Radius3",. "bottomRight": "Radius3",. "bottomLeft": "Radius3". },. "backgroundColor": "CoreBlue50". },. "name": {. "kind": "unknown",. "value": "content-ref". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1228
                            Entropy (8bit):4.243544929150826
                            Encrypted:false
                            SSDEEP:
                            MD5:DF852C661C303316FA709DCD2C6F555E
                            SHA1:A13E01C189273ED864EA657D068A3B25B98E833E
                            SHA-256:196B6966B9704E5C0CB6C9E763F9CDE6C588504BC8DAE6CF20CDA4D26F737038
                            SHA-512:20B404D43188858409298E0E724B996373BF3C750810A84E7D30CE586A8787C66273BBB50808C0C4FDDBF0786193A1CCADDA8CA7DA833D94B1EF5B17908A26EB
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "5",. "parts": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "image",. "id": "2",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "image",. "id": "4",. "meta": {},. "name": {. "kind": "unknown",. "
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):551
                            Entropy (8bit):3.5566104519715327
                            Encrypted:false
                            SSDEEP:
                            MD5:959A552F282B3139793BF5053F570E05
                            SHA1:EBA2B02784400DC82DC9B2DF4C5C888DC21EED56
                            SHA-256:B1BED8503AD566266CB592F9DB87A20D12274DF1BA13B30D582B1306B3EDAACA
                            SHA-512:95A44C9C1FD97FFF3BF21180BD1FAA08B9FB554F5FB9A3EC142E87B3F0ACCF32BE6D49F58CE72615DA0F5AB1849BC074987079D00AC5AA8F3A9BF389A7B312C5
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "4",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "info". }. },. {. "type": "icon",. "id": "2",. "meta": {},. "source": {. "kind": "known",. "name": "clarity". }. },. {. "type": "icon",. "id": "3",. "meta": {},. "source": {. "kind": "known",. "name": "feedback". }. }. ],. "name": {. "kind": "unknown",. "value": "block". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):311
                            Entropy (8bit):4.0011775153150975
                            Encrypted:false
                            SSDEEP:
                            MD5:F7EB6DF2505499F5318A7CC1146F82B1
                            SHA1:4CD56BDA982A8FE2F71559856C1A90511FA61B25
                            SHA-256:EDD8E72B4FD2EBFAE388A457007DEE28C0D0EFD0163842E2C5CA0048EED6F6ED
                            SHA-512:B3A0A1B649310178D328C498DD09ED9A553A1129414DEF775D5B3C6FA5153B480BE527084B39798A4DFFE371BB50D50004AC32B169AE406CC4519DD9C683425C
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Text",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "block". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):369
                            Entropy (8bit):4.161074662759907
                            Encrypted:false
                            SSDEEP:
                            MD5:EDC9FF40F9D06717A40E3B473841BAEF
                            SHA1:A470F2E7E8C3305484CCFD48F9A1BDF277F86C12
                            SHA-256:A992B2DE2F055300D016A73160F868C63B983B00C23ECFA30D268E8756CDA496
                            SHA-512:2DDE8B474525BE227F8C9E8A2BC0BD2C0BB9589683BC276345F36FACB99C5A38175857323E5CF971202405C8CECE498D66E244F24DCCFAE31E9B48B5C4AFE922
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a block",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "block". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):900
                            Entropy (8bit):4.232892462313103
                            Encrypted:false
                            SSDEEP:
                            MD5:58ED7DB9AA5A2A8D4AD2EFBCBA4776F1
                            SHA1:E69D843D1C922368D4C24B885824DB72D6D34190
                            SHA-256:7EED4AA4989E6C8014570E0ADDA3928EE6C3DF0174C82371FFB0590E9394BFBC
                            SHA-512:3DD9FA5D568BCECEF051953429DD494949A07B17D553360F2D5A962F7DBEA9F03150142AFCCBB206830C458F27A905C3A81480FECE392E40673B1B54F7C2D6CA
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "4",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "This is a very long text that before image",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "image",. "id": "2",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "text",. "id": "3",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a block after an image",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "block". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):2269
                            Entropy (8bit):3.5008510292897355
                            Encrypted:false
                            SSDEEP:
                            MD5:3E8A3A825AFBCB9625C8EC2585448DE3
                            SHA1:42766F0C57BAC946BCC077EF5B9FC0CF33B9A808
                            SHA-256:67CDFF71006C3DACFB7D716EB2C8EABED4C32A3520B155D7606C46E5398F52EE
                            SHA-512:FE0A126DA945E1E1E8597D55713A16CE94B07D606F919E83D2D083BD0D08EDF7A5879B2D96AF512FD20982862072F86E0CBF5A20B391FAA297E4AD9FBDFB1ADB
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "8",. "parts": [. {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "column-button". },. "kind": "secondary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "info". }. }. ],. "name": {. "kind": "unknown",. "value": "block-column-button". },. "spacing": {. "top": "0",. "right": "0.25",. "bottom": "0",. "left": "0.25". },. "verticalAlign": "middle". },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "shape": "square". },. {. "type": "button",. "id": "7",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):770
                            Entropy (8bit):4.03352959659558
                            Encrypted:false
                            SSDEEP:
                            MD5:257BC62704A3E3C1B572E5F4D0D918A6
                            SHA1:3CFF44890D0AE7A1EE21A35B3A4D969C2F72E5D8
                            SHA-256:5D46A8DED2B3670955CF533AB5DC7BFA7E2E44A668ACD72A70361D030428279A
                            SHA-512:C701BE9A3F023667610BD72A9EE8A7B6220078CE41A1445831AA08903AFEB0CFC584A8BB54448960938ECF01E04F76D561A7861C62FE19BF79C7EA5D8706B253
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "6",. "parts": [. {. "type": "count",. "id": "1",. "meta": {},. "value": "1000",. "backgroundColor": "CoreBlue20",. "textColor": "CoreNeutral0". },. {. "type": "count",. "id": "2",. "meta": {},. "value": "2000",. "backgroundColor": "CoreBlue40",. "textColor": "CoreNeutral0". },. {. "type": "count",. "id": "3",. "meta": {},. "value": "3000",. "backgroundColor": "CoreBlue60",. "textColor": "CoreNeutral0". },. {. "type": "alertsCount",. "id": "5",. "meta": {},. "size": "regular",. "textColor": "CoreNeutral90",. "format": []. }. ],. "name": {. "kind": "unknown",. "value": "block". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1171
                            Entropy (8bit):4.271207925997751
                            Encrypted:false
                            SSDEEP:
                            MD5:842694C1DAE98316D75442BC0E27CDF9
                            SHA1:5034651A157596B483138A0D2EC0EF09AA31266E
                            SHA-256:303006ECB18B9496EA6A680643403DA833E227CDED47DD7B556F39266E98FFB6
                            SHA-512:57ABEEB2CE409EBDFECFFA036C3E94D0C00101BAFDA738CC88936F7AAF58470AB25DFE7E094DD869190FC147B16537923D85BE85C0493B64DEBABE69FF23DF3E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "5",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 ",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "image",. "id": "2",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "Text1 Text1 Text1 Text1 ",. "tex
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):11235
                            Entropy (8bit):3.1920446037574957
                            Encrypted:false
                            SSDEEP:
                            MD5:41345CB51DB6E885448FD22D2F7A3E4C
                            SHA1:69627718F5C8FE53F6C69A68FA26D90FF55F1CCA
                            SHA-256:353C6721DF1660AE9604E66AF343AA1EBE65486C45CEF92087360F13AC3E520E
                            SHA-512:78DAB38114FD9AE488C8D7EDE506DAF7C6B689C392C030D3043E76D0BFA6D65A0CEA811CD5495A10A1CFFB317C153513AC58047AF97A1E881725F05BEE47D6A8
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "36",. "parts": [. {. "type": "alternativeChoice",. "id": "17",. "meta": {. "label": "Choose a different word". },. "alternatives": [. {. "label": {. "type": "button",. "id": "11",. "meta": {},. "name": {. "kind": "unknown",. "value": "select-0". },. "kind": "toggle",. "state": "deselected",. "label": {. "type": "block",. "id": "10",. "parts": [. {. "type": "text",. "id": "9",. "meta": {},. "size": "regular",. "text": "classic",. "textColor": "CoreBlue50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1172
                            Entropy (8bit):4.2690311034411295
                            Encrypted:false
                            SSDEEP:
                            MD5:4ABB40B30D3F15411011D801290F239F
                            SHA1:84ECA8090305DE4B44B0ED81C32D91C9F498B4F5
                            SHA-256:E178E4BB1575C505448F1AE7EFDE7888C5F29D3E4686466C475D105853F52187
                            SHA-512:0F9D3B6C393917E2554E7B37BE8CFE1C381ACB1CDF7961FD706339CDE5F03FF9A88423E9C09F16E9F9DCD2F8A285374635FCDB272740DA59BBE0D2D74FF7E3CD
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "5",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 ",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "image",. "id": "2",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "Text1 Text1 Text1 Text1 ",. "tex
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1170
                            Entropy (8bit):4.268394411811618
                            Encrypted:false
                            SSDEEP:
                            MD5:DF313BAECEA0AD8FA176273D3F9C1629
                            SHA1:F4734D9205954690B6A8B0D4916902C5AF55C787
                            SHA-256:E28FC763DEFAF64684FECB579B154E2FBBBDACF2FF5BEF70CC62DD536E1B58D6
                            SHA-512:32098E5DFE38E9B4C8DAF1E00B5F77CD63FC3ACCB920BB1E9A6EC0DA0B01F7933912442CE24CFF6ABDEE8254D723C28BA78A7CC0086DF3FFA6E0530BAA21833B
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "5",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 ",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "image",. "id": "2",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "Text1 Text1 Text1 Text1 ",. "tex
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):798
                            Entropy (8bit):3.6435185957205323
                            Encrypted:false
                            SSDEEP:
                            MD5:F23AAE33799A22476324202C51A5AA41
                            SHA1:A6E35BC4CCCA4DE60AAB3448064ED9D132B10521
                            SHA-256:00E1EC0B431AD26B34B282526989CBE60B87566B01CD44D5C422D1AF71C91492
                            SHA-512:CA3967AC6E0C917FEE485F4FD54AB0479FB8E3F57471FAAC90B4F32393D534D2D8E27FE1B305A7DBA7F36ADDF35CF2D703B6BB2EA7934224070102A815EC405E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "4",. "parts": [. {. "type": "row",. "id": "3",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Left",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "right": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Right",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "row". }. }. ],. "name": {. "kind": "unknown",. "value": "block". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1484
                            Entropy (8bit):3.5935227589881427
                            Encrypted:false
                            SSDEEP:
                            MD5:B3DCF91F13A64D5539759AA319F611F5
                            SHA1:5071216CE0CDACE6C4BB7CE4A1BC2A794F9AF800
                            SHA-256:B400A8A5D682FE4A9A4329E6FF6BA8A19C5B88CED7CBEB3805422ED6292963FE
                            SHA-512:494558E5AA19E532D93509C0FDA95063F980A786C3D9DD62A6C52A86B303CE88C93D65FF64914714796A2B77FDCAE0B4E293B60E7FFC4A87207A116C58428FE0
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "7",. "parts": [. {. "type": "row",. "id": "3",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Left",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "right": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Right",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "row". }. },. {. "type": "row",. "id": "6",. "left": [. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "Left",. "textColor": "CoreNeutral90",. "format": [],.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1301
                            Entropy (8bit):4.255309182873004
                            Encrypted:false
                            SSDEEP:
                            MD5:3C4A6390044588BDF4AA765912F2B868
                            SHA1:CA16A984E7163E43178A514552AEB6FCBE4D32D0
                            SHA-256:6F3FF1700092329713F07DF493D0C69E1BB5AC5688571BCE5327180354927E73
                            SHA-512:EF46BEDD67074F41CD38D51B36633220018C2F3025B85A9DA0E4A762FD519FEFF13F2D338B65077A29945BEAB4B8A075102EB9F10E94CB1AA483430BF5B77BCE
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "5",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 ",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "image",. "id": "2",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "Text1 Text1 Text1 Text1 ",. "tex
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1538
                            Entropy (8bit):3.756288018166747
                            Encrypted:false
                            SSDEEP:
                            MD5:C823B5E78DD6BCBCF78D6DE53D9CF8A0
                            SHA1:310D2805CC06ADF70DA481BBBD8CFE37F1B1CDFD
                            SHA-256:E0D03A06B381C5153868EA77062412B29319CFC71C600A32BABC22C3EFC19906
                            SHA-512:6D582D7A88772F3AFA813A18C96DD413F2E4F804D90D5D6D17C199B9F805E0E728E5E93298770FDCB7C892543BD756D7912D3B25E0BB4BF72A954E10970642C0
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "7",. "parts": [. {. "type": "column",. "id": "3",. "children": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "First",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "First - This is a very long text that should be wrapped inside a column",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "column-inside". }. },. {. "type": "column",. "id": "6",. "children": [. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "Second - This is a very long text that should b
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):631
                            Entropy (8bit):4.251597706150867
                            Encrypted:false
                            SSDEEP:
                            MD5:DCEF7BBE23EF6FC9D013435D57F71F3A
                            SHA1:B479B0B0A08C248318B8ED295F2E53CD5CD7E84B
                            SHA-256:58F6B5E89311C41AFA9F3361A909C2E10487EA9FA6408C16CCE3DD3BD28C00D3
                            SHA-512:F5A3127237F54BBEC40D1B4F9D0F9B157FCB4354EB0131CE2F7D614567E3A73D57E538CD9D3109705905DE70F5142009ED99BD5A7F978D51276DEDAD45E36777
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "3",. "parts": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Text1 Text1 Text1 Text1 ",. "textColor": "CoreBlue50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "block". },. "verticalAlign": "top".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1392
                            Entropy (8bit):3.6048120443504645
                            Encrypted:false
                            SSDEEP:
                            MD5:4904D971CE6EABA771ACA43EFCBE7DB2
                            SHA1:A4305D1EA7987025AD7C82339871946D3F5C2EBF
                            SHA-256:B5F8A0DBE57EC78E3AADDF283AEF054C0B2B61DD6CC14EA8262A103976061814
                            SHA-512:2B76F96EF26855D783C5DA1D6FA1B86B20BA3548348BFB198E5E67FC13ECA0704A3433507A5CB80E8373BBF8E8AF4BB369F6EBD896694BC9408CD7D56D33275E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "7",. "parts": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Block1 ",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Block1 ",. "textColor": "CoreBlue50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "block-in-1". }. },. {. "type": "block",. "id": "6",. "parts": [. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "Block2 ",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):634
                            Entropy (8bit):4.257242147493846
                            Encrypted:false
                            SSDEEP:
                            MD5:E2CFA2FA65035B81E9ECEBCBF6EA7CAA
                            SHA1:ADBE6DD11AC1556D4585F90C9FDF17BFF7749142
                            SHA-256:39BD68EEBEFF564A4299F62DC2A1FF53B8E67AA430C79D2D396DFC2E06537C4D
                            SHA-512:3AF60CBA1C207708322044FAABAE580334CDA99A97AEE5737FD12AE7710E195E2B1966751C2E39772DED4EE809D5B624EF3CC7F9BCDE24C726DDD6264DF7DBE8
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "3",. "parts": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Text1 Text1 Text1 Text1 ",. "textColor": "CoreBlue50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "block". },. "verticalAlign": "middle".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1504
                            Entropy (8bit):3.7404266087401314
                            Encrypted:false
                            SSDEEP:
                            MD5:F45C4DEE6C17103137E6817AEFF0BEFE
                            SHA1:3400F31582FB032C7E38DEA98BFEA00A60C1A2A9
                            SHA-256:0007CD0B7EBFFA98A4EC51B2784FA4DA1E483E18C22937017F463333DE490240
                            SHA-512:6A21DD47754C9E9D74F95FAFF61AEAC9E6C8F67C5FD4002E6E9C1C0B6091A9FFDE5EAA0958BFC81E2FCCF674AFDC18724B811E8303CEA7D531E774D1A45E1B07
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "7",. "parts": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Block1 Block1 Block1 Block1 Block1 Block1 Block1 Block1 ",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Block1 Block1 ",. "textColor": "CoreBlue50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "block-in-1". }. },. {. "type": "block",. "id": "6",. "parts": [. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "Block2 Block2 Block2 Block2 Block2 Block2 Block2 Block2 ",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):634
                            Entropy (8bit):4.257634034980697
                            Encrypted:false
                            SSDEEP:
                            MD5:EB23636664168C99BAEF96407A8FC093
                            SHA1:C54A555923CD3B384BA1CF9A47DF903B589B7D62
                            SHA-256:492ECB772A3A28C1CB65ECBB72454EA98FBB91B9B9B987B8D50A32A3F27D381D
                            SHA-512:38E4FB16CACC10C6E66FC4D3C2D1862AC2DF9E6E2692A51A14684B6F0CACCD16F70CEE8CBB6EE11D9ABC5795D3C120E538544D516E738E45F9157A7D25D153B3
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "3",. "parts": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Text1 Text1 Text1 Text1 ",. "textColor": "CoreBlue50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "block". },. "verticalAlign": "bottom".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):707
                            Entropy (8bit):4.079747282737652
                            Encrypted:false
                            SSDEEP:
                            MD5:D80F7D9DD0AFEBA2FCD3A53D5669FE3F
                            SHA1:26E7354D6215980298987BBD0435C61CAE90EA61
                            SHA-256:63EC85F464D04F50EA0EDDDB57DEB64F4BDC96D1A4FAD629405AEFD257AAE630
                            SHA-512:A0B06083EE01078D893025E41DD16A228783061977C6CC1CF02CFD348FA9B6228AE28171E30C95B5953E85C5097A947A41897ECF6CB870BB1523B87A86FB33B2
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 Text1 ",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Text2 Text2 Text2 Text2 Text2 Text2 Text2 Text2 Text2 Text2 Text2 Text2 Text2 Text2 Text2 Text2 Text2 Text2",. "textColor": "CoreBlue60",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "block". },. "maxLines": 3.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):2040
                            Entropy (8bit):4.303310111642998
                            Encrypted:false
                            SSDEEP:
                            MD5:54DA33AB425E19A39127684D7EC771B8
                            SHA1:4DC91CD5F6CFB8CDD98F23743D5AAD5B3C2BA889
                            SHA-256:F8222BA1D49DA1CE2EB23F624E5CA17486C5F8F31AA60E45A11BD24B9573669A
                            SHA-512:CF0C88E2DAA7B0AD6FA0A2ECA46BE59516329A64562D86FFF5524805879A519D81F5C88A56170854E790194AAC420C111BB1994D91D4DAC55A90D4DFD1FAEE0E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "6",. "parts": [. {. "type": "scroll",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "maxHeight": 5.0,. "name": {. "kind": "unknown",. "value": "scroll". }. },. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "prem
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4545
                            Entropy (8bit):3.3678696752678086
                            Encrypted:false
                            SSDEEP:
                            MD5:71946BDF31A6DC6724E38693435935BC
                            SHA1:7EC8E4CBE904C50F7F371A9C1D280E14892B8441
                            SHA-256:9D9F155F1AB79C26987E672AE993B02987884FB61A98B8DF4BF28CB5D347ECBA
                            SHA-512:85AA83BC684DFC98AF7B98635477F102677E9E1C5A00B65831A41D550665EF83A4F0DACF25D75BB007916963D7228522936E885414850745913740949011B4F7
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "5",. "parts": [. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "list",. "id": "4",. "meta": {},. "items": [. {. "id": "2",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Item.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "2",. "meta": {},. "label": {. "type": "t
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):882
                            Entropy (8bit):4.082415979246123
                            Encrypted:false
                            SSDEEP:
                            MD5:2D38A2C88237DDBF958CFB9991A3D553
                            SHA1:D2690A8B055F53231355FE4AECD5887F3552946B
                            SHA-256:F691C4E38BFA64D4F4D10AD5E61507BAEC3830F640FA54E6C2DDB538D069ADA9
                            SHA-512:D560A1007F3AEA9FCE4C28A81D6C509A86EE693AA39D6B89B97285DB6691C345CC21F7582CB87F6AEBD62FC587C841DF964ECD05D8C5C4F5361B8AAB6D4C45D0
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "3",. "parts": [. {. "type": "box",. "id": "2",. "child": {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. "name": {. "kind": "unknown",. "value": "count-box-1". },. "padding": {. "top": "0.25",. "right": "0.25",. "bottom": "0.25",. "left": "0.25". },. "borderRadius": {. "topLeft": "Radius2",. "topRight": "Radius2",. "bottomRight": "Radius2",. "bottomLeft": "Radius2". },. "backgroundColor": "CoreGreen10". }. ],. "name": {. "kind": "unknown",. "value": "block". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1706
                            Entropy (8bit):4.049904468563301
                            Encrypted:false
                            SSDEEP:
                            MD5:1191963A6E922A90970F13F2D92A3573
                            SHA1:98B1E004E15C6F86B00BF525B78F6F0DE20DC426
                            SHA-256:906BE68D91B3D606479BE9B9A3DF787F0D241371BE97166A45A4768BB5E3E311
                            SHA-512:E15D94ADD22EFDE6B5FCA0C93703F6F3EFEE0185FD768C8DFED26BAC62ED26FDAC5994C81162B5BB80BA9ADD0E147A2B860B0766D06803668E4C0FA4C03739ED
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "5",. "parts": [. {. "type": "box",. "id": "2",. "child": {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. "name": {. "kind": "unknown",. "value": "count-box-1". },. "padding": {. "top": "0.25",. "right": "0.25",. "bottom": "0.25",. "left": "0.25". },. "borderRadius": {. "topLeft": "Radius2",. "topRight": "Radius2",. "bottomRight": "Radius2",. "bottomLeft": "Radius2". },. "backgroundColor": "CoreGreen10". },. {. "type": "box",. "id": "4",. "child": {. "type": "text",. "id": "3",. "meta": {},. "size": "regular",. "text": "This is a box",
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):415
                            Entropy (8bit):4.275358231506667
                            Encrypted:false
                            SSDEEP:
                            MD5:4420C8348D1FB5914B0D762D9B3B1A8B
                            SHA1:FABF3EAC0839A2597D984E7CAF66A5E97D82BA32
                            SHA-256:9F2790B6921BC9038B4256C61BB0C963B46BFDB42F101BBB881D785AE293642C
                            SHA-512:812DEA3470779861AEF785166A2566ACDDEF6F94E500C78256BEE1F2842944CE67090C113A5F81666B63C8F251D79B819763E66182C1405B1A947CD63E8E8D56
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Box",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "0.25",. "right": "0.25",. "bottom": "0.25",. "left": "0.25". },. "backgroundColor": "CoreGreen10".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):507
                            Entropy (8bit):4.467224890123514
                            Encrypted:false
                            SSDEEP:
                            MD5:C10B00A7FD7C63BC58D7B2ECD9A92078
                            SHA1:68B7EBAC64B81385A954376195EC3823B730DD96
                            SHA-256:B173A0DE9EEC367A85F519943108EE5C523A32384A2A09C8AB4A517369E211CB
                            SHA-512:CB093C2DFDF6FD5A6666C77459B47E7F7C09329CE2DDA08F2ABC069A171E64F6591A719762636928A86DA5CE316D00053AFC6BA292CE330133A13C0C4B54FEB1
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Box-1-Box-1-Box-1-Box-1-Box-1-Box-1-Box-1-Box-1-Box-1-Box-1-Box-1-Box-1-Box-1-Box-1-Box-1-Box-1",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "0.25",. "right": "0.25",. "bottom": "0.25",. "left": "0.25". },. "backgroundColor": "CoreGreen10".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):266
                            Entropy (8bit):4.044352768326055
                            Encrypted:false
                            SSDEEP:
                            MD5:8EE0AA5226C3F53B5C52C703FF906828
                            SHA1:F72CAA223DCD60960DED5C6EF7D7477AFB2F6A77
                            SHA-256:B6A63E56B01FD8A90E04CCD4002FB6FC817B85699F78089398CEB12534D97B66
                            SHA-512:6C438D7A7DBEBB2FAF6938DB1E2E937ACD795B22F9493084D649F9B995133E0EF4AA3B0682425E135E3AC3A45EB9462DFF2391B22763635679B5351A04776A3E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "2",. "child": {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "feedback". }. },. "name": {. "kind": "unknown",. "value": "box". },. "backgroundColor": "CoreGreen10".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):389
                            Entropy (8bit):4.454882080436754
                            Encrypted:false
                            SSDEEP:
                            MD5:1CA9A82FCB02699EF9D72DA724674759
                            SHA1:11E3ABAF61C0F84F5AA52092232C3C9046B40810
                            SHA-256:1BA20258E3BFD0205DAD6FFDB9C754131D7E6E771491CA9DBE57CA377D168FBE
                            SHA-512:5FF5578FF6BA691FEFFADDD1C144B3121DD4697D531324A9F2290B5CA9FC240802D1C6206906B88FF24EDF8E7D11DA306238E1A30DCDC33E22BD0ECE1ADDC46E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "2",. "child": {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. "name": {. "kind": "unknown",. "value": "box". },. "backgroundColor": "CoreGreen10".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1052
                            Entropy (8bit):3.862689492915222
                            Encrypted:false
                            SSDEEP:
                            MD5:F3BD78A0B4212B4C2E56982DD64C3E62
                            SHA1:0FD0ADC2818E382A5A63AE6FF218AC46F7FD925D
                            SHA-256:E2389D96DEA121FD82A3088655759AAC45FFE8D327701D07838307E2596BE4A9
                            SHA-512:B4A80152C25F88F1A6767AE6E70DA7F3A10EB6DF12719ED88821A3A021819336D420525290D35D006092A5B42B9D7824346C09E85B55E85FB947E14749CA3AC8
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "4",. "child": {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "column-button". },. "kind": "secondary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "info". }. }. ],. "name": {. "kind": "unknown",. "value": "block-column-button". },. "spacing": {. "top": "0",. "right": "0.25",. "bottom": "0",. "left": "0.25". },. "verticalAlign": "middle". },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "shape": "square". },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "0.25",. "right": "0.25",. "bottom": "0.25",. "lef
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1375
                            Entropy (8bit):3.822852390589613
                            Encrypted:false
                            SSDEEP:
                            MD5:59C0C843CCB2293E08B79DCEA5B67FC8
                            SHA1:56C325528E6F41AB1EC174D62A5D3E4A79DD09BF
                            SHA-256:6CC9D272751D4B5333A6D95421272D3EC5AA8E04AA87881DDCBECA9A6DD4D05F
                            SHA-512:74B8D5E6174F74D2D1AEB59293AC96172F3A42AFCA97958646BEA9B9309DA2AF4CA05C84550A82619EBA2D4A725FBA7DB236F7088A0F5D64B5796C4EA8701874
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "5",. "child": {. "type": "button",. "id": "4",. "meta": {},. "name": {. "kind": "unknown",. "value": "column-button". },. "kind": "primary",. "state": "enabled",. "label": {. "type": "block",. "id": "3",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "close". }. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Tap Me",. "textColor": "CoreNeutral0",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "iconTextContainer". },. "spacing": {. "top": "0",. "right": "0.5",. "bottom": "0",. "left": "0.25". },. "innerSpacing": {. "vertical": "0",. "horizontal":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):387
                            Entropy (8bit):4.264844755771875
                            Encrypted:false
                            SSDEEP:
                            MD5:89BDFDF55BA9701B544FAB26A69D8AC2
                            SHA1:811CB7A7923D298A7C7AF8F13078DF5E2BF0F1C3
                            SHA-256:59C29DCDB6B4848585355AC1C1972467304BE65F1705A0620142583E62A6FEA6
                            SHA-512:826C1ED40E2ECAA8AD1615CBB79028D4AEBF489BA9E9E3907B785FA9E824AD647ED9456EDD7CCF449FCF187589DC81911D9C417FF279C94CFACDFAF293305AEC
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "2",. "child": {. "type": "count",. "id": "1",. "meta": {},. "value": "1000",. "backgroundColor": "CoreBlue20",. "textColor": "CoreNeutral0". },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "0.25",. "right": "0.25",. "bottom": "0.25",. "left": "0.25". },. "backgroundColor": "CoreCyan20".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):377
                            Entropy (8bit):4.284616045816932
                            Encrypted:false
                            SSDEEP:
                            MD5:757EF571DF795E354D893E85ED03F193
                            SHA1:A072BB0DA5A38C387D84B2C125D014BE0810A444
                            SHA-256:CA969BE55787925C8891FD6C1B8EB092144B2E9B5E0CA38CADE45C8F17844F98
                            SHA-512:E13FD8A9D66C42F8D0DD3B0F22E8B4830CBA00BCD0C38B14D30AC423AD434FF2F17EC7D94C2A06671896B10B36E0A118C07FF6E8FD0933F2CED987066F39B85B
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "3",. "child": {. "type": "alertsCount",. "id": "2",. "meta": {},. "size": "regular",. "textColor": "CoreNeutral90",. "format": []. },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "0.25",. "right": "0.25",. "bottom": "0.25",. "left": "0.25". },. "backgroundColor": "CoreCyan20".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):6105
                            Entropy (8bit):3.262260970286128
                            Encrypted:false
                            SSDEEP:
                            MD5:4DFB8C5B33080837CD88A969AD55ABD5
                            SHA1:8C558A69917AD492D905A7161E806EACCADEB6A7
                            SHA-256:EAFC3DB7F0F8A830B8E194BFF233CB0DB89B37B78E2B618D66305BE68C8F3A9D
                            SHA-512:9CCD400EDD9F1D5641E2AEFC23FA76DC51944124338F09F7D019F96739782620EE648673DF8289A1C9A2B46862E34DA9BBD2F107B3A8C6D7235BD2225DF0200E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "18",. "child": {. "type": "alternativeChoice",. "id": "17",. "meta": {. "label": "Choose a different word". },. "alternatives": [. {. "label": {. "type": "button",. "id": "11",. "meta": {},. "name": {. "kind": "unknown",. "value": "select-0". },. "kind": "toggle",. "state": "deselected",. "label": {. "type": "block",. "id": "10",. "parts": [. {. "type": "text",. "id": "9",. "meta": {},. "size": "regular",. "text": "classic",. "textColor": "CoreBlue50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "textContainer". },. "spacing": {. "top":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4675
                            Entropy (8bit):3.572274008723088
                            Encrypted:false
                            SSDEEP:
                            MD5:A223223150B51996C5BFBF64B81E8B24
                            SHA1:3A7379382AAF4890923836B78DC70687520D319B
                            SHA-256:D0E1B984EBD2DBEBB757B456216AD7B6FFB84CA2CD2BBC825EDB4F570BEA7DB2
                            SHA-512:CFA8B46A55C559CCC10E29BD34B53460CD87044B1FC06B27350477E4E8AA0269729DD74393EBABF8788407692FF3AA0C439E8AB6D42A049AC14563C1FEAC270C
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "19",. "child": {. "type": "alternativeSlider",. "id": "18",. "meta": {. "label": "How do you want to sound?". },. "segmentSize": 3.125,. "fillColor": "CorePurple50",. "choices": [. {. "id": "8",. "icon": {. "type": "icon",. "id": "7",. "source": {. "kind": "url",. "name": "neutral",. "url": "https://assets.grammarly.com/emoji/v1/1f610.2x.png",. "size": "1". }. },. "label": "Neutral",. "actions": [. {. "type": "selectAlternative",. "alternativeIndex": -1. },. {. "type": "notify",. "userAction": "selectSliderChoice". }. ],. "preview": {. "type": "block",. "id": "9",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "reg
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):858
                            Entropy (8bit):3.983052132686337
                            Encrypted:false
                            SSDEEP:
                            MD5:710A326BE7D3CD62E5F14409367F50F9
                            SHA1:FBA8B9442B8256A35C0A9007BDCF7E7700A32129
                            SHA-256:4BE7AA6D79EAE37FE303D464DA172B669B0C8677CDF775D8681F57A8F1022DD6
                            SHA-512:2ED32D56486803BD43247F131C9B5EB52492C75ADCBA5FFC5FDD3219B3A12BAD9E7D44B8700F7D94B62AD7C7A5FDAB47075DD84CF108545D25519F08F834D5B5
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "4",. "child": {. "type": "row",. "id": "3",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Left",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "right": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Right",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "row". }. },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "0.25",. "right": "0.25",. "bottom": "0.25",. "left": "0.25". },. "backgroundColor": "CoreYellow30".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):890
                            Entropy (8bit):4.0856865771214155
                            Encrypted:false
                            SSDEEP:
                            MD5:3A9C7B9EBAE4E8844AB8BCA7A039A464
                            SHA1:06A08550EB108CD5787AFC69B66DA0337C7F108E
                            SHA-256:57B9016F138617B7A21920C17A19E7B1AF9ABC7AEFEC54140F9DFCC1B91A373D
                            SHA-512:105B2FE9F8C958655C4F4DC691E8DA5656490DAE74C13A094AAA9E26439C5800BC693E62497F4A9FA5B8591DA47B80BD9DEAC9BF556F3BBCC94238884A22F3B0
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "4",. "child": {. "type": "column",. "id": "3",. "children": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "First",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "First - This is a very long text that should be wrapped inside a column",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "column-inside". }. },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "0.25",. "right": "0.25",. "bottom": "0.25",. "left": "0.25". },. "backgroundColor": "CoreYellow30".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):967
                            Entropy (8bit):4.124779315966745
                            Encrypted:false
                            SSDEEP:
                            MD5:AC243662ED9500B72D23821DEB2B1605
                            SHA1:3544E3D54C8DEE5D8BFA2ACAA029E612984280BD
                            SHA-256:4C6A94B742B6CBE07E3EC151E4C15F139D331F8F0CC5FC3608A9D61BDE6F95D3
                            SHA-512:A9A2F6F153607EE29E0C5CB240A2D0C9660CEB6B60EB8361AA5E5473B435C1821C6AEF58E98EE10DD49422221F42D772ED7F53E5DEC4F5BBB2872097DA645FE5
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "4",. "child": {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a block",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a block",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false,. "backgroundColor": "CoreBlue10". }. ],. "name": {. "kind": "unknown",. "value": "block". }. },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "0.25",. "right": "0.25",. "bottom": "0.25",. "left": "0.25". },. "backgroundColor": "CoreYellow30".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1024
                            Entropy (8bit):4.4273679214615065
                            Encrypted:false
                            SSDEEP:
                            MD5:616C03AACE9D12E202057869C858A989
                            SHA1:854FACAB42320AFF0407FB4DE5255AFAD7D456E0
                            SHA-256:5D5DA52E5BE33E513E79BDEEBBF44D99E641C5DAAE5818AFF420060465224C79
                            SHA-512:CAF1FE0279D59866A87E03E6D6BE65F43B5C09014E216D5F959B35823B37F88757012C6BA933753245A5AD23A6AC382867C4ADE306851C06EF92B2E2B52E6744
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "3",. "child": {. "type": "scroll",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "maxHeight": 5.0,. "name": {. "kind": "unknown",. "value": "scroll". }. },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "0.25",. "right": "0.25",. "bottom": "0.25",. "left": "0.25". },. "background
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4034
                            Entropy (8bit):3.530609309340547
                            Encrypted:false
                            SSDEEP:
                            MD5:CBF9B87B77437C88250BF05739F56DA5
                            SHA1:0DB9EFE5F6948443685ED3936EA97CCEA39486B3
                            SHA-256:B264F5FC19F3337028567A4AEFEB0AD817DEF12F143BA76EB99C3044A8D6F09D
                            SHA-512:3A356F0A549B13ABBC0D07C923568E7F972492313B5B26DA0E25522D31AA0022EF2BAA70A0D9BA79B2DA69D8D6AADEA39C77108AE3B4C300D0BF775F86B86079
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "4",. "child": {. "type": "list",. "id": "3",. "meta": {},. "items": [. {. "id": "2",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Item.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "2",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Item.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondar
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1313
                            Entropy (8bit):4.052821500225035
                            Encrypted:false
                            SSDEEP:
                            MD5:6C573424791C56100935D6B652311DC7
                            SHA1:0180E0D43A4A45548256D1B062C76CFBD5331283
                            SHA-256:3E5A44AEB5BF86086B86845A484795699396DCE5D43B09D0BD97A080BC23D46F
                            SHA-512:7EC7DF99C9A53C8F7A989DEDF089770B48CAAC1C1D96730963FE34976D012C1EE2FAC5A24B340716706341D1275A946759B687346D573DDED2DCCD5562225BF2
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "4",. "child": {. "type": "box",. "id": "3",. "child": {. "type": "box",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "1000",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "1",. "right": "1",. "bottom": "1",. "left": "1". },. "borderRadius": {. "topLeft": "Radius1",. "topRight": "Radius1",. "bottomRight": "Radius1",. "bottomLeft": "Radius1". },. "backgroundColor": "CoreBlue30". },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "0.5",. "right": "1",. "bottom": "0.5",. "left": "1". },. "borderRadius": {. "topLeft": "Radius2",. "topRight": "Radius
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):707
                            Entropy (8bit):4.200973567853497
                            Encrypted:false
                            SSDEEP:
                            MD5:3623AA5A8A46DA93174A4F3A9FDBAC2C
                            SHA1:5553C217216AB08207CED09790CBBEC95A41D110
                            SHA-256:BD28ED9F3E6F00E0DB872CBF5B4271A26B3ADF2F0591845EFAF77B6E9A3987C8
                            SHA-512:15950B19F8509C2956F5BB08138954A43E2064485D193C2624C7E9D202BDFC48EA718483F92E9257F2C080D3128295469E4D970557C5A1AABB8B4221C8D8B1D4
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "3",. "child": {. "type": "box",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "1000",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "name": {. "kind": "unknown",. "value": "box-inside". },. "borderRadius": {. "topLeft": "Radius1",. "topRight": "Radius1",. "bottomRight": "Radius1",. "bottomLeft": "Radius1". },. "backgroundColor": "CoreCyan40". },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "0.25",. "right": "0.75",. "bottom": "1",. "left": "1.25". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):563
                            Entropy (8bit):3.9656634904313353
                            Encrypted:false
                            SSDEEP:
                            MD5:88094BBA3B8CE9439B240B876B511925
                            SHA1:97395F4E408C93140C5C5D4E8E53EA80C9E4AA9D
                            SHA-256:4083C5A45F54E8D311281D76250B20E9185C110A0BBD33CC86AA0CD2C04EE1AD
                            SHA-512:C9550229E30F49CD2D9E078EED889D8B0A5EC3A3B10F8D3558DA2074F5D3FB1CAD8A055D18CF33D13DA1D0EA33CA3CBD69A4CBC4D3B8854D4EC5B2EF2EBFF135
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "3",. "left": [. {. "type": "box",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "A",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "name": {. "kind": "unknown",. "value": "box". },. "backgroundColor": "CoreBlue30",. "minWidth": 5.0. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "row". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):675
                            Entropy (8bit):4.238767612594718
                            Encrypted:false
                            SSDEEP:
                            MD5:CEB50CA222225FAF042374E486D1A3D1
                            SHA1:E82738891E8B0901B97070F527FEE5CEE3BE4DB8
                            SHA-256:07B97AF694C57805F6F2FDC27C508FB02C01676CDC1F5434132FECDF6A9888BF
                            SHA-512:7D41905D2D5AF79656BCAB71BBE0A92B69D04504BDF6C393E6327A22CA91D5E9F3189EB7200CF5D643909EEEFE7D43DF9743A2197D11644C6C8994396B5320EF
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "3",. "children": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "image",. "id": "2",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. }. ],. "name": {. "kind": "unknown",. "value": "column". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):409
                            Entropy (8bit):3.6167401071084675
                            Encrypted:false
                            SSDEEP:
                            MD5:884A23DB0951DEDF8F232A028813570D
                            SHA1:F9EFE5F6EA1696DB5B4A82F83EE61058493CDF58
                            SHA-256:EEFC71B855345A5CBD2054F8D8772D60D58171BCCE1957FA9FCFF42299CAC3E5
                            SHA-512:FB741047DA2B8DDC57241E2ADDD00617327FE8862BD6260C95CD7E4F3FDA810516A2E3DA1C28D99646C319A1D40F82181DA647D273798DD29321C64AF3A7AB5E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "3",. "children": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "info". }. },. {. "type": "icon",. "id": "2",. "meta": {},. "source": {. "kind": "known",. "name": "feedback". }. }. ],. "name": {. "kind": "unknown",. "value": "column". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):517
                            Entropy (8bit):3.9876195858500525
                            Encrypted:false
                            SSDEEP:
                            MD5:FBFB01EE3EE9D28D8A02E65CF094FDB5
                            SHA1:2C644CEC54328848A9B47FC3D7FAFBF58F5D3D0B
                            SHA-256:74E69524820D45AA5AE0DDBF9A0B618017A0FB84566A0C28FC015711AB68F787
                            SHA-512:02FBDCF97C5A5019D949E1ADF4D5318DBB608E293CCBB8E6AB77CE17031C9DACF2658396C695A996A0B2EBEDBF364C520A764DD41432088C3A743B0D943AFCAF
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "3",. "children": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Text1",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Text2",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "column". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):633
                            Entropy (8bit):4.156494914209711
                            Encrypted:false
                            SSDEEP:
                            MD5:F0AB08D96FE26CED650B6902BD708929
                            SHA1:B7BC80B9E68642551E3D0E5DCDF01703EB0633B9
                            SHA-256:ECF95BA8EC2255C90A3653E222DF67CF1A787DC2CD1479541C9C8231949609A6
                            SHA-512:DAD5D159D9DC88CE67D31918CD80475D1A97C4069DB7129EB2A32FCAEACC49E48F0D8C90E912202D6C57589964FE2401A7A296B3C6F4961398B6BB91C6EB365E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "3",. "children": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a column",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a column",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "column". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):654
                            Entropy (8bit):4.262608583551786
                            Encrypted:false
                            SSDEEP:
                            MD5:0F5E7E109197D8001ACB821509A035D5
                            SHA1:A1385C545CAE43C6EB7BEED7034313C21B8ECC2C
                            SHA-256:2AE313254067B20EE261063189D058EBD3004093BC4B754C527D76F37FFAEA2E
                            SHA-512:39B1E3B17650E49735B76FA1F6F87289794FA13B66BD567815AECF461928899CDF67A39B3BB22F080B2EDFD21C048894A411C308B9D80C9566C2C6B0A141A0B4
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "3",. "children": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a column",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "column". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3925
                            Entropy (8bit):3.3617224534844663
                            Encrypted:false
                            SSDEEP:
                            MD5:298185ED3D0779C46917F618BD204479
                            SHA1:A31BC4E668BFC2CC6E124887050E0727487F43C2
                            SHA-256:DA49089B54805BBF3D8763F302287DD9A882E6B974178613AAB04DBEE42B2579
                            SHA-512:59F3CBC677052538CAA0C1DC2C4439E6317FFC4DD5781CAF4C0B46A90B60C66ADEB38F7C48A01223C8BDC401DB924B4E8B9A55AA084A1F4465FD2179AFEE0CA7
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "13",. "children": [. {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "column-button". },. "kind": "secondary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "info". }. }. ],. "name": {. "kind": "unknown",. "value": "block-column-button". },. "spacing": {. "top": "0",. "right": "0.25",. "bottom": "0",. "left": "0.25". },. "verticalAlign": "middle". },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "shape": "square". },. {. "type": "button",. "id": "7"
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):2045
                            Entropy (8bit):4.299905282676248
                            Encrypted:false
                            SSDEEP:
                            MD5:72DC99703AADBEFF87FFD392531FA43D
                            SHA1:088BFF4435D5CEA37A7F4BC968D2025528F436BF
                            SHA-256:26844C90D64BBEB5263822D79834EA36CB4511999192526166A6541C67F2A7F3
                            SHA-512:237090D1ECBA851BD2F5C3FFE5362EFE856D0138D12440DE2A2AFB55EF80F3B229103E9F844556A1A91C86ED79061D5B0C563F2C5180A509B249D4E9B9BFA3BA
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "6",. "children": [. {. "type": "scroll",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "maxHeight": 5.0,. "name": {. "kind": "unknown",. "value": "scroll". }. },. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4550
                            Entropy (8bit):3.3704726452125007
                            Encrypted:false
                            SSDEEP:
                            MD5:221835478115223E08536CE3CC397844
                            SHA1:0FBA847E9BBEA0220C971ED95C6EEB1B014E280B
                            SHA-256:4D66E0B1072C0634F22E027574CF7AC25CA75FC956B26D25AE89D7BCA4F6838B
                            SHA-512:E7AAF26DA234C9F81CCD751C6BF73E780323AC74D8E0FB8298C3290C4B3AEB42E23ECF4C553ED95DCBD95C0D503467CE15895DC6248E6E7A39301F52BC8E3389
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "5",. "children": [. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. {. "type": "list",. "id": "4",. "meta": {},. "items": [. {. "id": "2",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Item.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "2",. "meta": {},. "label": {. "type"
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):775
                            Entropy (8bit):4.039566649064872
                            Encrypted:false
                            SSDEEP:
                            MD5:DE16C3476BB5D4BADD0A69EBBE51F5E4
                            SHA1:BBE48EA0F99A96DC1A06F829D5A5EA6FE0DB62DA
                            SHA-256:985807E30FAD40C208E98B72F3D10F47EE6933140EBDC6A14C4F080F27753506
                            SHA-512:8FF4C1324C98937B0262FB3B5428F4D381C4B3CB3668D3355D01CCF7DABB88D92F5390923B4C9916E3AC93DAD125E6FBEF9D51A405F0E7855A9215169EF7DFCD
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "6",. "children": [. {. "type": "count",. "id": "1",. "meta": {},. "value": "1000",. "backgroundColor": "CoreBlue20",. "textColor": "CoreNeutral0". },. {. "type": "count",. "id": "2",. "meta": {},. "value": "2000",. "backgroundColor": "CoreBlue40",. "textColor": "CoreNeutral0". },. {. "type": "count",. "id": "3",. "meta": {},. "value": "3000",. "backgroundColor": "CoreBlue60",. "textColor": "CoreNeutral0". },. {. "type": "alertsCount",. "id": "5",. "meta": {},. "size": "regular",. "textColor": "CoreNeutral40",. "format": []. }. ],. "name": {. "kind": "unknown",. "value": "column". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1175
                            Entropy (8bit):3.9456873246788335
                            Encrypted:false
                            SSDEEP:
                            MD5:416B839779BAD9142FBF6F2664FD8B4E
                            SHA1:0128DC0BD0542A86B76BB791DB76D5A5A421188C
                            SHA-256:728485CD8CDC37F044EC4E3C188BCE9928E5A92052663668929029D8FC4B4B63
                            SHA-512:4D54F337BE8E653896FF35573A1EDAE6EE32459893665844FEF282C07688F0C375D300D922E54B01EEDFEE2D86B77AE1EDAA2030B007AA4EF9D4B32E9D0291C3
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "5",. "children": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a column",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "block",. "id": "4",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a column",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "3",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a column",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false,. "backgroundColor": "CoreBlue10".
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4906
                            Entropy (8bit):3.3609362437492534
                            Encrypted:false
                            SSDEEP:
                            MD5:0F739C0D904D125881A18CD48A090E3F
                            SHA1:2C9142F2DDC39FB89FE6DD7D0B3140FF3C6DD58D
                            SHA-256:6E8C626760EDBCA0C4684B088629F97CA250A4942EFFB647F2A61C15C887B92B
                            SHA-512:E9CB8DEA536B114661FC2503DC09B8A722A7B9F1FFFC2E83EA63B48834A2D730BF4D82FDB9766C23F89D159154A8D9A0340E680A0966DAE1A722A5B64BE97AE7
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "19",. "children": [. {. "type": "alternativeSlider",. "id": "18",. "meta": {. "label": "How do you want to sound?". },. "segmentSize": 3.125,. "fillColor": "CorePurple50",. "choices": [. {. "id": "8",. "icon": {. "type": "icon",. "id": "7",. "source": {. "kind": "url",. "name": "neutral",. "url": "https://assets.grammarly.com/emoji/v1/1f610.2x.png",. "size": "1". }. },. "label": "Neutral",. "actions": [. {. "type": "selectAlternative",. "alternativeIndex": -1. },. {. "type": "notify",. "userAction": "selectSliderChoice". }. ],. "preview": {. "type": "block",. "id": "9",. "parts": [. {. "type":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):11240
                            Entropy (8bit):3.1933116519989126
                            Encrypted:false
                            SSDEEP:
                            MD5:746592CFB9E40E5551A5C477077BE7BF
                            SHA1:1442430935A54E8B7E860C927D1979F5BDF26EB2
                            SHA-256:628DD17980548636388F551D0F47F60F28A7A4A5348C9B4003C255DAD8B14F67
                            SHA-512:BAB5CBABE1F2FB1654FFAF15874F5C5D08B4693CB9621EFCA4CB198DF26E4A4E74D58FF61738DDB2D03FD0A0A4A46D66C8E94075E11926C4730C170F484E9C4C
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "36",. "children": [. {. "type": "alternativeChoice",. "id": "17",. "meta": {. "label": "Choose a different word". },. "alternatives": [. {. "label": {. "type": "button",. "id": "11",. "meta": {},. "name": {. "kind": "unknown",. "value": "select-0". },. "kind": "toggle",. "state": "deselected",. "label": {. "type": "block",. "id": "10",. "parts": [. {. "type": "text",. "id": "9",. "meta": {},. "size": "regular",. "text": "classic",. "textColor": "CoreBlue50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "val
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):2302
                            Entropy (8bit):3.676019331010546
                            Encrypted:false
                            SSDEEP:
                            MD5:ED477A1CED373859203862F38F542957
                            SHA1:DE2B0B4E9432280C9C2C39B0AEE4AF0F1CBBF428
                            SHA-256:74C5CB10BBF98C4292EF6B17A39CF33397F27F3E0105D899654E68B2C10F48E5
                            SHA-512:2543ECE20756D47A7F635C3321B89F45FD00DD810070D91DDA293F2CB877AE5CEA38B6966E78335D80926666307F35A5C2B01C9610320D4A1BB30667D3E7B746
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "10",. "children": [. {. "type": "row",. "id": "3",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Left",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "right": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Right",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "row". }. },. {. "type": "row",. "id": "6",. "left": [. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a row",. "t
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1543
                            Entropy (8bit):3.758860670367
                            Encrypted:false
                            SSDEEP:
                            MD5:7656356273ACB4FCDC400B7A54B1793B
                            SHA1:CD5209F2AD8EA5E919416C843EC1C8996FDF4690
                            SHA-256:9B2F7D7127379A678DFE6C224A52EF32225D8CD352C99A9FC8618069819D2E61
                            SHA-512:EE816259B0F8B87D5A643148A078AA98BE0C3BE79837A9768228151DFBAE55EE29E38AC80E8C08F024C5D0CF2863F0387B605305735EAF8C5E9B1EF878982AA1
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "7",. "children": [. {. "type": "column",. "id": "3",. "children": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "First",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "First - This is a very long text that should be wrapped inside a column",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "column-inside". }. },. {. "type": "column",. "id": "6",. "children": [. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "Second - This is a very long text that shou
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1482
                            Entropy (8bit):3.9289008715552085
                            Encrypted:false
                            SSDEEP:
                            MD5:4562BF25E84E765F9B6B56D53994A642
                            SHA1:AD0B3CCA2A48E28671D0EFBD2EA20555AE7A6A57
                            SHA-256:6F43C0755EFD758B0297613F0095F397F9C7D88E3FA8B650A4795152B972A79E
                            SHA-512:B936DE4A39BDB4F5C7C4CDE858343C80AB7B7E847FA42947BDA3F87166758077CEC0E0ED66929D8351B5BE02A80211BED83DF065E8BC77C03995A79FE094B272
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "5",. "children": [. {. "type": "box",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "1000",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "0.5",. "right": "1",. "bottom": "0.5",. "left": "1". },. "borderRadius": {. "topLeft": "Radius2",. "topRight": "Radius2",. "bottomRight": "Radius2",. "bottomLeft": "Radius2". },. "backgroundColor": "CoreYellow80",. "minWidth": 5.0. },. {. "type": "box",. "id": "4",. "child": {. "type": "text",. "id": "3",. "meta": {},. "size": "regular",. "text": "1000",. "textColor": "CoreNeutral90",. "format": [],. "selectable"
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3404
                            Entropy (8bit):3.6452297379844265
                            Encrypted:false
                            SSDEEP:
                            MD5:7F2FAAC9C48883FA1DA6B815696148B1
                            SHA1:B31AFC401C3A30472495BFDB3EFFFDDFAADFD153
                            SHA-256:C7FB9EBAE1ADFCF2AF2956A8E3D989582FC9113521A14E7DDB9EC44C238A862E
                            SHA-512:0EB9762534AE5105A33C7C62511BE7344DC5C396A68E53212E03EF87BBBC01C6E58D0F9B959C8B093236BC9068EFED2D088294B45AA249246F6EA4D978EA2433
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "3",. "meta": {},. "items": [. {. "id": "2",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Item",. "textColor": "CoreCyan60",. "format": [],. "selectable": false. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "2",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Item",. "textColor": "CoreCyan60",. "format": [],. "selectable": false. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "2",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):6956
                            Entropy (8bit):4.1920650305909435
                            Encrypted:false
                            SSDEEP:
                            MD5:08FE0DFFB628BD66C8BDD651A6B3A2C4
                            SHA1:977C037A166B3A7EA01AE0CEB07DA286BDFC5D0F
                            SHA-256:0BF3FCA4A4FD20B96A471C35D9C063915A8F184793000CC04BBDA277CC19F074
                            SHA-512:85F32F5456980A18393518BC1D377289BCEF6E84C044B277DBAF1BE00E9DA9057F5BE42FFC9CE58531BD5994F8A614332450C3373AB4B5A5126A9CD1EBFF9CB9
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "3",. "meta": {},. "items": [. {. "id": "2",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "2",. "meta": {},. "label": {. "type": "text",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3004
                            Entropy (8bit):3.431381847460494
                            Encrypted:false
                            SSDEEP:
                            MD5:7251037EB789B0AB3DA25D429106DF42
                            SHA1:7363D025A109DE7AA86EF30D4B765CCD4C2411C4
                            SHA-256:94412691B5FDFE91801DDBDD8A1D07BE1638815F65DEAE3322E7730E5E10F02A
                            SHA-512:9443729FD10860DE1DE755050A4FA0BE85FEB578792D153E6F8F8765CB4DE757D1F0A5EDA74FE071E835036F707B5F0C9584F65F970D169D21ABFE18670F50EA
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "3",. "meta": {},. "items": [. {. "id": "2",. "meta": {},. "label": {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "feedback". }. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "2",. "meta": {},. "label": {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "feedback". }. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "2",. "meta": {},. "label": {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "feedback". }. },.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4084
                            Entropy (8bit):3.9096288649183015
                            Encrypted:false
                            SSDEEP:
                            MD5:3F0D40EE7E24D22A941CA3B6102A9654
                            SHA1:8C388591F99773F0CB1C15A4D945E988FE2EFB07
                            SHA-256:BB3D41751254FD3275CACE5285FE716B88B94789935C4BA18186FE0E3013B69E
                            SHA-512:E517CD4EE3506B01BC3B2618355DC091B213122004A6E8D242DE84F203B9521EE540F4C15E9F6160D30C2566070414F23E92B5B1C6F9C2E3DFCD7DA39D543E4D
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "3",. "meta": {},. "items": [. {. "id": "2",. "meta": {},. "label": {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "2",. "meta": {},. "label": {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. "actions": [. {. "type": "notify",. "userAction": "click".
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):9604
                            Entropy (8bit):3.309270716923978
                            Encrypted:false
                            SSDEEP:
                            MD5:741CA8FE8B2FE28E0923285ACD6A19E7
                            SHA1:87093DC07E1F2152B182C07ADE9BF52B5134BEF5
                            SHA-256:39A1AA27F08EE1DBB8781A7D21F7FE7F8FE1B2A15DB32BDB4EEE8A1445746FDD
                            SHA-512:234433C40767CF4E660F49FCAF077E3AE819C30E97F528EA113A1241DB39F27DFD410A3CA917F0D717A084D20496B7DE3AFC18367B6CFB310E0F8D92CD0234A5
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "5",. "meta": {},. "items": [. {. "id": "4",. "meta": {},. "label": {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "column-button". },. "kind": "secondary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "info". }. }. ],. "name": {. "kind": "unknown",. "value": "block-column-button". },. "spacing": {. "top": "0",. "right": "0.25",. "bottom": "0",. "left": "0.25". },. "verticalAlign": "middle". },. "actions": [. {. "type": "
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):12636
                            Entropy (8bit):3.3122340665482612
                            Encrypted:false
                            SSDEEP:
                            MD5:9AD791691313181C4894F3D22277FFD7
                            SHA1:B6FD0A2CA0D4144B3E68C1FCAE45A1A86C747163
                            SHA-256:98D7B29226D3C4EDE66FC40BDF38FA2D58AEC1FF34F8472231A155671DDE84C1
                            SHA-512:13652AD65819D360AAE8B0195CE8CC555F6D8F3464EAC86C5113DAEAF89CFCE4F49E5CEE125578B10FFC5C2A66B4E710B843BE512D5DB8FE695BA70FADBB1039
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "6",. "meta": {},. "items": [. {. "id": "5",. "meta": {},. "label": {. "type": "button",. "id": "4",. "meta": {},. "name": {. "kind": "unknown",. "value": "column-button". },. "kind": "primary",. "state": "enabled",. "label": {. "type": "block",. "id": "3",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "close". }. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Tap Me",. "textColor": "CoreNeutral0",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3140
                            Entropy (8bit):3.7348708798960963
                            Encrypted:false
                            SSDEEP:
                            MD5:DFA2229F471597F5AF6A4539CF260073
                            SHA1:1CEB87D497F9D47A7F40057CCC713873416BFDC2
                            SHA-256:0731EC5CE141BFDF38F97E30295E589D0E36152E1D316E96AC396B73E9DA5822
                            SHA-512:83AC82094BCA8B9D7677CA89C9096D0539048C1DFE35C597F7298549833D266533C5DBF8D2226B75F676128E203402BAC3C7B87850D7D3A24782A5F77B3C3672
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "3",. "meta": {},. "items": [. {. "id": "2",. "meta": {},. "label": {. "type": "count",. "id": "1",. "meta": {},. "value": "1000",. "backgroundColor": "CoreBlue20",. "textColor": "CoreNeutral0". },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "2",. "meta": {},. "label": {. "type": "count",. "id": "1",. "meta": {},. "value": "1000",. "backgroundColor": "CoreBlue20",. "textColor": "CoreNeutral0". },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "2",. "meta": {},. "label": {. "type": "count",. "id": "1",. "meta": {},. "value": "1000",. "backgroundColor": "CoreBlue20"
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3060
                            Entropy (8bit):3.675271106304638
                            Encrypted:false
                            SSDEEP:
                            MD5:18EAEF808F17B4C84EFCD0260DB43AA6
                            SHA1:941620A01FA463341B3E5528EAC0FD3BAA314F22
                            SHA-256:48A0F931DF62FE2E110EA1B6BF4F5CA05AB3AE81070ABAE0C014358327165E39
                            SHA-512:3A6B222ECA087D54D8451B5F7437A7ACBAF2F957D776E79A25342092CB06C66E069365203621567A0F867232A336A3008057D040B73D21C62C2895FBBCD055F8
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "4",. "meta": {},. "items": [. {. "id": "3",. "meta": {},. "label": {. "type": "alertsCount",. "id": "2",. "meta": {},. "size": "regular",. "textColor": "CoreNeutral90",. "format": []. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "3",. "meta": {},. "label": {. "type": "alertsCount",. "id": "2",. "meta": {},. "size": "regular",. "textColor": "CoreNeutral90",. "format": []. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "3",. "meta": {},. "label": {. "type": "alertsCount",. "id": "2",. "meta": {},. "size": "regular",. "textColor": "CoreNeutral90",. "form
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):55957
                            Entropy (8bit):2.9119851266047356
                            Encrypted:false
                            SSDEEP:
                            MD5:21CBC1795D2B36D1B05AA45A67809F1F
                            SHA1:7559ECC5CCD952C531B5E2400F1CB49AB7F3C5EF
                            SHA-256:796472094F3EE498166126FA15E9CB14459D85BF8C2E122D6DCE9C4D4115A2D0
                            SHA-512:7A114F5B2682F7E2F58441EB49EA075D5D8B14644E7A898107CCF13ADB6BB31A584044A560C849FFAF5470725DE66246D4A53A1D9FB8E3DD078E5CD134012E78
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "19",. "meta": {},. "items": [. {. "id": "18",. "meta": {},. "label": {. "type": "alternativeChoice",. "id": "17",. "meta": {. "label": "Choose a different word". },. "alternatives": [. {. "label": {. "type": "button",. "id": "11",. "meta": {},. "name": {. "kind": "unknown",. "value": "select-0". },. "kind": "toggle",. "state": "deselected",. "label": {. "type": "block",. "id": "10",. "parts": [. {. "type": "text",. "id": "9",. "meta": {},. "size": "regular",. "text": "classic",. "textColor": "CoreBlue50",. "format": [],. "selectable"
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):42789
                            Entropy (8bit):3.192714020265613
                            Encrypted:false
                            SSDEEP:
                            MD5:5F3A6618D41021004273270F9A33A7AA
                            SHA1:485F32DA8E13DC0608A3C35783446D5A8A0ABDA3
                            SHA-256:912F06A5869FC4A06CC8362F4D479F5E001191DC9766E83AB872773DAD8ECB2E
                            SHA-512:D319F98E09C5730367034A0B69C13CAC7F82B4D4C88035DFE3084FA20A668D8A380F0D45746FCF3CDC643F80DEE5D68FB7EE03A6F0F5675927FA14EEAEF965FE
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "20",. "meta": {},. "items": [. {. "id": "19",. "meta": {},. "label": {. "type": "alternativeSlider",. "id": "18",. "meta": {. "label": "How do you want to sound?". },. "segmentSize": 3.125,. "fillColor": "CorePurple50",. "choices": [. {. "id": "8",. "icon": {. "type": "icon",. "id": "7",. "source": {. "kind": "url",. "name": "neutral",. "url": "https://assets.grammarly.com/emoji/v1/1f610.2x.png",. "size": "1". }. },. "label": "Neutral",. "actions": [. {. "type": "selectAlternative",. "alternativeIndex": -1. },. {. "type": "notify",. "userAction": "selectSliderChoice". }. ],. "
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):7692
                            Entropy (8bit):3.4051531414888716
                            Encrypted:false
                            SSDEEP:
                            MD5:80282E75744C72DFA666228618F33305
                            SHA1:1DA8CC923F947A5AC47D3A6C4C6F49C79E29CFF3
                            SHA-256:51C92687CBECFB3ED62665D989FADE0F920DEF0FD1606558016043927E469A25
                            SHA-512:3019EB88FF26A473C18F627894D01C9FAC35264568851D72C14967FD2B5AE8D30AD9E57ED1E9675070CA75D929BC370E0813001E32F971B956B44BFD56174AB0
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "5",. "meta": {},. "items": [. {. "id": "4",. "meta": {},. "label": {. "type": "row",. "id": "3",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Left",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "right": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Right",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "row". }. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": [].
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):7852
                            Entropy (8bit):3.5501659169091635
                            Encrypted:false
                            SSDEEP:
                            MD5:364AE955DF123BF29EFBA989A36F132A
                            SHA1:0C00117913AD6DA27DF9C2191009B2F85987CA8F
                            SHA-256:CEA04F48C2B2E37568A7E22EBD41923235CCEEFB5EE3E1A5AC1AE392D28AEEA0
                            SHA-512:39541C36C0C218EBC75AA04A277E39A45535C615C68737A26BA17A811A90896B1FE31E9A4FA24CEC5031557BEEE5DDB71020BD3ED426A638CE447C4B668DFC9B
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "5",. "meta": {},. "items": [. {. "id": "4",. "meta": {},. "label": {. "type": "column",. "id": "3",. "children": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "First",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "First - This is a very long text that should be wrapped inside a column",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "column-inside". }. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "sec
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):8500
                            Entropy (8bit):3.6277183283781946
                            Encrypted:false
                            SSDEEP:
                            MD5:76C39BFB44CB443187CB74B51F2711F4
                            SHA1:BA6E71FA00EA9AF4B5A184D4BE0F4C1DAE0AEA3F
                            SHA-256:D34A9C1B58FC422E928907EB77B19E88905EF2E4112E8822FF96251E93C54F10
                            SHA-512:E7AC8CD3267872E87C59CF489080B6A097483FDED3D93148A1197F68F171B37D32F2C264B0F2B8ACB8EC32B81F4F6CC14985B4BCF94911C42E62BCA42A798514
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "5",. "meta": {},. "items": [. {. "id": "4",. "meta": {},. "label": {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a block",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a block",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false,. "backgroundColor": "CoreBlue10". }. ],. "name": {. "kind": "unknown",. "value": "block". }. },. "actions": [. {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):8572
                            Entropy (8bit):4.090150630736311
                            Encrypted:false
                            SSDEEP:
                            MD5:E9DC5AAC9F09F0BB122DE655D42ADF92
                            SHA1:52BF68DD43B68CCCBC77A85E1F235652F605B137
                            SHA-256:13BC688A5D14563B6D3056A0FF0910EAEB5369472DB128882FEFE57122926FCB
                            SHA-512:9BEF57BE340A6D98C1E226E5E113BB67FB206AA0842B63E25E08DE738C1AD1B7AAB5058847DC34CA7230A81249E9329F2CDEAD883811381DEC75B28ABE506EF9
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "4",. "meta": {},. "items": [. {. "id": "3",. "meta": {},. "label": {. "type": "scroll",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "maxHeight": 5.0,. "name": {. "kind": "unknown",. "value": "scroll". }. },. "actions": [. {
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):11940
                            Entropy (8bit):3.572895983014405
                            Encrypted:false
                            SSDEEP:
                            MD5:43379C901E5091A8D206F718DAC5DCC8
                            SHA1:B71024BC939267993645212894CE139D63AB5737
                            SHA-256:27787F1893214ADBA7A2816D57BB1CED40ED75DD417132B22063921478955BCD
                            SHA-512:EC8794DA252D8C02DFF8C558E5CFFED654BF7B562E794D8EE655FC8C91DE51D29B7024631749C128F6F9C2C87D4987EAFBD91174A02ED71B106311249ADD529A
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "5",. "meta": {},. "items": [. {. "id": "4",. "meta": {},. "label": {. "type": "box",. "id": "3",. "child": {. "type": "box",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "1000",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "1",. "right": "1",. "bottom": "1",. "left": "1". },. "borderRadius": {. "topLeft": "Radius1",. "topRight": "Radius1",. "bottomRight": "Radius1",. "bottomLeft": "Radius1". },. "backgroundColor": "CoreBlue30". },. "name": {. "kind": "unkno
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):7380
                            Entropy (8bit):3.2331367565494733
                            Encrypted:false
                            SSDEEP:
                            MD5:69B82D4112209327267A2A5D14448D72
                            SHA1:7C86DBCC1C58CC796BE5C53C5F268E2303083755
                            SHA-256:02AFB9BBAD4AE6E91E3E7203DE94F8411D962818111DC3748D95B1E132CE3401
                            SHA-512:8F2579EE5ACE891E7E620E5A93BA932185BA42EB9CFC4135971C834073DD67B18B9E2901E8D2A4DF7549053C6081ED7F1831598E2174FA0CEFADDC6DCC153E2F
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "6",. "meta": {},. "items": [. {. "id": "5",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Item",. "textColor": "CoreCyan60",. "format": [],. "selectable": false. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": [. {. "id": "4",. "meta": {},. "label": {. "type": "icon",. "icon": {. "type": "icon",. "id": "3",. "meta": {},. "source": {. "kind": "known",. "name": "feedback". }. }. },. "onClickActions": [. {. "type": "notify",. "userAction": "click". }. ]. }. ]. },. {. "id": "5",. "met
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):19181
                            Entropy (8bit):2.995972655895753
                            Encrypted:false
                            SSDEEP:
                            MD5:F109ECD36FD118F576704EEF04C9A3D9
                            SHA1:4823A2DF8D5E4213C8426CB4FC3C9C6A43636D40
                            SHA-256:4BE3F51AD35A573707B0D7EB9DF7F38B9AB6CC0F620FF66FB0399C2D35101CA4
                            SHA-512:06E1913580D1270CAF8D697DDF001C41AC4A6E9CE22F3EA77F5DA57C4BCF8DA10E4AD818CCC45D5AABF9E7262BCF90CE09AD3C5754A624DDA84AE3E4D5C8EE43
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "list",. "id": "15",. "meta": {},. "items": [. {. "id": "14",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Item",. "textColor": "CoreCyan60",. "format": [],. "selectable": false. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": [. {. "id": "4",. "meta": {},. "label": {. "type": "icon",. "icon": {. "type": "icon",. "id": "3",. "meta": {},. "source": {. "kind": "known",. "name": "feedback". }. }. },. "onClickActions": [. {. "type": "notify",. "userAction": "click". }. ]. },. {. "id": "7",. "met
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1815
                            Entropy (8bit):4.239059014073907
                            Encrypted:false
                            SSDEEP:
                            MD5:F0CB6C13F9D7362D86B3AC21BFB00B45
                            SHA1:C1130461666EF852B70985668375B52E5EAC8813
                            SHA-256:57FBE2E04163958695C629CD2E5FD3EF60AEC2DF10595C03C2B12B6FBC84F5EC
                            SHA-512:1A653A91FC5A2651A1D85F12F788560653B9E3C556A1C8FAF79F1F4E3987589513427BBB3BBC8487E468ED5B69D9CF965CAD2B3008CB0B1024CF592CA7CB8B59
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "7",. "left": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. {. "type": "image",. "id": "2",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. }. ],. "right": [. {. "type": "image",. "id": "4",. "meta": {},. "name": {. "kind": "unknown",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):737
                            Entropy (8bit):3.5936252421411843
                            Encrypted:false
                            SSDEEP:
                            MD5:2C33CDB8F824BA0C78F7507158C91EC7
                            SHA1:960F18D37DEF6A7DA85F024416338AD7665DF816
                            SHA-256:AADF4DA556968056A5931578B4ADFD3E0947496279E6A554D7561A8CA6F3F9F7
                            SHA-512:A6FB660299345C3FC27C294F200DB655EBD4DBF800E7B1007F1FAFCFC1DE4883B85A466AD9AC6A0C08FB58FEF159F4924B46E31684EDE0A5FC6F30F5B9940E2F
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "info". }. },. {. "type": "icon",. "id": "2",. "meta": {},. "source": {. "kind": "known",. "name": "feedback". }. }. ],. "right": [. {. "type": "icon",. "id": "3",. "meta": {},. "source": {. "kind": "known",. "name": "info". }. },. {. "type": "icon",. "id": "4",. "meta": {},. "source": {. "kind": "known",. "name": "feedback". }. }. ],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "row". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1425
                            Entropy (8bit):4.2307430914768736
                            Encrypted:false
                            SSDEEP:
                            MD5:BB266ABA9F66094C2FE07D37AA79833C
                            SHA1:E8B04287A7EE0971D3702B40B45E428A2AD7B2FB
                            SHA-256:C77BB701F3FBC33EC5E0667A65542125757D7F36832A1D873041EE65F5C6B652
                            SHA-512:92A477CBBC0FC8311F30C947CDB5194F8D44C0C373CEAC4F22CA024614FC818EC8374B1533F3485AF0AD320FC9CB81A084719A8CD2A009D06FF0E7783482ECCE
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "5",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a row. This is a very long text that should be wrapped inside a row.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a row. This is a very long text that should be wrapped inside a row.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "right": [. {. "type": "text",. "id": "3",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a row. This is a very long text that should be wrapped inside a row.",. "textColor": "CoreNeutral90",. "format": [],. "selectable"
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4473
                            Entropy (8bit):3.500823557495235
                            Encrypted:false
                            SSDEEP:
                            MD5:AE77AF95D5C17AC2A4BEA6A114B21E97
                            SHA1:44342463A448991B925A30FF9AC81C4BF7FAA56D
                            SHA-256:C2ED9BD23391A3E6E39490F4F542F34A9A33C48BF1F02D84D9BFB48C6AAE0EA0
                            SHA-512:B479666ADC4C31A9860E9FFE7BC3FCF410A35AD2C53DA2A29C2578D27F3259CB98918C462A5B0D649EE3E32CDAFBDDFFCC6781F4CAE3BB12D46EE0A74228C5E0
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "15",. "left": [. {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "column-button". },. "kind": "secondary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "info". }. }. ],. "name": {. "kind": "unknown",. "value": "block-column-button". },. "spacing": {. "top": "0",. "right": "0.25",. "bottom": "0",. "left": "0.25". },. "verticalAlign": "middle". },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "shape": "square". },. {. "type": "button",. "id": "7",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1145
                            Entropy (8bit):4.0620222983198415
                            Encrypted:false
                            SSDEEP:
                            MD5:5E42D2D3935C31051F048EBE95884DF3
                            SHA1:F28D2FAC1D42F7AF78922CCED27C5716494F0EFC
                            SHA-256:496D2DF9CDD8CAE772EB709AA08D1502583E8ACBEE607EB4B8D93CDAD302E666
                            SHA-512:EFB19CB0D9CDAF144A793E4984806499231E99D1F84A37E8E1BD002B82E153DEC22057FA696189B6870D5B539347735263C0AC513F384595A9FF163632BFE43D
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "9",. "left": [. {. "type": "count",. "id": "1",. "meta": {},. "value": "Left 1",. "backgroundColor": "CoreBlue60",. "textColor": "CoreNeutral0". },. {. "type": "count",. "id": "2",. "meta": {},. "value": "Left 2",. "backgroundColor": "CoreBlue60",. "textColor": "CoreNeutral0". },. {. "type": "alertsCount",. "id": "4",. "meta": {},. "size": "regular",. "textColor": "CoreNeutral90",. "format": []. }. ],. "right": [. {. "type": "alertsCount",. "id": "6",. "meta": {},. "size": "regular",. "textColor": "CoreNeutral90",. "format": []. },. {. "type": "count",. "id": "7",. "meta": {},. "value": "Right 1",. "backgroundColor": "CoreBlue60",. "textColor": "CoreNeutral0". },. {. "type": "count",. "id": "8",. "meta": {},. "value": "Right 2",. "backgroundColor": "C
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):22407
                            Entropy (8bit):3.1915892499696445
                            Encrypted:false
                            SSDEEP:
                            MD5:DD016B7FCBC59B51333A764B3E780613
                            SHA1:E52DCEE5DB5B345345985AA9E199030F8C89A17C
                            SHA-256:2F43581B64D44727B3A715D9444457621E4E73FEBA875FABD01213285EC6437E
                            SHA-512:1DB6726D5F5475C6319694D2FD162432AC170E12CC1D584877E95CE6EF48F216A0F71CFE2CD46213F5085F5A9FAD599B9B371143A4983B3A55360CCD95A6CED5
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "71",. "left": [. {. "type": "alternativeChoice",. "id": "17",. "meta": {. "label": "Choose a different word". },. "alternatives": [. {. "label": {. "type": "button",. "id": "11",. "meta": {},. "name": {. "kind": "unknown",. "value": "select-0". },. "kind": "toggle",. "state": "deselected",. "label": {. "type": "block",. "id": "10",. "parts": [. {. "type": "text",. "id": "9",. "meta": {},. "size": "regular",. "text": "classic",. "textColor": "CoreBlue50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "t
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1529
                            Entropy (8bit):3.6242475888278194
                            Encrypted:false
                            SSDEEP:
                            MD5:5C1D0E7EF640F0DBDFF855D82F2FCFC6
                            SHA1:1F3B89ED608C56946C4ECD7ED4D260B3E50DA345
                            SHA-256:B20D4797EC22386F418A442FC99E3962F92629BB5EA5967392B85146BDDDEFE2
                            SHA-512:A2678F4BCDE58634B76F3570BA95B4A31C532C55AEECB1AB0745B7A510F224A1A12507396D3470FF4458B210E30C5207F9ABE2C49E9F21DA8A27032F15A2E289
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "7",. "left": [. {. "type": "row",. "id": "3",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Left",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "right": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Right",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "row". }. }. ],. "right": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "Left",. "textColor": "CoreNeutral90",. "format":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1267
                            Entropy (8bit):3.696206115342623
                            Encrypted:false
                            SSDEEP:
                            MD5:458985D39B6BF036AC3B8102BBE80500
                            SHA1:7953B5B87ED7EB01F8A085646C51813CD8D8D8DF
                            SHA-256:C47E25F572B88D7FDE0087D1C2D72FA0AB8D792E114515CC19C2EA165644BB49
                            SHA-512:864338C12855675F46F2D09571F4DE456E17251B2F814FF68382E25B93714972A0A27309198F07900DB94B2EABEB76255AEAECC117F59811E477D942521E015F
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "7",. "left": [. {. "type": "column",. "id": "3",. "children": [. {. "type": "count",. "id": "1",. "meta": {},. "value": "1000",. "backgroundColor": "CoreBlue40",. "textColor": "CoreNeutral0". },. {. "type": "count",. "id": "2",. "meta": {},. "value": "2000",. "backgroundColor": "CoreBlue60",. "textColor": "CoreNeutral0". }. ],. "name": {. "kind": "unknown",. "value": "column". }. }. ],. "right": [. {. "type": "column",. "id": "6",. "children": [. {. "type": "count",. "id": "4",. "meta": {},. "value": "1000",. "backgroundColor": "CoreBlue60",. "textColor": "CoreNeutral0". },. {. "type": "count",. "id": "5",. "meta": {},. "value": "2000",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1520
                            Entropy (8bit):3.793478652940094
                            Encrypted:false
                            SSDEEP:
                            MD5:A5D07ADB290DD4E5026E35B2821A5170
                            SHA1:EFDC0035DE70A73DB9909152029E025CCB1F1ADD
                            SHA-256:748E4BB8AA49FA0DE98F290D37C5F7B000DD778C29382AC1A5E79DD58A041809
                            SHA-512:79F21DEA0ECF0E9AD2EBCF89915A45C7A2C0F3A0F293EF4BF59829FDAFC0539BBF997E4467C0050748B4AAB55547FD9A9F214AE45E7B25C7DBDF96871E4E9F7E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "7",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Left",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "block". },. "fraction": 1. },. {. "type": "block",. "id": "4",. "parts": [. {. "type": "text",. "id": "3",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a row. ",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "block". },. "fraction": 3. }. ],. "right": [. {. "type": "block",. "id": "6",. "
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1521
                            Entropy (8bit):3.796336488272408
                            Encrypted:false
                            SSDEEP:
                            MD5:EF07A3C0C5F95FEBDC109C73537BE862
                            SHA1:9019CBFD2BD6C800343E83CF732557649E135CC9
                            SHA-256:85694EDD64815FF2D09D0FFFD3264C1FCF6480EF7907B7FA0174D90F2F8AC953
                            SHA-512:C4B3C9F3BB7B0907C204EF2BDEEE644FAA86BD1CF9CC5D2F1228B1AED0B55AF652F5EF2FB825790BF42B75EF51296241208BE84FB7556103B609ADBCDBBF0877
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "7",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. }. ],. "name": {. "kind": "unknown",. "value": "block". }. }. ],. "right": [. {. "type": "block",. "id": "4",. "parts": [. {. "type": "text",. "id": "3",. "meta": {},. "size": "regular",. "text": "Right",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "block". },. "fraction": 1. },. {. "type": "block",. "id": "6
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1667
                            Entropy (8bit):4.0566755399582695
                            Encrypted:false
                            SSDEEP:
                            MD5:963A9F6840B6958E4F6E42B0683E8965
                            SHA1:AAC2BCFDB35A9B86791A118C2A8A7ED2D527CEFA
                            SHA-256:8E0B5392138989A8FE580994EF7CA6C4ACEE2DD4E8374156D4311F668E4362CF
                            SHA-512:C579BCFE82EC8C1010A36EB22F4E06F54D62404C2B525A5E4CC43B52210DB4093CAAB5306A852538886CF97B5E5411301124FCF7CBB4A2D46FD9EFF58FC3B3D5
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "6",. "left": [. {. "type": "scroll",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "maxHeight": 5.0,. "name": {. "kind": "unknown",. "value": "scroll". }. }. ],. "right": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "text",. "id": "3"
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1805
                            Entropy (8bit):4.277637480275541
                            Encrypted:false
                            SSDEEP:
                            MD5:65FA03AB981E311A851B61CBC3735D82
                            SHA1:1A3A4BCFF0F5D8337ED70CD5997BC87F90D9C9A3
                            SHA-256:13269536546B072E8A79AC31DFBFE636A94AEC1084081238DE1354C7214CC923
                            SHA-512:7C628A166D297F914C5109F683C2218F4B4A81F126014581C6E1F3CC554584364AE9B4BECDDCF500531C68A1382ED211D6770882B8BB24B955CB9EC90979788E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "5",. "left": [. {. "type": "scroll",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "maxHeight": 5.0,. "name": {. "kind": "unknown",. "value": "scroll". }. }. ],. "right": [. {. "type": "scroll",. "id": "4",. "child": {. "type": "text",. "id": "3",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):979
                            Entropy (8bit):4.305048353615483
                            Encrypted:false
                            SSDEEP:
                            MD5:7D750A2E37BA048B0C549734BEA6FF54
                            SHA1:9F11A40239D8F3E2FFDAAA72FCBBFDDC496D1A27
                            SHA-256:1D14F6D1B488B2B66D9C31455511CDF084E30B8F3BBA547874BEAC1735BA530B
                            SHA-512:7A49D815F48C9727D19C099310CFBA51EED70A948C5B3B3B4DE1D96089682F8EC87D2B00835048454BD3017D34EB76CFF5A8A08D339E949A3D19BAE9F6F5BD5F
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "3",. "left": [. {. "type": "scroll",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "maxHeight": 5.0,. "name": {. "kind": "unknown",. "value": "scroll". }. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "row-row". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):2567
                            Entropy (8bit):3.550263558119269
                            Encrypted:false
                            SSDEEP:
                            MD5:FA1A733DF9E24906E12814BA57E969EE
                            SHA1:7DF382945D0B165AF404BDF25BAD386E64B3E39D
                            SHA-256:6112C0B06EB81325A0E749A6CD68E73D2489D2BFC11FED274E6EE0F17EF248D7
                            SHA-512:7FD91C4706AFBE8781A525B7DD6BAE34D407CDF63832A448B8FD01D5725A2AFD79DE20A722446DDA23C0D5136F6C6AD76E6D78577A25CC4BCADCBBB6E7CDFB3D
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "13",. "left": [. {. "type": "scroll",. "id": "8",. "child": {. "type": "column",. "id": "7",. "children": [. {. "type": "count",. "id": "1",. "meta": {},. "value": "1000",. "backgroundColor": "CoreBlue10",. "textColor": "CoreNeutral0". },. {. "type": "count",. "id": "2",. "meta": {},. "value": "2000",. "backgroundColor": "CoreBlue20",. "textColor": "CoreNeutral0". },. {. "type": "count",. "id": "3",. "meta": {},. "value": "3000",. "backgroundColor": "CoreBlue30",. "textColor": "CoreNeutral0". },. {. "type": "count",. "id": "4",. "meta": {},. "value": "4000",. "backgroundColor": "CoreBlue40",. "text
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):8461
                            Entropy (8bit):3.2689299030728765
                            Encrypted:false
                            SSDEEP:
                            MD5:D99BB714B15C32D7AD9D8B0970464222
                            SHA1:23621446CC4AF1CEA91155C040EC866C6BCC86C5
                            SHA-256:E8D2FD8470ED67AC0EDD3BABB75396E2DD49C3CFF059BE63BE70042C90E6B3C3
                            SHA-512:26F616751D0917C3706F50B91D5F6CD394A1144374739DB9F146094B72B27C4DCB42CCCA8B8CBD0A05CB254958A9C716836290DF33A56220048300DF2C4741EB
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "4",. "left": [. {. "type": "list",. "id": "3",. "meta": {},. "items": [. {. "id": "2",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Item.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "2",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Item.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "actions": [. {. "type
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1697
                            Entropy (8bit):4.090237230228881
                            Encrypted:false
                            SSDEEP:
                            MD5:E5183FDFFB2D00F377F3FFDB8B03BE6D
                            SHA1:8E69E862E523BBE5F73A31B3E0A89AD6FD390FB8
                            SHA-256:B5636949D81B20627A4B41638AC66F9493173F8EB8709A6CAFFC3F953F0BAE1E
                            SHA-512:F949F3E2579664C95D1ACCE47215E777ACC2053BC2288A72F7AB9764B4E2A803085A54549BF823FFCF1408805458CCE86575ACF02B50BB918ED15FE85739DE8D
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "5",. "left": [. {. "type": "box",. "id": "2",. "child": {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. },. "name": {. "kind": "unknown",. "value": "count-box-1". },. "padding": {. "top": "0.25",. "right": "0.25",. "bottom": "0.25",. "left": "0.25". },. "borderRadius": {. "topLeft": "Radius2",. "topRight": "Radius2",. "bottomRight": "Radius2",. "bottomLeft": "Radius2". },. "backgroundColor": "CoreGreen10". }. ],. "right": [. {. "type": "box",. "id": "4",. "child": {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1025
                            Entropy (8bit):4.298605756691385
                            Encrypted:false
                            SSDEEP:
                            MD5:755936A51E556266B3F1C15AC5532AE7
                            SHA1:B3F4CF8F9E9201721F259891645CF05F0680191C
                            SHA-256:8C3FFF8E3A8CBC11EFF27D2B00C8B0F9651E3DC50E0A3CFBE5230259F22ADA62
                            SHA-512:26998B434190C5D6E2194E365552AABC4785D265BB78AD612C32B191138A44227E9054848E49F027A8A736765703C7488DC4B29E2EF27CD34183A394E44F08DC
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "4",. "left": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a row. This is a very long text that should be wrapped inside a row.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "right": [. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. }. ],. "verticalAlign": "middle",. "name": {. "kind": "unknown",
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1025
                            Entropy (8bit):4.298605756691385
                            Encrypted:false
                            SSDEEP:
                            MD5:0D7A1EFD6A6447C5FBEE2BD4DA2644BA
                            SHA1:96D8B3CDAE2210AC3EEE282C441486566CFED764
                            SHA-256:D0793012C1956782B07B4EEF3FF16B357FF7F92C32EBE4989CC0EAA4747D7291
                            SHA-512:8D0EF70B1DB5F1742DD248010F24D1E489FF91C6DF6AD8B23DF210CCEE05AB3DCE6D933A316ABD402AC0ED44EC6DA6A688EA6C56C1E4DA80ABD3B61741620964
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "4",. "left": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. {. "type": "image",. "id": "2",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. }. ],. "right": [. {. "type": "text",. "id": "3",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a row. This is a very long text that should be wrapped inside a row.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "verticalAlign": "middle",. "name": {. "kind": "unknown",
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):927
                            Entropy (8bit):4.176764994531218
                            Encrypted:false
                            SSDEEP:
                            MD5:3F206DCC48CE9DA7647922C404C3400C
                            SHA1:0FAD1DB72B972DAA1DE88149EB09294AA2EEC46E
                            SHA-256:986AC5251AD6CAA84D1A8CB01A898B639BC2C9E590B367E9648A99AE1CAE876C
                            SHA-512:E6E09660BA54F42E0AD21CC5DE411D4C3595B9FB1DE5D42BBEBF188AF0745CFB063255A8B6097019301F81046D456617A68F5254A2D2F355B478940CA3E12943
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "4",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Text",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "image",. "id": "2",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 1.25,. "height": 1.25. }. ],. "right": [. {. "type": "text",. "id": "3",. "meta": {},. "size": "regular",. "text": "Text",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "row". },. "spacing": {. "top": "0.5",. "right": "1",. "bottom": "0.375",. "left": "0.5". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1102
                            Entropy (8bit):4.188551075647119
                            Encrypted:false
                            SSDEEP:
                            MD5:7841E25BE0F1158A4A96EDA2298082CF
                            SHA1:180B882FE86FEB9E2AFCA93BC260270E4B1A47F6
                            SHA-256:563DA8A3B6FBDECB9D777A71975225CED66AF99EE52315593964A2BEAECCE057
                            SHA-512:7E3D2B3DEC94D9DEB46A594379F13C65BB1BB325B8706AA280C3191E8D3113E1C894D9E2BE06B58AC9D9501B929FC3CC56A674AD6C13E820972BD99D5BC1981B
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "5",. "left": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Text",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "right": [. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "Text",. "textColor": "CoreNeutral90",. "format": [],. "selectable":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1105
                            Entropy (8bit):4.191944319524242
                            Encrypted:false
                            SSDEEP:
                            MD5:9D9E009A1AE76C355CF116CFE2BEB4E7
                            SHA1:00D41D6FDD5C5AF5CD97E6B0569491554956709C
                            SHA-256:19F9750A50D7E2F7D11CAD1101F5BD81ADDA2DFCB07B6E2BC4A785BC252D0E8C
                            SHA-512:F328C45D72315D35466866EA541BDC9F5508BC9F1C5F9775699B2BE0957320A892DC2D2397687B648D2C39E7113DB66E286E8F73AAFC94B4A6E0E860D324C3C8
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "5",. "left": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Text",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "right": [. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "Text",. "textColor": "CoreNeutral90",. "format": [],. "selectable":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1105
                            Entropy (8bit):4.193131111438394
                            Encrypted:false
                            SSDEEP:
                            MD5:41D4C97FEA843043C59D479DA149F01F
                            SHA1:FFA4BB099B56C46C4C173A64598DC28D558BC8A6
                            SHA-256:15080F76A3B44966CBF96C02468E678130FDD0C5291AFCBE79B3C0CD3DB6C49A
                            SHA-512:2CA52393C4158E885F1759E4F1E2141D6076D0662CCF251B6BC088E1BAE1FC56DB637855B51329ECDE2816C8F42E53501463D9339A9800C1F8E45EC6E89154B5
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "5",. "left": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Text",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "right": [. {. "type": "image",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. {. "type": "text",. "id": "4",. "meta": {},. "size": "regular",. "text": "Text",. "textColor": "CoreNeutral90",. "format": [],. "selectable":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):5106
                            Entropy (8bit):3.027057976934394
                            Encrypted:false
                            SSDEEP:
                            MD5:7875D33F94183E603A2D2446CF522291
                            SHA1:08C3CBA37C0B29283EF07A29898F6DC31BCE40D5
                            SHA-256:3566AD02BA8A47361D3917E07E3CC9BD34EDA784A1D4C7151CEE4C65D8C8BFBF
                            SHA-512:FFD5A28163DF41D3A56E5D531B34895BD8613416161EEAA528B79B106EB1D10C1C1CA5B947B46E1C592D93EBABB3EBB2A7F003652C085725964E5C439C18D8DA
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "15",. "left": [. {. "type": "block",. "id": "1",. "parts": [],. "name": {. "kind": "unknown",. "value": "block1". },. "fraction": 2. },. {. "type": "block",. "id": "7",. "parts": [. {. "type": "column",. "id": "6",. "children": [. {. "type": "button",. "id": "5",. "meta": {},. "name": {. "kind": "unknown",. "value": "left". },. "kind": "toggle",. "state": "deselected",. "label": {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):7021
                            Entropy (8bit):2.9466264669000384
                            Encrypted:false
                            SSDEEP:
                            MD5:4FB6F05DFE2B2DE175F75683FC67734C
                            SHA1:CCB84567493FB634F3182585E93A0C88F34E4A73
                            SHA-256:DC56BBFB6B4680559203EB1DCE9137526E0EBA7C5498CB45060BC17D5FEC4ACD
                            SHA-512:C04BA836A00B8708944AB6A996ECDAA4E0E134304D639E9DF2D75A953A08A37AD0E04113D88A4D6D330F7FA2486AA407510A087151CCFBC0E67805F3EC094EBD
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "19",. "left": [. {. "type": "block",. "id": "6",. "parts": [. {. "type": "column",. "id": "5",. "children": [. {. "type": "button",. "id": "4",. "meta": {},. "name": {. "kind": "unknown",. "value": "left". },. "kind": "toggle",. "state": "deselected",. "label": {. "type": "row",. "id": "3",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Left",. "textColor": "CoreBlue50",. "format": [],.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):304
                            Entropy (8bit):4.24048311343409
                            Encrypted:false
                            SSDEEP:
                            MD5:608B25231149F3FAF3C0FBE117CB647B
                            SHA1:56A7AFE32E9F8E07E8BE286EB5005BAC91EF9465
                            SHA-256:DB99BB69C768426504F2B323B1A59B733951A3DF3D42C35CC9CACDC3193A0E28
                            SHA-512:8D0FB1715A069CBFB6453C39E698CCB519843A7B483B3D393F5FC43EB254975AD991A568EC222496236A74C544B228CF201BB8247E83382253E7C77900DC7EED
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Text",. "textColor": "CoreYellow80",. "format": [],. "selectable": false. },. "maxHeight": 3.0,. "name": {. "kind": "unknown",. "value": "scroll". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):746
                            Entropy (8bit):4.443815820736847
                            Encrypted:false
                            SSDEEP:
                            MD5:9F713CD324D598027A3B64AD3CAE8E96
                            SHA1:5725A7AC4052D06A7C227451FB583D1FE4861001
                            SHA-256:59056A9DFAAA7F612DF61B1AB27E84FA0BA9B75446ECB00D2AB995C65C97780D
                            SHA-512:A82B6B90FE62868F36511416524EB49EC25E95C8A7ED1B9DCED36AAC86CCD03C2520AE2FA2E1591EFDCE63D1DEC5AFF821AB381D3DFD1FEF5B529924129ECE6F
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "maxHeight": 5.0,. "name": {. "kind": "unknown",. "value": "scroll". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):256
                            Entropy (8bit):4.0321885840975185
                            Encrypted:false
                            SSDEEP:
                            MD5:1054835E34E1A1B3898C2E6846D81027
                            SHA1:E165C55CD387DCDFF0612AFFCE83FEBA4535C400
                            SHA-256:9E8CE142D89287A15F5C8C60374FA2155B776AF08CCD080B15C76FE3CE38079D
                            SHA-512:D703C57EB3EC0356C0DC75F8B40378630486347499A06B8531E5497A3396BD220F1D34833BD15B506DAA404D21720503F38BCF9616AC6F7225CBF2A389D67F15
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "2",. "child": {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "feedback". }. },. "maxHeight": 3.0,. "name": {. "kind": "unknown",. "value": "scroll". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):379
                            Entropy (8bit):4.412603380703004
                            Encrypted:false
                            SSDEEP:
                            MD5:F8EB6027A92B9AE0D99C0A66CB1E864F
                            SHA1:78C84ABBC403B431BE4DDC8BC05973D5B218D18B
                            SHA-256:33F5B14C0F7781B28AAA2FB3371FE7D307673609BA7DACBCEA8D4333CA00E02A
                            SHA-512:3593B121E537E1040923932A71441C36CFB5D13453A4987FC3B4786516E0C5BD1A62825A5A30A71653A4942825955E1D65B5B068416BE71F4EFF01705AFFC258
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "2",. "child": {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "premium-footer-icon". },. "url": "https://assets.grammarly.com/icons/v1/diamond-small.2x.png",. "width": 4.0,. "height": 4.0. },. "maxHeight": 3.0,. "name": {. "kind": "unknown",. "value": "scroll". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):941
                            Entropy (8bit):3.785226203267225
                            Encrypted:false
                            SSDEEP:
                            MD5:9585F845C5A34CF9E72AF98A5AC272A4
                            SHA1:E9A57683892AE7CBF616F1E883085B5B7FD4EA5C
                            SHA-256:C434E500221A73FEBEBBDAE42B7CFCA6A52959555A7F62C01119E40012AEFC08
                            SHA-512:251CF679EFDB8115CEDB8688D5E3973A73E98357F8D6DB0073F15D41190F9A5A242C8CCF4D6BF54CAAB199D2DED4C6CA7E14E30B69C99B900B7706D5886B8971
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "4",. "child": {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "column-button". },. "kind": "secondary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "info". }. }. ],. "name": {. "kind": "unknown",. "value": "block-column-button". },. "spacing": {. "top": "0",. "right": "0.25",. "bottom": "0",. "left": "0.25". },. "verticalAlign": "middle". },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "shape": "square". },. "maxHeight": 3.0,. "name": {. "kind": "unknown",. "value": "scroll". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1264
                            Entropy (8bit):3.763040122596666
                            Encrypted:false
                            SSDEEP:
                            MD5:1A22C19818521344E035BD3FC7743D50
                            SHA1:EB50A3411D32C27D7982E2B9AECC0ADB549838FD
                            SHA-256:261F75133C6EF2DB13351C00566DD48E4E7615F1B8416E313CB5767098CCCB5A
                            SHA-512:E6F9675EECC140C1E5EF88F41CA5D50A46016716A1B491BE3664CE3B52CB4CB0750609838178B6FB4663CF029BE542F2CEF1201706F25F0BFCCF41CA52CEDBF7
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "5",. "child": {. "type": "button",. "id": "4",. "meta": {},. "name": {. "kind": "unknown",. "value": "column-button". },. "kind": "primary",. "state": "enabled",. "label": {. "type": "block",. "id": "3",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "close". }. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Tap Me",. "textColor": "CoreNeutral0",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "iconTextContainer". },. "spacing": {. "top": "0",. "right": "0.5",. "bottom": "0",. "left": "0.25". },. "innerSpacing": {. "vertical": "0",. "horizonta
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):277
                            Entropy (8bit):4.285056610702813
                            Encrypted:false
                            SSDEEP:
                            MD5:0C623F0D90291C1B6DFFEB9F889EEF9C
                            SHA1:E9C1A0EA6A942F613BCE3551E7C71D80AD9B0A70
                            SHA-256:86C9EE0F0DB8B59389C6453DC14C3EB87326FA3AF896FA33F36CD4699343BF24
                            SHA-512:7F7275B3613AC4FB4198E565D71097F69EA1DCFD376B41819EDDD5E842C825B6A771087B6D192B2824F39E60AF454BDDFD3B7F4BB206F4537D321ECC9D1C8221
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "2",. "child": {. "type": "count",. "id": "1",. "meta": {},. "value": "1000",. "backgroundColor": "CoreBlue20",. "textColor": "CoreNeutral0". },. "maxHeight": 3.0,. "name": {. "kind": "unknown",. "value": "scroll". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):267
                            Entropy (8bit):4.266670945318403
                            Encrypted:false
                            SSDEEP:
                            MD5:5701AFFD452808D78D94844EE659802F
                            SHA1:1B1D4C7DCF81FE033BED5E6A91168C315A9FDAD6
                            SHA-256:97DD9B4551FABBFE31DE260E73911C80B128CED6F25C5F67BACF09B5D7D89DEC
                            SHA-512:722C03EEB444BEA5367B04CEF39EBF8E1EF0A68A91FD8B6C0BD0F5BA2D0ADC642104ED05F5ABE17A509EB537939CA38E14793C2F95160DBF454E204652AD229D
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "3",. "child": {. "type": "alertsCount",. "id": "2",. "meta": {},. "size": "regular",. "textColor": "CoreNeutral90",. "format": []. },. "maxHeight": 3.0,. "name": {. "kind": "unknown",. "value": "scroll". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):5995
                            Entropy (8bit):3.232805357934598
                            Encrypted:false
                            SSDEEP:
                            MD5:1957043CC323BC082713465D9451369C
                            SHA1:E8F3B006A703AC0EE76104247835BCD782A8EADE
                            SHA-256:BDFDAA8D0F1FAEAE3A894DD7F869C0710A7E082D7A729B15BF77A4CE31B4AABD
                            SHA-512:E8F84F2FAC23F74E213687B3968492100A610F8CC4781B02993582F86FB44C85F0D9680FB6D2D39EF3FAB007A622C16CC10241642B3C85FAA59096A92BDC8B2A
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "18",. "child": {. "type": "alternativeChoice",. "id": "17",. "meta": {. "label": "Choose a different word". },. "alternatives": [. {. "label": {. "type": "button",. "id": "11",. "meta": {},. "name": {. "kind": "unknown",. "value": "select-0". },. "kind": "toggle",. "state": "deselected",. "label": {. "type": "block",. "id": "10",. "parts": [. {. "type": "text",. "id": "9",. "meta": {},. "size": "regular",. "text": "classic",. "textColor": "CoreBlue50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "textContainer". },. "spacing": {. "top
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4565
                            Entropy (8bit):3.545380797207303
                            Encrypted:false
                            SSDEEP:
                            MD5:9DB5E6840D996E9628716816EF688CAE
                            SHA1:DDA210F489B76EB9A8B9DD4A1CC786757C76F9EF
                            SHA-256:8AD4D1551606E2E698A5F0931B7267B212F4FC870F62226A9C5C3EDBCD0AF8AD
                            SHA-512:910DAA5C11FE6A58A6110C0B9EC0E0B06C98B609F7843F1562DD4F3D6A3D3DF49014CB698BBC499887479B4013B372C9AE324C7DB12FA4CACCC5F57C497BB9B8
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "19",. "child": {. "type": "alternativeSlider",. "id": "18",. "meta": {. "label": "How do you want to sound?". },. "segmentSize": 3.125,. "fillColor": "CorePurple50",. "choices": [. {. "id": "8",. "icon": {. "type": "icon",. "id": "7",. "source": {. "kind": "url",. "name": "neutral",. "url": "https://assets.grammarly.com/emoji/v1/1f610.2x.png",. "size": "1". }. },. "label": "Neutral",. "actions": [. {. "type": "selectAlternative",. "alternativeIndex": -1. },. {. "type": "notify",. "userAction": "selectSliderChoice". }. ],. "preview": {. "type": "block",. "id": "9",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):746
                            Entropy (8bit):3.891939570253586
                            Encrypted:false
                            SSDEEP:
                            MD5:BAA21C10FAC3F06B2F5C7D4FB65DEBA4
                            SHA1:F64669BBFF54F715162A7ED9773CF2DC9E55A49A
                            SHA-256:B6961E0C266A03AC90FE7C29E8DE87A5B970E3E3ED41E0EDCF150EB25F890304
                            SHA-512:C65E9067D1E054784D97DD18B7FAB4BA43BCD39B227E62B091901BD9DE404AB64333C69D6A74CBAA2CA39E60792F153E4AEB23EDBC2D198CC16BF52BFDB3C197
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "4",. "child": {. "type": "row",. "id": "3",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Left",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "right": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Right",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "row". }. },. "maxHeight": 3.0,. "name": {. "kind": "unknown",. "value": "scroll". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):778
                            Entropy (8bit):4.006059039838171
                            Encrypted:false
                            SSDEEP:
                            MD5:36A16D7A1B6F10EFE5A8FD1C3AF2E639
                            SHA1:5CFB6FAF116CFEF8E2C571C2E4CD8ADB41A06532
                            SHA-256:C6FDFFFAAA7FABE8504673FD6DD9FADE1B18061DEF68748AE538A9B1F92EDFB6
                            SHA-512:F4EA59E78C79A2C281FEC13837B61D294B0EA1B16ADD18A8CBA9834AA4B37D6DBA26ECA785194C249073D2E0DC4EFC97FC2AC13DE89128365FB05A56B2DCF153
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "4",. "child": {. "type": "column",. "id": "3",. "children": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "First",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "First - This is a very long text that should be wrapped inside a column",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "column-inside". }. },. "maxHeight": 3.0,. "name": {. "kind": "unknown",. "value": "scroll". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):855
                            Entropy (8bit):4.063194690095208
                            Encrypted:false
                            SSDEEP:
                            MD5:6A6FAB00BAB278E05CC9FEED2365F9F8
                            SHA1:203479C25B0B0741099DE4BFB8D748494F93FE66
                            SHA-256:960972D5006CA0F41A0739814BAC94093FF667A0F252C8856474BFEB85CCBCA3
                            SHA-512:A365154A03178D1394C39F2759F41C6C407083501D612F83DBA02082D658576246A4064963038C321BEAE430B3A9E8C204E6A6ED61908EF06F7E44CE9DC28E6E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "4",. "child": {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a block",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "This is a very long text that should be wrapped inside a block",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false,. "backgroundColor": "CoreBlue10". }. ],. "name": {. "kind": "unknown",. "value": "block". }. },. "maxHeight": 3.0,. "name": {. "kind": "unknown",. "value": "scroll". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):912
                            Entropy (8bit):4.381973176403082
                            Encrypted:false
                            SSDEEP:
                            MD5:46F152F8675DEFDCE68D87064C110926
                            SHA1:8370807E631CB22465D6440879A84C6D27F6C685
                            SHA-256:0E95F4CB4C3FF41DF9D6880912E1AE5994147F3EB4B913D784635714304E9BB5
                            SHA-512:70B440E352713793B91EE7F0787C33AAFBB1EB85D1228DAC82261DE465FB050AA5796A79B9FF17D81A5FF27F0CE8FCD767B4DAF8A3F9FF4823AFE685D435F921
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "3",. "child": {. "type": "scroll",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "maxHeight": 5.0,. "name": {. "kind": "unknown",. "value": "scroll". }. },. "maxHeight": 3.0,. "name": {. "kind": "unknown",. "value": "scroll". }.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3922
                            Entropy (8bit):3.4912824616796545
                            Encrypted:false
                            SSDEEP:
                            MD5:180DA40897901C625BDF854E0DE546A9
                            SHA1:AF10AEE41DCCAFF48903D51D55F5438F5B19B2D6
                            SHA-256:C6C17FAFCF01C60203C6C1DD0FFCC0380CE0BD7C45930CA21939FD2B727AA041
                            SHA-512:59C7E47EB498E7D8BE6BDFBDF26233801C83C475B46D298FD3EC8242F67E7630AAF7ED2039FE599FE171F893A06D9850BB7DD0AE56E7FB6385C1C3A26FDAC2F8
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "4",. "child": {. "type": "list",. "id": "3",. "meta": {},. "items": [. {. "id": "2",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Item.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secondaryButtons": []. },. {. "id": "2",. "meta": {},. "label": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Item.",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "secon
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1201
                            Entropy (8bit):4.020162303681614
                            Encrypted:false
                            SSDEEP:
                            MD5:CCEB7BBF583F5E19700919FA1A580B4F
                            SHA1:EAD23D8EA4748A32932CFA994EEC71D51687009F
                            SHA-256:2EA0093C949FF69C7D50586DB491C9D510B9A158335D9713BE193B58FB62039C
                            SHA-512:992227BAADF1D6A66B1E134D131ACAB5ECA0B2F0C3410832DF7F3089CC612387A30C8C9745CD274E65A2366D9CBB36C3D8A3AFE27F5C9D810AFCEBA54B81239B
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "scroll",. "id": "4",. "child": {. "type": "box",. "id": "3",. "child": {. "type": "box",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "1000",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "1",. "right": "1",. "bottom": "1",. "left": "1". },. "borderRadius": {. "topLeft": "Radius1",. "topRight": "Radius1",. "bottomRight": "Radius1",. "bottomLeft": "Radius1". },. "backgroundColor": "CoreBlue30". },. "name": {. "kind": "unknown",. "value": "box". },. "padding": {. "top": "0.5",. "right": "1",. "bottom": "0.5",. "left": "1". },. "borderRadius": {. "topLeft": "Radius2",. "topRight": "Rad
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1771
                            Entropy (8bit):3.1328690897542755
                            Encrypted:false
                            SSDEEP:
                            MD5:FA2C5AA7EB13975DDF949AD915738F66
                            SHA1:EA5ED31E0F2A783DDE44E8F0AD3C496DDDDEFF6E
                            SHA-256:81BC26E17196E51A7B8A8B9ACE5A81F7261C55937E3A45FDFAE225B0CAF48D25
                            SHA-512:6B6E41AAE75A2B44DA53C58966AF807F63CAE13F8E18119742E4E75952C8ADF8FD70887A4C91BF57B301E296C1A946A1E23331D5C824895FFE591C6AD8E32432
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "7",. "children": [. {. "type": "column",. "id": "6",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "The content ",. "textColor": "CoreNeutral90",. "format": [],. "selectable": true. },. {. "type": "text",. "id": "2",. "meta": {. "label": "insert \"reveals.\"". },. "size": "regular",. "text": "reveals.",. "textColor": "CoreBlue50",. "format": [. "bold". ],.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):39352
                            Entropy (8bit):3.116443299708325
                            Encrypted:false
                            SSDEEP:
                            MD5:7708AB076285B2C65B76F1084908B6FD
                            SHA1:CD73D4FE47000D7182FDE069250907A794FF1DDE
                            SHA-256:545D8BD83D6AFD06D96AD48F0DE1029CBC29AAB4A09636475076955001F7EBF9
                            SHA-512:E9E0AD7FED02F326BF4B39BDDB576BD0C95D2BE59A61F412EBD84BA0C1E88A779732983BEEB685126755D31B040F38D30D91A6935EB0106289FC79A8C4F141C1
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "viewStack",. "id": "header-viewStack",. "views": {. "default-suggestion": {. "type": "row",. "id": "15",. "left": [. {. "type": "viewStack",. "id": "openToneDetectorButton-viewStack",. "views": {. "show-open-tone-detector-button": {. "type": "button",. "id": "sdui:::open-tone-detector",. "meta": {. "label": "See how your text\nmay sound to readers". },. "name": {. "kind": "unknown",. "value": "openToneDetector". },. "kind": "secondary",. "state": "enabled",. "label": {. "type": "block",. "id": "3",. "parts": [. {. "type": "icon",. "id": "2",. "meta": {},. "source": {. "kind": "url",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):86345
                            Entropy (8bit):2.6279479914419532
                            Encrypted:false
                            SSDEEP:
                            MD5:E468BF466C2BACFC325E8E7D9966C1C3
                            SHA1:4B76418FFD00AF6404C9ED46BF6EB5643BBBBC74
                            SHA-256:806834DCBD4BFB82799D2C1E9BA5D8D70EC80C0259A46FB4369F557274E5B4F1
                            SHA-512:695052C1ACC7075CAD2B45089E3572FB85E32D789C86A8B31C8C4A34EDBB4C81809A6A90B757EA404DEA0A04957CEDFBDDD816F665F75AF5102FDD8341250C48
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "200",. "children": [. {. "type": "box",. "id": "26",. "child": {. "type": "row",. "id": "25",. "left": [. {. "type": "icon",. "id": "21",. "meta": {},. "source": {. "kind": "known",. "name": "clarity". },. "backgroundColor": "CoreBlue1". },. {. "type": "row",. "id": "24",. "left": [. {. "type": "block",. "id": "23",. "parts": [. {. "type": "text",. "id": "22",. "meta": {},. "size": "small",. "text": "Rewrite for clarity",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "n
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):54824
                            Entropy (8bit):2.335815417127763
                            Encrypted:false
                            SSDEEP:
                            MD5:A8368F28719CD15B06F7AE11E1670CD2
                            SHA1:4DE456115EC64A9DE142CFACBDC4E24AE06BC197
                            SHA-256:7525188BB3C2373B26C6CF567FF720BFE7D1FC16EBD5083F360AFEDEF4882FDC
                            SHA-512:E246AB564DFB2F66A2B2F721E33C2BB1C947B3545378D2A9ED0E262F58F12B49A364A37C0A8FA330367E108DD0A310073E8CDA0F59DC8DF69A1F43128DBEB8B9
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "strongAlertRef",. "id": "130",. "alertIds": [. "1",. "2",. "3",. "4",. "5",. "6". ],. "onEmpty": [. {. "type": "nextCard". }. ],. "child": {. "type": "viewStack",. "id": "bulk-viewStack",. "views": {. "bulk-accept": {. "type": "column",. "id": "112",. "children": [. {. "type": "row",. "id": "50",. "left": [. {. "type": "icon",. "id": "46",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "49",. "left": [. {. "type": "block",. "id": "48",. "parts": [. {. "type":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):40936
                            Entropy (8bit):2.51031089079267
                            Encrypted:false
                            SSDEEP:
                            MD5:EB43D9A8BAC2A148424326FEDEC18292
                            SHA1:01E08904365763FD6C0C41DE986E68332449182B
                            SHA-256:A56558A5B0855A16C8A189602564137E4F564EC4B447EACF3BB2D8124755AA8A
                            SHA-512:345A287235EFC3FD7EF0BD2F1C946BB8B236285893E7098FE248EEC748A6798C47AFF852C7A32681A7DD527FAB74A74C01AF6969751A479E7EF36ED257DF8237
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "strongAlertRef",. "id": "113",. "alertIds": [. "1",. "2",. "3",. "4",. "5",. "6". ],. "onEmpty": [. {. "type": "nextCard". }. ],. "child": {. "type": "column",. "id": "112",. "children": [. {. "type": "row",. "id": "50",. "left": [. {. "type": "icon",. "id": "46",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "49",. "left": [. {. "type": "block",. "id": "48",. "parts": [. {. "type": "text",. "id": "47",. "meta": {},. "size": "small",. "text": "Correctness . Add a period",. "textColor"
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):29789
                            Entropy (8bit):2.5955806228436047
                            Encrypted:false
                            SSDEEP:
                            MD5:445FBAE53978919F3E8335A850553972
                            SHA1:F2398D6E962B33F02C1A229B9D7131A1311C90CE
                            SHA-256:3A484846F1B424B78F114A130B4C9BEB30127E78F4DACC57927BDFBE7DA191EB
                            SHA-512:B7DCEABEC00411A73D52A48C00A6A5BEE60697824C1100E9962DCD6FF5564167C3C199A37A232839DD105172F9598662D1D95CB5D7327D16A5A05856C5E03A50
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "strongAlertRef",. "id": "63",. "alertIds": [. "1",. "2",. "3",. "4",. "5",. "6". ],. "onEmpty": [. {. "type": "nextCard". }. ],. "child": {. "type": "column",. "id": "62",. "children": [. {. "type": "row",. "id": "8",. "left": [. {. "type": "icon",. "id": "2",. "meta": {},. "source": {. "kind": "known",. "name": "sparkles". },. "backgroundColor": "CoreYellow1". },. {. "type": "row",. "id": "7",. "left": [. {. "type": "block",. "id": "6",. "parts": [. {. "type": "block",. "id": "5",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):13173
                            Entropy (8bit):2.84708562985151
                            Encrypted:false
                            SSDEEP:
                            MD5:25E82334B91B3E6CF735793FF4090924
                            SHA1:B182B507016F51AE35007611D90B19F8520E6DDC
                            SHA-256:18336C03841E76B13E68A7B78E5E33345C05F20C3CA766216D5A1C31146B7C38
                            SHA-512:B55ED89883B7174C8B627BB2F4743D47F1133F1CA821F9A875B2BE57AD9A00A7435B38DB83F0EA4319541B8181FD4D4209D91AAD47BC4531D403F0487D859BB8
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "29",. "children": [. {. "type": "row",. "id": "1",. "left": [],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "title-row". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.25",. "left": "0.75". }. },. {. "type": "column",. "id": "12",. "children": [. {. "type": "row",. "id": "11",. "left": [. {. "type": "block",. "id": "7",. "parts": [. {. "type": "image",. "id": "2",. "meta": {},. "name": {. "kind": "unknown",. "value": "bulk-dismiss-buffer-card-content-image". },. "url": "https://assets.grammarly.com/icons/v1/bulk-dismiss-buffer-card.2x.png",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):14549
                            Entropy (8bit):2.6921119410598555
                            Encrypted:false
                            SSDEEP:
                            MD5:8FE29B33F30E246D3CA3ADC578B6E851
                            SHA1:835CA3A2E50F05E319585AA72E5CB245F43C5922
                            SHA-256:5D0321839C2ABDF848598AF4C976236574A39F3475EEC60F3BDB0E994DC7F94E
                            SHA-512:F946990E0858479B145F3F175C66652D9275FBBB124C9F9F50BA60E48227C1D1605D63AF7440388CD33E554A0E4292F46B78E514BD1F7EFBAF8CE3216F58AF65
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "31",. "children": [. {. "type": "row",. "id": "29",. "left": [. {. "type": "box",. "id": "14",. "child": {. "type": "column",. "id": "13",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "default_button". },. "kind": "darkPrimary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):14561
                            Entropy (8bit):2.6944021622667917
                            Encrypted:false
                            SSDEEP:
                            MD5:8869E9FACA2A26323347F52374E125F9
                            SHA1:109E54EF82B8BFCAB57DFACC3037C13289A63152
                            SHA-256:2FFFE238E940AC36AB3EB3E2EF29D7294E15C4B2EC584E3B23BA74639469D7BE
                            SHA-512:C1FDA8606DEDC18BC13047EA53701C0E9E5D3C4F636A8178B5ADA57384D6E9033CDDC78CD8D08ACBAE27387451A376716C9B68B0C7C9F46CF423012B61075592
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "31",. "children": [. {. "type": "row",. "id": "29",. "left": [. {. "type": "box",. "id": "14",. "child": {. "type": "column",. "id": "13",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "default_button". },. "kind": "darkSecondary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4663
                            Entropy (8bit):3.284459467616275
                            Encrypted:false
                            SSDEEP:
                            MD5:DFAF09ABCFEF54A2CA1C6321B4B1E8B2
                            SHA1:F33ACA39633D0482E979FF1D23445F4097611652
                            SHA-256:E5E19C7CBD4A2A74F45666F7CA7B44AECCE7487D83AA30613E9E5ADC7971E785
                            SHA-512:09988761F217D69E8549BC8D074C5225ECEFB74CC8CFB755E875C83C0BB1DB491313A41013483C2BDD11702A38C3BEBAD137EDC364D9B07EBD0B83C49BEAC6DF
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "13",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "default_button". },. "kind": "ggoPrimary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Enabled by default",. "textColor": "CoreNeutral0",. "format": [. "bold". ],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "textContainer". },. "spacing": {. "top": "0",. "rig
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4513
                            Entropy (8bit):3.306983492869207
                            Encrypted:false
                            SSDEEP:
                            MD5:C31C9E13621D07023320FC4A74CBE105
                            SHA1:8E27C81964A6F1E79FBC0A5D2B5815329979BC97
                            SHA-256:FBC793D937C2B739A296FD92080F05D25F6606EFAF9C7119CC6F48C7F8DC55D9
                            SHA-512:871F7225D82296B8F488827F54BA8C0861E83E63EDD6812341ADCB259A84D4B26E0E3A37D666A80F4C457907BFB7C3F51F9E250C84E3419CA9C2087BFFADFD5E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "13",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "default_button". },. "kind": "link",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Enabled by default",. "textColor": "CoreBlue40",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "textContainer". },. "spacing": {. "top": "0",. "right": "0.5",. "bottom": "0",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):14739
                            Entropy (8bit):2.957964432937597
                            Encrypted:false
                            SSDEEP:
                            MD5:9E71618BC497E12D99F5EDC7EC5B7F7F
                            SHA1:B21AE4E2D78B4ED2133356C9AF7174D6F78C82A1
                            SHA-256:2B2782E6D919AD90B64ADE4FE70022AAE95F3E2F3C48140D69316581DCBB92DE
                            SHA-512:750C20A393B3F1F6776310DB5F97D9306EDFE077BBE77945228CB8F7CF583038AA31B8681BD35865A431E173F56355A65330C1BD58FD5298AFD04A4B2C8E13E9
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "38",. "children": [. {. "type": "row",. "id": "35",. "left": [. {. "type": "block",. "id": "12",. "parts": [. {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "tone". },. "kind": "outlined",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "icon". },. "url": "https://assets.grammarly.com/emoji/v1/1f913.2x.png",. "width": 2.5,. "height": 2.5. }.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4528
                            Entropy (8bit):3.314886698319036
                            Encrypted:false
                            SSDEEP:
                            MD5:E908FD7B742B6B77C91296F142BDA997
                            SHA1:7AE555A63B5804EBBE137D4B40F574E4D9992199
                            SHA-256:C3474F8CBCABE7FBB275EEC8C2AD69D21C10E747E37E04529E7A138D956DFDA1
                            SHA-512:CCFB93FBFD3FF872F58B71D759E908C8D0F76BFBB15A84DC25E7459DB9C150BE5B7F066E67B59DB546C6056531FB59FA897EEACDFABE1919A74F99F04588754C
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "13",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "default_button". },. "kind": "primary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Enabled by default",. "textColor": "CoreNeutral0",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "textContainer". },. "spacing": {. "top": "0",. "right": "0.5",. "bottom": "0",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4537
                            Entropy (8bit):3.3207430071864295
                            Encrypted:false
                            SSDEEP:
                            MD5:BA7242B684213E5A7589056CEEDFFB2C
                            SHA1:7FEC21432C736233784C1F4DC4443C775445A546
                            SHA-256:F1DBEA5EB09D81990B4435DBC8A35AD1F2F1D99E4C752CBEDF4121F3AB2D9B1B
                            SHA-512:9BCD192314EE18091931D32BB77D18B52A2567BD76639DE384E5451C72154D3833D1E4FB34CCA40C8023DDD4BAC5273CC1B0622B4C1CC2B2EE7D650970B24BE8
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "13",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "default_button". },. "kind": "secondary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Enabled by default",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "textContainer". },. "spacing": {. "top": "0",. "right": "0.5",. "bottom": "0",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):6016
                            Entropy (8bit):3.3119339475080274
                            Encrypted:false
                            SSDEEP:
                            MD5:24161B72A40F0B622E5585D68EEB26CD
                            SHA1:EA97C835EB9246D479BDD6F8EFD85CEB156B2F84
                            SHA-256:BD0D8AD928358881309A7395986D6087C99A2C9116281179D95E9FAF7ECD886C
                            SHA-512:686E3E5F001ABD518585A6AB64DA5102B0C9D98ABBC44A7C5EA7EA056DA7ABFB14CBBF97D5FB282362F33D52086602E2546E1ED12D17782B139BC2C2F35BCEFE
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "17",. "children": [. {. "type": "row",. "id": "13",. "left": [. {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "default_button". },. "kind": "toggle",. "state": "deselected",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Deselected by default",. "textColor": "CoreBlue50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "textContainer". },. "spacing": {. "top": "0",. "right": "0.5",. "bottom": "0",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4525
                            Entropy (8bit):3.3162136919351366
                            Encrypted:false
                            SSDEEP:
                            MD5:3771CFF791CBA9AFADF1D28B84EFF67F
                            SHA1:55254FB90263E26D957D9462CC6125EDE441C5F9
                            SHA-256:717967B1408AEAC218422D65A531F416AC1C4966E97FDF44ECC20DE0C6107449
                            SHA-512:D219928CD42E8524F19063F5FE245A19E38A6E2B69A8D67A1FAD0761AE53294F45A7DC2DCFD45A045DCC3716E5FDF54401529C2B9FF43ADD5B38EA5C958D70C1
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "13",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "default_button". },. "kind": "yellow",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Enabled by default",. "textColor": "CoreYellow80",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "textContainer". },. "spacing": {. "top": "0",. "right": "0.5",. "bottom": "0",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):5220
                            Entropy (8bit):3.2092134242356276
                            Encrypted:false
                            SSDEEP:
                            MD5:4F0ADB91ED3DF411B2CE81FE0B55DE1F
                            SHA1:C01E737751AF04B46357C7420BA8DC02E5E512B8
                            SHA-256:C8713A829956F474C36A95200C67DBE0B87C18B00300B2661CB72572D5DA755F
                            SHA-512:F37D429BE61DAA7A2F9FEDD3A2FDBB09F27240E02B7C63504575F1771B83A2526F2D1B411B0637FEA8267C03C41A20D5EFAF67FD37FE9AA704D728CE4FFB92BB
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "14",. "left": [. {. "type": "row",. "id": "8",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "13",. "left": [. {. "type": "block",. "id": "12",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Small text, many icons",. "textColor": "CoreNeutral5
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):5275
                            Entropy (8bit):3.231510311483688
                            Encrypted:false
                            SSDEEP:
                            MD5:9EBEA4CED4A2732046A89031BF545D27
                            SHA1:A4ACDBBE39EC383C082F0619025D51BCE3FA3C04
                            SHA-256:66A6624BA4BCA1203CD8185D00538B44C772CAACD30A11E9AF375E413B72375C
                            SHA-512:AD560B26536889C045A1E30A883D658081332F94FCC82E38F8F26C14112562F03D113572342E2D82CC974B6162ED0E7D532D6387773D040987870F6C1A2C9498
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "14",. "left": [. {. "type": "row",. "id": "8",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "13",. "left": [. {. "type": "block",. "id": "12",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Change to sound more fluent long title example, which overflow in
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):3527
                            Entropy (8bit):3.287285526820792
                            Encrypted:false
                            SSDEEP:
                            MD5:93ABFDB5E7754674CA7EE5896BAF05E1
                            SHA1:4A9EDCDB65CC46CAAA432851D7E40333444EE2DC
                            SHA-256:55527E0361B02EFC94F1629F2E8379AF41F44AA1826F05F6362E1D2CC2201ECB
                            SHA-512:4F635FC796DF8BEC5C12C920808EB5394960085285B8CBF8D9D0B43F009895EA45A92EEACCB342103C4366A04EDC2329C74123E9E30755954B82C9B95C9C6F4E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "10",. "left": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "8",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Change to sound more fluent long title example",. "tex
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):3558
                            Entropy (8bit):3.305729235121329
                            Encrypted:false
                            SSDEEP:
                            MD5:B2C551D744A9F95ACD217E0D0A5999B8
                            SHA1:14D131580AA4D45B9BF125D50487D58165778A2E
                            SHA-256:EACEA96AF4C9609BD685AE38158BE7C282152828048D09FB51E333E6A5FB21D3
                            SHA-512:30DC810DEDF3C58244C6284795522ABDDCF1879D2F6E10F370D29E0F9C2E35DC119D1206D8FF8B527FEB5012484314D2EE30B0B12D5F28370E4B3BEB727443F0
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "10",. "left": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "8",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Change to sound more fluent long title example, which overflow into
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):14642
                            Entropy (8bit):2.9258692328489158
                            Encrypted:false
                            SSDEEP:
                            MD5:60ABF51D1ACF97467D51149D6DA5CF9C
                            SHA1:FEE0BFA5BDF1B868D1AFAA69DC1E1712085E7E44
                            SHA-256:572729A93B5F90E262FF862D4E47F9574B436D4B43DAFF0CE1253BC02310F71A
                            SHA-512:585064E575D8111EBE98648B951FB983703435112EFE11A81169309DFDD76CDBC1FA72A7F2D592269C9CC32937FD4B9EE148C3CCA9E36A7E5484053358B8234B
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "31",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "8",. "parts": [.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):14788
                            Entropy (8bit):2.9182252067745145
                            Encrypted:false
                            SSDEEP:
                            MD5:1FCD3E898F825F58724AD52420F1BCBF
                            SHA1:9B30159BB4270120A1D1E0111769BFC395C3FEFE
                            SHA-256:B10022E176D4DC2C91D84C08BF5FC3CBFB959ACA3895AF79162E236A9A35570A
                            SHA-512:9E62F73C3DF35BB2670BEC123A5DCDE03FDD1E809C8F63C03071027C82D5BA5407628C19B1DB5CD8D184A8091AEB854E787AC00398DAE68C9A258C776C755B52
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "35",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "8",. "parts": [.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):22686
                            Entropy (8bit):2.6072010088575404
                            Encrypted:false
                            SSDEEP:
                            MD5:B9D510FB0C0FA91B8989225F6D0936F6
                            SHA1:5987E0FE5644452A8BB12A0F7FC0E2E93CCAF73D
                            SHA-256:4AE3A2845A7C0497DB77C2B40ABF9461640A4830D6BF010CBA07DC0C8563AFA7
                            SHA-512:34ADC312BD9DD85CF525C2E3AE2D1D6C2D4F8F963A248F15F540949D8180D6F60A91185726CBDF926D42137E7990DE982F4530122C1BA8EFF4DCF5347059F3F1
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "41",. "children": [. {. "type": "row",. "id": "18",. "left": [],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "title-row". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.25",. "left": "0.75". }. },. {. "type": "column",. "id": "27",. "children": [. {. "type": "row",. "id": "26",. "left": [. {. "type": "block",. "id": "22",. "parts": [. {. "type": "image",. "id": "19",. "meta": {},. "name": {. "kind": "unknown",. "value": "citation-style-card-content-image-icon". },. "url": "https://assets.grammarly.com/sdui/v1/citation-style-card.2x.png",. "
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):52935
                            Entropy (8bit):2.4924351536943417
                            Encrypted:false
                            SSDEEP:
                            MD5:6191DC406E67D8C00A0BEEB78CA1EA07
                            SHA1:E9BB37638BB77734A0EB96A89D5589C5F0C87289
                            SHA-256:510C2F8328501C330E7365A9C69DC2A2E0F1F484C665983B16BEDE037E5E7836
                            SHA-512:B1B1F5B8417F9B81C0A084C8A1DDE3E3C5279104BBC3AB199AD0D4E5AB7FEF1C8D44B539F57070F304668516602A3BA9A2C8AAF8B509D7329E13EF61B415BB12
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "strongAlertRef",. "id": "96",. "alertIds": [. "1". ],. "onEmpty": [. {. "type": "nextCard". }. ],. "child": {. "type": "column",. "id": "95",. "children": [. {. "type": "row",. "id": "81",. "left": [. {. "type": "icon",. "id": "77",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "80",. "left": [. {. "type": "block",. "id": "79",. "parts": [. {. "type": "text",. "id": "78",. "meta": {},. "size": "small",. "text": "Resolve inconsistent punctuation",. "textColor": "CoreNeutral50",. "fo
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):2938
                            Entropy (8bit):3.6144630662024615
                            Encrypted:false
                            SSDEEP:
                            MD5:5AC21F49646FB8D05EF3A4523D855A8F
                            SHA1:E8B1F5AAF440F16C093DBA6BB4F281755AB06EB6
                            SHA-256:DA5FF89EA231C02461FFA1E3A1F560DF396833546618BB9ADFC1EF4B851A61D7
                            SHA-512:2B481D9F14A12A4B8CDA8FABEF4DDD56583CB59DED0F0F3011E21E762A9D924F8CBB605011A47CFC44EFCCD3B6262DAC0F341B6C00E07A6578C9FBA9697218A0
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "7",. "parts": [. {. "type": "button",. "id": "3",. "meta": {. "label": "Previous suggestion". },. "name": {. "kind": "known",. "value": "button:prev". },. "kind": "secondary",. "state": "disabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "arrow-left". }. }. ],. "name": {. "kind": "unknown",. "value": "block-prev". },. "spacing": {. "top": "0",. "right": "0.25",. "bottom": "0",. "left": "0.25". },. "verticalAlign": "middle". },. "actions": [. {. "type": "prevCard". },. {. "type": "transition",. "fromName": "title",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):9534
                            Entropy (8bit):2.7744475061817786
                            Encrypted:false
                            SSDEEP:
                            MD5:BD95E8E9BBA034636C923BE38BCAEA4E
                            SHA1:9534E58C0CA44546BD2F264C331387F886BF6E10
                            SHA-256:167EDE23CF2756E7AA1568C2F4801471F562DFA9B24772EA3532068578B9744F
                            SHA-512:4D3267295A22CF0DBD6BB4E62304F484FAF11E1F392B09C95C2E16CE18CA8EEA8FE1E85572BD180334692120ED5DAC0F186B3907F32BDEAA4E5327828E825679
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "26",. "children": [. {. "type": "box",. "id": "25",. "child": {. "type": "column",. "id": "24",. "children": [. {. "type": "row",. "id": "4",. "left": [],. "right": [. {. "type": "button",. "id": "3",. "meta": {. "label": "Close panel". },. "name": {. "kind": "unknown",. "value": "close". },. "kind": "secondary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "c
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):10249
                            Entropy (8bit):2.812054850987549
                            Encrypted:false
                            SSDEEP:
                            MD5:C5273C9EEF652B6A4FC15F2D544048DA
                            SHA1:B0320DFB07303041FE768FF4B159B9D61B67E0FE
                            SHA-256:33D8DBEEA19E884190D447B7871497161427591AA8A0C5554B6BE0F25F9D98A4
                            SHA-512:03ACBB6D8850FA8561FC61575EBFF6E08562F14E9ABABB63048766B83FD48A56B9D0A5F6DB93944EE0E2EB2FE6C5B2EC5C4EFC2FC77D4A0FF7ECBC49E334597B
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "30",. "children": [. {. "type": "box",. "id": "29",. "child": {. "type": "column",. "id": "28",. "children": [. {. "type": "row",. "id": "4",. "left": [],. "right": [. {. "type": "button",. "id": "3",. "meta": {. "label": "Close panel". },. "name": {. "kind": "unknown",. "value": "close". },. "kind": "secondary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "c
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):11743
                            Entropy (8bit):2.5557932351920996
                            Encrypted:false
                            SSDEEP:
                            MD5:F7C7BFCFBEB92422D586E1D91DDA2A28
                            SHA1:AA7AE3A51215E77D353CB650627D4F1AD4DF03E1
                            SHA-256:5E036EA3AFEF92B20306EAD42B3EEEC049FB4D8772E53FA447CFF3E547EF720E
                            SHA-512:6E537A9B2688CE018D7B30DB8098F543DD87E2A02573067F40F7ACA1075B2BFF96B54BAA52895EE60090EC1FDA1F4D3263F73475819DAD70E9DE2CC59C0782E3
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "27",. "children": [. {. "type": "column",. "id": "26",. "children": [. {. "type": "box",. "id": "7",. "child": {. "type": "row",. "id": "6",. "left": [. {. "type": "block",. "id": "5",. "parts": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "opt-in-image". },. "url": "https://assets.grammarly.com/sdui/v1/premium-shiny-diamond.2x.png",. "width": 9.0,. "height": 7.6. }. ],. "name": {. "kind": "unknown",. "value": "image-container". },. "fraction": 1,.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):162
                            Entropy (8bit):4.1632261812484135
                            Encrypted:false
                            SSDEEP:
                            MD5:B2171FDCFFE50BEDB519941CB53337F7
                            SHA1:1F631F4C2A4F065CB1E82134FAB80595020C14E0
                            SHA-256:22739A7CEFE8CE6947D33CF4F5622A609BA1061B3318DAAB05D7DBDDCB8D6145
                            SHA-512:B8E8483589A4A527FB16408BA83A51486744016B926911C03F3DBAAA27B4F9D72A0EE695DEEAD47DCED23B7DF0359578FC624FF3DB3E10E5FBA18CE93EF926EF
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "gButton",. "id": "gButton-default",. "meta": {},. "actions": [. {. "type": "pushAssistantFeed",. "feedId": "default-feed". }. ].}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):172
                            Entropy (8bit):4.262077302766162
                            Encrypted:false
                            SSDEEP:
                            MD5:B20172519863FA5825B5FD31B3DED1DD
                            SHA1:AF049116B1D1E16025122CFF19EC1125FB6CC644
                            SHA-256:28EF24C374E4A507E3D54CF46C9C3ACB9AB457758E11473D9E242B4ED8967109
                            SHA-512:F027749D734371F905E14F287DD43997C2CE7523C3EB9CBC598AF5698046737F1896EBBE270521F7712385AC280E80B65BB1267B0A087C502B0CDA96491051F9
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "gButton",. "id": "gButton-experimental",. "meta": {},. "actions": [. {. "type": "pushAssistantFeed",. "feedId": "experimental-feed". }. ].}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):245
                            Entropy (8bit):4.114501498563662
                            Encrypted:false
                            SSDEEP:
                            MD5:8CEA73ADC02DE5A91865614D75F04608
                            SHA1:A84654A1B0E11ADE31842297454F690A6D32C5A1
                            SHA-256:F73004140A9D6D8C8D2B033228DE59B74DFE5DE55E8EC308E83F8E4DD91005C4
                            SHA-512:F25EADF03AA2D5CFDB21BBE414808C711535A3D8BC91B915787AB2934A2F14E8FC482DBEEC1D4B29A87A1005DE09D71AE9265FB8230BAF2B927B3BF66B3AA12D
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "proofitButton",. "id": "proofitButton",. "meta": {},. "actions": [. {. "type": "pushAssistantFeed",. "feedId": "default-feed". },. {. "type": "pushAssistantFeed",. "feedId": "proofit-feed". }. ].}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):249
                            Entropy (8bit):4.157516064589453
                            Encrypted:false
                            SSDEEP:
                            MD5:03649C9D9C208C9E1647D49000DCCA46
                            SHA1:3B350EA0CF2BFF9E4E27C82E5F1DFFB2C82F98DA
                            SHA-256:273D8D54EACB60DF3FE9EC2FAE2648105F4315B0B906F9B8AFBDD7194F91A653
                            SHA-512:F1F0C8F84D7BE40004FF2C89AFAD45E3FB34770C8A8F7D625629D100313784B9690BC3A899ECE9C1AF55E0C90FFFEACE4A707986D049AA0488D55ED50B17BF38
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "gButton",. "id": "gButton-tone",. "meta": {},. "actions": [. {. "type": "pushAssistantFeed",. "feedId": "default-feed". },. {. "type": "pushAssistantFeed",. "feedId": "tone-insights-card-feed". }. ].}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):69601
                            Entropy (8bit):2.4466962722111596
                            Encrypted:false
                            SSDEEP:
                            MD5:894EF95567B4C3561413DE3514128E29
                            SHA1:F53410D069604533D142589A5E743ED951E9A276
                            SHA-256:366DB1D7D60BA7C3DA05015232E0148E4F5DC216369D2670B889824CA348977F
                            SHA-512:5FD9012143746E6B9A9A5D806981E0A055CEA3F75259A8731A27F44D5748110AA9A0C906B19B084BA730C43059B3EF1E9A0D825A7B105531B6AC7D5778E1010B
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "strongAlertRef",. "id": "129",. "alertIds": [. "1". ],. "onEmpty": [. {. "type": "nextCard". }. ],. "child": {. "type": "column",. "id": "128",. "children": [. {. "type": "row",. "id": "114",. "left": [. {. "type": "icon",. "id": "110",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "113",. "left": [. {. "type": "block",. "id": "112",. "parts": [. {. "type": "text",. "id": "111",. "meta": {},. "size": "small",. "text": "Resolve inconsistent dates",. "textColor": "CoreNeutral50",. "f
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):70867
                            Entropy (8bit):2.44162549136341
                            Encrypted:false
                            SSDEEP:
                            MD5:39BAA8B1FBB1E1238EE00581762BE01D
                            SHA1:6090DEF51AB664382FF7CE886DE9CC5102FFA4C7
                            SHA-256:9640DF2542474E21B0931268EED00FEAD8140640CAB6B263ACB4470199A612FC
                            SHA-512:28A7E7678B5227E7B206758BCFADA4FEC01BBB09F6DADA0C700CE9C33C8ACD266A155395C734D527FC3242A7AA36A641EFC2CF49BDBC56B2E29B37ED6D2D4F4E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "strongAlertRef",. "id": "129",. "alertIds": [. "1". ],. "onEmpty": [. {. "type": "nextCard". }. ],. "child": {. "type": "column",. "id": "128",. "children": [. {. "type": "row",. "id": "114",. "left": [. {. "type": "icon",. "id": "110",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "113",. "left": [. {. "type": "block",. "id": "112",. "parts": [. {. "type": "text",. "id": "111",. "meta": {},. "size": "small",. "text": "Resolve inconsistent dates",. "textColor": "CoreNeutral50",. "f
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):584
                            Entropy (8bit):4.060117619010496
                            Encrypted:false
                            SSDEEP:
                            MD5:BD34D6871FC8663461D573E67541D21D
                            SHA1:D8827F39E48FB05ABC6EEF46E4B68A99510A0C7A
                            SHA-256:0801DD5E55D4029D1240EEBE708C57C73C8102A7211007973EFC477FC31139D1
                            SHA-512:B73DA59FDDAD081893F54007A75168AA68848E7507A581F98DBADD9AB45F82BD549360BBDC952653CB57B1A77DA87E3706529A02812EEB6F2EB215FA63134387
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "4",. "children": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Before... ",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "globalPartPlaceholder",. "id": "2",. "globalPartId": "default-sample-placeholder". },. {. "type": "text",. "id": "3",. "meta": {},. "size": "regular",. "text": " ...after",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. }. ].}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):68258
                            Entropy (8bit):2.4780050271282192
                            Encrypted:false
                            SSDEEP:
                            MD5:9699397397E69037BB7C4C755B41A9DE
                            SHA1:F7ED609DF79559FA6DBC8EA39331E512C047AE54
                            SHA-256:3B982272E263D683AF95200FA97818598C1E5415AA5E85D3A41E7663D53F0F15
                            SHA-512:9FC9BC89C62B7C3FC12A674A3CBF8C5312DD84725C16C52B5F4FE5C11A7B23F9BE5996F5755E48E53A24EB73AB59F676B4D1BAF6830FD8C9BA9E813CA261F79A
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "99",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "8",. "parts": [.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3477
                            Entropy (8bit):3.3589785007570603
                            Encrypted:false
                            SSDEEP:
                            MD5:1C30786D33657E3A807DDD665D88923D
                            SHA1:2F5CAE1EE8C98AFDA2126D9DEB822129E0290577
                            SHA-256:AC597A65A99248E2ECAE693331D7D896971F48C115BED135AD1E17024FE4E14B
                            SHA-512:6AD7FE725DA8D4A16F1A1C20C87DEEF1D5E69B2AB91D161BAEB5B5475173A114C62E668C8DA63380843E2B15322DD5AC63760FEEB7EB65EE672011D93757170E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "11",. "children": [. {. "type": "row",. "id": "8",. "left": [. {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "enabled_button". },. "kind": "primary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Enabled",. "textColor": "CoreNeutral0",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "textContainer". },. "spacing": {. "top": "0",. "right": "0.5",. "bottom": "0",. "l
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):57
                            Entropy (8bit):4.113358988404305
                            Encrypted:false
                            SSDEEP:
                            MD5:1696B86D2BD180AC9C31263E037F251B
                            SHA1:1169262F4C638A745CAE445C990F92D40F705528
                            SHA-256:A825E8C240C4576807386CCC51D6EB9546311FEF8661771BE829E87BEECC6047
                            SHA-512:8BF51DE5959D6AE513C15AB48A2D2CEBD87B0E78C0E304945785BAC86B03F1F075EE7C111E5848DF4855DCA1089E5B4E8EDE1B62159ABAA5148288FBE6D1A417
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "horizontalRule",. "id": "1",. "meta": {}.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):12620
                            Entropy (8bit):2.875104564464711
                            Encrypted:false
                            SSDEEP:
                            MD5:084ECD99F1B6A1C375D863628181AB0A
                            SHA1:EA2927412BEF92851D2706F92A2DD58E27F40FDB
                            SHA-256:A8DF49E726FF6AC92F6EF3F766AFA3F6F8949658E29FD87D454EE9BFC54B7A0C
                            SHA-512:4B90AE4BB379A71AE7E6F35B9609D9A3FE38375E1FA2609468E9156D921DA34C4705ADF827474AA1FBCB523AE89CD536E54C1C958AACDE429C1A9F89270CBF7B
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "32",. "children": [. {. "type": "column",. "id": "14",. "children": [. {. "type": "box",. "id": "13",. "child": {. "type": "list",. "id": "12",. "meta": {},. "items": [. {. "id": "11",. "meta": {},. "label": {. "type": "box",. "id": "10",. "child": {. "type": "column",. "id": "9",. "children": [. {. "type": "row",. "id": "3",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):12586
                            Entropy (8bit):2.866913253324193
                            Encrypted:false
                            SSDEEP:
                            MD5:D21623E673EC10A69C72A8D7B71FEDF4
                            SHA1:ABF48EF5D30EF5870CCF16C54D99642D589ED802
                            SHA-256:04D4218A19BFB43B7E165DC1A1AF98685DDED6494A8F68A7465E01875E29B51E
                            SHA-512:42B2BE2AD86D5A8A5AF36684E22237E943A6017DC0DAD62200B38D01A08D13393875ED4C6CC0685E2C429A6B5D590AE6BE85E2D1538535CF64517A952DA1B7A6
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "32",. "children": [. {. "type": "column",. "id": "14",. "children": [. {. "type": "box",. "id": "13",. "child": {. "type": "list",. "id": "12",. "meta": {},. "items": [. {. "id": "11",. "meta": {},. "label": {. "type": "box",. "id": "10",. "child": {. "type": "column",. "id": "9",. "children": [. {. "type": "row",. "id": "3",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):10092
                            Entropy (8bit):2.8387105468826315
                            Encrypted:false
                            SSDEEP:
                            MD5:6B69D15E3E0FA4FD75C71E33C28222B9
                            SHA1:8685B59570CA218FB388AFF87DEBCC1269CFCACB
                            SHA-256:A8226D515212E35E3418E5E2C595438FE877576CD8B36BA69157DBA04047C738
                            SHA-512:617CBF17C200B5C2C34D9D0FFD5D44FA93128BFED401E6A99EF43675BE94805E92C3FC608F0396F369D4D9F30369F773193F8CC5B8402320FD7D13F776DBC992
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "27",. "children": [. {. "type": "column",. "id": "9",. "children": [. {. "type": "box",. "id": "8",. "child": {. "type": "list",. "id": "7",. "meta": {},. "items": [. {. "id": "6",. "meta": {},. "label": {. "type": "box",. "id": "5",. "child": {. "type": "column",. "id": "4",. "children": [. {. "type": "box",. "id": "3",. "child": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):9305
                            Entropy (8bit):2.8730352725129604
                            Encrypted:false
                            SSDEEP:
                            MD5:2C38C217E80B68296F346CCEFB18AEB5
                            SHA1:AB158A359E4EE2F1128D80DD0DE5AA38FA074DE6
                            SHA-256:941C481F57041005BD4D7FCEB24F0F0436BF5C100C1495E3843F67E52023191F
                            SHA-512:8203A5621F7451C2D2D44D386ECBF8CBFB8A55FFBC1ABF370B55B0FD20FA7FA256D11E7AF69B90EADBF17E526D9F232F262171B55FC91126B8793061EBB7DCB4
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "25",. "children": [. {. "type": "column",. "id": "12",. "children": [. {. "type": "box",. "id": "11",. "child": {. "type": "box",. "id": "10",. "child": {. "type": "column",. "id": "9",. "children": [. {. "type": "row",. "id": "3",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "small",. "text": "Add a.page number",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):11752
                            Entropy (8bit):3.0239684823223807
                            Encrypted:false
                            SSDEEP:
                            MD5:522D71EC5983ED92832CCC5B9AB031FA
                            SHA1:ECC43CD80553154B8EA857E9AD4EFAEDD2966B4F
                            SHA-256:9005AE6DA74427608DF797C53A0BCBEB90410F5356F998A89F17BCDF2941B22F
                            SHA-512:1B5BED59DD27361D9926371FD43CB8433AA1F73E096751A176A21C91F6A5AE3DCFDDF03BA32A09EF16110F72BF3A10549D1EF249DE30D763CCD6D10F7BFD1EE6
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "31",. "children": [. {. "type": "column",. "id": "12",. "children": [. {. "type": "box",. "id": "11",. "child": {. "type": "list",. "id": "10",. "meta": {},. "items": [. {. "id": "9",. "meta": {},. "label": {. "type": "box",. "id": "8",. "child": {. "type": "column",. "id": "7",. "children": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "small",. "text": "Rewrile in active voice",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. },.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):16201
                            Entropy (8bit):2.5918412379366385
                            Encrypted:false
                            SSDEEP:
                            MD5:D2F1FDDD4CD4DC20B369E6131606E1D8
                            SHA1:62953908D83ED77D8C6EA30296F10C2F830BD7BB
                            SHA-256:125DF526931CE58577057683FB21D534A05751932102E628DC3FB4613A497DA5
                            SHA-512:77B0485D07CC7C3EC8B1BDB96659FC6C6B2CD4CF5D74547BE92336A06B4AD8AA9E713D8A43FFFF895A29A4C8B4BB9514216205527D17800BBF8F456F3A84CF95
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "37",. "children": [. {. "type": "column",. "id": "24",. "children": [. {. "type": "box",. "id": "23",. "child": {. "type": "list",. "id": "22",. "meta": {},. "items": [. {. "id": "21",. "meta": {},. "label": {. "type": "box",. "id": "20",. "child": {. "type": "column",. "id": "19",. "children": [. {. "type": "row",. "id": "3",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3351
                            Entropy (8bit):3.2264028532970097
                            Encrypted:false
                            SSDEEP:
                            MD5:602DEB94AB336A0316F4D10CD001D89A
                            SHA1:8BDE43D991C992ACE951B18E009D3172F7E1FE1E
                            SHA-256:E4355CCFEA08B572897FB60C4BA5546F363AE3A7F6E3E9DD3F8CEAB9B98E0BBC
                            SHA-512:6CC22FAC3BE7EDAD207474C59F34BE5668C30A0EFEA7DB2F3BEB025A6D93C4426C485F9D67CE11CE0515AC05D6B2F7771FA551B9FACFDCC2DA91465A8AAC9FF9
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "inlineCard",. "id": "11",. "meta": {},. "child": {. "type": "box",. "id": "10",. "child": {. "type": "column",. "id": "9",. "children": [. {. "type": "box",. "id": "4",. "child": {. "type": "row",. "id": "3",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "small",. "text": "Long",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "header-wrapper". },. "spacing": {. "top": "0",. "right": "0.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3296
                            Entropy (8bit):3.1996591088312467
                            Encrypted:false
                            SSDEEP:
                            MD5:37851D1AFA0C3ADD0EEB7ABEA4067A93
                            SHA1:CF03B682077BA8EFC2998865561A15DF7F0F4C60
                            SHA-256:A3F49913409386FCCD45F440899D2CEA0225107BF1BFC1FD23E5F6EAAEED9646
                            SHA-512:CAEB9CE13D30B1AB6C981209B7E0685598CD549F83DF0852DF54358552F184C7DFB6BC39BCD1096170A180A6C21AE3F9F521D8C33A17BBF68E6C7718DC320639
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "inlineCard",. "id": "11",. "meta": {},. "child": {. "type": "box",. "id": "10",. "child": {. "type": "column",. "id": "9",. "children": [. {. "type": "box",. "id": "4",. "child": {. "type": "row",. "id": "3",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "small",. "text": "Short",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "header-wrapper". },. "spacing": {. "top": "0",. "right": "0
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):13607
                            Entropy (8bit):2.6433634234314964
                            Encrypted:false
                            SSDEEP:
                            MD5:CA3E843082E29CD898EE9B3FD15DDC00
                            SHA1:8125B43338B5B0A6AB47565497E2E23B26BAA2DC
                            SHA-256:16FBBA076BAAE9043C83B20F930E393FDD85917858A1B68A1E062571181D95AD
                            SHA-512:A50BED494C107C1812894041FC65D65A1F9BD804940388A8BFDB17004E3E9C5F89D3426129B84AAAAA45A1AC4868EC79B1A06E4320A2CF79928C8F2C490BE235
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "32",. "children": [. {. "type": "column",. "id": "19",. "children": [. {. "type": "box",. "id": "18",. "child": {. "type": "list",. "id": "17",. "meta": {},. "items": [. {. "id": "16",. "meta": {},. "label": {. "type": "box",. "id": "15",. "child": {. "type": "column",. "id": "14",. "children": [. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):11789
                            Entropy (8bit):2.7305370376958806
                            Encrypted:false
                            SSDEEP:
                            MD5:A4C69F0E8000856F880E9176D5355531
                            SHA1:AC7B217955B58890FCC7853A01781C7485810112
                            SHA-256:72B316E62A10EEDF43E202E351BE51D504EF83D8467044BA76E21BC3FADD4C08
                            SHA-512:7C392BF20F6D1E278ED06912720FFF61B879610C4913113275EAC8D64B5573B40292AA0EE87A8DD71E16AEAB75C267006D9EF4779908A2CC77C8F388B2205C83
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "29",. "children": [. {. "type": "column",. "id": "16",. "children": [. {. "type": "box",. "id": "15",. "child": {. "type": "list",. "id": "14",. "meta": {},. "items": [. {. "id": "13",. "meta": {},. "label": {. "type": "box",. "id": "12",. "child": {. "type": "column",. "id": "11",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "url",. "name": "i
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):12566
                            Entropy (8bit):2.859780863182339
                            Encrypted:false
                            SSDEEP:
                            MD5:913EF6B2A46EFA1F0D105B239BBED921
                            SHA1:8D714826D6C2B2949F589F2E5C7A2F75489BE155
                            SHA-256:23590ABE3F4E9E8F5EFE1050C412AB59DAB6F978C2C6E05ED011AA0567524B60
                            SHA-512:F0F6E3230CC357ED4745B092863F680707C937FD9F2CC421C72BEA33F55E4DF919986B65CD3AD24789EB341854B194BCAAA80A967174AFEA197E5ACB12556F42
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "32",. "children": [. {. "type": "column",. "id": "14",. "children": [. {. "type": "box",. "id": "13",. "child": {. "type": "list",. "id": "12",. "meta": {},. "items": [. {. "id": "11",. "meta": {},. "label": {. "type": "box",. "id": "10",. "child": {. "type": "column",. "id": "9",. "children": [. {. "type": "row",. "id": "3",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):13322
                            Entropy (8bit):2.9170210132638865
                            Encrypted:false
                            SSDEEP:
                            MD5:181A2FB316A9869B9780CC3360C9E922
                            SHA1:7CB98C5EDDAC56CFA2A4939E71C76FCB71AF6A8C
                            SHA-256:F9DAAABA50082D5F674D382C6E80434669683776DAEFDB0AB443E7D8334ABB8A
                            SHA-512:835815068C3AC70BA39D3E813E28D7A5C702FABEF67668CE92267ABE30E594D806725FBD98FEDF2669CC1EE1D345724DBCEB9AEB4D63BD497D0A6C9ECB074DA1
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "33",. "children": [. {. "type": "column",. "id": "14",. "children": [. {. "type": "box",. "id": "13",. "child": {. "type": "list",. "id": "12",. "meta": {},. "items": [. {. "id": "11",. "meta": {},. "label": {. "type": "box",. "id": "10",. "child": {. "type": "column",. "id": "9",. "children": [. {. "type": "row",. "id": "3",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):10283
                            Entropy (8bit):2.9966228716894516
                            Encrypted:false
                            SSDEEP:
                            MD5:530D6CB44DE1C17614EBB50364581586
                            SHA1:29230D0066C91ABC11BB6260029EEF48FE985310
                            SHA-256:153D86CF50BAE1F435CC90C089ED6B7B38E84E178A98D903B7454E36B61D00E2
                            SHA-512:E6778DD0BD0BE2EC8685CEBC27F97BB209BDCF71229B41E3A28426DF5AFA5899CC605AF5E84AAF1C1042E6A5C87D76560A683742FE2261C8CCD57B5685E00440
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "27",. "children": [. {. "type": "box",. "id": "4",. "child": {. "type": "row",. "id": "3",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "small",. "text": "Type this often? Turn your text into a reusable snippet",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "header-wrapper". },. "spacing": {. "top": "0",. "right": "0.5",. "bottom": "0.125",. "left": "0". }. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):10611
                            Entropy (8bit):3.2431156755167474
                            Encrypted:false
                            SSDEEP:
                            MD5:BCCAE53E97A1CE7F7E475F9E8914C897
                            SHA1:4593FB951268417449BA237FB0F0FC9261B434EC
                            SHA-256:E393A0A96FCE90B37A77E35624247CAA71830F6ED9ED24BB5DAB5985151BAD2B
                            SHA-512:1DDA3DC32021444ABBD8BB91A3DE784D437F3F333110867F427377844ED61B5C81C39AC8652DE6943496B672E56CFE0ADDB4F23BF422CDE95C74F9901EF602A0
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "29",. "children": [. {. "type": "box",. "id": "6",. "child": {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "url",. "name": "institution-logo",. "url": "https://static.institution.grammarly.com/logo/ec8c59d1a4c7b0698cda682c3ee2f69ed3d7279d.png",. "size": "1". },. "backgroundColor": "CoreNeutral1". },. {. "type": "block",. "id": "4",. "parts": [. {. "type": "text",. "id": "3",. "meta": {},. "size": "small",. "text": "Grammarly style guide",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "na
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):9731
                            Entropy (8bit):2.7320777227457747
                            Encrypted:false
                            SSDEEP:
                            MD5:93B980A1A5BA78CDB1BC7455D1981AF5
                            SHA1:16A6CF5F44646E044A16E16F40FF77616179960C
                            SHA-256:13D13B88D6FB51F13017490C24B7BE02AE2D08A93B3BF449A2B7C380DC167659
                            SHA-512:42A7CEB6A8E214BD150C8E4ADE65C717909C739C743C44A5F70CB968DDD148AFBD2C8ED4A67A278330AEE72D78A51E52C71A86551CA61252B2AB54729A2D1FFB
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "25",. "children": [. {. "type": "column",. "id": "12",. "children": [. {. "type": "box",. "id": "11",. "child": {. "type": "list",. "id": "10",. "meta": {},. "items": [. {. "id": "9",. "meta": {},. "label": {. "type": "box",. "id": "8",. "child": {. "type": "column",. "id": "7",. "children": [. {. "type": "row",. "id": "3",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):10094
                            Entropy (8bit):2.838983790708947
                            Encrypted:false
                            SSDEEP:
                            MD5:4D1376A93120794B056D224B0D8CB1DD
                            SHA1:428FA973BDFCA8E5D4FF5C8EBCC95B9737F48719
                            SHA-256:869507FBE3B31DC63C84785BDE26253A72C5D3470161E2F40CDE377D650EA07B
                            SHA-512:DD7AFF790BD0838D9AA25C18F256C27F42E73D21CC43979519700A7FBE6E04831027C49D155C45B221608BE663A5C653DF4DA484C92D2853EE8130DB004467B6
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "27",. "children": [. {. "type": "column",. "id": "9",. "children": [. {. "type": "box",. "id": "8",. "child": {. "type": "list",. "id": "7",. "meta": {},. "items": [. {. "id": "6",. "meta": {},. "label": {. "type": "box",. "id": "5",. "child": {. "type": "column",. "id": "4",. "children": [. {. "type": "box",. "id": "3",. "child": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):15166
                            Entropy (8bit):2.6916137302786827
                            Encrypted:false
                            SSDEEP:
                            MD5:9C590904E17E803B3946BABF798A26BE
                            SHA1:EEBF20AEBD6F4C97408CA32B664C19262AD80F00
                            SHA-256:2A80CA66C72FC9436D7DF6E8C90C9CA23FCB5CBDE8A121F19816D81CA3244AE3
                            SHA-512:693D27C8124FD906149B0C6117A01960FBD9C50EDE436E52CB5A92067567EC4A296F435BF154623F211FF96969F23E9BED0DBB36E84A4FEC21706500E4613D69
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "39",. "children": [. {. "type": "column",. "id": "21",. "children": [. {. "type": "box",. "id": "20",. "child": {. "type": "list",. "id": "19",. "meta": {},. "items": [. {. "id": "6",. "meta": {},. "label": {. "type": "box",. "id": "5",. "child": {. "type": "column",. "id": "4",. "children": [. {. "type": "box",. "id": "3",. "child": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):11857
                            Entropy (8bit):2.9974306502656844
                            Encrypted:false
                            SSDEEP:
                            MD5:B1A547BB9C114CE78C43B8664580D76A
                            SHA1:74C2E497BAA6D89FCF766F8313E9153D41F618F9
                            SHA-256:DB410614337016784E6208710EFA1AEA04E899EA6846106B6DA37DE5AF39D8F3
                            SHA-512:A2672CC47CBCE5185509E2C926727B014CFF59579F2E18F3F7BF51FFB08B40840ECFE00A09FA088311BF720E93CACFD50EFCA4DB27E84A7FDA92434CFBB02A39
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "26",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "url",. "name": "institution-logo",. "url": "https://static.institution.grammarly.com/logo/ec8c59d1a4c7b0698cda682c3ee2f69ed3d7279d.png",. "size": "1". },. "backgroundColor": "CoreNeutral1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "New knowledge hub term",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):12467
                            Entropy (8bit):2.6468335577008726
                            Encrypted:false
                            SSDEEP:
                            MD5:03A5C9C603A3F3CC7ED60247F09E8DCA
                            SHA1:F1C7B0FA26B2B2195E47899263DB272A2CCB0D56
                            SHA-256:6E457938A5B6C25EFFC7C41D630B9B3917CB1C53C6A2606BB0EC7FF7C7233D0D
                            SHA-512:476CB7156E2C8CAFE5DE2E7E096B17EF858B54D418CEF1ECCE5218410E6A0E150304B9506BC39C3DA7E8129F6C5BB65F3095C4DD625F0074C7A221F438811FBC
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "block",. "id": "30",. "parts": [. {. "type": "block",. "id": "29",. "parts": [. {. "type": "column",. "id": "28",. "children": [. {. "type": "block",. "id": "4",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "The word ",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "effect",. "textColor": "CoreNeutral90",. "format": [. "bold",. "italic". ],. "selectable": false.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):4462
                            Entropy (8bit):2.986166577068902
                            Encrypted:false
                            SSDEEP:
                            MD5:917B1FB1182153D0AD2F4C040C5CDC20
                            SHA1:3CE253E3B106F28E3E73D0833C86002B8B0492A1
                            SHA-256:8EE3368E180B0D531DF166A52DD2935B2E849C8FFE7404A9379774DE598F47C9
                            SHA-512:D656E77816CBB4EA403D93EE00F217FB644D8F04DFCAF741A423505DE8E8C4066ED77DBCC27499F95CDB4AB3D9A2098EB916E931A8C0E882EC5FF9275769FFDD
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "strongAlertRef",. "id": "34",. "alertIds": [. "1",. "2",. "3",. "4",. "5",. "6". ],. "onEmpty": [],. "child": {. "type": "collapsedCard",. "id": "33",. "meta": {. "label": "Accept all suggestions at once". },. "child": {. "type": "block",. "id": "32",. "parts": [. {. "type": "row",. "id": "31",. "left": [. {. "type": "block",. "id": "29",. "parts": [. {. "type": "icon",. "id": "21",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". }. ],. "name": {. "kind": "unknown",. "value": "collapsed-card-outcome". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):3388
                            Entropy (8bit):3.1713333249956337
                            Encrypted:false
                            SSDEEP:
                            MD5:D57D633B140976E335F9DFF81877A117
                            SHA1:315B9EF8A361B20D5F9FB59DAF886A3D277486A0
                            SHA-256:F4A10EF5AEBE49695EA88741948F63B45940AF28D63F49976EE6633FA9D0EC1F
                            SHA-512:2EF36ADB3953E649637AAFC41103B0018CFBA8D772842ED8BDD074A01AA9FFE00A5C5EF2858B629490048C4741EA092EC337A70EE411CBD6167D8ABCBBE027AC
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "collapsedCard",. "id": "11",. "meta": {. "label": "Correct your spelling",. "description": "delete \"effect\", insert \"affect\". Click to expand the suggestion details". },. "child": {. "type": "block",. "id": "10",. "parts": [. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "7",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "clarity". },. "backgroundColor": "CoreBlue1". }. ],. "name": {. "kind": "unknown",. "value": "collapsed-card-outcome". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "0.5". }. }
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):6064
                            Entropy (8bit):3.268937111019277
                            Encrypted:false
                            SSDEEP:
                            MD5:92B88CFA9E1D1643C770E1AE3556F819
                            SHA1:7CC15E4B0127BBC764AB10E3E63F90805FC7A5AF
                            SHA-256:ABEA43F1DB0D5621F199981BC96EE507B5F75151F971830A6EAD3C9D4DA16E41
                            SHA-512:DC8CB53F48B821E45AA97FD8A322C594711651B45AA45017BDF7B2B32C7EC89586810F8396607C3368A4ABCA682D19CAB52F1B042AA24A3CCDC0D368F197AAB3
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "collapsedCard",. "id": "18",. "meta": {. "label": "Correct your spelling",. "description": "delete \"effect\", insert \"affect\". Click to expand the suggestion details". },. "child": {. "type": "block",. "id": "16",. "parts": [. {. "type": "row",. "id": "15",. "left": [. {. "type": "block",. "id": "13",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "clarity". },. "backgroundColor": "CoreBlue1". }. ],. "name": {. "kind": "unknown",. "value": "collapsed-card-outcome". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "0.5". }.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):4782
                            Entropy (8bit):3.2614604913292786
                            Encrypted:false
                            SSDEEP:
                            MD5:A9D40EC53DDF616F0B166F4F979FC584
                            SHA1:E3921E3947B9CBABB998034FF5EBF5757056F718
                            SHA-256:F18BAF59DEB57DC237E90BB23C252888AA8001FC83831C5C413F293394798CA6
                            SHA-512:765F573326C3193F0AAD37376AA541E5B69682779DCB52CC675B3E0C45FB175027385B4F3386B74492AB6F524240935FD6B4BB66ACC07AF15908304DB7FB2C0E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "collapsedCard",. "id": "15",. "meta": {. "label": "Correct your spelling",. "description": "delete \"effect\", insert \"affect\". Click to expand the suggestion details". },. "child": {. "type": "block",. "id": "13",. "parts": [. {. "type": "row",. "id": "12",. "left": [. {. "type": "block",. "id": "10",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "clarity". },. "backgroundColor": "CoreBlue1". }. ],. "name": {. "kind": "unknown",. "value": "collapsed-card-outcome". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "0.5". }.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):4462
                            Entropy (8bit):3.024412057320694
                            Encrypted:false
                            SSDEEP:
                            MD5:0E3E3AE764228EDCDACA374FB13DB252
                            SHA1:A9F9076ECB652539B260ED85761E62ADD1F91EA3
                            SHA-256:8FB88B8C390B86538AAB970BFCB9BFC8C0B4C028A848F28D5EC9BF989DBDA4FB
                            SHA-512:3BC8E600E27C675517B808D8785771FCD02800EE2CB523A2C8D19E3E8BE9572588A4882B4ED781C20482004274AA7444A78C9A3774593D36A8726FEC93D7E182
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "collapsedCard",. "id": "14",. "meta": {. "label": "Premium suggestions". },. "child": {. "type": "block",. "id": "13",. "parts": [. {. "type": "row",. "id": "12",. "left": [. {. "type": "block",. "id": "10",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "diamond". },. "backgroundColor": "CoreNeutral0". }. ],. "name": {. "kind": "unknown",. "value": "collapsed-card-outcome". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "0.5". }. },. {. "type": "box",. "id": "11",. "child": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):26140
                            Entropy (8bit):2.737063915477266
                            Encrypted:false
                            SSDEEP:
                            MD5:13511854C242FA16DB863E672E196AC1
                            SHA1:EF8418AD0D43CCF5FBD03A359303CDA5AB56538B
                            SHA-256:0D93889CF934989BBF8320B8FCC92FF5FEA759BE3E2D52E98DED4CB0B71D6A70
                            SHA-512:64ABB9825F2D591C9425A5887E7EAB72FC3B739B9E19B5260D971673A21D56F84BCF5CAB045A2277A91B52DE5A8EF6F43A2FBE5D7B6A4374E224B1426FE5C120
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "54",. "children": [. {. "type": "row",. "id": "38",. "left": [. {. "type": "row",. "id": "34",. "left": [. {. "type": "icon",. "id": "29",. "meta": {},. "source": {. "kind": "known",. "name": "engagement". },. "backgroundColor": "CoreGreen1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "37",. "left": [. {. "type": "block",. "id": "36",. "parts
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):22268
                            Entropy (8bit):2.7908949428953287
                            Encrypted:false
                            SSDEEP:
                            MD5:A51C503CC35F3F16022491B454798FE5
                            SHA1:A352FD9CB2D25DC23EDA0E0B67B2D980BB2EF3E9
                            SHA-256:488DC790AB14DC8EFC02676CB08BE3824E6DCF08AC27E1DC45483E097F5AB44F
                            SHA-512:8DCC6376A6C7CA28D068ABE72B7686A47BB4243D56C72E65E767332B4E736933E7C5A6F8C530388BCC6F8A39B18C57A55B26F428E35A697BCD1B669FFB9EBF4D
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "46",. "children": [. {. "type": "row",. "id": "30",. "left": [. {. "type": "row",. "id": "26",. "left": [. {. "type": "icon",. "id": "21",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "29",. "left": [. {. "type": "block",. "id": "28",. "parts"
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):27276
                            Entropy (8bit):2.7562159095331764
                            Encrypted:false
                            SSDEEP:
                            MD5:AC4E5B0D140A95198F35C5478EE1AA60
                            SHA1:EEEA26044156536FB9D0F4158123A65FEA84A161
                            SHA-256:B963E01B674C8AD696E86067D67B5A8E8E040A375CCD16D8F9E78286C88FFE9A
                            SHA-512:D1BE7D3F3C7A5B68E089B23F477B903C1FB42CD66F621BB1D5EA796E4DE4E7EFB0BBF3347B1D92EE7BF971A344CD452B480083381814DDAEA95C93ABD2429903
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "63",. "children": [. {. "type": "row",. "id": "22",. "left": [. {. "type": "row",. "id": "18",. "left": [. {. "type": "image",. "id": "13",. "meta": {},. "name": {. "kind": "unknown",. "value": "title-icon-inclusivity". },. "url": "https://assets.grammarly.com/icons/v1/inclusivity.2x.png",. "width": 1.0,. "height": 1.0. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "21",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):26301
                            Entropy (8bit):2.9328495193484305
                            Encrypted:false
                            SSDEEP:
                            MD5:8A198848D3F895E7385D274459253E38
                            SHA1:79CB32748F71E5A7C0A8C984FCD53F8CCD2E8ABB
                            SHA-256:535F2ADBBD3C5566FB36B73E134774FA4A5A50D887434300C8B76061D72AA14C
                            SHA-512:8F485595C091F000D80891E624259E7D7914A6CFD34E99D974CB9B0AE47B1B2425D244338E7CF827B4AD086FFA24F826D40A9D7BA58E422263439B44D7C698C9
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "61",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Punctuation samples",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):27883
                            Entropy (8bit):2.694688941837926
                            Encrypted:false
                            SSDEEP:
                            MD5:E630109BAB292070F5760BE418CDBC3C
                            SHA1:31C34BBC0B6B3B0CA88A6A46877AC50D445E2DE4
                            SHA-256:E9EF49FDCDF44269E6F17CF19A14C8339F8C8B75A01B233E9827E7C6FA5B771F
                            SHA-512:D820B2AAA317DF4676ABEBFF5A221E0208278E131A746ECC27257491EDA9C8A2CB7EE8BBCC3983DE37DD745DABE3256973D6CE98A3F3A2A7692BB81E0A263E6D
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "61",. "children": [. {. "type": "row",. "id": "35",. "left": [. {. "type": "row",. "id": "31",. "left": [. {. "type": "icon",. "id": "26",. "meta": {},. "source": {. "kind": "url",. "name": "friendly",. "url": "https://assets.grammarly.com/emoji/v1/1f917.2x.png",. "size": "1.25". }. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "34",. "left": [. {. "type
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):25737
                            Entropy (8bit):2.7439273890923883
                            Encrypted:false
                            SSDEEP:
                            MD5:BB58B7C8203ED17B5E6E1411C5B1F219
                            SHA1:5F213EE26F85874B3080A0F8FA6416658C43FCB2
                            SHA-256:7AD32A19C35B4F3E9B4DC2BCB86EC577DC6DAB89C2D8234996A511C16493A042
                            SHA-512:20463D62190EFAE15A960A4A12620A3572C7BB7901663FCC9C5E263096207717769B8A672626EC0D4C664DE12F97AAD075F3F6D74E3C9BE3B53A47FC652E4779
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "55",. "children": [. {. "type": "row",. "id": "29",. "left": [. {. "type": "row",. "id": "25",. "left": [. {. "type": "icon",. "id": "20",. "meta": {},. "source": {. "kind": "url",. "name": "friendly",. "url": "https://assets.grammarly.com/emoji/v1/1f917.2x.png",. "size": "1.25". }. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "28",. "left": [. {. "type
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):25683
                            Entropy (8bit):2.7378816019920387
                            Encrypted:false
                            SSDEEP:
                            MD5:51E800BEF0939CFD60E97FF4251FADA4
                            SHA1:57EC771015807433857B9A25E9F2EDC7CD8DCF8C
                            SHA-256:425AC93ACEE9610E226C6DB2C82EFE0799805AA12FAC52DC64BC6D5821CB022A
                            SHA-512:9E8FED97C9639A07FC05065C63FEE4546708FFD2621E5A9FFEAFE45F6BAEC9011BB4AD2D3FBCD5A4EA4EF2AE0FDD073E52D9A0E6241EDE72774B81711C4913F3
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "55",. "children": [. {. "type": "row",. "id": "29",. "left": [. {. "type": "row",. "id": "25",. "left": [. {. "type": "icon",. "id": "20",. "meta": {},. "source": {. "kind": "url",. "name": "friendly",. "url": "https://assets.grammarly.com/emoji/v1/1f917.2x.png",. "size": "1.25". }. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "28",. "left": [. {. "type
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):9954
                            Entropy (8bit):2.936328747125033
                            Encrypted:false
                            SSDEEP:
                            MD5:D329A73AA3EA865E34AF9B50A41FCBBC
                            SHA1:87E44B33D2A99146E65425479FBD4C083D172129
                            SHA-256:873188204380AFE473C6FC636FBF32EBF3B9C317EF11A14B624347394425AC7B
                            SHA-512:761BD4154F39C676BA6289841A3DD188D84E1C8FEE413C69E8BF3FD895DDD457F830AE4023A4403B9DD922ABA90E75C087FE34A781BEC05AED59FC3700E924BF
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "23",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Complete the sentence",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):22746
                            Entropy (8bit):2.7811226212720657
                            Encrypted:false
                            SSDEEP:
                            MD5:0F1C6F175AE1D3E1B9B5C62598B4E011
                            SHA1:6DD4C41E24E6993D60BAF0D76207B2C11CB534E9
                            SHA-256:AC6EF3C8F70A65C46078E95F4B3740966C7438BD9A6974A6D1A72CA3C5121D9F
                            SHA-512:F971B6E36FAF0E2C8D93BEDC151530ACA7FF34C74DF558149127C8ECD07A224F5BC7AB8742B3EFB6E5C6E4481F9DBC5452A7ACF09F1C7320B74DA6B8A6FFB177
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "54",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "title-icon-inclusivity". },. "url": "https://assets.grammarly.com/icons/v1/inclusivity.2x.png",. "width": 1.0,. "height": 1.0. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "9",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):14065
                            Entropy (8bit):2.993704676331677
                            Encrypted:false
                            SSDEEP:
                            MD5:B4773387EAF91ADDBA8B760899823228
                            SHA1:10899C7ED9D9F735C5A7C781E69D67E785113CC2
                            SHA-256:3FF8675477208D6199F456E9B5B9920C6BAC3EEEAF341B879885D81B7879B570
                            SHA-512:C3F022BC2D195BBA0AB1161195EAFCA1DDAA8B7090F4E84C4D60FE613511EB5929A67612734FBC4B45EF7982001AAF45AB74BAAC4B6B85E7D678EB4026561B9F
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "33",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "url",. "name": "ukraine",. "url": "https://assets.grammarly.com/emoji/v1/1f1fa-1f1e6.2x.png",. "size": "1.25". }. },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Grammarly stands with Ukraine",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):12868
                            Entropy (8bit):2.942988900289474
                            Encrypted:false
                            SSDEEP:
                            MD5:6C4BB317A424097B949585B715176914
                            SHA1:18917FE3D49031DE5F1F84182EEB6DC5EE9E2B78
                            SHA-256:AC7C1C1E0C28E041C034DC13241AAC4D17A87145CA0D12E0E3307DF3D08E3B19
                            SHA-512:84DB7A2BC57AE8C88DC0417A6B798A054887E6D307B8CB2403BF044D07370219946483AEAFA7F4B8C491A6CBC577DF07644C355A70AAE719F3A4F1DFDE5198C4
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "30",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "sensitivity". }. },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Are you having a hard time?",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {. "top": "0",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):12638
                            Entropy (8bit):2.9158063894004767
                            Encrypted:false
                            SSDEEP:
                            MD5:412953F24006C125CD9853CD6FA1CF10
                            SHA1:5C0AC8F6F1B36A5481AB7704C4BA69F46EE7D37F
                            SHA-256:826C509D2088DB2175326BB7A3E64EFEC9BA0A5539C311E49EAF5ED2E5B3B27C
                            SHA-512:2959446367CDA7247CB0ED5E2846CAAE59E45BA6AE22210C7648CFFCFA59E1E783C0981230F417E13837D19B85E9BF02AE6325561297B024087E249DD846FD77
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "29",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Unknown word",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):10848
                            Entropy (8bit):2.9842358312867274
                            Encrypted:false
                            SSDEEP:
                            MD5:5F5ADDF9D1FB07A4924784FFFACFE388
                            SHA1:2BC2CF72DEDAC1D508903E304DBEAE97309C3E29
                            SHA-256:F72ED08A7291F777D252C872C2B2D50B78EA1B4733CC57DE2406A087A9BE8025
                            SHA-512:243B957153529F121C41706252B3F50300F728419DE21A6696637180FEA67ECC454778FC73D5BF34E2B7EA8F082D7BA18A480996B7A4826D4BDE52E2DC1DDC07
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "25",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "url",. "name": "institution-logo",. "url": "https://static.institution.grammarly.com/logo/ec8c59d1a4c7b0698cda682c3ee2f69ed3d7279d.png",. "size": "1". },. "backgroundColor": "CoreNeutral1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Company Style Guide",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):7379
                            Entropy (8bit):3.324869765464323
                            Encrypted:false
                            SSDEEP:
                            MD5:F9CEA12C9B3219F3C7D6B6F8805C786C
                            SHA1:DE33CF68E419A28E5DA861D766CC90EBBACB0AE3
                            SHA-256:4B5D60B62C78C618BE4842C28CFACD8157E0AE482AE658F48D3E372CAE205B7C
                            SHA-512:FCB5F2A152105FAB4591213D2199A8EA42C84344CBDE6C491B84A0EC2D76404BD86C7BE2163109C0734B6E090BFC9EC40986656444174F41C766C48D54234E4C
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "20",. "children": [. {. "type": "box",. "id": "8",. "child": {. "type": "row",. "id": "7",. "left": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "opt-in-image". },. "url": "https://assets.grammarly.com/sdui/v1/prize_cup_performance_score.2x.png",. "width": 5.0,. "height": 5.0. }. ],. "name": {. "kind": "unknown",. "value": "image-container". },. "fraction": 1,. "spacing": {. "top": "0.5",. "right": "0.75",. "bottom": "0.5",. "left": "0.5". },. "horizontalAlig
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):2924
                            Entropy (8bit):3.2044503693273803
                            Encrypted:false
                            SSDEEP:
                            MD5:CD8782C9575E7F37F8DB0580203590D9
                            SHA1:A87DC54A2812536E2DC131F8B65DDC03F21D3DE7
                            SHA-256:B9C7509EFCDDBCC6FE3EB8D74A0CEB595D87E265C86158CC8F159FEE26338C44
                            SHA-512:0296635107FA493CD9C69E6D1D9D21F55F6B0972DC6CBA1E28EE36AA783E47AD1FF669C88A41A6757D4C2270B193C640175028C5C30E100080D1D58DF5D35440
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "collapsedCard",. "id": "10",. "meta": {. "label": "Plagiarism detected". },. "child": {. "type": "block",. "id": "9",. "parts": [. {. "type": "row",. "id": "8",. "left": [. {. "type": "block",. "id": "6",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "plagiarism". }. }. ],. "name": {. "kind": "unknown",. "value": "collapsed-card-outcome". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "0.5". }. },. {. "type": "box",. "id": "7",. "child": {. "type": "block",. "id": "5",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):12716
                            Entropy (8bit):3.009681017332033
                            Encrypted:false
                            SSDEEP:
                            MD5:4951486DB2741D8F8283B23026DCB60C
                            SHA1:48D42E880E74A5F82A86F6D720D5F76ACF35F872
                            SHA-256:DDC687A1B7B2F60772B06B9FC4732F00123712353B95DDD91552E015D1830ECC
                            SHA-512:0D9CA5E93324F25CF3751B87CC868E859B62DC8345F3B32BDB907DA9827B4E60B3DB30E541CCD8314D4AE340876A3F6564EA280D9DE40552C70E6CF02675849A
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "29",. "children": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "icon",. "id": "5",. "meta": {},. "source": {. "kind": "known",. "name": "plagiarism". },. "backgroundColor": "CoreNeutral10". },. {. "type": "block",. "id": "4",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "19%",. "textColor": "CoreGreen60",. "format": [. "bold". ],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": " of this text matches ",. "textColor": "CoreNeutral90",. "format": [],. "
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):15095
                            Entropy (8bit):3.0252904272142733
                            Encrypted:false
                            SSDEEP:
                            MD5:A05EB9F03EFCC2C2D34712F166C33753
                            SHA1:6435BA5CDD6E293DFF64C495D5F5EAFFAD98CB52
                            SHA-256:87F4B61F5B24B0AAF0DB0C1C445228FEAEB8DEF82621D74C202BF430F4E85CC0
                            SHA-512:1CCB40CA8F505665EE7A6344F9E096B892FFB829DA9144AE57B6BA8B30E00518E325CAA8282E9FFDAE101ED7475EFCEF78DF192506CF619EF51E31F88DCD4888
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "34",. "children": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "icon",. "id": "5",. "meta": {},. "source": {. "kind": "known",. "name": "plagiarism". },. "backgroundColor": "CoreNeutral10". },. {. "type": "block",. "id": "4",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "19%",. "textColor": "CoreGreen60",. "format": [. "bold". ],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": " of this text matches ",. "textColor": "CoreNeutral90",. "format": [],. "
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):10435
                            Entropy (8bit):3.169834574536181
                            Encrypted:false
                            SSDEEP:
                            MD5:5B38B9BD2AF7B7EAF42FD42D2758262D
                            SHA1:04EEA10BB4FFD03CDF7196019B4711CD73784A2E
                            SHA-256:1F594A4482ACA7319DAB0C9C079F746D3D1C0F81C634D17D534244BF34B679AD
                            SHA-512:011953D6D9CE60FA0019CB16B79553132FBAE2951018F163A6D6B2CFC0F904D86115AFB9F17CF7DE41671B4D028E1280F005D4796A3EA9011BA1B8B17A062DA7
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "27",. "children": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "icon",. "id": "5",. "meta": {},. "source": {. "kind": "known",. "name": "plagiarism". },. "backgroundColor": "CoreNeutral10". },. {. "type": "block",. "id": "4",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "19%",. "textColor": "CoreGreen60",. "format": [. "bold". ],. "selectable": false. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": " of this text matches ",. "textColor": "CoreNeutral90",. "format": [],. "
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):16662
                            Entropy (8bit):2.762520925089321
                            Encrypted:false
                            SSDEEP:
                            MD5:955579C07303390997ED1F6F1AD0FD3C
                            SHA1:664C93406D05B3EDA507B3F04EAD2F08F02CBCE7
                            SHA-256:4139FFFBFF875729997EF026017075589DF35BA5A2FDFA8C2869FC7DA7CDEB1C
                            SHA-512:85EA29CE687D4498FC9EFEF6675B4409F8D98760581B7EBF05A80FDFA556FECFC64B3BD651FB78AC5BA453598C83F11144BE66B0939681EEAC8B9B76E14D6732
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "37",. "children": [. {. "type": "block",. "id": "19",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1.25",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "20",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1.25",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "21",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1.25",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "22",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):29910
                            Entropy (8bit):2.4944254393378125
                            Encrypted:false
                            SSDEEP:
                            MD5:D1FA3935570491D795EDC8E8C7500B92
                            SHA1:37E1CA2F869D99B2A26E2C42142668F0153A7B92
                            SHA-256:C94CD1ED36C36DF353FC3E63E15BEF1D06F2FB5F9BD8743689AA6182467A8AB1
                            SHA-512:5D39D309983A8564226B09BAEE98DEA6C3F91FF1C4A747017BB8A0DD1F61DC857B0553B459C6ABC122D435797E158CC97D14207D894A36D9FD499A4664164D8D
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "51",. "children": [. {. "type": "block",. "id": "40",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1.25",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "41",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1.25",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "42",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1.25",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "43",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):9328
                            Entropy (8bit):2.753682787416939
                            Encrypted:false
                            SSDEEP:
                            MD5:A23926E4284EFD019115BD39FDAC75AE
                            SHA1:DE00CA586E99B494E394230F02C2C887DA126741
                            SHA-256:6AE7B16DD58A9288572AE5FCEDC0B5453A2C01FCCFA60479B04123590B516F3E
                            SHA-512:8B35B18E4A0351D3ED6727D2C6080338A38DBBE979ECD437F7AD880EE40A67DD1B129BDD96CC7FB77ECEA650E6E1CCB60AA54B894C7379A2E4A5C6E6C44B7FF6
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "19",. "children": [. {. "type": "block",. "id": "11",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1.25",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "12",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1.25",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "13",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1.25",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "14",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):13047
                            Entropy (8bit):2.593683795778972
                            Encrypted:false
                            SSDEEP:
                            MD5:73A0C606A294AEA7FBACAABC02DA6C8B
                            SHA1:D1E5634272FB9E35A100389A59EAFA7485E2E27D
                            SHA-256:B4F97EDFFBE68DE3DE8E9C2407CE416C6EE9312D9E73B9422F2E91F71ECBE850
                            SHA-512:C15B84FB9E8D8F4574EABC4DA606DF8399742BBE9E05FE00392A4CBE59E25F555B05AE4302C40638E2F0BC2288D48E4469B4BA8C3716E60F329147B2B2DB1A18
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "25",. "children": [. {. "type": "block",. "id": "17",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1.25",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "18",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1.25",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "19",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1.25",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "20",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):17281
                            Entropy (8bit):2.8751474654344973
                            Encrypted:false
                            SSDEEP:
                            MD5:D03672C9FBBA5732D38F1E40E5E05B5A
                            SHA1:E2152DBAE2851F64DA7057486F13BD8F945ED447
                            SHA-256:CADD4D3994C68B24F1163E882FC6B25AB2F0960BC9C711B59401D33650B0E1A1
                            SHA-512:D29A0B22F15721685BC5357C6A3F5941D0082B5594CDF0A8B4F640CC7F7D9958285419FA936E57BB3DB22D03677412A0015F7EE4413AE6CAA1BF34BDB2A5F852
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "46",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "icon",. "id": "6",. "meta": {},. "source": {. "kind": "known",. "name": "clarity". },. "backgroundColor": "CoreBlue1". },. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "8",. "parts": [. {. "type": "text",. "id": "7",. "meta": {},. "size": "small",. "text": "Rewrite for clarity",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):17282
                            Entropy (8bit):2.875477810358719
                            Encrypted:false
                            SSDEEP:
                            MD5:7430314892038BF84113405486848177
                            SHA1:89ADA2E0251E2E4E6AB717ACCFDCB719ECFAD783
                            SHA-256:E82CFF910B7B52D44E84DECFFBF86F56CC83B57E20894A62A12C08AB4F115BF3
                            SHA-512:EE7385C8A312C31324BF8A2130A691B3562EB3B36305176543945A042F15D0EC66F729CCAD7C979CF39D52F3532F0030D4C9B2355B0E44F7F417141F923119F5
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "47",. "children": [. {. "type": "row",. "id": "11",. "left": [. {. "type": "icon",. "id": "7",. "meta": {},. "source": {. "kind": "known",. "name": "clarity". },. "backgroundColor": "CoreBlue1". },. {. "type": "row",. "id": "10",. "left": [. {. "type": "block",. "id": "9",. "parts": [. {. "type": "text",. "id": "8",. "meta": {},. "size": "small",. "text": "Rewrite for clarity",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):3310
                            Entropy (8bit):3.121783195946647
                            Encrypted:false
                            SSDEEP:
                            MD5:E56BB5D1FCB78393E8B61CBD419A9A19
                            SHA1:88C0E627FC19B6CBC1368B96DB31B92E2647D296
                            SHA-256:96824422A170A8079BBFCB40C5C9156C49FC55F336C8230B95AE1D8F8C8FFE75
                            SHA-512:8924652B4B5A21E633199397DF55F308E9D5A8B827BAD85DF9441269D4BC66D5BC7482BDD91122309B218F07819462BC5DC86AE7348A9AA588233DDB87672AD0
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "collapsedCard",. "id": "11",. "meta": {. "label": "Rewrite for clarity". },. "child": {. "type": "block",. "id": "10",. "parts": [. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "7",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "diamondSmall". },. "backgroundColor": "CoreYellow20". }. ],. "name": {. "kind": "unknown",. "value": "collapsed-card-outcome". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "0.5". }. },. {. "type": "box",. "id": "8",. "child": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):153
                            Entropy (8bit):4.418126978214743
                            Encrypted:false
                            SSDEEP:
                            MD5:4824B3E780C38F0ED79A935DBFB63B43
                            SHA1:F1AC81CB0EB9181693D3234F80DFEFBD42E3404A
                            SHA-256:D6CD88359BD17DAE9A2F1E7DAF6F39585CD8F85FF6259F97FECBE864DB6BAD1C
                            SHA-512:D97E016D78B119B6832BDDAE03EB38EB9EF5BFE1BBEE41607978245EF4BC44BD6C4E822CF565B9732A0F3C7751432CD54F26F33CCC91617B4B7912B8558899E1
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "progressBar",. "id": "1",. "meta": {},. "backgroundColor": "CoreRed10",. "fillColor": "CoreRed50",. "value": 25,. "state": "default".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):178
                            Entropy (8bit):4.475794037925911
                            Encrypted:false
                            SSDEEP:
                            MD5:D36EB38D82BC06501CA8B034F6BC05E4
                            SHA1:52E847E13950F84AEBF3E187F9A1EC98C5C1E771
                            SHA-256:ECDB75222AAC259C4D367CE39EA117FFEE120072E071D96284977B9711F95D46
                            SHA-512:E54EA0D731F5BCC42A517A5B86C1B90CEF92E571099547BFB9E9BB8604F4FF354FF29D232325CA0E952BA8A3EA6F3B521ACD85C3E758DF0BB5710AE772905E26
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "progressBar",. "id": "1",. "meta": {},. "backgroundColor": "CoreBlue10",. "fillColor": "CoreBlue50",. "value": 50,. "state": "default",. "pinPointValue": 20.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):180
                            Entropy (8bit):4.500459741119957
                            Encrypted:false
                            SSDEEP:
                            MD5:5DFC536E10B59C6D50E36041C901D743
                            SHA1:BEF34B02022A5D23149B115ED343F8DAA3BD25E5
                            SHA-256:AD8E2D8F31452733079BC2F9BA940915A9CB2613FDB0CE86AAB1DDC0639D9AD0
                            SHA-512:A1F0C9899682A3F675FC35AB9766411D36E89DA63475F8296FF71EC3B91FB4C1A0CD135291B09315AA9A6415C405E77DEAD3DE42BE02D27A8BBEDBF9AEDE3D69
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "progressBar",. "id": "1",. "meta": {},. "backgroundColor": "CoreGreen10",. "fillColor": "CoreGreen50",. "value": 75,. "state": "loading",. "pinPointValue": 30.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):182
                            Entropy (8bit):4.470332368855199
                            Encrypted:false
                            SSDEEP:
                            MD5:0A9A931F70B13C9CC4F831FDD444AA8C
                            SHA1:63DE02168A8A6B69B67932766AA414F5EE68DF90
                            SHA-256:C09CF5F207B9A7277C5FC0CF3B011E94FEF781C309EEDF61658967E9F5435BE3
                            SHA-512:6E3C3C83BB773D36CCBE320111400181A26E10D2C2460CE43C145A01084804A57F45C7115076966795B3C6DAD258AB34DF362D0171A285C3B17A62BE785A461E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "progressBar",. "id": "1",. "meta": {},. "backgroundColor": "CorePurple10",. "fillColor": "CorePurple50",. "value": 50,. "state": "default",. "pinPointValue": 50.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3387
                            Entropy (8bit):3.693872881432058
                            Encrypted:false
                            SSDEEP:
                            MD5:A756B6F0CF73013EDC3F578AEA84BF76
                            SHA1:C984E455299C699BBAE37EFBED3C0691BF9E20D4
                            SHA-256:6CBFC6FEA35B63992BBB22D664AE1CD5E2CD4093A3827C2CF791FB14E906656A
                            SHA-512:8350117C05F64EE8A70247CEA94A34FBE3B464C9873FDCBF01F94D57C63F05CA574F4FF11FB7A16E3458C7EA404953C842A475C8A8B0E6692051A8BC5F84B00B
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "row",. "id": "12",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "box",. "id": "2",. "child": {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "row-left: blue box",. "textColor": "CoreBlue50",. "format": [],. "selectable": false. },. "name": {. "kind": "unknown",. "value": "blue-box". },. "padding": {. "top": "0.25",. "right": "0",. "bottom": "0",. "left": "0". }. }. ],. "name": {. "kind": "unknown",. "value": "blue-box-block". },. "fraction": 2,. "verticalAlign": "middle". },. {. "type": "block",. "id": "5",. "parts": [. {. "type": "progressBar",. "id": "4",. "meta": {},.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):206
                            Entropy (8bit):4.428455876149599
                            Encrypted:false
                            SSDEEP:
                            MD5:27BDAA2D08EB72731AC48DEA96F2B0B1
                            SHA1:25982BE39EF364A555915CB3B21AB695B91CABEC
                            SHA-256:F6A9436E783FA03EAD9ED520DE5520ABE25DC4BAC1B05F5D10EE38EFC849BD8D
                            SHA-512:76F43FCECCBAD98D92C2386B47534953F1DDEE4CD2755DF6E969FC043E49F1E8A7E9FBBB8A27D2BA49F498615397675672127C50A5E9726037A7E507FD204C26
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "progressBar",. "id": "1",. "meta": {},. "backgroundColor": "CoreGreen10",. "fillColor": "CoreGreen70",. "value": 77,. "state": "default",. "borderColor": "CoreGreen70",. "height": 1.0.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1337
                            Entropy (8bit):3.3690763619523953
                            Encrypted:false
                            SSDEEP:
                            MD5:42A6D75380B3392B313CA9A911727D1F
                            SHA1:76275E5BEED0945027C139FDDDFC1D7967D5DD6E
                            SHA-256:3F0C76B954C4BF0BA7596F1D793404616F8A3948B8409DB209B64561A29F8889
                            SHA-512:F28B4A7074045F25AC4EB0C7A258E281F60DD116FF11C41CF0830C824255A7F1B1BA0ABC06470BB3FF3F3DCA08C146E80A8454EB6B46E775408C6F2061DFAD22
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "6",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "selectableDropDownMenu",. "id": "4",. "meta": {},. "onSelectActions": [],. "select": {. "meta": {},. "label": "Citation Style",. "items": [. {. "id": "1",. "meta": {},. "label": "APA",. "onClickActions": []. },. {. "id": "2",. "meta": {},. "label": "MLA",. "onClickActions": []. },. {. "id": "3",. "meta": {},. "label": "Chicago",. "onClickActions": []. }. ]. },. "name": {. "kind": "unknown",. "value": "citation-style". },. "placeholder": "Select style".
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1386
                            Entropy (8bit):3.4119971578437758
                            Encrypted:false
                            SSDEEP:
                            MD5:853B3D223898FEDBB164DF9032BD45B9
                            SHA1:B9F7AA3FDEDBE179E491245D08891C92678B701A
                            SHA-256:D9756883F662BA182A86DBDCACBBEE386F2AA09E464F96CF213CD6E8181EF164
                            SHA-512:D371093E6D5EC957687BF1CA067A471C8C03EC98F2D219F0AC140DF7BF7D162FE39159227BE1B13713FF978F12130965B0E5ED4EA53B215CDDD8C88EF3336E79
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "5",. "children": [. {. "type": "row",. "id": "4",. "left": [. {. "type": "selectableDropDownMenu",. "id": "3",. "meta": {},. "onSelectActions": [],. "select": {. "meta": {},. "label": "Citation Style",. "items": [. {. "id": "1",. "meta": {},. "label": "APA",. "onClickActions": []. },. {. "id": "mla-option",. "meta": {},. "label": "MLA",. "onClickActions": []. },. {. "id": "2",. "meta": {},. "label": "Chicago",. "onClickActions": []. }. ]. },. "name": {. "kind": "unknown",. "value": "citation-style". },. "selectedItem": "mla-option",
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):11821
                            Entropy (8bit):2.982139683935855
                            Encrypted:false
                            SSDEEP:
                            MD5:4DA611667909318990F6D4D0B7C5097B
                            SHA1:74B6892867D2A8BD2F5329F3A760C8FCC6BB1C9F
                            SHA-256:BF9F6315F86D278A3E96D13ABC69163E0E1A6C95D32A47CA83F9F28D2A2DA770
                            SHA-512:9FA6B3FAF4C494F26C8A6916D4C1C514E68F954ABBD0FB82650E6765916C5564D3C594264CF3B1E30A11CB9CAFB711880D9BA7A38D26389F6A72221725AB3CF5
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "26",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "url",. "name": "institution-logo",. "url": "https://static.institution.grammarly.com/logo/ec8c59d1a4c7b0698cda682c3ee2f69ed3d7279d.png",. "size": "1". },. "backgroundColor": "CoreNeutral1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "New snippet",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):4652
                            Entropy (8bit):3.107115632941386
                            Encrypted:false
                            SSDEEP:
                            MD5:76F7A2CD4C44CC4988423F3503C23222
                            SHA1:2EC87EA6F09D255E9B7BB28DE6CD2CBEDFE53CE6
                            SHA-256:E1C8B0218A00F2FAC8064600A6835C84C0397C830B3FFDDC931C8848185B71B8
                            SHA-512:83EF163677FB68D17E155A684A79C719F905CBE38BC5045913C0500769E4DDBB352D7F7702421D56EF96F4E379E533012AEE8499B7D68C23441F4807F02505F2
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "15",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "icon",. "id": "6",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "8",. "parts": [. {. "type": "text",. "id": "7",. "meta": {},. "size": "small",. "text": "Resolve inconsistent punctuation",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):242
                            Entropy (8bit):4.338026520121747
                            Encrypted:false
                            SSDEEP:
                            MD5:112F263856EBC0B839DD50E259641456
                            SHA1:3C5BE5B3DF97427F2A50384DF11D783927E3CE36
                            SHA-256:722053C0B0C6537AE2805BB4AFBD4FFF9445E21220E492892CEBBC0DE5246BAB
                            SHA-512:E8C5AC6E9E8941A97FE093B39D1E65ED7AE83FDDD25E7C7616B13E876DDD3FC6E255CB558834A3ACA1B534688837935D6E45CCDFE2E3C487DCC6C45B51CD5C9F
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "text",. "id": "1",. "meta": {. "label": "Remove Lorem Ipsum". },. "size": "regular",. "text": "Lorem Ipsum",. "textColor": "CoreNeutral90",. "format": [. "bold",. "strikeoutHorizontal". ],. "selectable": false.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):170
                            Entropy (8bit):4.407679167606611
                            Encrypted:false
                            SSDEEP:
                            MD5:E330372308130F8DFB6CF084991BFE40
                            SHA1:D546FC1F5FA97BA2D23D717AEE053FE5B232BDF9
                            SHA-256:CFABF245A263FB7FF6AEC14C4C9F79E7E18BBCC0C8774CD1E43EBA3341095AB0
                            SHA-512:B1DA10807360F5B9585ACEA8ED69BFC38621679E464BAD56D90607B1687A21E88FF4E95CB6C1C8CB5BC32D20BAE2A86AE20A01AE47689FCF1AF2C00899617751
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "text",. "id": "1",. "meta": {},. "size": "headingLevel1",. "text": "Lorem Ipsum",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):170
                            Entropy (8bit):4.419443873488964
                            Encrypted:false
                            SSDEEP:
                            MD5:A6D88105DFB115E64B3E4E0CA70EFE21
                            SHA1:C6B17C0F3E6D71F85BF0759F692AC89930B620A5
                            SHA-256:6ACA7081F733EF9BD686540B9003E79CEE842181B51E050D1B50EF69E0239661
                            SHA-512:2C8424C78B85C63587B10CF2D5698D7F8C0C4A006F197F302D86793058F4895AC77B5ABC301650ED4C06F044836887211DA3D03FCCF5F4BD460C4E3C4F439709
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "text",. "id": "1",. "meta": {},. "size": "headingLevel3",. "text": "Lorem Ipsum",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):170
                            Entropy (8bit):4.419443873488964
                            Encrypted:false
                            SSDEEP:
                            MD5:7CC6D383A5BCEFF2B24D05AF4A79F101
                            SHA1:14269FC83283941609581AEE3ABC95FD184C08F5
                            SHA-256:8183EE07B7784E7B07D27B6117348AB935713D2947B1C4F4FB229A4B5D0918D3
                            SHA-512:43F952C532D3F5FF15E98F278F1906FC3F952C8C90CFE42E02AFB7673FDE3ABC763335BD482B9B5284407A2B3CD761659B367F222D1635D8162D644DE4C27AF4
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "text",. "id": "1",. "meta": {},. "size": "headingLevel4",. "text": "Lorem Ipsum",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):163
                            Entropy (8bit):4.293155375054379
                            Encrypted:false
                            SSDEEP:
                            MD5:CBE26DA36431E506940511613A9CF7C5
                            SHA1:7CDF02F2B1895C354CD2870D189192A8C5BC7C25
                            SHA-256:4EF344FB209774CBD17F7F097638B59BE49A0A2C04D3C50A03223CF07E8F784C
                            SHA-512:9726508F6C28D68E857B05D9655B799D9A14D11D3198CE34DB701734E2EDC9C523C4602EADA4C3DC06B0ADFEE733C8A5F2839EB8FDA3EE504997BA16B061DCEE
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "text",. "id": "1",. "meta": {},. "size": "medium",. "text": "Lorem Ipsum",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):164
                            Entropy (8bit):4.29879704401407
                            Encrypted:false
                            SSDEEP:
                            MD5:E67976B0B848A549A938A4D5FA9FA044
                            SHA1:385F529D265AB561A51BE829F20157C3FF4DFEDA
                            SHA-256:710E0865D3142349F2C510648701385A171C826D5348559259F8AAD19FCA8E91
                            SHA-512:659A1B4F8CAF8499259203C8EEC35B58025131513926A9D4A697E23185D59E758712A46037BF96E289BEA21A8BCDEF942596C3CD9907B5603F88F3C3BB00BABA
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Lorem Ipsum",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):162
                            Entropy (8bit):4.2719313616321175
                            Encrypted:false
                            SSDEEP:
                            MD5:79AAC7BA8DBF298C37B07F8D27749D01
                            SHA1:22285BB72600289DCFC8121C86F8E2B77FF434B1
                            SHA-256:8249482B8A1397FB2FAE6A109C18B574058B764B272CA139B2700DDDCDF5C356
                            SHA-512:1309644CD1A71B1FEBD54583753D2E4FE51A50C63DBB65D284BEDE85B54FFAC7E2D83BAEE2F5347985528E5D7EC7EC1B0FB9855D01A7B6D30CCB1623E6CB192F
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "text",. "id": "1",. "meta": {},. "size": "small",. "text": "Lorem Ipsum",. "textColor": "CoreNeutral90",. "format": [],. "selectable": false.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):193
                            Entropy (8bit):4.348962708561647
                            Encrypted:false
                            SSDEEP:
                            MD5:8E1D5E5E6D32BC6C1B419E2A0326BD37
                            SHA1:0C93BBA52234CD92F57A2C31F55965BDB93C0383
                            SHA-256:5986344CB7A83FE251F0D3E859C0B64705886AEB56B0CFC358B80365FE2460C6
                            SHA-512:37FC72EF8EFDF014E0A7B6AF27E5C23AFE876093E548092B21270C9C5FE25ABAC1A97984311392D68FB342A47D134636A78D5E6B095BD59986E66A33E6942EEE
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Lorem Ipsum",. "textColor": "CoreNeutral90",. "format": [. "strikeoutHorizontal". ],. "selectable": false.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):242
                            Entropy (8bit):4.338026520121747
                            Encrypted:false
                            SSDEEP:
                            MD5:3E07089CA0A897AB616E6948DF3F5BFE
                            SHA1:4D98054447AA652138692762065A9D20F13490E7
                            SHA-256:2727DEBCEE7449F542A512622D7390D7DCBA31DF9D870D8B05F1F9699C005F04
                            SHA-512:ED877FF52BFCDB71D4092E2C872FE1CC0E971A3BDAFA3E170A206D1E724DED0AA3738061D3B12B7ACB3E3FCFCBCBBB6B9C4A604B143BBE292A3BD549095CA5B1
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "text",. "id": "1",. "meta": {. "label": "Remove Lorem Ipsum". },. "size": "regular",. "text": "Lorem Ipsum",. "textColor": "CoreNeutral90",. "format": [. "strikeoutHorizontal",. "bold". ],. "selectable": false.}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):21460
                            Entropy (8bit):2.8293250726545085
                            Encrypted:false
                            SSDEEP:
                            MD5:6519FEBFDA1DC0B2D477CBBD5B0E1639
                            SHA1:B327EBE0ED3A30D18B2A869214EBC82CE3EEFD48
                            SHA-256:ABC00AEF0CCACE6D6D33ACCB4A8D01CF74547FB0BBBD4716D79E560B5C3D6A1B
                            SHA-512:A1DAD4578949A5B0805F71779CBAFAB74E0A7A829AB7F70861970A90C448D1137386360E25522940BE07D32F9E5C5D532BA59045940AC047F53B1D3E55CF89D1
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "52",. "children": [. {. "type": "row",. "id": "12",. "left": [. {. "type": "row",. "id": "7",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "delivery". },. "backgroundColor": "CorePurple1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "11",. "left": [. {. "type": "block",. "id": "10",. "parts":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):21478
                            Entropy (8bit):2.8298120630080112
                            Encrypted:false
                            SSDEEP:
                            MD5:DD3556678A0C8D78051FF8DF30F372A8
                            SHA1:A69CED7E6FE78732EFCAF091C1EF6DAD99A0E947
                            SHA-256:D1CD0758B81D5E3EBF556531805DD0D8CB07806809D425B1CC3493B2B57DBD13
                            SHA-512:A9A233CC11ABEC459943219126F2C75EB6B309F1DC2A04781C9665C5A6359E85768B2537F982BF3E8FB19F82F447C337E5C96D114C632CFB52444689BBE72C4B
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "52",. "children": [. {. "type": "row",. "id": "12",. "left": [. {. "type": "row",. "id": "7",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "delivery". },. "backgroundColor": "CorePurple1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "11",. "left": [. {. "type": "block",. "id": "10",. "parts":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):21878
                            Entropy (8bit):2.8280410765888107
                            Encrypted:false
                            SSDEEP:
                            MD5:0F256AEA040978B0E51ED846A6F69AD1
                            SHA1:FF18A8F539AB4B1012953C1FDFD1148645B48324
                            SHA-256:315093F7D38AA90AAFB790D647F41A5ACA9B63A0F73F9D840C1B3D549E0880A0
                            SHA-512:F2D02F8EA610D84FDF22E5ACE308BA1B6C0856F722089EA5716DE7BFB422000F22C149E05A15E7806699D535710ACFBE848F6E3A4825FD41989DAD0A6D8642D3
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "53",. "children": [. {. "type": "row",. "id": "12",. "left": [. {. "type": "row",. "id": "7",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "delivery". },. "backgroundColor": "CorePurple1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "11",. "left": [. {. "type": "block",. "id": "10",. "parts":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):22004
                            Entropy (8bit):2.825792181525689
                            Encrypted:false
                            SSDEEP:
                            MD5:10FDFCED0971B9A5B8FA339D965FA266
                            SHA1:0C71D6966BBF037EF06CC02879B7DF80B7E7FAAC
                            SHA-256:7C35E385A0388700A758B45B6C8058CDC69D5F0AE549C118CFB48599CD9ED939
                            SHA-512:FE5D17F1C85FBF37915EDD45BB7B727B363C444D45F34E04F23F874D49F2E8716B2FF84A3E67CECF9BDF8623C6577DEE865822ABD6F8CAAAF9F31261027FFB1B
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "53",. "children": [. {. "type": "row",. "id": "12",. "left": [. {. "type": "row",. "id": "7",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "delivery". },. "backgroundColor": "CorePurple1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "11",. "left": [. {. "type": "block",. "id": "10",. "parts":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):23747
                            Entropy (8bit):2.829403694256576
                            Encrypted:false
                            SSDEEP:
                            MD5:46E68E9C0028D8D8BAD707788E744B88
                            SHA1:6E42445BE8B5FAA141D44CE415BC0A632FF562F9
                            SHA-256:1DFC1F1177059BA2AFC073CF8B1C0BF3D17D679599463587D8C14B7CB0DC0A0B
                            SHA-512:9E96DA8C72573FF811FD7A2E8A70431588156E0064830050CD7350B52773F0C674A69B4CB71841E192C8B4FD2AAE5E44594BF1B4F915B1F9755A6BD9A7E47026
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "58",. "children": [. {. "type": "row",. "id": "12",. "left": [. {. "type": "row",. "id": "7",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "delivery". },. "backgroundColor": "CorePurple1". }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "11",. "left": [. {. "type": "block",. "id": "10",. "parts":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1042
                            Entropy (8bit):3.847193267710645
                            Encrypted:false
                            SSDEEP:
                            MD5:E021DD7D1F873F8896D61A9D0484CCDD
                            SHA1:0014F82AB16261AA32247D1350D505F0E21944C6
                            SHA-256:09C3A67A3C6A5F9EF5785902BB1AA29CA7AB1E6F341CE4714A9CF9AD2242BCCE
                            SHA-512:E1C0FD6E7D2F1299D529AC2D6D460BBC7FC9F0B3C6329993FE6E2C64538BA51556F443FB381F9C5F5D87E5B8E35DD68DD6C1E3053DBEED87418D876FE02FD1EC
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "tooltip",. "id": "4",. "meta": {},. "name": {. "kind": "unknown",. "value": "tooltipWrapper". },. "text": "Bottom tooltip",. "child": {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "bottom". },. "kind": "primary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Click me",. "textColor": "CoreNeutral0",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "textContainer". },. "spacing": {. "top": "0",. "right": "0.5",. "bottom": "0",. "left": "0.5". },. "verticalAlign": "middle". },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "shape
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1042
                            Entropy (8bit):3.8502287537664186
                            Encrypted:false
                            SSDEEP:
                            MD5:374A7767988F8A9084F8E6E5D745C236
                            SHA1:6E27071D50716A1B7172D578CBFD60CEA6762BE5
                            SHA-256:DB96C4578C45BC83146443984427B370D46D19DB9BC7455C39B56CF8C9169097
                            SHA-512:150304ED047E3BF709BBB5AD5210D31F9237A94BCFED3648B397DD41FFA1B1ED1DEF89EB283FB87FE1C04E89821DD3E84C006C4B588B4B5BF1179513AF745E05
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "tooltip",. "id": "4",. "meta": {},. "name": {. "kind": "unknown",. "value": "tooltipWrapper". },. "text": "Default tooltip",. "child": {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "default". },. "kind": "primary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Click me",. "textColor": "CoreNeutral0",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "textContainer". },. "spacing": {. "top": "0",. "right": "0.5",. "bottom": "0",. "left": "0.5". },. "verticalAlign": "middle". },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "sha
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1036
                            Entropy (8bit):3.839018899107968
                            Encrypted:false
                            SSDEEP:
                            MD5:F55DC0032F49D60821D3F1823D5C438E
                            SHA1:F5557D7B7D92E6E3B9EEAB016BA756E12E4A9772
                            SHA-256:25CB36B4613160DC7B1024AC7603A93CD6573EB304CB0FBB4CCAB8DC96843A5D
                            SHA-512:93D1DD15C2BFD1EC2BFEAE94B53FF4ADAC51C2EED90230EA9D327B093318A3A96AB2CA9B0691EDD3174C5CDF6D022C5623DD5120804CDC85052E2442D5DBF9B2
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "tooltip",. "id": "4",. "meta": {},. "name": {. "kind": "unknown",. "value": "tooltipWrapper". },. "text": "Left tooltip",. "child": {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "left". },. "kind": "primary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Click me",. "textColor": "CoreNeutral0",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "textContainer". },. "spacing": {. "top": "0",. "right": "0.5",. "bottom": "0",. "left": "0.5". },. "verticalAlign": "middle". },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "shape": "
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1039
                            Entropy (8bit):3.852852370406934
                            Encrypted:false
                            SSDEEP:
                            MD5:463CB19CAB8F88A8294B8B54F92E29E7
                            SHA1:7AD9B004AF543AD8BE264E9315391F1D91C3D6FF
                            SHA-256:44A929DD1382488DD5DCFDEBEFB56EB91BA964B82F9FBE545C1E9B84F7302EE9
                            SHA-512:1BBED1DE59AAE328B053C51F2CF83763830E95420A88F1E016F9AB30ECDCB63A654D14AE15E0FAFF55E0301F74E60A15E91945125CE9BEC2991BA6D8355F28C9
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "tooltip",. "id": "4",. "meta": {},. "name": {. "kind": "unknown",. "value": "tooltipWrapper". },. "text": "Right tooltip",. "child": {. "type": "button",. "id": "3",. "meta": {},. "name": {. "kind": "unknown",. "value": "right". },. "kind": "primary",. "state": "enabled",. "label": {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Click me",. "textColor": "CoreNeutral0",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "textContainer". },. "spacing": {. "top": "0",. "right": "0.5",. "bottom": "0",. "left": "0.5". },. "verticalAlign": "middle". },. "actions": [. {. "type": "notify",. "userAction": "click". }. ],. "shape":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):430
                            Entropy (8bit):4.355141576083792
                            Encrypted:false
                            SSDEEP:
                            MD5:EECEC5DAC1FC64D75A4EBC6D06727CBF
                            SHA1:10D6C8D477DB0E5EFAFEC11EE1B2EC1414E1ABE0
                            SHA-256:EC07E5649189893631D0EC6AB5F6CE689A23C8628F307A87A1D008376C0B86D8
                            SHA-512:2809B96B7D93C8F9918E6B786519291333A137AE34CFE358134E2B3A945EE461E048A1B2008157A9EAE40331C4093405ECBAD6A39AE84023B6D3E81A946365C1
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "tooltip",. "id": "2",. "meta": {},. "name": {. "kind": "unknown",. "value": "tooltipWrapper". },. "text": "Default tooltip",. "child": {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "tone-detector". },. "url": "https://assets.grammarly.com/icons/v1/notification-ok.2x.png",. "width": 2.0,. "height": 2.0. },. "alignment": "auto".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):464
                            Entropy (8bit):4.420734394813903
                            Encrypted:false
                            SSDEEP:
                            MD5:1D35644B9AB6906C2A4A05035AE68554
                            SHA1:0591FB8C214851C10FBCB08F2A747FA03F02B8B6
                            SHA-256:885F80C5745F1767F174D89F5C3D788CBC1B1D24CD9472F4CD5254F45231C483
                            SHA-512:DDD565C4DE78D5E0971B1031846FF1EBEB9982341BA6515722FEE7527C0F3502CFB51F3B98A3A316E64E47EE6E1481CDCE21DA02D1BEE40BCC2CEBDB5E2CAEBE
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "tooltip",. "id": "2",. "meta": {},. "name": {. "kind": "unknown",. "value": "tooltipWrapper". },. "text": "This score represents\nthe quality of this text.",. "child": {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "tone-detector". },. "url": "https://assets.grammarly.com/icons/v1/notification-ok.2x.png",. "width": 2.0,. "height": 2.0. },. "alignment": "right".}
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):15498
                            Entropy (8bit):2.8610102777850535
                            Encrypted:false
                            SSDEEP:
                            MD5:35BFB5D9A2CACA765B80CE3AC1CF9204
                            SHA1:EE94753B55FAD6E0635D0429F841F939B106C793
                            SHA-256:BB0B6D04B047BFE7791E4717CF324C0D4D3054FA46F6250F2F1AA4DA3B021327
                            SHA-512:862FC455CF7EAF514DA4580A4DFE912D53693C65B0EC3E672DBA8EFB764D95A2B3B3F94A492AC5469D3D144EC5322408185A16AB246B01D35DA0A3D383DF1AF8
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "37",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Add a comma",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):15500
                            Entropy (8bit):2.8573939374513215
                            Encrypted:false
                            SSDEEP:
                            MD5:BAB9FA4033974F26740FFD3305CE4932
                            SHA1:87CD53540CD5F361B9878D8C021119C184136EC3
                            SHA-256:5D1D51B5BFC714DC335007D8925FEAB38FE5CE42895A99D5412F9B66A569C30F
                            SHA-512:70EF9FDABBF93D88FF39E1B865E182741615B07545F8C73D3EA9ECD606F0A7F87C0A48C7CA27E4EB44C0B30EEF2DEF48F429F18D5B7B4AD02A31480834F40AEC
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "37",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Add a space",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):15536
                            Entropy (8bit):2.8748825668784974
                            Encrypted:false
                            SSDEEP:
                            MD5:5F4FF107E8CA543F07F1AE10D9DF9E45
                            SHA1:2A36CE870FF6C9CB127F9592527D71E868470EF2
                            SHA-256:12ADBF19A3EBEC4C2FC00C5106AC04E83E17CD608A2867252140DCD0135E3B90
                            SHA-512:ABA7D58FDA3AF5E716D06071EF9651AC5A266E9CB8015E0377A327B9C8714F9CE5FBF8F6A35D64EED018A5D3CA080CE1E0BD92438D9BB209FC2226487AA2AC10
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "37",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "delivery". },. "backgroundColor": "CorePurple1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Emphasize key information",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):17276
                            Entropy (8bit):2.872676097472713
                            Encrypted:false
                            SSDEEP:
                            MD5:6AF40391481C7EF1BB80DBD0EAC9F758
                            SHA1:3BCB487DD0037A01F5EF772622ECF99BDC6D5108
                            SHA-256:4CE140E27D3B79478525348BBF2D0285674CCBC6DA5FA58BEB04F01A51393E3B
                            SHA-512:811D38A63968134710D34AA9CB4B6523D3FC32C9426E551B842D6BD510671DE4D37B33873699079EF6B09F18D0321BF7407AA691746D13A326369FC309F3DE78
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "41",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "clarity". },. "backgroundColor": "CoreBlue1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Rewrite for clarity",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):17445
                            Entropy (8bit):2.851571946014794
                            Encrypted:false
                            SSDEEP:
                            MD5:AC0485B5ABD39957B70489D0595D00EA
                            SHA1:F80C67614688FEFC85CE89053CA44BB90434A48D
                            SHA-256:36A3BF7EC5A1FC876785D95B226E597D7270B1EB3DE8A141D14500F59BC5FB6C
                            SHA-512:6619EECD7476A38A231857DAED6A6013697E7B453129ABB3297FCD3FC6B2AACC95EB3CCAF7472DBA6C5E35830CFF6E205F7EF85D6AB7577DB73462D1481C95A8
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "41",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Correct your spelling",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):24275
                            Entropy (8bit):2.812576109599334
                            Encrypted:false
                            SSDEEP:
                            MD5:3EBB599B69935A4B498B9626F3B5D734
                            SHA1:4253B98A074237E432664B7E178F31634F225113
                            SHA-256:C855F04524BFA73B2C9598BB3D15EA40CA0D2C252FDFA32D9DCDD00AADE681B2
                            SHA-512:FDE2188A83E8EE2DEE47428822B37627F5036C6A0987585D582ADF9EA3ED7FD88C15960860BB0118396232C94BC9FE6BCB3B72F8199B3B1750971F7EDC70BD7F
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "58",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "title-icon-inclusivity". },. "url": "https://assets.grammarly.com/icons/v1/inclusivity.2x.png",. "width": 1.0,. "height": 1.0. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "9",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):15570
                            Entropy (8bit):2.868465967857996
                            Encrypted:false
                            SSDEEP:
                            MD5:3DD391DAD22EC30D9C06A735A125A37E
                            SHA1:661D8E4AA17F012628B69AE52CA18E501284D2D8
                            SHA-256:3A807DB9F6CB2274A586BDA49CF7B33C2BA7DC7A424B9BE5C9094224B7CAF227
                            SHA-512:DD780489ADC3D225AA3620EB1373B58CB2EBA1A2E36C7929F719F23B7C1D7AAE4A406BCB8EBB4F6B60EB54DC338F96D05D6A87D8BA3A929BC1D37AD266EA3B63
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "37",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Remove a comma",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):15519
                            Entropy (8bit):2.8591010955520377
                            Encrypted:false
                            SSDEEP:
                            MD5:1E4FBA99B4562B2AF71E779ACA525923
                            SHA1:608C1682B6E2CE81D1EC8679805C3A8B1D164353
                            SHA-256:BEF635860DF440F6585E8C59E84D0AAC0898CCF319CB510D5433F07085E6A682
                            SHA-512:8CF128EC2A2D940EF065EA72DA9B7F026D87093DA790326476E3726535A09AE35CB8DC68308958A625DECAB4CF90161CCDEFE7219AC97F8120499F6FBA05875B
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "37",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Remove a space",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):15508
                            Entropy (8bit):2.8609321721684964
                            Encrypted:false
                            SSDEEP:
                            MD5:D8410B600C9DD686A809E0D8C4D6DFC5
                            SHA1:374E1F2F976F2E7901674B25B0F71A55F5D6BA8D
                            SHA-256:DB1CE8AB50B409B721C9E6F5302F741C53BFE15F6541279B571635B675E7778A
                            SHA-512:9020A521DDB0D5A3562B06F323E94585BF756D0156CF560C6C78868C178534A702269F16C19D058ADB1473E02868E979014630872C2D40B56119C6F421E97D23
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "37",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Remove a space",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):15507
                            Entropy (8bit):2.8567272846672176
                            Encrypted:false
                            SSDEEP:
                            MD5:46A8C6718A03F500DB0A9F7F16A880F3
                            SHA1:A1905E669965BCF33A5EBDFB9728303416469BF2
                            SHA-256:0E17A9A1AD7B7792CDE468458ADA46A46B0895CFD6A27FF5D15F1BD88E71BF6C
                            SHA-512:21EB21E93EAB14664E0AD006882AFB1D9CEFB16C45750F504CFD963FEC3484D0BE505D4243107F06E48D63CAD7E9848C5FEBCF692C1B4211B978117ABC2923E8
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "37",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Remove a space",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):15506
                            Entropy (8bit):2.860477815493476
                            Encrypted:false
                            SSDEEP:
                            MD5:C9A7774CFFCF46144AFC0896E1EBB924
                            SHA1:28F1ACB21A880563B79BF746F45CD7F90F21E952
                            SHA-256:1F0947923F10679DF012A6FF08F34D4A8CE85C117899F0C81F875A4E8D1584DF
                            SHA-512:2E03FF526C79FC58D0A31A8FB414CBFEB0E13618D0154C587695E0FB3D94DAA93A9EA0169C7D88634AE2C2A1BE9F2785B58772998FECD14F2790758C031319EB
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "37",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Remove a space",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):15504
                            Entropy (8bit):2.8587962637163886
                            Encrypted:false
                            SSDEEP:
                            MD5:15A71CD41351276C7F98122DC5F0579B
                            SHA1:C31883C4CF099D19665D1E86D57DD1B1FB31C3AB
                            SHA-256:7D29D72F3AE73A26A50F8DE9BB898642BD531D44FE0EA095DDAA925AB8FCDFE6
                            SHA-512:9D7E3DF1DDD7975373837023713624CBA9B55DD5823A3FA09976624F90D69D9E28C72F2ABD03D46E9EB954B4F69780E8DCFBCA7690A732487D0D6A53D0F9DEE1
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "37",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "correctness". },. "backgroundColor": "CoreRed1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Remove a space",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "titleText". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):17655
                            Entropy (8bit):2.8533393631173616
                            Encrypted:false
                            SSDEEP:
                            MD5:9A86A08FD58B96CAD92A3B137B130529
                            SHA1:1D18403437A4C3B41AF195585B8A2DAB21D08377
                            SHA-256:03A937C40D90851E927A83901A2D5CE484365A49C04709A61DF085D42B1F22A8
                            SHA-512:4DF03276D10E7EFDDD56727100F22BFB3D9D4152955B3D653EB9041A464911FCDAB9EEFC062655FDE09238A5CA0BB3A430B44F11E17795A1E2DD7E2B366BCDEE
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "41",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "url",. "name": "confident",. "url": "https://assets.grammarly.com/emoji/v1/1f91d.2x.png",. "size": "1.25". }. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "9",. "left": [. {. "type":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):17662
                            Entropy (8bit):2.854445202632267
                            Encrypted:false
                            SSDEEP:
                            MD5:C4B0EECEEE06D821820C0FAD320CDED5
                            SHA1:A37A076D08DE8D01956A0036B26C6FDD6C3FF371
                            SHA-256:6ECCB8B4BC311BB69AADA67E2553135B56E0FC1255E64A7F9411588039AF03DE
                            SHA-512:87A61B00B963B1BDB751E3CA8E10B33E49488A3625D11DB1D6373F0ECDBBD4A05B37243AE60F85060DF4914B430AB605D945488CADA739BFC5108CE5FB21E762
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "41",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "url",. "name": "confident",. "url": "https://assets.grammarly.com/emoji/v1/1f91d.2x.png",. "size": "1.25". }. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "9",. "left": [. {. "type":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):17978
                            Entropy (8bit):2.8549276131347994
                            Encrypted:false
                            SSDEEP:
                            MD5:95D550CE2ED243FC14DA68408C7DC2B9
                            SHA1:52ED8E31101F3F02FDEC535138336A4CA8C3506A
                            SHA-256:1592BA584E3C6EF7660D47B85D03B28A6A902D2ADBA70374CFD338F9E4C28FF5
                            SHA-512:8ED250746090B9AB27DE75D1C55C21CFD39CCAFA76659F55DE7059566B120F02D0449537C3849AD78E86A578C5A19AC71D6FDADC68C389F8B8F48EF82A01C742
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "42",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "url",. "name": "confident",. "url": "https://assets.grammarly.com/emoji/v1/1f91d.2x.png",. "size": "1.25". }. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "9",. "left": [. {. "type":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):17346
                            Entropy (8bit):2.8547079355190816
                            Encrypted:false
                            SSDEEP:
                            MD5:A68A4C1625DD121480689451B3417506
                            SHA1:8A610973B44B1CF53099DC042322F7FAAA846A2D
                            SHA-256:39C567CF7425434B249EC014C8864E2B7A94A732455BD6B130B05185605DA00D
                            SHA-512:5816F0FDC3DDAA4C05058D01C998F4DEFAB23F800613C5C305F2794DBE18502CDBC413EDB0379B1790F75C7C322601BC7195786FC4F6E9106300E052F5D7AB38
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "40",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "row",. "id": "6",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "url",. "name": "confident",. "url": "https://assets.grammarly.com/emoji/v1/1f91d.2x.png",. "size": "1.25". }. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "icon-wrapper". },. "behaviors": [. {. "type": "behavior:popoverAnchor",. "id": "card:headerIcon",. "positionHint": "left". }. ]. },. {. "type": "row",. "id": "9",. "left": [. {. "type":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):14515
                            Entropy (8bit):3.0036545946522173
                            Encrypted:false
                            SSDEEP:
                            MD5:64C2D4555403A0107657FEE50A3E9C10
                            SHA1:072309009B1D8C90B9B5F1CCCA23BECBAC249D1E
                            SHA-256:1B55213FFBF8934166FC341A7D5B4E3D4D47D6CCE0753B3CB48386AED1EED235
                            SHA-512:B1D5F38DC113597B76CAF1355EA478DAE94E8ADFAAEB80A778DA6075F21BE7B1B17D1EE92058B5EC567CD241168504892972C2E37603E020D0557D8A53039169
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "31",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "url",. "name": "ukraine",. "url": "https://assets.grammarly.com/emoji/v1/1f1fa-1f1e6.2x.png",. "size": "1.25". }. },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Experimental Ukrainian suggestion",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):21372
                            Entropy (8bit):2.849745632908368
                            Encrypted:false
                            SSDEEP:
                            MD5:34F709A74145227C1E65D2CF90F2BAEE
                            SHA1:3404B891E93768670129F1637871D2D628CF0F03
                            SHA-256:AA8B46CD4BD32589475A759FD12C39D832971CAB18AC93962825EE24687CDD91
                            SHA-512:803BB56D2690DA773CA64957FFE25C053F5D82B19AECA78A90905056B19C5B71EBD4405BDF8F4A1E2534325EA870D56047CF581986F7C89339C273DD1830A617
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "49",. "children": [. {. "type": "row",. "id": "5",. "left": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "url",. "name": "institution-logo",. "url": "https://static.institution.grammarly.com/logo/ec8c59d1a4c7b0698cda682c3ee2f69ed3d7279d.png",. "size": "1". },. "backgroundColor": "CoreNeutral1". },. {. "type": "row",. "id": "4",. "left": [. {. "type": "block",. "id": "3",. "parts": [. {. "type": "text",. "id": "2",. "meta": {},. "size": "small",. "text": "Company Style Guide",. "textColor": "CoreNeutral50",. "format": [],. "selectable": false. }.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):22383
                            Entropy (8bit):2.820590372522669
                            Encrypted:false
                            SSDEEP:
                            MD5:75B00375DD6A9D9561D6A627B938D1A0
                            SHA1:7B9D5799DF2CBCD8B63F3B7D4C8FAB87C83B9E0E
                            SHA-256:434467B88585F190792FDC1712CB588B0CC9B3306FBCD930DC8B3E1202CC9951
                            SHA-512:A3F6FEEE5D94721C01DC120C2D49B6B331D2CEF649F263AF70F17A27553BA6DD4DF8D385FFE3A5B5849F3F27370FC27E3D28F5636CAA28A2D095D18DEBB32EF0
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "54",. "children": [. {. "type": "row",. "id": "2",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Premium suggestions available:",. "textColor": "CoreNeutral90",. "format": [. "bold". ],. "selectable": false. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "header". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "1". }. },. {. "type": "column",. "id": "36",. "children": [. {. "type": "row",. "id": "13",. "left": [. {. "type": "block",. "id": "8",. "parts": [. {. "type": "strongAlertRef",. "id": "7",
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):16899
                            Entropy (8bit):2.9449140263432163
                            Encrypted:false
                            SSDEEP:
                            MD5:6C2E952B39017C99D7F7ACF3AC9CAEB3
                            SHA1:974929AA6DB5EE5A6917FCB3A04DDC295E3E1E72
                            SHA-256:3F663F8AEA7FEB4DB42B14CEEBD4ABD4C7CE866B6196BF8A1526AAD006CE8FF0
                            SHA-512:327916E036A08C11C39D65E14C197F8E255468E7CFE764872BAF78E309ED75C8237C6CD6CFE566336E02FDA00A45040C3D3FBFAC55E3516DCE77B4EAFCD09E77
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "42",. "children": [. {. "type": "row",. "id": "2",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Premium suggestions available:",. "textColor": "CoreNeutral90",. "format": [. "bold". ],. "selectable": false. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "header". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "1". }. },. {. "type": "column",. "id": "24",. "children": [. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "4",. "parts": [. {. "type": "count",. "id": "3",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):16861
                            Entropy (8bit):2.9376824005398894
                            Encrypted:false
                            SSDEEP:
                            MD5:C48C76BF8D3A54B002866619A884EB2A
                            SHA1:52B4B32D32C480738C159BCA8506B8A9328DB72E
                            SHA-256:9A1EAD515C610FADC2BFA742C2E4B23866EB299C0BF88E04AE15A0A4D6EE42A5
                            SHA-512:99C8D4272B671C75C75C25B4E7820C5188DDA335B755F294F8E6986138D4020F11DB3A6469992B71C7BCE4FF0A67D22D4648B3E7038001B36FC1D69CB74FFB5F
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "42",. "children": [. {. "type": "row",. "id": "2",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Premium suggestions available:",. "textColor": "CoreNeutral90",. "format": [. "bold". ],. "selectable": false. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "header". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "1". }. },. {. "type": "column",. "id": "24",. "children": [. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "4",. "parts": [. {. "type": "count",. "id": "3",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):16972
                            Entropy (8bit):2.9556996656420993
                            Encrypted:false
                            SSDEEP:
                            MD5:42E5312A1C7C566DE0C24E49E061AA86
                            SHA1:6D98A48FBE09A12114D025A0AF1296875E18068B
                            SHA-256:DB7EEB5BEB9BCD38DE887CF81529A331C839FA489AC60304E66104648F5A2D22
                            SHA-512:EBE58E4AC5220A0DC5B06F4084BBFB5B4B127B039D22391A7F1FF223F1BE5DB8F5E90E32475933B09825A9A28A95703D81DDFD5A36F79C51AA60D4B9560F95D4
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "42",. "children": [. {. "type": "row",. "id": "2",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Grammarly Business suggestions available:",. "textColor": "CoreNeutral90",. "format": [. "bold". ],. "selectable": false. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "header". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "1". }. },. {. "type": "column",. "id": "24",. "children": [. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "4",. "parts": [. {. "type": "count",. "id": "3"
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):14442
                            Entropy (8bit):2.913484676334703
                            Encrypted:false
                            SSDEEP:
                            MD5:64F3B2FDE091707DEC8353EDBAFA4680
                            SHA1:85519C76236415967093E081492E23416F0C649B
                            SHA-256:62AAA5D1A332B208F7D331B75A468990CB38EC7CCC0667824C0BF18E2D42CA49
                            SHA-512:8C8604F08B4E1E4E6FD0089CE02D0F208ECF2AA69DF4CF14C25D4D85325F409B6AE33A54B50531260050883850117CFBABFBE2D373800497CB49AD4B128B0E3A
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "35",. "children": [. {. "type": "row",. "id": "2",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Premium suggestions available:",. "textColor": "CoreNeutral90",. "format": [. "bold". ],. "selectable": false. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "header". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "1". }. },. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "4",. "parts": [. {. "type": "count",. "id": "3",. "meta": {},. "value": "2",. "backgroundColor": "CoreBlue50",. "textC
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):15641
                            Entropy (8bit):2.9515462753385324
                            Encrypted:false
                            SSDEEP:
                            MD5:4D28F2DC21B83B796B32CFFA80A17E05
                            SHA1:7D3CA821E86BB93940D43A1F3733FD022ED4CEE2
                            SHA-256:FB53379B73036DB4D85E1E4F8F11DF6D32319C4F21BF590E4A8190CA10A1E6CA
                            SHA-512:F087C024DBFB1D301F581178D43660F4D941790900DC116DF93F27EB3A1AEB2F7567FC90C8B1ADE10D3BA4131DEB7DB6E758C3B402A8488852F8063141E27A49
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "37",. "children": [. {. "type": "row",. "id": "2",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Premium suggestions available:",. "textColor": "CoreNeutral90",. "format": [. "bold". ],. "selectable": false. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "header". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "1". }. },. {. "type": "column",. "id": "19",. "children": [. {. "type": "row",. "id": "13",. "left": [. {. "type": "block",. "id": "10",. "parts": [. {. "type": "count",. "id": "3",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):14459
                            Entropy (8bit):2.946768755927639
                            Encrypted:false
                            SSDEEP:
                            MD5:CA1E8A7A6836C88E5F519B413A99612F
                            SHA1:0588F52D93F72CA0595F8A011E7086362AF1593C
                            SHA-256:4A61DC96B2B5BFF88FA4EA3354C9B0E81680778EA783537BF0F822005933BF1B
                            SHA-512:4D05F53C3466D8354A6C76C975650F81C998AC9D201B595C21E9F2BB10A3A544058B220F15B201C8ECD42845371821F57FB8BA1E032A58CC91C71490FBD0D370
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "34",. "children": [. {. "type": "row",. "id": "2",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Premium suggestions available:",. "textColor": "CoreNeutral90",. "format": [. "bold". ],. "selectable": false. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "header". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "1". }. },. {. "type": "column",. "id": "16",. "children": [. {. "type": "row",. "id": "10",. "left": [. {. "type": "block",. "id": "7",. "parts": [. {. "type": "count",. "id": "3",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):16863
                            Entropy (8bit):2.938724489562648
                            Encrypted:false
                            SSDEEP:
                            MD5:8755F2718E9AADA3DC186028FF6EEA19
                            SHA1:0D5F77C4D9D75E250398F13EA1D93C7F31CCF994
                            SHA-256:AE5E6495C3B204C2DDD9969645F260027CA29D52E4E326008A4507EFFEADA055
                            SHA-512:997532565414FA7A04512D2D0058306918F8EBA8F10A65F2A351FA054D74C10E9C868C5DF94E4F15DF91DC256F59B7D81C2FD1C8DBE4C2DBA3D47C7B3A27A1E7
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "42",. "children": [. {. "type": "row",. "id": "2",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Premium suggestions available:",. "textColor": "CoreNeutral90",. "format": [. "bold". ],. "selectable": false. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "header". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "1". }. },. {. "type": "column",. "id": "24",. "children": [. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "4",. "parts": [. {. "type": "count",. "id": "3",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):14444
                            Entropy (8bit):2.9147013215328936
                            Encrypted:false
                            SSDEEP:
                            MD5:C6E20150B1D8565D1828D2155A7959E2
                            SHA1:97EFF098360530DEB75654A9AB0E0D9E2768690C
                            SHA-256:F2D93E8D2AC4653EF5B4A36C061BC997D2CFFDC31A2C5ECAB2DB2975A93CF112
                            SHA-512:988F3F61C482C28BCB00E390DCB95F49596CAE9C05084587E8B058B3541EA3302040190AAA0035580A758828B95378A7FF98837B6132683A7001A7D923626F0C
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "35",. "children": [. {. "type": "row",. "id": "2",. "left": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "regular",. "text": "Premium suggestions available:",. "textColor": "CoreNeutral90",. "format": [. "bold". ],. "selectable": false. }. ],. "right": [],. "verticalAlign": "middle",. "name": {. "kind": "unknown",. "value": "header". },. "spacing": {. "top": "0.5",. "right": "0.5",. "bottom": "0.5",. "left": "1". }. },. {. "type": "row",. "id": "9",. "left": [. {. "type": "block",. "id": "4",. "parts": [. {. "type": "count",. "id": "3",. "meta": {},. "value": "2",. "backgroundColor": "CoreBlue50",. "textC
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1706
                            Entropy (8bit):4.000211564079604
                            Encrypted:false
                            SSDEEP:
                            MD5:D1AE28405C1C84946D38C5F51D7F63CA
                            SHA1:D233D37D6CEE85A9ACB1C466650A989DD61F7D78
                            SHA-256:65AE59AD5F941774EAE1651BC75B13A87D56FE0C21EA27966FD449CC6F6A8A6C
                            SHA-512:1A4736CDDC2F2FFE62AD266605F055B663CDCEDBB0AA7C68C54C72E372FB4C596B161C8FF8E7538E25429485C03FEF22427057C16D39035B556090FAF4C668D5
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "5",. "children": [. {. "type": "button",. "id": "sdui::10_F#S_suggestion@Short:upgrade-hook-click_advancedIssues_singleCardAssistant_premium",. "meta": {},. "name": {. "kind": "unknown",. "value": "goPremium". },. "kind": "yellow",. "state": "enabled",. "label": {. "type": "block",. "id": "3",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "diamond". }. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Get Premium",. "textColor": "CoreYellow80",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "iconTextContainer". },. "s
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1657
                            Entropy (8bit):3.9111045974733205
                            Encrypted:false
                            SSDEEP:
                            MD5:FBF3EFF63B9809073194B3980F673439
                            SHA1:0E8F1D1FFF66692AAAFA8912E9E9547017561975
                            SHA-256:FDB79B7A7F640BB6B72AFA41418F8CFB20424627B8430D86D0AB439391F2D092
                            SHA-512:BF95C284C44B542DE4EDE4B42BDAF1050CC723F345CABD97DDD22057080ACC1234197EEDEF7B400E243211EE66D080D6E61AC621BA9EF642B6EF73988513F272
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "5",. "children": [. {. "type": "button",. "id": "sdui::10_F#S_suggestion@Short:upgrade-hook-click_advancedIssues_singleCardAssistant_premiumTrial",. "meta": {},. "name": {. "kind": "unknown",. "value": "goPremium". },. "kind": "yellow",. "state": "enabled",. "label": {. "type": "block",. "id": "3",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "diamond". }. },. {. "type": "text",. "id": "2",. "meta": {},. "size": "regular",. "text": "Try For Free",. "textColor": "CoreYellow80",. "format": [],. "selectable": false. }. ],. "name": {. "kind": "unknown",. "value": "iconTextContainer". },.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):178250
                            Entropy (8bit):2.1268362361107838
                            Encrypted:false
                            SSDEEP:
                            MD5:151EA5F86883438E02D45168319550AA
                            SHA1:CB1FEB5C469A948B6BC076EF7E485113B53649C2
                            SHA-256:E00EEFE7938144EC40068326A1CD1A9B3049A4C18614D849990229F55FDBF010
                            SHA-512:04C03054121700E9EBACA863BCC76D17E927A0384867AC3FF6F743AF7470E05177E6854390737B4CB5A5C12F2C4798B826BD867F6BB01DEEB15A85F8B17DCA98
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "276",. "child": {. "type": "row",. "id": "275",. "left": [. {. "type": "block",. "id": "1",. "parts": [],. "name": {. "kind": "unknown",. "value": "left". },. "fraction": 225. },. {. "type": "block",. "id": "273",. "parts": [. {. "type": "column",. "id": "272",. "children": [. {. "type": "block",. "id": "28",. "parts": [. {. "type": "box",. "id": "27",. "child": {. "type": "inlineCard",. "id": "26",. "meta": {},. "child": {. "type": "column",. "id": "25",. "children": [. {. "type":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):178350
                            Entropy (8bit):2.1319653935238914
                            Encrypted:false
                            SSDEEP:
                            MD5:D38901754B5462A59A6708D13D8BFAE5
                            SHA1:E57F63BA4FF9762C4730A38C1E51530B5EC64FBA
                            SHA-256:49413C323246B494D5F17BECE5B33C05E4BE128992F7CC112D6C67CED1EB73EC
                            SHA-512:C8B75ADCE0DC54F88CC13C419C7F7DAB219F98B7F95DF73CFDE51470598C7FF6CCD2392972A5FA2BBECDE1F9D96E0374EC9AE20B693BF4BEC790FD1D0EC4BA0E
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "276",. "child": {. "type": "row",. "id": "275",. "left": [. {. "type": "block",. "id": "1",. "parts": [],. "name": {. "kind": "unknown",. "value": "left". },. "fraction": 225. },. {. "type": "block",. "id": "273",. "parts": [. {. "type": "column",. "id": "272",. "children": [. {. "type": "block",. "id": "28",. "parts": [. {. "type": "box",. "id": "27",. "child": {. "type": "inlineCard",. "id": "26",. "meta": {},. "child": {. "type": "column",. "id": "25",. "children": [. {. "type":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):160640
                            Entropy (8bit):2.132686070724102
                            Encrypted:false
                            SSDEEP:
                            MD5:38AEB3B95A8507940BB25C942A11EE68
                            SHA1:A4B76857D9E6DA4A0EF5E15F3D6AE2AC5BE0995C
                            SHA-256:C12572617044ED750F63A57497F5F4E0987CB5C8C2334501EE6A68F8ECE6AE90
                            SHA-512:618AF5E9CC94496A0B37EF78A57BFEE1383DC5D98E9A9FD24850D92704B354AE1A8231180D5055757E92989C3A959FC11F9F43CE8B876CA1DF26E23CC35FE0BE
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "249",. "child": {. "type": "row",. "id": "248",. "left": [. {. "type": "block",. "id": "1",. "parts": [],. "name": {. "kind": "unknown",. "value": "left". },. "fraction": 225. },. {. "type": "block",. "id": "246",. "parts": [. {. "type": "column",. "id": "245",. "children": [. {. "type": "block",. "id": "28",. "parts": [. {. "type": "box",. "id": "27",. "child": {. "type": "inlineCard",. "id": "26",. "meta": {},. "child": {. "type": "column",. "id": "25",. "children": [. {. "type":
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):18508
                            Entropy (8bit):2.672526831876578
                            Encrypted:false
                            SSDEEP:
                            MD5:8CD5BBE6D699FE36B8DA812492D8B7BB
                            SHA1:49C3E25ECA64AB1B1EAED6189D941B9DD80CAE0C
                            SHA-256:FAA4C7974DEDA86852132B38C26108384229CE8F558F127CADEC39B6D1B16F27
                            SHA-512:2474E6909EF1EA710F26BA68AB2F7A98D47AC1D7634A620207B5A54601BFC9C72796B89EDD0A4B4C4819937687613FFB253B6AC1B24AD09B37C88E98F7ADF167
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "40",. "children": [. {. "type": "block",. "id": "21",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "22",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "23",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {. "top": "1",. "right": "0",. "bottom": "0",. "left": "0". }. },. {. "type": "block",. "id": "24",. "parts": [],. "name": {. "kind": "unknown",. "value": "push". },. "spacing": {.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):14246
                            Entropy (8bit):2.3311840055462576
                            Encrypted:false
                            SSDEEP:
                            MD5:0A577E9D8E8EFBFB95518F6CD1FD8A2D
                            SHA1:2EBB26DBC29B458A7BD290599D12E58D78538EB0
                            SHA-256:3EBE543C6DD442342A1B1A0AEE06BCE81566380639A1E26CAA6DC2836CCC9A06
                            SHA-512:2A83092CB6C0B68609A111E38C9BE7C8E27AA7F976AB107BB36B8E199AFC31E8699EAACBBF3057741AB8E501549780E107A828DF5A7ED612E9BDF48B4747541F
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "box",. "id": "28",. "child": {. "type": "row",. "id": "27",. "left": [. {. "type": "block",. "id": "1",. "parts": [],. "name": {. "kind": "unknown",. "value": "left". },. "fraction": 225. },. {. "type": "block",. "id": "25",. "parts": [. {. "type": "column",. "id": "24",. "children": [. {. "type": "box",. "id": "23",. "child": {. "type": "inlineCard",. "id": "22",. "meta": {},. "child": {. "type": "column",. "id": "21",. "children": [. {. "type": "row",. "id": "11",. "left": [. {. "type": "box",.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):2000
                            Entropy (8bit):3.148263273987085
                            Encrypted:false
                            SSDEEP:
                            MD5:D9EBF36B810FB9BA5BC2DB88BE123BB3
                            SHA1:714A6FB830D038428FF1FB3A150D6513461B072B
                            SHA-256:C5BAF11EDB1F9BB354DF3D3636017BFC308FBF72120FD56ACAD611A8B4334B29
                            SHA-512:A133D9766A2F26C3AA2373329399E4B81FF8E0AA864981C6FD336712FC9E529F15EB7742369C2D919886310B524B558D7BA145553056549CF7E2B09A24E9B1D5
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "7",. "children": [. {. "type": "box",. "id": "6",. "child": {. "type": "box",. "id": "5",. "child": {. "type": "box",. "id": "4",. "child": {. "type": "column",. "id": "3",. "children": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "text",. "id": "1",. "meta": {},. "size": "headingLevel4",. "text": "Reviewing your text...",. "textColor": "CoreNeutral0",. "format": [. "bold". ],. "selectable": true. }. ],. "name": {. "kind": "unknown",. "value": "alignment-block". },. "spaci
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):6377
                            Entropy (8bit):3.0147497169255293
                            Encrypted:false
                            SSDEEP:
                            MD5:345BC80E7C0E16DE3ED3B500BCC6A2D3
                            SHA1:4E5122BE1D985E09F0AB0277C71A39C5D09B3610
                            SHA-256:ABFAB4D57BF2D9EEE4E60D441C955E589E6B3908606F4A4EBE6D8A6475F48FCE
                            SHA-512:B33A9990D6BC92624CD14E0603971779F67A9FE139C67BCFD5835A8F033F9C0D26B907F01DEFCA39B092BE7EA08AE56B66CD1C963AA7B28AAD2F5E19BC9C3E4C
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "16",. "children": [. {. "type": "column",. "id": "15",. "children": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "warning". }. }. ],. "name": {. "kind": "unknown",. "value": "alignment-block". },. "spacing": {. "top": "0",. "right": "0",. "bottom": "0.5",. "left": "0". },. "horizontalAlign": "center",. "verticalAlign": "middle". },. {. "type": "block",. "id": "4",. "parts": [. {. "type": "text",. "id": "3",. "meta": {},. "size": "headingLevel4",. "text": "Someth
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):4164
                            Entropy (8bit):3.173436756955829
                            Encrypted:false
                            SSDEEP:
                            MD5:0418688B9693431DDC5B46A7711295E2
                            SHA1:F44E71285EBD98E8E391D1A83777129479AC3DD7
                            SHA-256:B1D0910E7A49C3F811790C053FD2EB8FFA58A7B694DC8C78793C560B5ED271FB
                            SHA-512:0D5A942875A45070A221AB74C489F0A829D92BE217A473AD2F125546FEEC4CA106380813C22D2D6F16BC91C07E4FBA6DEC89CF24526FF3CB3AFFB57E4922F14D
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "12",. "children": [. {. "type": "column",. "id": "11",. "children": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "warning". }. }. ],. "name": {. "kind": "unknown",. "value": "alignment-block". },. "spacing": {. "top": "0",. "right": "0",. "bottom": "0.5",. "left": "0". },. "horizontalAlign": "center",. "verticalAlign": "middle". },. {. "type": "block",. "id": "4",. "parts": [. {. "type": "text",. "id": "3",. "meta": {},. "size": "headingLevel4",. "text": "Someth
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:Unicode text, UTF-8 text
                            Category:dropped
                            Size (bytes):6405
                            Entropy (8bit):3.0297391104255893
                            Encrypted:false
                            SSDEEP:
                            MD5:3F73C81A45169B88A1110D2F16D42955
                            SHA1:9F3AE9FDD07F7D8AD53A24112131DACFCD2758A2
                            SHA-256:DC1B2D5B2E05860FB44BC95821B17EF9474C5C377C0745B41138E446087D01CC
                            SHA-512:C75A74D59A20BC2153A3C180C717782F73BBC56424E05124DD9B1B9DDD47906269057050267F49EC13527FAB5385C677035F80C2C68A0F698D211F95FA718FF2
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "16",. "children": [. {. "type": "column",. "id": "15",. "children": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "icon",. "id": "1",. "meta": {},. "source": {. "kind": "known",. "name": "warning". }. }. ],. "name": {. "kind": "unknown",. "value": "alignment-block". },. "spacing": {. "top": "0",. "right": "0",. "bottom": "0.5",. "left": "0". },. "horizontalAlign": "center",. "verticalAlign": "middle". },. {. "type": "block",. "id": "4",. "parts": [. {. "type": "text",. "id": "3",. "meta": {},. "size": "headingLevel4",. "text": "That.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):4366
                            Entropy (8bit):3.228424908873834
                            Encrypted:false
                            SSDEEP:
                            MD5:7E8E4A4955F10214B66CF2A5C9E31E65
                            SHA1:35B75247A44AD062B9A408628E51401CD0D05515
                            SHA-256:99A944ECEBBFCECAC821134A53B47867ED8CD2BDFCBEBAB65DE3544FC9AB32D7
                            SHA-512:0143D406BD0C049D9FE830AC8D877369E552CD0C76DBB6493F4C03A2C1EAD1F7CCDB4C962A445A7060ABC0926884FE504D18B40ED24678A16712A6D4F285071C
                            Malicious:false
                            Reputation:unknown
                            Preview:{. "type": "column",. "id": "12",. "children": [. {. "type": "column",. "id": "11",. "children": [. {. "type": "block",. "id": "2",. "parts": [. {. "type": "image",. "id": "1",. "meta": {},. "name": {. "kind": "unknown",. "value": "success-image". },. "url": "https://assets.grammarly.com/sdui/v1/writing-expert-success.2x.png",. "width": 4.0,. "height": 4.0. }. ],. "name": {. "kind": "unknown",. "value": "alignment-block". },. "spacing": {. "top": "0",. "right": "0",. "bottom": "0.5",. "left": "0". },. "horizontalAlign": "center",. "verticalAlign": "middle". },. {. "type": "block",. "id": "4",. "parts": [.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32+ executable (DLL) (console) Aarch64, for MS Windows
                            Category:dropped
                            Size (bytes):138336
                            Entropy (8bit):6.0683103090419515
                            Encrypted:false
                            SSDEEP:
                            MD5:CCE3A16D055DCAD3253ECECBF7968BE0
                            SHA1:21E37322C44F0B28114429999A1A18DBFF6F9547
                            SHA-256:1F6700C9307776FE16614E5FF8FA6612CFA67F9F1720777341F3959968E00A52
                            SHA-512:77C26CAEE0E1F458F7B0604E9E69B661DABE7E9DA710E143E31B7E2DB519675438975DF1E61F3585339CBA718AE9D945B9E28EC21CB61A7286748BD1B885C31F
                            Malicious:false
                            Reputation:unknown
                            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d...X..e.........." .....4...........Y.......................................P......f~....`A............................................0.......(....0..................`(...@..........8.......................(... Q..@...............h...8...`....................text....2.......4.................. ..`.rdata......P.......8..............@..@.data...............................@....pdata..............................@..@.tls......... ......................@....rsrc........0......................@..@.reloc.......@......................@..B................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) ARMv7 Thumb, for MS Windows
                            Category:dropped
                            Size (bytes):1259104
                            Entropy (8bit):7.162806856103191
                            Encrypted:false
                            SSDEEP:
                            MD5:B41DF08FE3FDE9A1B40C50B3D788D447
                            SHA1:465430FAED1B595932BE9C337A59AD2A09FAD494
                            SHA-256:73B2F4AAAF9510451D1A4B3873CC463B2351BC6753E71697ED6FAE80E6A91799
                            SHA-512:DA35E926E8984F9B312AC595C76745FA3AF8C3FC8A5A49719BD3B07E9747B593CA13FFFB817D7D392ED88003D89057DD1445D3B43770E42EC0C888A3AB5C891F
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........|.../.../.../....../....../....../.../.../....../....../....../H...../H...../H.X/.../H...../Rich.../................PE.......>.e.........."!.........t...............................................`............@A.............................$......(...............`[......`(......He......T...........................p................................................text............................... ..`.rdata..\T.......V..................@..@.data...<X... ...L..................@....pdata..`[.......\...J..............@..@.rsrc...............................@..@.reloc..He.......f..................@..B................................................................................................................................................................................................................................................................
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                            Category:dropped
                            Size (bytes):162400
                            Entropy (8bit):6.213152016661655
                            Encrypted:false
                            SSDEEP:
                            MD5:511A2050E287B3FD083459E8B23784E3
                            SHA1:989759DDD0CAC14AC598AB5B5EB0EFBB8A0BD7C2
                            SHA-256:5BFFB0256D2E53230D465950CD2574CD314ABD959F58D879A1EB10DE0C17FA39
                            SHA-512:970FE8B06DB58A7CD4953B6CD6292C6B2B9CBC6DA6ECAAF37A9E513EA412FF007D7D2F7A7D2285B465E64A4D8F9CFAE5C27118EB929A088BF04C0AD785C090BE
                            Malicious:false
                            Reputation:unknown
                            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d...X..e.........." .....P..........0N....................................................`A........................................q...0.......(............@.......R..`(..............T.......................(....a..@.......................`....................text....O.......P.................. ..`.rdata......`.......T..............@..@.data........ ......................@....pdata.......@......................@..@.gxfg........`.......,..............@..@.retplne.............>...................tls.................@..............@..._RDATA..\............B..............@..@.rsrc................D..............@..@.reloc...............J..............@..B........................................................................................................................................................................................................................
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                            Category:dropped
                            Size (bytes):1753696
                            Entropy (8bit):6.554523722744925
                            Encrypted:false
                            SSDEEP:
                            MD5:064CF4C26BE0576DEC70437DD4C4EE3D
                            SHA1:DB752D997A63A66C6A91AD4999E4B46F7A991326
                            SHA-256:89B3B9C9F8613D07BB012CEDABB386C9CF95E3343A1331D2A4C2E0BC8F7C6A88
                            SHA-512:88F0498C9246DF593381621DE62CDC6E0575B031C38BF2F25071EAC7BCDD45693E140F4CEC1FEEA255AF92E3A030FF6A651B0663815D6CCAE0E0E4FD03F9E7D8
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........B....................q...................k.......................+......+......+.N....+......Rich...................PE..d...0>.e.........." .................E....................................................`A........................................ ....$...)..(.......................`(..............T...........................P...8............................................text.............................. ..`.rdata...v.......x..................@..@.data........@...n...*..............@....pdata..............................@..@_RDATA..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                            Category:dropped
                            Size (bytes):116832
                            Entropy (8bit):6.530491871658741
                            Encrypted:false
                            SSDEEP:
                            MD5:DA36B0483FDE018B72AC5F19B670BBE5
                            SHA1:8132DE66DC35328FF0B4A1539CAC6C52EBA14621
                            SHA-256:25190B989BEF24B563622FC8E00241F60DF10629AFDA391334CD317B647A0DD6
                            SHA-512:FD7A7F4D2A1D163FFD0F620797438C1781C68B4730E44449ADCDCD7C3DB2E3788805E96DC131B2F402C88DEC454452F84C0E530446D6FA1DAC598926867109BF
                            Malicious:false
                            Reputation:unknown
                            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..L...X..e.........."!.................F....................................................@A.........................u..0....v..(.......................`(...........n..8...................|l......`...............Xx..<...`t..`....................text............................... ..`.rdata...u.......v..................@..@.data...,............z..............@....tls................................@....rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                            Category:dropped
                            Size (bytes):1428064
                            Entropy (8bit):6.789326901329877
                            Encrypted:false
                            SSDEEP:
                            MD5:6E86806F5B9F663506864734D604660B
                            SHA1:173D3C9B08A947583E9B04FE0C3D5A33CE99791B
                            SHA-256:0CB011696A7C0732647398F7D40695945ED76E08450E8FF39A2161BCA5F29B84
                            SHA-512:6A3344B5B27231D911725B920BED6CF50A4551DE848FAAD30078B8EF54363B6CFCE3DE752D1D20F1603366490F8E0BF9AA79311F7469DB45FF1A2529B1161F91
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........Y.p7..p7..p7...4..p7...2.&p7...3..p7...6..p7..p6.4p7...2..p7...3..p7...4..p7.|.3..p7.|.7..p7.|...p7.|.5..p7.Rich.p7.................PE..L...=>.e...........!.....T...X......`4.......p............................................@A.............................$......(....0..................`(...@..L.......T...........................P...@............p...............................text....R.......T.................. ..`.rdata...X...p...Z...X..............@..@.data....Z.......N..................@....rsrc........0......................@..@.reloc..L....@......................@..B................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):58057
                            Entropy (8bit):6.10612944031567
                            Encrypted:false
                            SSDEEP:
                            MD5:81D0F75F2FC5ECBA5E7D80765CF5EF14
                            SHA1:6E3757E6F07AFEB7AE50F6B155826DF90C0226A9
                            SHA-256:5AF875807B7EE0BA80CB4EE33803F30B6F9AE159C5AD981EEC2E7D80EDABAF2F
                            SHA-512:E0EBF7AE638FF62BA6F303138A3E55398152E2B6A3CC044E7649E528154502E8C1B8A6BA112F086FBED30D3B80C5F3B2DFA5300CAFCAF6197C9B6F4B815BDB4C
                            Malicious:false
                            Reputation:unknown
                            Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):58805
                            Entropy (8bit):6.105366777698636
                            Encrypted:false
                            SSDEEP:
                            MD5:BB0804426FB8F7B82F0D5DB7B3217B83
                            SHA1:59ED37B9C55361631E7705B3B36056E60AB947BE
                            SHA-256:E04744F1B21A64FDF4770EFCB802D56FD62187A54B9C543837F495108D5E51BB
                            SHA-512:48D8F9FF5A0875629C77CDFA0039FEA476E4275998436226876ADCE2AEF4BF1353BCA9526DF8D7EF219EF388BD09ABC5703A7BE4BC0702EAD33BB76F4EBA5EFF
                            Malicious:false
                            Reputation:unknown
                            Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UW
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):34101
                            Entropy (8bit):6.052329991875386
                            Encrypted:false
                            SSDEEP:
                            MD5:EF6E83984F244B74C4B65B94C42E4C4A
                            SHA1:63350420C225B492B1346E0DF01BCBEC223DDD64
                            SHA-256:74F713430D057982FFED4F744F1E27BCD4EB865A4851AF083C6A38BC4E0F947D
                            SHA-512:C1C60EAB55434DF40A36404E5B5CCFDAE005E891E4DC5DDB8C393AA25F6CE9C3F1AA9FEF64213B7A770D50A6987CBC500E8A0A6496A8161384405098F655ECE4
                            Malicious:false
                            Reputation:unknown
                            Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAAMAAAAAAAAAAAA=","dual_engine":{"ie_to_edge":{"redirection_mode":0}},"edge":{"perf_center":{"efficiency_mode_v2_is_active":false,"perf_game_mode":true,"performance_mode":3,"performance_mode_is_on":false},"tab_stabs":{"closed_without_unfreeze_never_unfrozen":0,"closed_without_unfreeze_previously_unfrozen":0,"discard_without_unfreeze_never_unfrozen":0,"discard_without_unfreeze_previously_unfrozen":0},"tab_stats":{"frozen_daily":0,"unfrozen_daily":0}},"edge_ci":{"metrics_bookmark":"\u003CBookmarkList Direction='backward'>\r\n\u003C/BookmarkList>","num_healthy_bro
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):58097
                            Entropy (8bit):6.105802106887572
                            Encrypted:false
                            SSDEEP:
                            MD5:207D18EE0879FED06FB9AFAE91CC141B
                            SHA1:292F76364D7757E8ED1E0D24CA31A623AD968460
                            SHA-256:733870B120E3DF12CE7A82063867BAD2951CC5314467A5373E3D0DD608B59730
                            SHA-512:89D2690DD85147EF4628EE68BB87A3BFBDC761DB3E11B4AD418397BFBC7314212D3FCD997793EF02250FA849FD5ACE4FA74371F229FE3B1419E63840FE315BBA
                            Malicious:false
                            Reputation:unknown
                            Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:93EC2B55A788BD92FFEB668E5AFBE796
                            SHA1:771E9444D7D1E8520F9CE1C08A7817CE93D4C9F9
                            SHA-256:34D244E45186447E2EECFB50DAFACF5C586253588D0B0EB9F7FCB0B313840FBA
                            SHA-512:FB1AF98B6C16D7769145A37FEB8FC549C4BB2C32106E273855E7A4071534C7C97035F7EF85E7D5BB3BDDAD51DBA8B0E3DB6D94004FF2563A673BFBFA9A4C3D54
                            Malicious:false
                            Reputation:unknown
                            Preview:{"sites":[{"url":"24video.be"},{"url":"7dnifutbol.bg"},{"url":"6tv.dk"},{"url":"9kefa.com"},{"url":"aculpaedoslb.blogspot.pt"},{"url":"aek-live.gr"},{"url":"arcadepunk.co.uk"},{"url":"acidimg.cc"},{"url":"aazah.com"},{"url":"allehensbeverwijk.nl"},{"url":"amateurgonewild.org"},{"url":"aindasoudotempo.blogspot.com"},{"url":"anorthosis365.com"},{"url":"autoreview.bg"},{"url":"alivefoot.us"},{"url":"arbitro10.com"},{"url":"allhard.org"},{"url":"babesnude.info"},{"url":"aysel.today"},{"url":"animepornx.com"},{"url":"bahisideal20.com"},{"url":"analyseindustrie.nl"},{"url":"bahis10line.org"},{"url":"apoel365.net"},{"url":"bahissitelerisikayetleri.com"},{"url":"bambusratte.com"},{"url":"banzaj.pl"},{"url":"barlevegas.com"},{"url":"baston.info"},{"url":"atomcurve.com"},{"url":"atascadocherba.com"},{"url":"astrologer.gr"},{"url":"adultpicz.com"},{"url":"alleporno.com"},{"url":"beaver-tube.com"},{"url":"beachbabes.info"},{"url":"bearworldmagazine.com"},{"url":"bebegimdensonra.com"},{"url":"autoy
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):104017
                            Entropy (8bit):4.637055340481339
                            Encrypted:false
                            SSDEEP:
                            MD5:93EC2B55A788BD92FFEB668E5AFBE796
                            SHA1:771E9444D7D1E8520F9CE1C08A7817CE93D4C9F9
                            SHA-256:34D244E45186447E2EECFB50DAFACF5C586253588D0B0EB9F7FCB0B313840FBA
                            SHA-512:FB1AF98B6C16D7769145A37FEB8FC549C4BB2C32106E273855E7A4071534C7C97035F7EF85E7D5BB3BDDAD51DBA8B0E3DB6D94004FF2563A673BFBFA9A4C3D54
                            Malicious:false
                            Reputation:unknown
                            Preview:{"sites":[{"url":"24video.be"},{"url":"7dnifutbol.bg"},{"url":"6tv.dk"},{"url":"9kefa.com"},{"url":"aculpaedoslb.blogspot.pt"},{"url":"aek-live.gr"},{"url":"arcadepunk.co.uk"},{"url":"acidimg.cc"},{"url":"aazah.com"},{"url":"allehensbeverwijk.nl"},{"url":"amateurgonewild.org"},{"url":"aindasoudotempo.blogspot.com"},{"url":"anorthosis365.com"},{"url":"autoreview.bg"},{"url":"alivefoot.us"},{"url":"arbitro10.com"},{"url":"allhard.org"},{"url":"babesnude.info"},{"url":"aysel.today"},{"url":"animepornx.com"},{"url":"bahisideal20.com"},{"url":"analyseindustrie.nl"},{"url":"bahis10line.org"},{"url":"apoel365.net"},{"url":"bahissitelerisikayetleri.com"},{"url":"bambusratte.com"},{"url":"banzaj.pl"},{"url":"barlevegas.com"},{"url":"baston.info"},{"url":"atomcurve.com"},{"url":"atascadocherba.com"},{"url":"astrologer.gr"},{"url":"adultpicz.com"},{"url":"alleporno.com"},{"url":"beaver-tube.com"},{"url":"beachbabes.info"},{"url":"bearworldmagazine.com"},{"url":"bebegimdensonra.com"},{"url":"autoy
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):280
                            Entropy (8bit):3.0811074620762002
                            Encrypted:false
                            SSDEEP:
                            MD5:535FF0B3E6B0A85FD180603FBB0ED5B3
                            SHA1:8E10F1E3D6792325987D31720BB5BFB13D36D1AB
                            SHA-256:F0AB937146357DC2FAB1A7FCC6D691FB6BBF2099D62FCE1C7D15A86169133B2C
                            SHA-512:FD4D872A3E85FF913874B12E03326E65A41BADD19BFFAFC3B7243E38EDE3304BE77648CC648D53D716B745C774583D6489D7055B178F3DC2C0137CB7A742D140
                            Malicious:false
                            Reputation:unknown
                            Preview:sdPC......................z....K..s...x.................................................................................................................................47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=....................7dc5f755-0f90-4102-bc8e-37d02917bdc7............
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):25185
                            Entropy (8bit):5.570801681552164
                            Encrypted:false
                            SSDEEP:
                            MD5:7D6744681C37A16293A6872B8CFB90FC
                            SHA1:CFB48CE9D4C844450F760FE2210525BC5008A2DB
                            SHA-256:167E8638B93F72DE4786D064DF1554F98DD28E29D08A7702F48C1E84B4C19D7C
                            SHA-512:A799C35803C5D57ED4A4B997B4ECB4CEBC1DBE098C9A30E5DDFB5388AFC2069E18A68116D5163EFB65FD6D87673225A43B014F4FBB8E5732B86C3CC3590D64E7
                            Malicious:false
                            Reputation:unknown
                            Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13358425947811214","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13358425947811214","location":5,"ma
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):9474
                            Entropy (8bit):5.087179439810005
                            Encrypted:false
                            SSDEEP:
                            MD5:9949298D090A9CA6F6B70E3A736BEA27
                            SHA1:01A4511D81D091D9BABF23DBA44494C85F69A0DF
                            SHA-256:593D551A35CFAA1D15B03BF3C0FD5BC9292F6FAB7E25BE0339915515607BC42D
                            SHA-512:F0A16AFB624A6B16157126DE1B42349383561F84BD0354E70496A16B4B761D0946C33A80440C7D61D92B230B8DE478D6F380FB4988AF884008BAF22505C6ED6F
                            Malicious:false
                            Reputation:unknown
                            Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13358425954932139","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":914,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":70,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"li
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:very short file (no magic)
                            Category:dropped
                            Size (bytes):1
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:5058F1AF8388633F609CADB75A75DC9D
                            SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                            SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                            SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                            Malicious:false
                            Reputation:unknown
                            Preview:.
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):9032
                            Entropy (8bit):5.079605307228003
                            Encrypted:false
                            SSDEEP:
                            MD5:C760D7DA1C8615145A0E66D19F2A454B
                            SHA1:7134BAED82E8EA3383EC2BAD22302C4CC832C8CD
                            SHA-256:E8B8300AF5207AE5970967D420D10D30310E1F180B2948A0A54E2BF5A167726B
                            SHA-512:4DED585738F8E44F43F9EC2D9F539CFA15BF40D6B3044D89F3BA263E79F282D95E6600922BA1BA986A271F3D6964757855CFEC6EF1041C0173DF0603051A4532
                            Malicious:false
                            Reputation:unknown
                            Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13358425954932139","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":914,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":70,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"dips_timer_la
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):24691
                            Entropy (8bit):5.5684161260829965
                            Encrypted:false
                            SSDEEP:
                            MD5:8A7158845967F4D0C209D1103D6830BD
                            SHA1:22DF6392E32C8D2C107739C7647AC0AE7855A812
                            SHA-256:4549C856E0C5F463254873B21EABB9DED15249EC691B53837333842ACC22F384
                            SHA-512:AD67A4F4371162613199AF479348CD7FE57C6D5014D82ECC275D91B6BDC0868CEBA9863DA9E9C2D5119930EBF2AE144D2EAE8E88333B07EED2D7875C771CD975
                            Malicious:false
                            Reputation:unknown
                            Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13358425947811214","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13358425947811214","location":5,"ma
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):374811
                            Entropy (8bit):5.396162071254282
                            Encrypted:false
                            SSDEEP:
                            MD5:D417E990935CEA194A3D811E7D8F7A60
                            SHA1:E9FC8B6B178A53EA24D48ED2C5A4A003BE7470BC
                            SHA-256:34F18E7FA4F2F55A7C867E2C6E2AD515B4C1BB5844916BF4BCF404C46F06CB6F
                            SHA-512:CFC3163A1AE75F2F942ED170C9B857C97338AC2C77B42E0E9D08FE512E0E7958E67CE35FDF675E7B5F5EEB84593E8EEAC9F6856BDDFB4711B0F16513709F6F17
                            Malicious:false
                            Reputation:unknown
                            Preview:{"aee_config":{"ar":{"price_regex":{"ae":"(((ae|aed|\\x{062F}\\x{0660}\\x{0625}\\x{0660}|\\x{062F}\\.\\x{0625}|dhs|dh)\\s*\\d{1,3})|(\\d{1,3}\\s*(ae|aed|\\x{062F}\\x{0660}\\x{0625}\\x{0660}|\\x{062F}\\.\\x{0625}|dhs|dh)))","dz":"(((dzd|da|\\x{062F}\\x{062C})\\s*\\d{1,3})|(\\d{1,3}\\s*(dzd|da|\\x{062F}\\x{062C})))","eg":"(((e\\x{00a3}|egp)\\s*\\d{1,3})|(\\d{1,3}\\s*(e\\x{00a3}|egp)))","ma":"(((mad|dhs|dh)\\s*\\d{1,3})|(\\d{1,3}\\s*(mad|dhs|dh)))","sa":"((\\d{1,3}\\s*(sar\\s*\\x{fdfc}|sar|sr|\\x{fdfc}|\\.\\x{0631}\\.\\x{0633}))|((sar\\s*\\x{fdfc}|sar|sr|\\x{fdfc}|\\.\\x{0631}\\.\\x{0633})\\s*\\d{1,3}))"},"product_terms":"((\\x{0623}\\x{0636}\\x{0641}\\s*\\x{0625}\\x{0644}\\x{0649}\\s*\\x{0627}\\x{0644}\\x{0639}\\x{0631}\\x{0628}\\x{0629})|(\\x{0623}\\x{0636}\\x{0641}\\s*\\x{0625}\\x{0644}\\x{0649}\\s*\\x{0627}\\x{0644}\\x{062D}\\x{0642}\\x{064A}\\x{0628}\\x{0629})|(\\x{0627}\\x{0634}\\x{062A}\\x{0631}\\x{064A}\\s*\\x{0627}\\x{0644}\\x{0622}\\x{0646})|(\\x{062E}\\x{064A}\\x{0627}\\x{0631}
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):523
                            Entropy (8bit):5.512565559425749
                            Encrypted:false
                            SSDEEP:
                            MD5:6464ABAB0229C8DA0437001DCE51E40B
                            SHA1:0D758695D672730F814B29E1BFE7C9582E0C14F6
                            SHA-256:61995BD9B27BC8337B04144A876E64F29CA11CA8A98E72E07C8E0470290F7281
                            SHA-512:BB08F467F6D8A480BB47CCF01B98136B0689257C77C9F476C586894D5C7325F67E700A1776883A9F2A7360672C15926C524A6A63DF43A4C848ABE452D79F1110
                            Malicious:false
                            Reputation:unknown
                            Preview:{"sts":[{"expiry":1745488370.334198,"host":"M4bfUnCmQAi4PNb3B8aI/2+SVJhHKsMfMMT7fzi6ij4=","mode":"force-https","sts_include_subdomains":true,"sts_observed":1713952370.334203},{"expiry":1713973973.289762,"host":"M6Q8WzbcYDrVuDnXhGFW3pTGMzde2ntTvl3QGcUodnA=","mode":"force-https","sts_include_subdomains":false,"sts_observed":1713952373.289766},{"expiry":1745488378.501057,"host":"TZmujbl93Yt3JI8wZ4X/zjkA0WFNGNW44A+o7h4YyHw=","mode":"force-https","sts_include_subdomains":true,"sts_observed":1713952378.501061}],"version":2}
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:C760D7DA1C8615145A0E66D19F2A454B
                            SHA1:7134BAED82E8EA3383EC2BAD22302C4CC832C8CD
                            SHA-256:E8B8300AF5207AE5970967D420D10D30310E1F180B2948A0A54E2BF5A167726B
                            SHA-512:4DED585738F8E44F43F9EC2D9F539CFA15BF40D6B3044D89F3BA263E79F282D95E6600922BA1BA986A271F3D6964757855CFEC6EF1041C0173DF0603051A4532
                            Malicious:false
                            Reputation:unknown
                            Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13358425954932139","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":914,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":70,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"dips_timer_la
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:C760D7DA1C8615145A0E66D19F2A454B
                            SHA1:7134BAED82E8EA3383EC2BAD22302C4CC832C8CD
                            SHA-256:E8B8300AF5207AE5970967D420D10D30310E1F180B2948A0A54E2BF5A167726B
                            SHA-512:4DED585738F8E44F43F9EC2D9F539CFA15BF40D6B3044D89F3BA263E79F282D95E6600922BA1BA986A271F3D6964757855CFEC6EF1041C0173DF0603051A4532
                            Malicious:false
                            Reputation:unknown
                            Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13358425954932139","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":914,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":70,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"dips_timer_la
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:C760D7DA1C8615145A0E66D19F2A454B
                            SHA1:7134BAED82E8EA3383EC2BAD22302C4CC832C8CD
                            SHA-256:E8B8300AF5207AE5970967D420D10D30310E1F180B2948A0A54E2BF5A167726B
                            SHA-512:4DED585738F8E44F43F9EC2D9F539CFA15BF40D6B3044D89F3BA263E79F282D95E6600922BA1BA986A271F3D6964757855CFEC6EF1041C0173DF0603051A4532
                            Malicious:false
                            Reputation:unknown
                            Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13358425954932139","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":914,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":70,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"dips_timer_la
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:C760D7DA1C8615145A0E66D19F2A454B
                            SHA1:7134BAED82E8EA3383EC2BAD22302C4CC832C8CD
                            SHA-256:E8B8300AF5207AE5970967D420D10D30310E1F180B2948A0A54E2BF5A167726B
                            SHA-512:4DED585738F8E44F43F9EC2D9F539CFA15BF40D6B3044D89F3BA263E79F282D95E6600922BA1BA986A271F3D6964757855CFEC6EF1041C0173DF0603051A4532
                            Malicious:false
                            Reputation:unknown
                            Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13358425954932139","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":914,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":70,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"dips_timer_la
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:C760D7DA1C8615145A0E66D19F2A454B
                            SHA1:7134BAED82E8EA3383EC2BAD22302C4CC832C8CD
                            SHA-256:E8B8300AF5207AE5970967D420D10D30310E1F180B2948A0A54E2BF5A167726B
                            SHA-512:4DED585738F8E44F43F9EC2D9F539CFA15BF40D6B3044D89F3BA263E79F282D95E6600922BA1BA986A271F3D6964757855CFEC6EF1041C0173DF0603051A4532
                            Malicious:false
                            Reputation:unknown
                            Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13358425954932139","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13341058280410352","arbitration_using_experiment_config":false,"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":914,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":70,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"list":[]},"default_apps_install_state":3,"dips_timer_la
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:8A7158845967F4D0C209D1103D6830BD
                            SHA1:22DF6392E32C8D2C107739C7647AC0AE7855A812
                            SHA-256:4549C856E0C5F463254873B21EABB9DED15249EC691B53837333842ACC22F384
                            SHA-512:AD67A4F4371162613199AF479348CD7FE57C6D5014D82ECC275D91B6BDC0868CEBA9863DA9E9C2D5119930EBF2AE144D2EAE8E88333B07EED2D7875C771CD975
                            Malicious:false
                            Reputation:unknown
                            Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13358425947811214","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13358425947811214","location":5,"ma
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:8A7158845967F4D0C209D1103D6830BD
                            SHA1:22DF6392E32C8D2C107739C7647AC0AE7855A812
                            SHA-256:4549C856E0C5F463254873B21EABB9DED15249EC691B53837333842ACC22F384
                            SHA-512:AD67A4F4371162613199AF479348CD7FE57C6D5014D82ECC275D91B6BDC0868CEBA9863DA9E9C2D5119930EBF2AE144D2EAE8E88333B07EED2D7875C771CD975
                            Malicious:false
                            Reputation:unknown
                            Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13358425947811214","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13358425947811214","location":5,"ma
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:8A7158845967F4D0C209D1103D6830BD
                            SHA1:22DF6392E32C8D2C107739C7647AC0AE7855A812
                            SHA-256:4549C856E0C5F463254873B21EABB9DED15249EC691B53837333842ACC22F384
                            SHA-512:AD67A4F4371162613199AF479348CD7FE57C6D5014D82ECC275D91B6BDC0868CEBA9863DA9E9C2D5119930EBF2AE144D2EAE8E88333B07EED2D7875C771CD975
                            Malicious:false
                            Reputation:unknown
                            Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13358425947811214","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13358425947811214","location":5,"ma
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:8A7158845967F4D0C209D1103D6830BD
                            SHA1:22DF6392E32C8D2C107739C7647AC0AE7855A812
                            SHA-256:4549C856E0C5F463254873B21EABB9DED15249EC691B53837333842ACC22F384
                            SHA-512:AD67A4F4371162613199AF479348CD7FE57C6D5014D82ECC275D91B6BDC0868CEBA9863DA9E9C2D5119930EBF2AE144D2EAE8E88333B07EED2D7875C771CD975
                            Malicious:false
                            Reputation:unknown
                            Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13358425947811214","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13358425947811214","location":5,"ma
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):111
                            Entropy (8bit):4.718418993774295
                            Encrypted:false
                            SSDEEP:
                            MD5:285252A2F6327D41EAB203DC2F402C67
                            SHA1:ACEDB7BA5FBC3CE914A8BF386A6F72CA7BAA33C6
                            SHA-256:5DFC321417FC31359F23320EA68014EBFD793C5BBED55F77DAB4180BBD4A2026
                            SHA-512:11CE7CB484FEE66894E63C31DB0D6B7EF66AD0327D4E7E2EB85F3BCC2E836A3A522C68D681E84542E471E54F765E091EFE1EE4065641B0299B15613EB32DCC0D
                            Malicious:false
                            Reputation:unknown
                            Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:ASCII text, with very long lines (3951), with CRLF line terminators
                            Category:dropped
                            Size (bytes):11755
                            Entropy (8bit):5.190465908239046
                            Encrypted:false
                            SSDEEP:
                            MD5:07301A857C41B5854E6F84CA00B81EA0
                            SHA1:7441FC1018508FF4F3DBAA139A21634C08ED979C
                            SHA-256:2343C541E095E1D5F202E8D2A0807113E69E1969AF8E15E3644C51DB0BF33FBF
                            SHA-512:00ADE38E9D2F07C64648202F1D5F18A2DFB2781C0517EAEBCD567D8A77DBB7CB40A58B7C7D4EC03336A63A20D2E11DD64448F020C6FF72F06CA870AA2B4765E0
                            Malicious:false
                            Reputation:unknown
                            Preview:{.. "DefaultCohort": {.. "21f3388b-c2a5-4791-8f6e-a4cad6d17f4f.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.BingHomePage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Covid.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Finance.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Jobs.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.KnowledgeCard.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Local.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.NTP3PCLICK.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.NotifySearchPage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Recipe.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.SearchPage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Sports.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Travel.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Weather.Bubble": 1,.. "2cb2db96-3bd0-403e-abe2-9269b3761041.Bubble": 1,.
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):120
                            Entropy (8bit):3.32524464792714
                            Encrypted:false
                            SSDEEP:
                            MD5:A397E5983D4A1619E36143B4D804B870
                            SHA1:AA135A8CC2469CFD1EF2D7955F027D95BE5DFBD4
                            SHA-256:9C70F766D3B84FC2BB298EFA37CC9191F28BEC336329CC11468CFADBC3B137F4
                            SHA-512:4159EA654152D2810C95648694DD71957C84EA825FCCA87B36F7E3282A72B30EF741805C610C5FA847CA186E34BDE9C289AAA7B6931C5B257F1D11255CD2A816
                            Malicious:false
                            Reputation:unknown
                            Preview:C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t.\.E.d.g.e.\.A.p.p.l.i.c.a.t.i.o.n.\.m.s.e.d.g.e...e.x.e.
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:207D18EE0879FED06FB9AFAE91CC141B
                            SHA1:292F76364D7757E8ED1E0D24CA31A623AD968460
                            SHA-256:733870B120E3DF12CE7A82063867BAD2951CC5314467A5373E3D0DD608B59730
                            SHA-512:89D2690DD85147EF4628EE68BB87A3BFBDC761DB3E11B4AD418397BFBC7314212D3FCD997793EF02250FA849FD5ACE4FA74371F229FE3B1419E63840FE315BBA
                            Malicious:false
                            Reputation:unknown
                            Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:207D18EE0879FED06FB9AFAE91CC141B
                            SHA1:292F76364D7757E8ED1E0D24CA31A623AD968460
                            SHA-256:733870B120E3DF12CE7A82063867BAD2951CC5314467A5373E3D0DD608B59730
                            SHA-512:89D2690DD85147EF4628EE68BB87A3BFBDC761DB3E11B4AD418397BFBC7314212D3FCD997793EF02250FA849FD5ACE4FA74371F229FE3B1419E63840FE315BBA
                            Malicious:false
                            Reputation:unknown
                            Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:207D18EE0879FED06FB9AFAE91CC141B
                            SHA1:292F76364D7757E8ED1E0D24CA31A623AD968460
                            SHA-256:733870B120E3DF12CE7A82063867BAD2951CC5314467A5373E3D0DD608B59730
                            SHA-512:89D2690DD85147EF4628EE68BB87A3BFBDC761DB3E11B4AD418397BFBC7314212D3FCD997793EF02250FA849FD5ACE4FA74371F229FE3B1419E63840FE315BBA
                            Malicious:false
                            Reputation:unknown
                            Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:207D18EE0879FED06FB9AFAE91CC141B
                            SHA1:292F76364D7757E8ED1E0D24CA31A623AD968460
                            SHA-256:733870B120E3DF12CE7A82063867BAD2951CC5314467A5373E3D0DD608B59730
                            SHA-512:89D2690DD85147EF4628EE68BB87A3BFBDC761DB3E11B4AD418397BFBC7314212D3FCD997793EF02250FA849FD5ACE4FA74371F229FE3B1419E63840FE315BBA
                            Malicious:false
                            Reputation:unknown
                            Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:207D18EE0879FED06FB9AFAE91CC141B
                            SHA1:292F76364D7757E8ED1E0D24CA31A623AD968460
                            SHA-256:733870B120E3DF12CE7A82063867BAD2951CC5314467A5373E3D0DD608B59730
                            SHA-512:89D2690DD85147EF4628EE68BB87A3BFBDC761DB3E11B4AD418397BFBC7314212D3FCD997793EF02250FA849FD5ACE4FA74371F229FE3B1419E63840FE315BBA
                            Malicious:false
                            Reputation:unknown
                            Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:207D18EE0879FED06FB9AFAE91CC141B
                            SHA1:292F76364D7757E8ED1E0D24CA31A623AD968460
                            SHA-256:733870B120E3DF12CE7A82063867BAD2951CC5314467A5373E3D0DD608B59730
                            SHA-512:89D2690DD85147EF4628EE68BB87A3BFBDC761DB3E11B4AD418397BFBC7314212D3FCD997793EF02250FA849FD5ACE4FA74371F229FE3B1419E63840FE315BBA
                            Malicious:false
                            Reputation:unknown
                            Preview:{"abusive_adblocker_etag":"\"8ABCE35666CBACA121128B98C75E78308AAC1CE803625FAFB4A7AFA722C77CA4\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):270336
                            Entropy (8bit):8.280239615765425E-4
                            Encrypted:false
                            SSDEEP:
                            MD5:D0D388F3865D0523E451D6BA0BE34CC4
                            SHA1:8571C6A52AACC2747C048E3419E5657B74612995
                            SHA-256:902F30C1FB0597D0734BC34B979EC5D131F8F39A4B71B338083821216EC8D61B
                            SHA-512:376011D00DE659EB6082A74E862CFAC97A9BB508E0B740761505142E2D24EC1C30AA61EFBC1C0DD08FF0F34734444DE7F77DD90A6CA42B48A4C7FAD5F0BDDD17
                            Malicious:false
                            Reputation:unknown
                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
                            Category:dropped
                            Size (bytes):262512
                            Entropy (8bit):9.553120663130604E-4
                            Encrypted:false
                            SSDEEP:
                            MD5:053DD740ACCAD8E0C0A6A3B3EBED5969
                            SHA1:835289DB2E1F806E4E4F4F252EDB53DA1F935ACF
                            SHA-256:D01E2450B3F48DD35B26416BF7D72E7F0E3179246CC77FB100A30216ABB3B3C3
                            SHA-512:01115544332E88D4E174E01DFABD6EA8C0BED75DE4016659AFF2682A0EFF0BAB600F53C2D4B8C527843D9C5D5AC32C830A24E1109577E504B65BF5244ADAACBE
                            Malicious:false
                            Reputation:unknown
                            Preview:........................................e...ju/.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:ASCII text, with no line terminators
                            Category:dropped
                            Size (bytes):29
                            Entropy (8bit):4.030394788231021
                            Encrypted:false
                            SSDEEP:
                            MD5:52E2839549E67CE774547C9F07740500
                            SHA1:B172E16D7756483DF0CA0A8D4F7640DD5D557201
                            SHA-256:F81B7B9CE24F5A2B94182E817037B5F1089DC764BC7E55A9B0A6227A7E121F32
                            SHA-512:D80E7351E4D83463255C002D3FDCE7E5274177C24C4C728D7B7932D0BE3EBCFEB68E1E65697ED5E162E1B423BB8CDFA0864981C4B466D6AD8B5E724D84B4203B
                            Malicious:false
                            Reputation:unknown
                            Preview:topTraffic_638004170464094982
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:raw G3 (Group 3) FAX, byte-padded
                            Category:dropped
                            Size (bytes):460992
                            Entropy (8bit):7.999625908035124
                            Encrypted:true
                            SSDEEP:
                            MD5:E9C502DB957CDB977E7F5745B34C32E6
                            SHA1:DBD72B0D3F46FA35A9FE2527C25271AEC08E3933
                            SHA-256:5A6B49358772DB0B5C682575F02E8630083568542B984D6D00727740506569D4
                            SHA-512:B846E682427CF144A440619258F5AA5C94CAEE7612127A60E4BD3C712F8FF614DA232D9A488E27FC2B0D53FD6ACF05409958AEA3B21EA2C1127821BD8E87A5CA
                            Malicious:false
                            Reputation:unknown
                            Preview:...2lI.5.<C.;.{....._+jE.`..}....-...#.A...KR...l.M0,s...).9..........x.......F.b......jU....y.h'....L<...*..Z..*%.*..._...g.4yu...........'c=..I0..........qW..<:N....<..U.,Mi..._......'(..U.9.!........u....7...4. ..Ea...4.+.79k.!T.-5W..!..@+..$..t|1.E..7F...+..xf....z&_Q...-.B...)8R.c....0.......B.M.Z...0....&v..<..H...3.....N7K.T..D>.8......P.D.J.I4.B.H.VHy...@.Wc.Cl..6aD..j.....E..*4..mI..X]2.GH.G.L...E.F.=.J...@}j~.#...'Y.L[z..1.W/.Ck....L..X........J.NYd........>...N.F..z*.{nZ~d.N..../..6.\L...Q...+.w..p...>.S.iG...0]..8....S..)`B#.v..^.*.T.?...Z.rz.D'.!.T.w....S..8....V.4.u.K.V.......W.6s...Y.).[.c.X.S..........5.X7F...tQ....z.L.X..(3#j...8...i.[..j$.Q....0...]"W.c.H..n..2Te.ak...c..-F(..W2.b....3.]......c.d|.../....._...f.....d....Im..g.b..R.q.<x*x...i2..r.I()Iat..b.j.r@K.+5..C.....nJ.>*P,.V@.....s.4.3..O.r.....smd7...L.....].u&1../t.*.......uXb...=@.....wv......]....#.{$.w......i.....|.....?....E7...}$+..t).E.U..Q..~.`.)..Y@.6.h.......%(
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):330
                            Entropy (8bit):4.989864781293748
                            Encrypted:false
                            SSDEEP:
                            MD5:BA0367A38B591265E424CB3073B04B0D
                            SHA1:31647ABF3D3FAFED9C0C19EF7D7F45F6CF0BCCDD
                            SHA-256:EED96AC1DEEB06EEBC3BEC7FCE0CBEAC651262725256C97EACE2C06BA5C567B3
                            SHA-512:6765F1A6C23B99608014F4061FBED57FB246BA350BA08F578749D710F3E3726F12EFAE4A639E1691CDC3D6DBE867971DE6D273D0B514525C054AA1C0CAE4CB7A
                            Malicious:false
                            Reputation:unknown
                            Preview:{"version":1,"cache_data":[{"file_hash":"a81ff3d75eee53b2","server_context":"1;f94c025f-7523-6972-b613-ce2c246c55ce;unkn:100;0.01","result":1,"expiration_time":1714053158848525},{"file_hash":"4e10948c7caf613e","server_context":"1;f94c025f-7523-6972-b613-ce2c246c55ce;unkn:100;0.01","result":1,"expiration_time":1714053158062839}]}
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):86
                            Entropy (8bit):4.3751917412896075
                            Encrypted:false
                            SSDEEP:
                            MD5:E9E365607374115B92E4ABE4B9628101
                            SHA1:D5054EA9B22317DCA83801EB3586017BFCC0E2A8
                            SHA-256:5CD2C4D9F13524923046198C92213691539407E04FA520CDAE9EADE1BAD3D91D
                            SHA-512:A84D65ED53E43883E5ECB7848FBD48F5305A63E6975E6AF480CF85532879720061106BE54F2A5888EBC3569F7123081A0E6EB48CCB8D7DBA3E1DA1C8A3C50401
                            Malicious:false
                            Reputation:unknown
                            Preview:{"user_experience_metrics.stability.exited_cleanly":false,"variations_crash_streak":3}
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):2278
                            Entropy (8bit):3.8512315134394637
                            Encrypted:false
                            SSDEEP:
                            MD5:BBD26C481FD84583D841F5BB546C2C32
                            SHA1:64F5702B37335EA411264E4F09F3063568074280
                            SHA-256:F453313EB7C9F17A3ED20E2B005E9421DCBB7DCD57E30F4994E1C71551E9BAA5
                            SHA-512:A4A56639CCAC174625FB8786ADF221B6325096A24AE465656EDC43E0DE26D9990E62305767D3721ACB8409F3A8382DB4FBAA8CB34BAF370DA95EFBD6233163EC
                            Malicious:false
                            Reputation:unknown
                            Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".W.i.p.w.W.M.+.N.H.l.b.C.D.m.s.Z.p.8.S.O.s.j.h.t.F.B.s.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".g.B.v.U.g.z.W.W.2.g.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.y.e.p.7.I.T.
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):4622
                            Entropy (8bit):3.997825785430122
                            Encrypted:false
                            SSDEEP:
                            MD5:6985FE075192D0E7E5B053B0E494C901
                            SHA1:DC19AC89EBBE29877018E6AE8303D8C05382B84B
                            SHA-256:9E795D0F5B3F2A1351BC505D99F42EE130DB4AB631D18E662A003677AC62C6A8
                            SHA-512:48F8943E7B19F6A5CA3671689F1D427BCE3CBBCAA70F08509987A7D1CFA891FB66B3DBED0B64E09D161B1CB77FDB33E305D02BABFDE67FFA990B8C28A8EE3638
                            Malicious:false
                            Reputation:unknown
                            Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".z.3.U.T.q.T.b.3.7./.u.z.h.i.f.l.b.4.0.f.z.h.D.r.E.s.w.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".2.R.f.V.a.S.2.W.2.g.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.w.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.y.e.p.7.I.T.
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):1420
                            Entropy (8bit):5.414266586820699
                            Encrypted:false
                            SSDEEP:
                            MD5:352B151B90363B4BC1ED78C612F4D40E
                            SHA1:339B441283398FD2D50BB52AB3456F57F289D418
                            SHA-256:1F10965FBDD9151B8AC432CA62854F9E652F3B5D0B5501031C6F83DE3B6D9122
                            SHA-512:C44DB1D3E7E4517F298776A83B9D4CB2965DDDA467462463CACB3885038A711A32C74E887E1A1089B585FC4CA1FB635C3B4CEE3D5C1B559A6D5E68DD60EAD1E3
                            Malicious:false
                            Reputation:unknown
                            Preview:{"logTime": "1006/090722", "correlationVector":"rmkayOhJfEabcRCB2/Bp31","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1006/090722", "correlationVector":"jqHPV/yTVN5KYgOfDN/5Rr","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1006/090722", "correlationVector":"25C1A0EE3BD244A1BB83CF2641B12F1A","action":"FETCH_UX_CONFIG", "result":""}.{"logTime": "1006/093120", "correlationVector":"a/GaihlkzouX6tpAQ3civy","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1006/093121", "correlationVector":"2831F27CA5B645488E2DF2452C16A59E","action":"FETCH_UX_CONFIG", "result":""}.{"logTime": "1006/093243", "correlationVector":"7DhT8FK3VbHYWFgub0ZtsN","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1006/093243", "correlationVector":"83EFC8979E1A419495133BAFAFA5A23F","action":"FETCH_UX_CONFIG", "result":""}.{"logTime": "1006/093745", "correlationVector":"Bxyvid0fodNJ7Wehc/BC7P","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1006/093746", "correlationVector":"B1516CBB
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):60745429
                            Entropy (8bit):6.670116413071613
                            Encrypted:false
                            SSDEEP:
                            MD5:60EAACE4A765CED6278F3C1C7B60EF5D
                            SHA1:C539B307A2B13E20A167ADE2D4F56CE64DD6869F
                            SHA-256:3F695937AEC62B4D7E0D9119F539E9455C5F2EF717C2B4C01DE82157283E132B
                            SHA-512:AECC2D486FCBA688EF13A727E5C84517FDBBD96407ECA74766A4DDEDAD5C165ABDF7DCC37AABA60A6A35C3696E62C05F1A003F518AF79F95030C685C2A270384
                            Malicious:false
                            Reputation:unknown
                            Preview:........,..............................>.......................................................................d...........................................................................................................................................................................b...o...........$...j...............,...............................................................................................................................V...M...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows
                            Category:dropped
                            Size (bytes):3745792
                            Entropy (8bit):6.546944660250478
                            Encrypted:false
                            SSDEEP:
                            MD5:E746969A96345CA1D329F5D64310B0A4
                            SHA1:1CD87CC5036B6F7739F9F025175A47D170037B6A
                            SHA-256:8D8FC1D4EEAB292C88829F410BAB72BD36E9A2507B041C1E8675E4378B7B6E81
                            SHA-512:F97B2785139332294D1550649D0DB08FF1F255C1E0680A0B2969EAF29C20FC804B42320A9115C616EB51237EBE00E37D81225507F90595B7D4A79C36E11F4D2E
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...#M.a...........#...%..&...9..F...6&.......&...8g..........................9.......9...@... .......................4.......5.`....@5..J....................8..+....................................................5.x............................text.....&.......&.................`..`.data....@....&..B....&.............@....rdata........&.......&.............@..@.eh_framp...........................@..@.bss....PE....4..........................edata........4.......4.............@..@.idata..`.....5.. ....4.............@....CRT....,.... 5.......4.............@....tls.........05.......4.............@....rsrc....J...@5..J....4.............@....reloc...+....8..,....7.............@..B........................................................................................................................................................................................
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                            Category:dropped
                            Size (bytes):12288
                            Entropy (8bit):5.814115788739565
                            Encrypted:false
                            SSDEEP:
                            MD5:CFF85C549D536F651D4FB8387F1976F2
                            SHA1:D41CE3A5FF609DF9CF5C7E207D3B59BF8A48530E
                            SHA-256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8
                            SHA-512:531D6328DAF3B86D85556016D299798FA06FEFC81604185108A342D000E203094C8C12226A12BD6E1F89B0DB501FB66F827B610D460B933BD4AB936AC2FD8A88
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......qr*.5.D.5.D.5.D...J.2.D.5.E.!.D.....2.D.a0t.1.D.V1n.4.D..3@.4.D.Rich5.D.........PE..L.....Oa...........!....."...........*.......@...............................p............@..........................B.......@..P............................`.......................................................@..X............................text.... .......".................. ..`.rdata..c....@.......&..............@..@.data...x....P.......*..............@....reloc.......`.......,..............@..B................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                            Category:modified
                            Size (bytes):7168
                            Entropy (8bit):5.298362543684714
                            Encrypted:false
                            SSDEEP:
                            MD5:675C4948E1EFC929EDCABFE67148EDDD
                            SHA1:F5BDD2C4329ED2732ECFE3423C3CC482606EB28E
                            SHA-256:1076CA39C449ED1A968021B76EF31F22A5692DFAFEEA29460E8D970A63C59906
                            SHA-512:61737021F86F54279D0A4E35DB0D0808E9A55D89784A31D597F2E4B65B7BBEEC99AA6C79D65258259130EEDA2E5B2820F4F1247777A3010F2DC53E30C612A683
                            Malicious:false
                            Reputation:unknown
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........................,.................Rich...........................PE..L.....Oa...........!......................... ...............................P............@..........................$..l.... ..P............................@....................................................... ...............................text............................... ..`.rdata..<.... ......................@..@.data........0......................@....reloc.......@......................@..B................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:Google Chrome extension, version 3
                            Category:dropped
                            Size (bytes):11185
                            Entropy (8bit):7.951995436832936
                            Encrypted:false
                            SSDEEP:
                            MD5:78E47DDA17341BED7BE45DCCFD89AC87
                            SHA1:1AFDE30E46997452D11E4A2ADBBF35CCE7A1404F
                            SHA-256:67D161098BE68CD24FEBC0C7B48F515F199DDA72F20AE3BBB97FCF2542BB0550
                            SHA-512:9574A66D3756540479DC955C4057144283E09CAE11CE11EBCE801053BB48E536E67DC823B91895A9E3EE8D3CB27C065D5E9030C39A26CBF3F201348385B418A5
                            Malicious:false
                            Reputation:unknown
                            Preview:Cr24..............0.."0...*.H.............0.........N.......E#......9e.u.q...VYY..@.+.C..k.O..bK.`..6.G..%.....3Z...e _.6....F..1p..K.Z......./ .3...OT..`..0...Y...FT..43.th.y...}....p.L...2S.&i.`..o...f.oH.....N..:..ijT.3.F{.0.,.f?'f.CQt;b_"Pc.. ..~S.I.c.8Z.;.....{G.a......k...>.`.o..%.$>;.....g.............jg?.R..@.:..........&..{...x@.Py..;kT....%F".S..w...N....9...A..@X.t!i.@..1;......1E..X.....[.~$....J......;=T.;)k..Y...$......S......M.P..P..>..=..u.....2p...w.9..1qw.a\A..Vj .C.....A..Cf1.r6.A...L. _m...[..l.Wr_../.. .B..9!.!+..ZG.K.......0.."0...*.H.............0.........^SUd%Q.L].......Cl2o...\[.....'*...;R=....N.C5....d. .....J.C>u.kr..Y..syJC.XS.q..E.n?....(G.5..)2.G..!.M.SS.{..U....!.EE..M[.#qs.A.1...g)nQ.c..G....Bd..7... .O.BI..KXQ..4.d.K.0......g.....-p....Z.E{...M&.~n.TE7..{0....5.#.C+3.y)pd9.e.........@..3.9..B.....I....2nX........2.?.~..S....]G.N.....Lr.O.Ve....9..D1.G..W)...P.?=.#..7.R.lz..a.wX.e..h.h.~....v..RP.@X....d.G
                            Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                            File Type:Google Chrome extension, version 3
                            Category:dropped
                            Size (bytes):139091
                            Entropy (8bit):7.817886952439696
                            Encrypted:false
                            SSDEEP:
                            MD5:87996BA4DD83A8988D96E918DCB2BC62
                            SHA1:23910F09EA806D13D9A337A1E23D5FA49B383269
                            SHA-256:6409D21A03FAFF1503AA83A19BE0B7DCB701F5E4501C4FEFB81877147E869D57
                            SHA-512:A9A1B4BB6ED0410232DB0414AB238BAA594F6C936A801213E0E6FD7FF96F34AB57036CD0070C68D75A8CFDA89B7240B6FB8F661BC9C4D9A45666A798D7D12999
                            Malicious:false
                            Reputation:unknown
                            Preview:Cr24....."........0.."0...*.H.............0.........^...1"...w.g..t..2J.G1.)X4..=&.?[j,Lz..j.u.e[I.q*Ba/X...P.h..L.....2%3_o.......H.)'.=.e...?.......j..3UH.|.X.M..u..s[.*..?$....F%....I....)..,-./.e5).f..O.q.^........9..(.._.ph2..^.YBPXf_8....h[.v...S.*1`.#..5.SF.:f-.#.65.i..b.]9...y2.'....k[........:.W.!........5.y.i%e..S.....+.h/...e.p|/.l}t.9....W.......Ie<.o..uO....[:.....,.w.SKOp..0...@.gT..W.6.R.d.1.b.~..8..I......DMf9A>.O5....?.....4{..g..2m.Ckp......{...9..I.$.h#to..[.%..\.s..n^zr.P.9..r|.(.1..Q..Vld..h..<.P......+.y.wH..p..=.!..x......[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...G0E.!..h.G...A.t..;.zl..q..z{...... .;..oQ*f.....S..$./.....6.r..".@...........|[s.:.._..wW!0^..m...X".]@.vu.". 0.I....~....t.t...d.....CB.....s.q...i..~.?..-...L.....u....v>....s}..f......6.W}*.9...]e......m[.....p..bX..{~.m...~....>^.2....NGs|.:f..>...1.....kU.vL...uo.u......K......|ic!.."..5.g.9..0w2.C90.V.
                            Process:C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
                            File Type:PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
                            Category:dropped
                            Size (bytes):2244
                            Entropy (8bit):7.873992547923548
                            Encrypted:false
                            SSDEEP:
                            MD5:25935ACC2535E69B837A41061D959E4E
                            SHA1:327BF8BB5D28F477A5C8A9B573FF6891BDD610F2
                            SHA-256:D86BE7FA7398A846EAE9F769622215E84EE3769ED8860627EB284CCFDFDA98A7
                            SHA-512:9D2B43AA71CAA80917A9F0055A011C4EE66F3297BAA268D88A03F2FFA5055D14B8DEEBD2EE3AF4C58C7529A507750964A9A110CF6804FE59980523A7DBD30BA6
                            Malicious:false
                            Reputation:unknown
                            Preview:.PNG........IHDR...0...0.....W.......sRGB.........gAMA......a.....pHYs..........o.d...YIDAThC.Z{PTU........4.....N.5=....5....4:.c....`w.UT 5IEQ.QPTJA..|Q&.$!. .8....oX`......^........+...}.s..=.].W..0P.-zU........9>:....U...T..>.G.1....7@X0..!D=......Pi.SV..7.".....F.:.4a...l.~i..>....zu....OQO`E"u.,$b.fM..K...D....=\i..LM}.d..y..:..A..e....`;"..V.F2.=j....x..*.p.v...A...G..;.....L.......E.!.C.`...z...a.xc.!V.C.u...c.....?b..e01f.,.....).'3..r../..7.4.?..A.w.'..a...x@...%..&.h!.N.7.:Zy7.....B.d8s...Mw........j.J.nm.&K.T.Mp.Z.D.v......o.N..t..=jxxp...dNx.....l...2.`GG.W.1.f3.$'.3...7/.IX.y..L.....Y.......?ggB...U....n..."L...(...P........9.._...mm......o.!........K...KM..;.n.....0~S8W.]...V.h.K.55.;.....}..p(C;......~...f...#V-....8.>...W....Qp.B.T..2......x..U..|.g.l.K..&..I...1..]."Q.V.......`.(x.....G.~.u..<s...9,.31...Cx.xc..........b.*....&N...,......zXq8...[.........@<T...........(..l..l...E}s.d.k..aQ..<x.1.....-."e?...N..n.L..Q
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):949
                            Entropy (8bit):5.667941006065508
                            Encrypted:false
                            SSDEEP:
                            MD5:E8032FF1E06E3EAB00908F9EA0598979
                            SHA1:AFB97A7643B9D06B8E679853EEF1D9D6911E063F
                            SHA-256:868DFFC2A1EBBA118B1F08F65DA622DF5FAA954F738CBACF511903814CACCCF1
                            SHA-512:8BA178B1A9BDC9ED5825D923B85C2A98CBAC3ACB73BBE53D2608C118C167CBDC7429D2554A077F5F3C6B39776A59F52A973383B19E843A84A29EAE2C40A8CDB2
                            Malicious:false
                            Reputation:unknown
                            Preview:{"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAAAF6nMrn6c13Ab5Bt5RWCLncCOgZoYawOOOniyrgxysNAAAAAAOgAAAAAIAACAAAAAVy9xTF3vkHgGMaBroC1ADBc3dZd0yth82Rw5LJQwrcjAAAACBloUjouJtlqai8iu/HyOihMag083x+CjMi3aY8CrW8rAAKbaADJYjZyWUINdsTXdAAAAA1h8as5mn+4e7sPg+BKR897/JVgTzmPoKF+oJp62JiI5ZiEjKJg+5mrUPdDdceL1Kq9CTvmMFvsQXGp2P/vY2+w=="},"uninstall_metrics":{"installation_date2":"1713952333"},"user_experience_metrics":{"client_id2":"{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}C:\\Users\\user0s:92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A","diagnostics":{"last_data_collection_level_on_launch":1},"low_entropy_source3":4020,"pseudo_low_entropy_source":2235,"reset_client_id_deterministic":true,"stability":{"browser_last_live_timestamp":"13358425933775001","stats_buildtime":"1695934310","stats_version":"117.0.2045.47-64","system_crash_count":0}}}
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3436
                            Entropy (8bit):5.264271212140568
                            Encrypted:false
                            SSDEEP:
                            MD5:4BDEEBF9A68446CB9E0778B851F6483E
                            SHA1:A0FE594D3BDC626BD6C6685A7C35E4A2824FC21C
                            SHA-256:D66081748158168BD8697467E5A74F0A8F7F800A8A44B765097302D15F5C5186
                            SHA-512:3CCAD4D297A6713A1ECA420AA5DA7C329E3A5126A5DBC7AB61AC5B8E7F572251D65BF52D3DAD0D0865E32A3AA4A856E4FF248DB9495CBAD16D6B9865C0F27ABE
                            Malicious:false
                            Reputation:unknown
                            Preview:{"dual_engine":{"ie_to_edge":{"redirection_mode":0}},"edge":{"tab_stabs":{"closed_without_unfreeze_never_unfrozen":0,"closed_without_unfreeze_previously_unfrozen":0,"discard_without_unfreeze_never_unfrozen":0,"discard_without_unfreeze_previously_unfrozen":0},"tab_stats":{"frozen_daily":0,"unfrozen_daily":0}},"fre":{"oem_bookmarks_set":true},"hardware_acceleration_mode_previous":true,"is_dsp_recommended":true,"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.713952335346767e+12,"network":1.713952336e+12,"ticks":5473221978.0,"uncertainty":2392643.0}},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAAAF6nMrn6c13Ab5Bt5RWCLncCOgZoYawOOOniyrgxysNAAAAAAOgAAAAAIAACAAAAAVy9xTF3vkHgGMaBroC1ADBc3dZd0yth82Rw5LJQwrcjAAAACBloUjouJtlqai8iu/HyOihMag083x+CjMi3aY8CrW8rAAKbaADJYjZyWUINdsTXdAAAAA1h8as5mn+4e7sPg+BKR897/JVgTzmPoKF+oJp62
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):2052
                            Entropy (8bit):5.445120396867814
                            Encrypted:false
                            SSDEEP:
                            MD5:56EC66E3A316CFAA0780BF0704F0EB96
                            SHA1:D48CE60393B1314C3B6B394C5938216C7F74E6DD
                            SHA-256:EFD2853556643873F90A379068AA3B1CD57A4343D6879AE07AC1734B6DA02C3F
                            SHA-512:78AAAE8B3AA7D13C9A4F3C44ADB313EE23B75CCF896D5C358FE573B100A90C1840E1FFB7E013AB494FB2CBC6C620F0A2080A5A7F410BC5B6EE858026DBF60C0C
                            Malicious:false
                            Reputation:unknown
                            Preview:{"dual_engine":{"ie_to_edge":{"redirection_mode":0}},"edge":{"tab_stabs":{"closed_without_unfreeze_never_unfrozen":0,"closed_without_unfreeze_previously_unfrozen":0,"discard_without_unfreeze_never_unfrozen":0,"discard_without_unfreeze_previously_unfrozen":0},"tab_stats":{"frozen_daily":0,"unfrozen_daily":0}},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAAAF6nMrn6c13Ab5Bt5RWCLncCOgZoYawOOOniyrgxysNAAAAAAOgAAAAAIAACAAAAAVy9xTF3vkHgGMaBroC1ADBc3dZd0yth82Rw5LJQwrcjAAAACBloUjouJtlqai8iu/HyOihMag083x+CjMi3aY8CrW8rAAKbaADJYjZyWUINdsTXdAAAAA1h8as5mn+4e7sPg+BKR897/JVgTzmPoKF+oJp62JiI5ZiEjKJg+5mrUPdDdceL1Kq9CTvmMFvsQXGp2P/vY2+w=="},"policy":{"last_statistics_update":"13358425933926894"},"profile":{"info_cache":{},"profile_counts_reported":"13358425933962983","profiles_order":[]},
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):2899
                            Entropy (8bit):5.283952427295385
                            Encrypted:false
                            SSDEEP:
                            MD5:D9F1B428E44B77E1D6DD1CA02A1F059E
                            SHA1:1B07D493E19A89966AC30D8E6B3C151AA6024AFE
                            SHA-256:8136452CA9C183F7FF00246E0EA2688E727A0D849FA610CFEB7B005A42504066
                            SHA-512:58E287F67AE2DD5ED5CBD0193EDBE963C946072A24F85A7DB3E6E6F6777C93C1A27003A69EED5D910694A1B477466C30CB4D39B93BD08BB0A81A4B6F6FB61999
                            Malicious:false
                            Reputation:unknown
                            Preview:{"dual_engine":{"ie_to_edge":{"redirection_mode":0}},"edge":{"tab_stabs":{"closed_without_unfreeze_never_unfrozen":0,"closed_without_unfreeze_previously_unfrozen":0,"discard_without_unfreeze_never_unfrozen":0,"discard_without_unfreeze_previously_unfrozen":0},"tab_stats":{"frozen_daily":0,"unfrozen_daily":0}},"fre":{"oem_bookmarks_set":true},"hardware_acceleration_mode_previous":true,"legacy":{"profile":{"name":{"migrated":true}}},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAAAF6nMrn6c13Ab5Bt5RWCLncCOgZoYawOOOniyrgxysNAAAAAAOgAAAAAIAACAAAAAVy9xTF3vkHgGMaBroC1ADBc3dZd0yth82Rw5LJQwrcjAAAACBloUjouJtlqai8iu/HyOihMag083x+CjMi3aY8CrW8rAAKbaADJYjZyWUINdsTXdAAAAA1h8as5mn+4e7sPg+BKR897/JVgTzmPoKF+oJp62JiI5ZiEjKJg+5mrUPdDdceL1Kq9CTvmMFvsQXGp2P/vY2+w=="},"policy":{"last_statistics_update":"13358425933926894"},"profile":{"info_cache":{"Default":{"avatar_icon":"chrome://t
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3414
                            Entropy (8bit):5.266352954491558
                            Encrypted:false
                            SSDEEP:
                            MD5:54D3AE0B794E09C9D9EFE7E8934D383D
                            SHA1:7506D95BF8825CB3DD6912F9698A8EAC6E9F88D9
                            SHA-256:29AB800FE287AFC33969ADB394E93DCBB88B64335A35506F52F5C92017EF8DA2
                            SHA-512:539510F9B479C36440856BA6C1FB827AABBC180B265DFAAB9D7CDE563566209F21C70D34EF46EDB22CDE7B91ECAE1FECB80F13D286227F2385D7B98D63131C1E
                            Malicious:false
                            Reputation:unknown
                            Preview:{"dual_engine":{"ie_to_edge":{"redirection_mode":0}},"edge":{"tab_stabs":{"closed_without_unfreeze_never_unfrozen":0,"closed_without_unfreeze_previously_unfrozen":0,"discard_without_unfreeze_never_unfrozen":0,"discard_without_unfreeze_previously_unfrozen":0},"tab_stats":{"frozen_daily":0,"unfrozen_daily":0}},"fre":{"oem_bookmarks_set":true},"hardware_acceleration_mode_previous":true,"is_dsp_recommended":true,"legacy":{"profile":{"name":{"migrated":true}}},"network_time":{"network_time_mapping":{"local":1.713952335346767e+12,"network":1.713952336e+12,"ticks":5473221978.0,"uncertainty":2392643.0}},"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAAAF6nMrn6c13Ab5Bt5RWCLncCOgZoYawOOOniyrgxysNAAAAAAOgAAAAAIAACAAAAAVy9xTF3vkHgGMaBroC1ADBc3dZd0yth82Rw5LJQwrcjAAAACBloUjouJtlqai8iu/HyOihMag083x+CjMi3aY8CrW8rAAKbaADJYjZyWUINdsTXdAAAAA1h8as5mn+4e7sPg+BKR897/JVgTzmPoKF+oJp62
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):1310720
                            Entropy (8bit):0.6523485424484741
                            Encrypted:false
                            SSDEEP:
                            MD5:F42000C85C4744D40B23144003958892
                            SHA1:CD4D1138C42DB16EF4202C0E213D17AFB0DBBCE6
                            SHA-256:B044737E0D3E4CEFAF579BFF3CFB1CFAC8352146AEF5A5CB7B4EE3C12E6B52BA
                            SHA-512:60A6726C60D2F5324FF1904444C7AD20496E0E01974C313A897731BD45205C0FC4243B728491739E1B0AEB55F1291BE5518E66F1F6AC171CB0B73C0CED63C790
                            Malicious:false
                            Reputation:unknown
                            Preview:...@............C.].....@...................8...............`... ...i.y.........BrowserMetrics......i.y..Yd. .......A...................v.0.....UV&K.k<................UV&K.k<................UMA.PersistentHistograms.InitResult.....8...i.y.[".................................................i.y.Pq.30....O.........117.0.2045.47-64".en-GB*...Windows NT..10.0.190452(..x86_64..?........".wjpnxw20,1...x86_64J....?.^o..P......................>..*......qW:00000000000000000000000000000000000000000000!00000000000000000000000000000000000000000000!Grammarly.Desktop.exe.)1900/01/01:00:00:00!Grammarly.Desktop.exe".1.2.73.13742...".*.:..............,..(.......EarlyProcessSingleton.......Default3.(..$.......msEdgeEDropUI.......triggered....8..4... ...msDelayLoadAuthenticationManager....triggered....<..8...#...msSleepingTabsShorterTimeoutDefault.....triggered....8..4... ...msEdgeMouseGestureDefaultEnabled....triggered....8..4.......msEdgeShowHomeButtonByDefault.......triggered....<..8...$...msConsum
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):280
                            Entropy (8bit):1.8745027105796201
                            Encrypted:false
                            SSDEEP:
                            MD5:21D5494CE6FDD5D3ACC927ECE86669E7
                            SHA1:6755EBD263A50859771F54BEE3F5687FFFAFFCEA
                            SHA-256:F63CEADD187809198732C01D56B742DC4B26F0B28DB85A4AD1B3075DB5ACE8AF
                            SHA-512:C59ADB643EB911772BB1F068AD83A1997B584C955D23212C11FD029DC35D3B8252AFF027CE4F420917E8B6C61D35FC387793046884AAD466C7C194751B3AD0CE
                            Malicious:false
                            Reputation:unknown
                            Preview:sdPC.....................W.x..M..a2P...................................................................................................................................................................................................{F3017226-FE2A-4295-8BDF-00C3A9A7E4C.}C:........
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):20
                            Entropy (8bit):3.6219280948873624
                            Encrypted:false
                            SSDEEP:
                            MD5:9E4E94633B73F4A7680240A0FFD6CD2C
                            SHA1:E68E02453CE22736169A56FDB59043D33668368F
                            SHA-256:41C91A9C93D76295746A149DCE7EBB3B9EE2CB551D84365FFF108E59A61CC304
                            SHA-512:193011A756B2368956C71A9A3AE8BC9537D99F52218F124B2E64545EEB5227861D372639052B74D0DD956CB33CA72A9107E069F1EF332B9645044849D14AF337
                            Malicious:false
                            Reputation:unknown
                            Preview:level=none expiry=0.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):6780
                            Entropy (8bit):5.5802957975348475
                            Encrypted:false
                            SSDEEP:
                            MD5:4F18C12442E98560AAC6B6FEC57E2AA6
                            SHA1:CB955C5580D118C59099A5FB51C7A762D33EB935
                            SHA-256:469295C4A1B19184182340489FE0E50620BE3A9A5EFEAB91FC1699C21EB4F802
                            SHA-512:B90A470D669C50EA7B7F59E7F62FAC0634C32AF701448C8AF98413F6C0A5212E188CBCF5D92B7E451B301A39198B2AF2774F7A0B4DA5E62441F17F84D7939538
                            Malicious:false
                            Reputation:unknown
                            Preview:{"extensions":{"settings":{"dgiklkfkllikcanfonkcabmbdfmgleag":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13358425934029904","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13358425934029904","location":5,"manifest":{"content_capabilities":{"include_globs":["https://*excel.officeapps.live.com/*","https://*onenote.officeapps.live.com/*","https://*powerpoint.officeapps.live.com/*","https://*word-edit.officeapps.live.com/*","https://*excel.officeapps.live.com.mcas.ms/*","https://*onenote.officeapps.live.com.mcas.ms/*","https://*word-edit.officeapps.live.com.mcas.ms/*","https://*excel.partner.officewebapps.cn/*","https://*onenote.partner.officewebapps.cn/*","https://*powerpoint.partner.officewebapps.cn/*","https://*word-edit.partner.officewebapps.cn/*","https://*excel.gov.online.office365.us/*","
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):5925
                            Entropy (8bit):4.829232806841579
                            Encrypted:false
                            SSDEEP:
                            MD5:1F4A9EF9D96451C388DCE4D3957B316F
                            SHA1:494FD7ECA4299377C554E79310479A715F3A537D
                            SHA-256:33D717F47A31643AEC9CB01459E81196EF5220EA52E9EA10E6203635EC05A132
                            SHA-512:E2597374B0890FA69F354DFAC38C46A72CB2615CF297B64D6F612CE0AC03517EFCE6E24624939181C400385CE11AAF9FFCBA957C50F98A3604A6C14C40980370
                            Malicious:false
                            Reputation:unknown
                            Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13358425934706597","alternate_error_pages":{"backup":true,"enabled":false},"autocomplete":{"retention_policy_last_version":117},"autofill":{"autostuff_enabled":false,"credit_card_enabled":false,"custom_data_enabled":false,"custom_data_fill_enabled":false,"custom_data_identify_info_from_form_enabled":false,"custom_data_save_enabled":false},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false},"browser_content_container_height":618,"browser_content_container_width":1060,"browser_content_container_x":0,"browser_content_container_y":0,"countryid_at_install":17224,"credentials_enable_service":false,"dips_timer_last_update":"13358425934566723","domain_diversity":{"last_reporting_timestamp":"13358425934707113"},"dual_engine":{"consumer_mode":{"ie_user":false},"consumer_site_list_with_ie_entries":false,"consumer_sitelist_location":"","consumer_sitelist_version":"","external_consumer_shared_cookie_data"
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:dBase III DBT, next free block index 3238316739, block length 1024
                            Category:dropped
                            Size (bytes):45056
                            Entropy (8bit):0.02796958733322039
                            Encrypted:false
                            SSDEEP:
                            MD5:F39B91A6318226228A8FF4561BA6B5C3
                            SHA1:C2DE49CC394213159736028BF996849416FC1C81
                            SHA-256:3833EC2CFCE3B7AABC4D009A16C0A927334B97E00E39AEFC44D7DE23EAFF18BA
                            SHA-512:D9BC6B9E6BEE21593ED3D58901E693B52A61248FF3B894A1826ED8C47210DEBA0994F1AE6BAC99A1E888A9B4485BF8957688E5BA4F3717E3052DA74A652F09C3
                            Malicious:false
                            Reputation:unknown
                            Preview:............$...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):270336
                            Entropy (8bit):0.07088945182108078
                            Encrypted:false
                            SSDEEP:
                            MD5:3D0E73C825DFA70E2E0E30B61ECFC5A3
                            SHA1:27F1948D95959C1841DB725AE16B1D6A367938E0
                            SHA-256:C40490471ED9119623053222A2688004D3C0C16FC00A09FA002468674B8654D2
                            SHA-512:7DF9557C2FC3E0D0F05A1B02F566BFA6D92A87156CFF401B9311E0D2CD22CE9F701146BBE8BB48A2208D9F8D7DE14623DE044B0D16B50837C4861D20683F55A3
                            Malicious:false
                            Reputation:unknown
                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:dBase III DBT, next free block index 3238316739, block length 1024
                            Category:dropped
                            Size (bytes):1056768
                            Entropy (8bit):0.1619826176816203
                            Encrypted:false
                            SSDEEP:
                            MD5:9E463B76FAC7A50763303A0C6C18C9ED
                            SHA1:246014C4DB9C4F2F1AD5133FEE410E89F7D4317D
                            SHA-256:E84D4B5E2D1A57287D52F0F85686CEA5C915E857EB4ED7BE215B6B471381BF25
                            SHA-512:32F9B3B580E123D9D8BF66923E91D12F6C30EAE180D3A2FD8C8A39102BEA630A90E39188AE6976F8C323193968F245D383BB6A9D28A5DC430FF1F187B8B74AB8
                            Malicious:false
                            Reputation:unknown
                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text, with very long lines (42191), with no line terminators
                            Category:dropped
                            Size (bytes):42191
                            Entropy (8bit):5.4196958794644745
                            Encrypted:false
                            SSDEEP:
                            MD5:71DA315A16A080DAF9691A68631F92F8
                            SHA1:BDBBCDE5E326AA7B01EA33818BC2CF9CD463DC2B
                            SHA-256:F360A80CE6539AE8C3C717287373AC04E6BC23EC708656A473E7A9AE361C99C3
                            SHA-512:4F4AE49C3251065A1986C3EB4D3213F469C11B3F7E35B7B6252B94B5CC457C73C370C4F523C28881788E017801114BDF8C2C6A747C047BE6190842F95E1C926C
                            Malicious:false
                            Reputation:unknown
                            Preview:a,abbr,acronym,address,applet,article,aside,audio,b,big,blockquote,body,canvas,caption,center,cite,code,dd,del,details,dfn,div,dl,dt,em,embed,fieldset,figcaption,figure,footer,form,h1,h2,h3,h4,h5,h6,header,hgroup,html,i,iframe,img,ins,kbd,label,legend,li,main,mark,menu,nav,object,ol,output,p,pre,q,ruby,s,samp,section,small,span,strike,strong,sub,summary,sup,table,tbody,td,tfoot,th,thead,time,tr,tt,u,ul,var,video{border:0;font-size:100%;font:inherit;margin:0;padding:0;vertical-align:baseline}article,aside,details,figcaption,figure,footer,header,hgroup,main,menu,nav,section{display:block}[hidden]{display:none}body{line-height:1}menu,ol,ul{list-style:none}blockquote,q{quotes:none}blockquote:after,blockquote:before,q:after,q:before{content:"";content:none}table{border-collapse:collapse;border-spacing:0}:root{--blue-0:#f3f6ff;--blue-10:#d1dbfe;--blue-20:#adbff9;--blue-30:#7d99f0;--blue-40:#5d7fe9;--blue-60:#2551da;--blue-80:#02379e;--blue-90:#000a62;--blue-100:#000a26;--blue-gray-0:#f4f4f6;
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text, with very long lines (65473)
                            Category:dropped
                            Size (bytes):927052
                            Entropy (8bit):5.475498304622294
                            Encrypted:false
                            SSDEEP:
                            MD5:81A4735CDC2B402F4C592D28EC548DDD
                            SHA1:8915150EAFA7DA194BCE365E050DBEEC8FE6BD96
                            SHA-256:2A8E7260FAB8C5518D94AAC07100A2885A90799BBB0290083B39106B5CAC17BE
                            SHA-512:4FD5E64685A47624FF4BB69E70FEB23F6002954CA2AD3EC606CB88AFCB421DE327EBD4D4EF890A44F24317E1E70DA7EC86FA691A3D3C34EBCF67C385B5993167
                            Malicious:false
                            Reputation:unknown
                            Preview:/*! For license information please see index.js.LICENSE.txt */.(()=>{var e,t,n,r={4125:(e,t,n)=>{"use strict";n.d(t,{e:()=>r});var r,i=n(2641),o=n(6356);!function(e){var t=e.empty={hovered:void 0,disabled:void 0,active:void 0},n=e.withValue=(e,t)=>(0,i._)({},e,t);e.emptyWithName=e=>n(t,{name:e}),e.Context=o.createContext(t)}(r||(r={}))},1972:(e,t,n)=>{"use strict";n.d(t,{$n:()=>Le});var r,i=n(2641),o=n(1676),a=n(6356),s=n(2226),l=n(3595),u=n(3879),c=n(9148),f=n(2363),d=n(4610),p=n(7720),h=n(5167),m=n(6881),g=n(4125),v=n(1107);!function(e){e.None="none",e.FromClickPoint="fromClickPoint",e.FromCenter="fromCenter"}(r||(r={}));class y extends a.Component{componentDidMount(){this._el&&(this._subscription=this.props.mouseDownEvents.pipe(f.M((e=>{if(!this._disabled.get()&&this._el){const t=this._getAnimationStyle(this._el,e);this._ripples.modify((e=>[...e,t]))}})),d.B(1e3),f.M((()=>this._ripples.modify((()=>[]))))).subscribe())}componentWillUnmount(){Boolean(this._subscription)&&this._subscri
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
                            Category:dropped
                            Size (bytes):524656
                            Entropy (8bit):5.027445846313988E-4
                            Encrypted:false
                            SSDEEP:
                            MD5:CCE267A8A471B9C37DC1A817A331D0C8
                            SHA1:461C85A526D55F649B0D02472CEDB142FFAF5DF6
                            SHA-256:2FDBA47D836E2214500B47ACC092C21F29DE2493C34242BB8FC0C73162F4BDCE
                            SHA-512:CDF2728FC5948941E60B3535CF15FF80C4DE5B3AFDCA8EF83AD2C98B72B93BDF2F68A8B5A60CA4EF0337C5B4BA5112708796C8423C12D73CFDA4BDC954478029
                            Malicious:false
                            Reputation:unknown
                            Preview:.........................................=..ju/.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):24
                            Entropy (8bit):2.1431558784658327
                            Encrypted:false
                            SSDEEP:
                            MD5:54CB446F628B2EA4A5BCE5769910512E
                            SHA1:C27CA848427FE87F5CF4D0E0E3CD57151B0D820D
                            SHA-256:FBCFE23A2ECB82B7100C50811691DDE0A33AA3DA8D176BE9882A9DB485DC0F2D
                            SHA-512:8F6ED2E91AED9BD415789B1DBE591E7EAB29F3F1B48FDFA5E864D7BF4AE554ACC5D82B4097A770DABC228523253623E4296C5023CF48252E1B94382C43123CB0
                            Malicious:false
                            Reputation:unknown
                            Preview:0\r..m..................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):48
                            Entropy (8bit):2.9972243200613975
                            Encrypted:false
                            SSDEEP:
                            MD5:B2FC7BE21198B44A43485818545F2EC4
                            SHA1:FE73594E7E53A12508DE0C4C7522AC271A67769C
                            SHA-256:ABB2E39C37A4EEF299C5982067EBAF9DB2BDA86FEEAD3F800D1C2FC52EE55121
                            SHA-512:48BC0A25306A256BDBCF59A6E853303DCBDA89074A7F225F60CB272F799DE51A8C3A41E392EF91057A5C938C525CA515D0F4EFB120EB18C7F6A216B877B6A4E8
                            Malicious:false
                            Reputation:unknown
                            Preview:(...T.4=oy retne...........................ju/.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:B2FC7BE21198B44A43485818545F2EC4
                            SHA1:FE73594E7E53A12508DE0C4C7522AC271A67769C
                            SHA-256:ABB2E39C37A4EEF299C5982067EBAF9DB2BDA86FEEAD3F800D1C2FC52EE55121
                            SHA-512:48BC0A25306A256BDBCF59A6E853303DCBDA89074A7F225F60CB272F799DE51A8C3A41E392EF91057A5C938C525CA515D0F4EFB120EB18C7F6A216B877B6A4E8
                            Malicious:false
                            Reputation:unknown
                            Preview:(...T.4=oy retne...........................ju/.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):48
                            Entropy (8bit):2.955557653394731
                            Encrypted:false
                            SSDEEP:
                            MD5:2F926C59287E32C14DC77CDE418F7552
                            SHA1:3FF700244267AB43758C75DA460035385E22ADF4
                            SHA-256:325553961101D739DC71998EE2087DF8F4C2EF2A4CD253D3812D9933881F16F0
                            SHA-512:AFC601059CB7EB3E7C08E105069754048E113AAE4330ABAA9226CA8782FB7E1F05289177117C7DEBACB5FF62DE6A718683717C94A2DB9070019F70BA2EDBBC51
                            Malicious:false
                            Reputation:unknown
                            Preview:(....=..oy retne........................Hu..ju/.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:2F926C59287E32C14DC77CDE418F7552
                            SHA1:3FF700244267AB43758C75DA460035385E22ADF4
                            SHA-256:325553961101D739DC71998EE2087DF8F4C2EF2A4CD253D3812D9933881F16F0
                            SHA-512:AFC601059CB7EB3E7C08E105069754048E113AAE4330ABAA9226CA8782FB7E1F05289177117C7DEBACB5FF62DE6A718683717C94A2DB9070019F70BA2EDBBC51
                            Malicious:false
                            Reputation:unknown
                            Preview:(....=..oy retne........................Hu..ju/.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:FoxPro FPT, blocks size 512, next free block index 3284796609, field type 0
                            Category:dropped
                            Size (bytes):8192
                            Entropy (8bit):0.01057775872642915
                            Encrypted:false
                            SSDEEP:
                            MD5:CF89D16BB9107C631DAABF0C0EE58EFB
                            SHA1:3AE5D3A7CF1F94A56E42F9A58D90A0B9616AE74B
                            SHA-256:D6A5FE39CD672781B256E0E3102F7022635F1D4BB7CFCC90A80FFFE4D0F3877E
                            SHA-512:8CB5B059C8105EB91E74A7D5952437AAA1ADA89763C5843E7B0F1B93D9EBE15ED40F287C652229291FAC02D712CF7FF5ECECEF276BA0D7DDC35558A3EC3F77B0
                            Malicious:false
                            Reputation:unknown
                            Preview:............$...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):270336
                            Entropy (8bit):0.0012471779557650352
                            Encrypted:false
                            SSDEEP:
                            MD5:F50F89A0A91564D0B8A211F8921AA7DE
                            SHA1:112403A17DD69D5B9018B8CEDE023CB3B54EAB7D
                            SHA-256:B1E963D702392FB7224786E7D56D43973E9B9EFD1B89C17814D7C558FFC0CDEC
                            SHA-512:BF8CDA48CF1EC4E73F0DD1D4FA5562AF1836120214EDB74957430CD3E4A2783E801FA3F4ED2AFB375257CAEED4ABE958265237D6E0AACF35A9EDE7A2E8898D58
                            Malicious:false
                            Reputation:unknown
                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
                            Category:dropped
                            Size (bytes):262512
                            Entropy (8bit):9.553120663130604E-4
                            Encrypted:false
                            SSDEEP:
                            MD5:2A96F1074CE211038061517A84CA5FF0
                            SHA1:40C07C0FCC11081BD242AB323A685FB0D13A4D43
                            SHA-256:B9CBA7044A32CD66D55948F7CCF9A4A1216B9C173250470329C556FC3B342004
                            SHA-512:912BD266C92CAF771F10D38010BAD6CDA99BB083D59B1114EFA211C6A7A4DC49D385578B9614BEBDCABEE6328693AB811BC893BEEC8E10C7AA1CAD032AE8B189
                            Malicious:false
                            Reputation:unknown
                            Preview:............................................ju/.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):355
                            Entropy (8bit):5.238673969005795
                            Encrypted:false
                            SSDEEP:
                            MD5:AECCA0D8AA055FCEFC5101C8F1439590
                            SHA1:8F6122D328CB307ACD30ADDD45FB814C21F00390
                            SHA-256:7233F9F2C2DFB4AEAC03AD42DB14168FB8935E425D6E7B5AAAF686A7842EAF8A
                            SHA-512:5225E7E834DB3CA5374C30BFB92D84DA22595FB053854467FDFBEC77BF48FD8748556B21A89F9874FAB1CC49CDA59274A6CA71EA473808ECD1F4F852B71BB79F
                            Malicious:false
                            Reputation:unknown
                            Preview:2024/04/24-11:52:14.173 95c Creating DB C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Extension Rules since it was missing..2024/04/24-11:52:14.202 95c Reusing MANIFEST C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Extension Rules/MANIFEST-000001.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):38
                            Entropy (8bit):1.8784775129881184
                            Encrypted:false
                            SSDEEP:
                            MD5:51A2CBB807F5085530DEC18E45CB8569
                            SHA1:7AD88CD3DE5844C7FC269C4500228A630016AB5B
                            SHA-256:1C43A1BDA1E458863C46DFAE7FB43BFB3E27802169F37320399B1DD799A819AC
                            SHA-512:B643A8FA75EDA90C89AB98F79D4D022BB81F1F62F50ED4E5440F487F22D1163671EC3AE73C4742C11830214173FF2935C785018318F4A4CAD413AE4EEEF985DF
                            Malicious:false
                            Reputation:unknown
                            Preview:.f.5................f.5...............
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):359
                            Entropy (8bit):5.2132020845702005
                            Encrypted:false
                            SSDEEP:
                            MD5:C5F9F0E8657794D4213C361773F72C57
                            SHA1:434C4E8C6B4081BA1A222103F7121B9F0E46E51A
                            SHA-256:3B077B85C7ED7004F3245F1EAC626AFDA938AF62C9248ECF1BE364816B61CF1C
                            SHA-512:5A0E6115348F299E21084612002C8A64252D9321FD750E2FDD188811DFA9FF750784613E50B44CEED03E8E77909017D4F1A0150D8D4AA4272DC53B728F16D028
                            Malicious:false
                            Reputation:unknown
                            Preview:2024/04/24-11:52:14.209 95c Creating DB C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Extension Scripts since it was missing..2024/04/24-11:52:14.244 95c Reusing MANIFEST C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Extension Scripts/MANIFEST-000001.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):114
                            Entropy (8bit):1.8784775129881184
                            Encrypted:false
                            SSDEEP:
                            MD5:891A884B9FA2BFF4519F5F56D2A25D62
                            SHA1:B54A3C12EE78510CB269FB1D863047DD8F571DEA
                            SHA-256:E2610960C3757D1757F206C7B84378EFA22D86DCF161A98096A5F0E56E1A367E
                            SHA-512:CD50C3EE4DFB9C4EC051B20DD1E148A5015457EE0C1A29FFF482E62291B32097B07A069DB62951B32F209FD118FD77A46B8E8CC92DA3EAAE6110735D126A90EE
                            Malicious:false
                            Reputation:unknown
                            Preview:.f.5................f.5................f.5................f.5................f.5................f.5...............
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):355
                            Entropy (8bit):5.193866524802256
                            Encrypted:false
                            SSDEEP:
                            MD5:9DF8C468BA4D199F0CBB8E6EBD19B819
                            SHA1:2B2644A9A9690BD11A070A849404A0EFA6F8AF5E
                            SHA-256:60969131BA82E3ABFA358F7568DD7DE6AA2AC984873CD044D407EA3FDFF85212
                            SHA-512:048DD997F21BF831D8BB5B5583FC1B140D7BB0C103182F31722827962414DEB16CD34AA2380AB32DFF548860AE58B9799BFF0FF154C1A31E8D77EE5F1EE6A899
                            Malicious:false
                            Reputation:unknown
                            Preview:2024/04/24-11:52:15.003 a74 Creating DB C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Extension State since it was missing..2024/04/24-11:52:15.025 a74 Reusing MANIFEST C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Extension State/MANIFEST-000001.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 10, cookie 0x8, schema 4, UTF-8, version-valid-for 1
                            Category:dropped
                            Size (bytes):20480
                            Entropy (8bit):0.6975083372685086
                            Encrypted:false
                            SSDEEP:
                            MD5:F5BBD8449A9C3AB28AC2DE45E9059B01
                            SHA1:C569D730853C33234AF2402E69C19E0C057EC165
                            SHA-256:825FF36C4431084C76F3D22CE0C75FA321EA680D1F8548706B43E60FCF5B566E
                            SHA-512:96ACDED5A51236630A64FAE91B8FA9FAB43E22E0C1BCB80C2DD8D4829E03FBFA75AA6438053599A42EC4BBCF805BF0B1E6DFF9069B2BA182AD0BB30F2542FD3F
                            Malicious:false
                            Reputation:unknown
                            Preview:SQLite format 3......@ ..........................................................................j..........g....._.c...~.2.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................s...;+...indexfavicon_bitmaps_icon_idfavico
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):8192
                            Entropy (8bit):0.011852361981932763
                            Encrypted:false
                            SSDEEP:
                            MD5:0962291D6D367570BEE5454721C17E11
                            SHA1:59D10A893EF321A706A9255176761366115BEDCB
                            SHA-256:EC1702806F4CC7C42A82FC2B38E89835FDE7C64BB32060E0823C9077CA92EFB7
                            SHA-512:F555E961B69E09628EAF9C61F465871E6984CD4D31014F954BB747351DAD9CEA6D17C1DB4BCA2C1EB7F187CB5F3C0518748C339C8B43BBD1DBD94AEAA16F58ED
                            Malicious:false
                            Reputation:unknown
                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
                            Category:dropped
                            Size (bytes):262512
                            Entropy (8bit):9.553120663130604E-4
                            Encrypted:false
                            SSDEEP:
                            MD5:61CE4FFA5365BB147EBCD450A3DC4D9E
                            SHA1:BA2426D6252377F236049C923177A34125559664
                            SHA-256:6E6899FDC3377F9193936FE597A7D6533B866E9F5CC7C0DF5F0007040B8DA131
                            SHA-512:6D64C6747381F36AE359E77CFD98B64D706827628D3B0C284A5750C56D9E0389BFB493232422153933D3FF1474C5DE4CB207118DACB66FBB108D6EF4413EB707
                            Malicious:false
                            Reputation:unknown
                            Preview:........................................F,..ju/.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 2, database pages 38, cookie 0x1f, schema 4, UTF-8, version-valid-for 2
                            Category:dropped
                            Size (bytes):155648
                            Entropy (8bit):0.5794459579013007
                            Encrypted:false
                            SSDEEP:
                            MD5:558B77CC92507C24B08C8D5C00E35A87
                            SHA1:13BA93492AA7B289DD6F530E9EC225A83E1199AB
                            SHA-256:055C88D08A032D6FBE4F9144CA516C83682D147FEEAACCCCF7637033B7D3EC92
                            SHA-512:7C4F2B24B5276709E3BD5DCC034C198795A592CE5218E299BB02ACF7DC720D01B019047E208B19DA8F27822C88535F3BD06B5E117C9B659172AB52244AF4CF19
                            Malicious:false
                            Reputation:unknown
                            Preview:SQLite format 3......@ .......&..................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):369
                            Entropy (8bit):5.259526074140952
                            Encrypted:false
                            SSDEEP:
                            MD5:1B881636D3D931F2BA81EF12FF261605
                            SHA1:FA67E0731A00B58F82E2D18FF8EEB32711CAF4B1
                            SHA-256:D1D4813CEDC2FCB5A08CDBBE89601D785B98B907705B4CE3C1D19540D10EA748
                            SHA-512:0312841BFBB6A3A0D3CE891BB4C4C2266B8DCA503834D211F5A7F5812341B3BD0B9261A9EB15670A4CF83A5A0C2529B4777794631E0053CC2E5320937CE4AEBA
                            Malicious:false
                            Reputation:unknown
                            Preview:2024/04/24-11:52:14.734 18ac Creating DB C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Local Storage\leveldb since it was missing..2024/04/24-11:52:14.939 18ac Reusing MANIFEST C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Local Storage\leveldb/MANIFEST-000001.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 21, cookie 0xc, schema 4, UTF-8, version-valid-for 1
                            Category:dropped
                            Size (bytes):43008
                            Entropy (8bit):0.9009435143901008
                            Encrypted:false
                            SSDEEP:
                            MD5:FB3D677576C25FF04A308A1F627410B7
                            SHA1:97D530911F9CB0C37717ABB145D748982ADA0440
                            SHA-256:A79300470D18AF26E3C5B4F23F81915B92D490105CE84A8122BF8100EC0C7517
                            SHA-512:ED6666B064958B107E55BD76E52D2E5BF7A4791379902D208EF909A6B68803240D372CE03641249EB917C241B36A5684656A48D099A8A084AD34BA009857B098
                            Malicious:false
                            Reputation:unknown
                            Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):2
                            Entropy (8bit):1.0
                            Encrypted:false
                            SSDEEP:
                            MD5:D751713988987E9331980363E24189CE
                            SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                            SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                            SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                            Malicious:false
                            Reputation:unknown
                            Preview:[]
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):59
                            Entropy (8bit):4.619434150836742
                            Encrypted:false
                            SSDEEP:
                            MD5:78BFCECB05ED1904EDCE3B60CB5C7E62
                            SHA1:BF77A7461DE9D41D12AA88FBA056BA758793D9CE
                            SHA-256:C257F929CFF0E4380BF08D9F36F310753F7B1CCB5CB2AB811B52760DD8CB9572
                            SHA-512:2420DFF6EB853F5E1856CDAB99561A896EA0743FCFF3E04B37CB87EDDF063770608A30C6FFB0319E5D353B0132C5F8135B7082488E425666B2C22B753A6A4D73
                            Malicious:false
                            Reputation:unknown
                            Preview:{"net":{"network_qualities":{"CAESABiAgICA+P////8B":"3G"}}}
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):40
                            Entropy (8bit):4.1275671571169275
                            Encrypted:false
                            SSDEEP:
                            MD5:20D4B8FA017A12A108C87F540836E250
                            SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                            SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                            SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                            Malicious:false
                            Reputation:unknown
                            Preview:{"SDCH":{"dictionaries":{},"version":2}}
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 7, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 7
                            Category:dropped
                            Size (bytes):20480
                            Entropy (8bit):0.6732424250451717
                            Encrypted:false
                            SSDEEP:
                            MD5:CFFF4E2B77FC5A18AB6323AF9BF95339
                            SHA1:3AA2C2115A8EB4516049600E8832E9BFFE0C2412
                            SHA-256:EC8B67EF7331A87086A6CC085B085A6B7FFFD325E1B3C90BD3B9B1B119F696AE
                            SHA-512:0BFDC8D28D09558AA97F4235728AD656FE9F6F2C61DDA2D09B416F89AB60038537B7513B070B907E57032A68B9717F03575DB6778B68386254C8157559A3F1BC
                            Malicious:false
                            Reputation:unknown
                            Preview:SQLite format 3......@ ..........................................................................j...$......g..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 4, database pages 9, cookie 0x4, schema 4, UTF-8, version-valid-for 4
                            Category:dropped
                            Size (bytes):36864
                            Entropy (8bit):0.5559635235158827
                            Encrypted:false
                            SSDEEP:
                            MD5:9AAAE8C040B616D1378F3E0E17689A29
                            SHA1:F91E7DE07F1DA14D15D067E1F50C3B84A328DBB7
                            SHA-256:5B94D63C31AE795661F69B9D10E8BFD115584CD6FEF5FBB7AA483FDC6A66945B
                            SHA-512:436202AB8B6BB0318A30946108E6722DFF781F462EE05980C14F57F347EDDCF8119E236C3290B580CEF6902E1B59FB4F546D6BD69F62479805B39AB0F3308EC1
                            Malicious:false
                            Reputation:unknown
                            Preview:SQLite format 3......@ ..........................................................................j..........g...D.........7............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 9, cookie 0x6, schema 4, UTF-8, version-valid-for 3
                            Category:dropped
                            Size (bytes):36864
                            Entropy (8bit):0.36515621748816035
                            Encrypted:false
                            SSDEEP:
                            MD5:25363ADC3C9D98BAD1A33D0792405CBF
                            SHA1:D06E343087D86EF1A06F7479D81B26C90A60B5C3
                            SHA-256:6E019B8B9E389216D5BDF1F2FE63F41EF98E71DA101F2A6BE04F41CC5954532D
                            SHA-512:CF7EEE35D0E00945AF221BEC531E8BF06C08880DA00BD103FA561BC069D7C6F955CBA3C1C152A4884601E5A670B7487D39B4AE9A4D554ED8C14F129A74E555F7
                            Malicious:false
                            Reputation:unknown
                            Preview:SQLite format 3......@ ..........................................................................j.......X..g...}.....$.X..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):111
                            Entropy (8bit):4.718418993774295
                            Encrypted:false
                            SSDEEP:
                            MD5:807419CA9A4734FEAF8D8563A003B048
                            SHA1:A723C7D60A65886FFA068711F1E900CCC85922A6
                            SHA-256:AA10BF07B0D265BED28F2A475F3564D8DDB5E4D4FFEE0AB6F3A0CC564907B631
                            SHA-512:F10D496AE75DB5BA412BD9F17BF0C7DA7632DB92A3FABF7F24071E40F5759C6A875AD8F3A72BAD149DA58B3DA3B816077DF125D0D9F3544ADBA68C66353D206C
                            Malicious:false
                            Reputation:unknown
                            Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"3G"}}}
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:1F4A9EF9D96451C388DCE4D3957B316F
                            SHA1:494FD7ECA4299377C554E79310479A715F3A537D
                            SHA-256:33D717F47A31643AEC9CB01459E81196EF5220EA52E9EA10E6203635EC05A132
                            SHA-512:E2597374B0890FA69F354DFAC38C46A72CB2615CF297B64D6F612CE0AC03517EFCE6E24624939181C400385CE11AAF9FFCBA957C50F98A3604A6C14C40980370
                            Malicious:false
                            Reputation:unknown
                            Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13358425934706597","alternate_error_pages":{"backup":true,"enabled":false},"autocomplete":{"retention_policy_last_version":117},"autofill":{"autostuff_enabled":false,"credit_card_enabled":false,"custom_data_enabled":false,"custom_data_fill_enabled":false,"custom_data_identify_info_from_form_enabled":false,"custom_data_save_enabled":false},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false},"browser_content_container_height":618,"browser_content_container_width":1060,"browser_content_container_x":0,"browser_content_container_y":0,"countryid_at_install":17224,"credentials_enable_service":false,"dips_timer_last_update":"13358425934566723","domain_diversity":{"last_reporting_timestamp":"13358425934707113"},"dual_engine":{"consumer_mode":{"ie_user":false},"consumer_site_list_with_ie_entries":false,"consumer_sitelist_location":"","consumer_sitelist_version":"","external_consumer_shared_cookie_data"
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text, with no line terminators
                            Category:dropped
                            Size (bytes):182
                            Entropy (8bit):4.2629097520179995
                            Encrypted:false
                            SSDEEP:
                            MD5:643E00B0186AA80523F8A6BED550A925
                            SHA1:EC4056125D6F1A8890FFE01BFFC973C2F6ABD115
                            SHA-256:A0C9ABAE18599F0A65FC654AD36251F6330794BEA66B718A09D8B297F3E38E87
                            SHA-512:D91A934EAF7D9D669B8AD4452234DE6B23D15237CB4D251F2C78C8339CEE7B4F9BA6B8597E35FE8C81B3D6F64AE707C68FF492903C0EDC3E4BAF2C6B747E247D
                            Malicious:false
                            Reputation:unknown
                            Preview:Microsoft Edge settings and storage represent user-selected preferences and information and MUST not be extracted, overwritten or modified except through Microsoft Edge defined APIs.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:4F18C12442E98560AAC6B6FEC57E2AA6
                            SHA1:CB955C5580D118C59099A5FB51C7A762D33EB935
                            SHA-256:469295C4A1B19184182340489FE0E50620BE3A9A5EFEAB91FC1699C21EB4F802
                            SHA-512:B90A470D669C50EA7B7F59E7F62FAC0634C32AF701448C8AF98413F6C0A5212E188CBCF5D92B7E451B301A39198B2AF2774F7A0B4DA5E62441F17F84D7939538
                            Malicious:false
                            Reputation:unknown
                            Preview:{"extensions":{"settings":{"dgiklkfkllikcanfonkcabmbdfmgleag":{"active_permissions":{"api":[],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13358425934029904","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13358425934029904","location":5,"manifest":{"content_capabilities":{"include_globs":["https://*excel.officeapps.live.com/*","https://*onenote.officeapps.live.com/*","https://*powerpoint.officeapps.live.com/*","https://*word-edit.officeapps.live.com/*","https://*excel.officeapps.live.com.mcas.ms/*","https://*onenote.officeapps.live.com.mcas.ms/*","https://*word-edit.officeapps.live.com.mcas.ms/*","https://*excel.partner.officewebapps.cn/*","https://*onenote.partner.officewebapps.cn/*","https://*powerpoint.partner.officewebapps.cn/*","https://*word-edit.partner.officewebapps.cn/*","https://*excel.gov.online.office365.us/*","
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):247
                            Entropy (8bit):5.0905332905724885
                            Encrypted:false
                            SSDEEP:
                            MD5:1D96E4FFB8D93409D8BE7038C5A2DF90
                            SHA1:5B7083FFAB127901334349DE26D005849D7FB77B
                            SHA-256:175542D89FC86B14A560AD37ACA1FEFAC680923A774E34B482731965E1CA0AC6
                            SHA-512:178ACE5A82F10648116F590E0B81A2B001DF16074504CA4AE10F4BAA7CC33E9470D1328831BEA2CB9B7722F865FBB4079D0490CEE4F2DEA09F246554485B5E57
                            Malicious:false
                            Reputation:unknown
                            Preview:*...#................version.1..namespace-..Yh................next-map-id.1.Inamespace-47b539d5_64a4_4938_994a_50aafb9c6132-https://app.grammarly.com/.0...oW...............Inamespace-47b539d5_64a4_4938_994a_50aafb9c6132-https://app.grammarly.com/
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):357
                            Entropy (8bit):5.218919850983416
                            Encrypted:false
                            SSDEEP:
                            MD5:17E7166920CD494A64334E9BFF96C9D9
                            SHA1:C7D7E1FB76ABC901828F4384BA3B27067DDA0CA7
                            SHA-256:6013A2EBBDB596F0069C0FFA394724D9F15DADC6DD5E97C6811BACE81364B0DC
                            SHA-512:FDD5B7FEE1BEBA4BB882B1366B1A66E82454817D22C6531CA0F12E44808A4CBBEFEBC75FCFE6B595585A69FF9459A92375B500A3F158950BC671E03E7298404C
                            Malicious:false
                            Reputation:unknown
                            Preview:2024/04/24-11:52:16.090 18ac Creating DB C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Session Storage since it was missing..2024/04/24-11:52:16.137 18ac Reusing MANIFEST C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Session Storage/MANIFEST-000001.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:OpenPGP Secret Key
                            Category:dropped
                            Size (bytes):41
                            Entropy (8bit):4.704993772857998
                            Encrypted:false
                            SSDEEP:
                            MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                            SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                            SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                            SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                            Malicious:false
                            Reputation:unknown
                            Preview:.|.."....leveldb.BytewiseComparator......
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):40
                            Entropy (8bit):3.473726825238924
                            Encrypted:false
                            SSDEEP:
                            MD5:148079685E25097536785F4536AF014B
                            SHA1:C5FF5B1B69487A9DD4D244D11BBAFA91708C1A41
                            SHA-256:F096BC366A931FBA656BDCD77B24AF15A5F29FC53281A727C79F82C608ECFAB8
                            SHA-512:C2556034EA51ABFBC172EB62FF11F5AC45C317F84F39D4B9E3DDBD0190DA6EF7FA03FE63631B97AB806430442974A07F8E81B5F7DC52D9F2FCDC669ADCA8D91F
                            Malicious:false
                            Reputation:unknown
                            Preview:.On.!................database_metadata.1
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):383
                            Entropy (8bit):5.166753845498659
                            Encrypted:false
                            SSDEEP:
                            MD5:5BBEED42FEAE407A83F2BFF7E0DE2215
                            SHA1:7684EEB9AB7A7B0EEBF764195D48CE632C0924BE
                            SHA-256:69D4FE721ACC406E603C2E5E2CCCF876381FBB77BA5C6348C420F58F3CB0F99E
                            SHA-512:DDB492E9202152CDB67505D707678B9869AC688B44FF467B8C1559AF84D34335187C2B766AF86B8E339E55A3C30891E908FB76647C682217E61C477A09E5B030
                            Malicious:false
                            Reputation:unknown
                            Preview:2024/04/24-11:52:14.021 998 Creating DB C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Site Characteristics Database since it was missing..2024/04/24-11:52:14.043 998 Reusing MANIFEST C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Site Characteristics Database/MANIFEST-000001.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):46
                            Entropy (8bit):4.019797536844534
                            Encrypted:false
                            SSDEEP:
                            MD5:90881C9C26F29FCA29815A08BA858544
                            SHA1:06FEE974987B91D82C2839A4BB12991FA99E1BDD
                            SHA-256:A2CA52E34B6138624AC2DD20349CDE28482143B837DB40A7F0FBDA023077C26A
                            SHA-512:15F7F8197B4FC46C4C5C2570FB1F6DD73CB125F9EE53DFA67F5A0D944543C5347BDAB5CCE95E91DD6C948C9023E23C7F9D76CFF990E623178C92F8D49150A625
                            Malicious:false
                            Reputation:unknown
                            Preview:...n'................_mts_schema_descriptor...
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):359
                            Entropy (8bit):5.275415249634573
                            Encrypted:false
                            SSDEEP:
                            MD5:940D5522DFE026192EC8DB03A1A96C21
                            SHA1:A66476A9FFD3AB7E04956BA41CF426355CA3338F
                            SHA-256:82EC5A7816966908F7B6D200C060F1792DA7F7BBD9D97EA7687F4D2644C892D2
                            SHA-512:557ED0847AB0F72F08527C93D6C68493E9E66F2A49D9AA1289B0E3EAB313264F79951B36F71D2E7EFFE114B5017889F61F997F49546F7CBD7FBDDB02DB5D04CD
                            Malicious:false
                            Reputation:unknown
                            Preview:2024/04/24-11:52:14.605 f6c Creating DB C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Sync Data\LevelDB since it was missing..2024/04/24-11:52:14.697 f6c Reusing MANIFEST C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\Sync Data\LevelDB/MANIFEST-000001.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):131072
                            Entropy (8bit):0.0033769341339387224
                            Encrypted:false
                            SSDEEP:
                            MD5:455236BB327B831B3A1E9D8D0C450554
                            SHA1:91DA1DBABC38F377F9F37B01B99A555318A5EA19
                            SHA-256:68579C9DE01FAC957EA12AAE7513A7CF75F6E0E1408E25FBECA4DBB33344FDAF
                            SHA-512:69FF874F59815FAA2FA6FF6068FFDB601711B06D93C6641D263F12CF387367B4D35A549983509031FAA23154EE93B60536D6833148060016761B6F37E22ED624
                            Malicious:false
                            Reputation:unknown
                            Preview:VLnk.....?......b.~.v..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 87, cookie 0x36, schema 4, UTF-8, version-valid-for 3
                            Category:dropped
                            Size (bytes):178176
                            Entropy (8bit):0.9338277588251305
                            Encrypted:false
                            SSDEEP:
                            MD5:7515FD2738E1D446CBFBC66A17B717A7
                            SHA1:AC4DCE726129431DE4B46E4B9A4644B19DB336E4
                            SHA-256:A607620D464381E093B8E2010C2C81BA870EAF9303EBCF73A935E143DAA918D2
                            SHA-512:83083D9F35C8A1C2A882A778358605A7C3BCDDF785A2A3E165192C6CE9E0E9AEE482DF24D20286F96B773E9F0ABD6927D8630CF2E9DC1D4FC95A844E01A42C2E
                            Malicious:false
                            Reputation:unknown
                            Preview:SQLite format 3......@ .......W...........6......................................................j............W........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):16
                            Entropy (8bit):3.2743974703476995
                            Encrypted:false
                            SSDEEP:
                            MD5:46295CAC801E5D4857D09837238A6394
                            SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                            SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                            SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                            Malicious:false
                            Reputation:unknown
                            Preview:MANIFEST-000001.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:46295CAC801E5D4857D09837238A6394
                            SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                            SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                            SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                            Malicious:false
                            Reputation:unknown
                            Preview:MANIFEST-000001.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):355
                            Entropy (8bit):5.296871342245127
                            Encrypted:false
                            SSDEEP:
                            MD5:5569300B51C28CE37CD376934277E0E0
                            SHA1:1E0C4C9792FD7DD5F5468EDFD07FD0A6AD9BB231
                            SHA-256:E489CBB031EA5883AD630CB2CC868E113E8054BEFA59AA61C3F241B4A72AE864
                            SHA-512:16F1B4837F9E633F3310EA8D59B0A5BB943A3C704F3893017B520722A6A42E2A954D84C040E7D3C64CD425008066EFFFC5880904B9CF0467EF61DC6C258A7F47
                            Malicious:false
                            Reputation:unknown
                            Preview:2024/04/24-11:52:14.971 f6c Creating DB C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\shared_proto_db since it was missing..2024/04/24-11:52:14.999 f6c Reusing MANIFEST C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\shared_proto_db/MANIFEST-000001.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):184
                            Entropy (8bit):3.699504921578472
                            Encrypted:false
                            SSDEEP:
                            MD5:FB729719541614015C04FF5BCF0B407F
                            SHA1:251C060D883D1296CB19E7795FD92AFB05D16D23
                            SHA-256:EAE67D21C90C433D684316B8E732E676414B202F8019EF48A22C50E7C2D52C82
                            SHA-512:2BA63889997CE6659DC3700587DEEEBB1CE016FBACB508B320EF4647CD16473CCD8685F4E4400E8850536133FF7555F95B4F51D9521115327213954E005D7EAA
                            Malicious:false
                            Reputation:unknown
                            Preview:.h.6.................__global... .t...................__global... .9..b.................33_..........................21_......-.t.................21_......'..................33_.....
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text
                            Category:dropped
                            Size (bytes):375
                            Entropy (8bit):5.248113172302075
                            Encrypted:false
                            SSDEEP:
                            MD5:368B592F8FF7308F1B5D86B27B4D2715
                            SHA1:6B107EF93D0BD5F99550A4A6E253131F410C4570
                            SHA-256:F8F80ECD00A92FE41D0BAAB2DBC301CDB7434BA01462D5117B5F2955606498AB
                            SHA-512:B3ECA6B24A5502D76F9D593F8C490AF020BEF615079DDFA6A13E9454F02B8E1E9C982E5AF422352FF29F18B3AD9A5A4757DC8D90C37ECFF030DEC51B2C281138
                            Malicious:false
                            Reputation:unknown
                            Preview:2024/04/24-11:52:14.703 166c Creating DB C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\shared_proto_db\metadata since it was missing..2024/04/24-11:52:14.747 166c Reusing MANIFEST C:\Users\user\AppData\Roaming\Grammarly\DesktopIntegrations\WebViewUserDataFolder\EBWebView\Default\shared_proto_db\metadata/MANIFEST-000001.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
                            Category:dropped
                            Size (bytes):262512
                            Entropy (8bit):9.553120663130604E-4
                            Encrypted:false
                            SSDEEP:
                            MD5:1457930D9D82973DB92A903D5B125A35
                            SHA1:C5EB359E3C7ECFF2C95CECFEC71680197527050E
                            SHA-256:E7A0E056F7BBDDFC7BDB0737A5E5FC2DA261E8A845BFBA25EB9E65653BB41657
                            SHA-512:450A31BCBA16846ACE388791D39F07939BD6FD5B06436952D54CAB9E1089235719D6280FF6FD77B1711F2385425C3A7F7C672B4BBC0E7BC26BD77409EA995D73
                            Malicious:false
                            Reputation:unknown
                            Preview:..........................................ju/.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
                            Category:dropped
                            Size (bytes):262512
                            Entropy (8bit):9.553120663130604E-4
                            Encrypted:false
                            SSDEEP:
                            MD5:23070F1F049EC172CB9867FB8C98E4B9
                            SHA1:5B9D5DD9C31987BF23D4DFCE09E96F1573A808A7
                            SHA-256:816D329355530FB72B009CACE4FEA82B7242AAC954CC12978573606E1D9A899C
                            SHA-512:A3860AB3ED1C17492F8CCF7CCE36FBF9E1E4196D1143F810D97CDA3CCD53A6A54584AF91899B557D1A82654F86C1CE035AE7C14AA5C2B23C6C76C45A4A36AC47
                            Malicious:false
                            Reputation:unknown
                            Preview:............................................ju/.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text, with no line terminators
                            Category:dropped
                            Size (bytes):13
                            Entropy (8bit):2.7192945256669794
                            Encrypted:false
                            SSDEEP:
                            MD5:BF16C04B916ACE92DB941EBB1AF3CB18
                            SHA1:FA8DAEAE881F91F61EE0EE21BE5156255429AA8A
                            SHA-256:7FC23C9028A316EC0AC25B09B5B0D61A1D21E58DFCF84C2A5F5B529129729098
                            SHA-512:F0B7DF5517596B38D57C57B5777E008D6229AB5B1841BBE74602C77EEA2252BF644B8650C7642BD466213F62E15CC7AB5A95B28E26D3907260ED1B96A74B65FB
                            Malicious:false
                            Reputation:unknown
                            Preview:117.0.2045.47
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:E8032FF1E06E3EAB00908F9EA0598979
                            SHA1:AFB97A7643B9D06B8E679853EEF1D9D6911E063F
                            SHA-256:868DFFC2A1EBBA118B1F08F65DA622DF5FAA954F738CBACF511903814CACCCF1
                            SHA-512:8BA178B1A9BDC9ED5825D923B85C2A98CBAC3ACB73BBE53D2608C118C167CBDC7429D2554A077F5F3C6B39776A59F52A973383B19E843A84A29EAE2C40A8CDB2
                            Malicious:false
                            Reputation:unknown
                            Preview:{"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAAAF6nMrn6c13Ab5Bt5RWCLncCOgZoYawOOOniyrgxysNAAAAAAOgAAAAAIAACAAAAAVy9xTF3vkHgGMaBroC1ADBc3dZd0yth82Rw5LJQwrcjAAAACBloUjouJtlqai8iu/HyOihMag083x+CjMi3aY8CrW8rAAKbaADJYjZyWUINdsTXdAAAAA1h8as5mn+4e7sPg+BKR897/JVgTzmPoKF+oJp62JiI5ZiEjKJg+5mrUPdDdceL1Kq9CTvmMFvsQXGp2P/vY2+w=="},"uninstall_metrics":{"installation_date2":"1713952333"},"user_experience_metrics":{"client_id2":"{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}C:\\Users\\user0s:92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A","diagnostics":{"last_data_collection_level_on_launch":1},"low_entropy_source3":4020,"pseudo_low_entropy_source":2235,"reset_client_id_deterministic":true,"stability":{"browser_last_live_timestamp":"13358425933775001","stats_buildtime":"1695934310","stats_version":"117.0.2045.47-64","system_crash_count":0}}}
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:E8032FF1E06E3EAB00908F9EA0598979
                            SHA1:AFB97A7643B9D06B8E679853EEF1D9D6911E063F
                            SHA-256:868DFFC2A1EBBA118B1F08F65DA622DF5FAA954F738CBACF511903814CACCCF1
                            SHA-512:8BA178B1A9BDC9ED5825D923B85C2A98CBAC3ACB73BBE53D2608C118C167CBDC7429D2554A077F5F3C6B39776A59F52A973383B19E843A84A29EAE2C40A8CDB2
                            Malicious:false
                            Reputation:unknown
                            Preview:{"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAAAF6nMrn6c13Ab5Bt5RWCLncCOgZoYawOOOniyrgxysNAAAAAAOgAAAAAIAACAAAAAVy9xTF3vkHgGMaBroC1ADBc3dZd0yth82Rw5LJQwrcjAAAACBloUjouJtlqai8iu/HyOihMag083x+CjMi3aY8CrW8rAAKbaADJYjZyWUINdsTXdAAAAA1h8as5mn+4e7sPg+BKR897/JVgTzmPoKF+oJp62JiI5ZiEjKJg+5mrUPdDdceL1Kq9CTvmMFvsQXGp2P/vY2+w=="},"uninstall_metrics":{"installation_date2":"1713952333"},"user_experience_metrics":{"client_id2":"{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}C:\\Users\\user0s:92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A","diagnostics":{"last_data_collection_level_on_launch":1},"low_entropy_source3":4020,"pseudo_low_entropy_source":2235,"reset_client_id_deterministic":true,"stability":{"browser_last_live_timestamp":"13358425933775001","stats_buildtime":"1695934310","stats_version":"117.0.2045.47-64","system_crash_count":0}}}
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:E8032FF1E06E3EAB00908F9EA0598979
                            SHA1:AFB97A7643B9D06B8E679853EEF1D9D6911E063F
                            SHA-256:868DFFC2A1EBBA118B1F08F65DA622DF5FAA954F738CBACF511903814CACCCF1
                            SHA-512:8BA178B1A9BDC9ED5825D923B85C2A98CBAC3ACB73BBE53D2608C118C167CBDC7429D2554A077F5F3C6B39776A59F52A973383B19E843A84A29EAE2C40A8CDB2
                            Malicious:false
                            Reputation:unknown
                            Preview:{"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAAAF6nMrn6c13Ab5Bt5RWCLncCOgZoYawOOOniyrgxysNAAAAAAOgAAAAAIAACAAAAAVy9xTF3vkHgGMaBroC1ADBc3dZd0yth82Rw5LJQwrcjAAAACBloUjouJtlqai8iu/HyOihMag083x+CjMi3aY8CrW8rAAKbaADJYjZyWUINdsTXdAAAAA1h8as5mn+4e7sPg+BKR897/JVgTzmPoKF+oJp62JiI5ZiEjKJg+5mrUPdDdceL1Kq9CTvmMFvsQXGp2P/vY2+w=="},"uninstall_metrics":{"installation_date2":"1713952333"},"user_experience_metrics":{"client_id2":"{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}C:\\Users\\user0s:92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A","diagnostics":{"last_data_collection_level_on_launch":1},"low_entropy_source3":4020,"pseudo_low_entropy_source":2235,"reset_client_id_deterministic":true,"stability":{"browser_last_live_timestamp":"13358425933775001","stats_buildtime":"1695934310","stats_version":"117.0.2045.47-64","system_crash_count":0}}}
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):0
                            Entropy (8bit):0.0
                            Encrypted:false
                            SSDEEP:
                            MD5:E8032FF1E06E3EAB00908F9EA0598979
                            SHA1:AFB97A7643B9D06B8E679853EEF1D9D6911E063F
                            SHA-256:868DFFC2A1EBBA118B1F08F65DA622DF5FAA954F738CBACF511903814CACCCF1
                            SHA-512:8BA178B1A9BDC9ED5825D923B85C2A98CBAC3ACB73BBE53D2608C118C167CBDC7429D2554A077F5F3C6B39776A59F52A973383B19E843A84A29EAE2C40A8CDB2
                            Malicious:false
                            Reputation:unknown
                            Preview:{"os_crypt":{"audit_enabled":true,"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaEAAAAB4AAABNAGkAYwByAG8AcwBvAGYAdAAgAEUAZABnAGUAAAAQZgAAAAEAACAAAAAF6nMrn6c13Ab5Bt5RWCLncCOgZoYawOOOniyrgxysNAAAAAAOgAAAAAIAACAAAAAVy9xTF3vkHgGMaBroC1ADBc3dZd0yth82Rw5LJQwrcjAAAACBloUjouJtlqai8iu/HyOihMag083x+CjMi3aY8CrW8rAAKbaADJYjZyWUINdsTXdAAAAA1h8as5mn+4e7sPg+BKR897/JVgTzmPoKF+oJp62JiI5ZiEjKJg+5mrUPdDdceL1Kq9CTvmMFvsQXGp2P/vY2+w=="},"uninstall_metrics":{"installation_date2":"1713952333"},"user_experience_metrics":{"client_id2":"{F3017226-FE2A-4295-8BDF-00C3A9A7E4C5}C:\\Users\\user0s:92C86F7C-DB2B-4F6A-95AD-98B4A2AE008A","diagnostics":{"last_data_collection_level_on_launch":1},"low_entropy_source3":4020,"pseudo_low_entropy_source":2235,"reset_client_id_deterministic":true,"stability":{"browser_last_live_timestamp":"13358425933775001","stats_buildtime":"1695934310","stats_version":"117.0.2045.47-64","system_crash_count":0}}}
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):8192
                            Entropy (8bit):0.012340643231932763
                            Encrypted:false
                            SSDEEP:
                            MD5:41876349CB12D6DB992F1309F22DF3F0
                            SHA1:5CF26B3420FC0302CD0A71E8D029739B8765BE27
                            SHA-256:E09F42C398D688DCE168570291F1F92D079987DEDA3099A34ADB9E8C0522B30C
                            SHA-512:E9A4FC1F7CB6AE2901F8E02354A92C4AAA7A53C640DCF692DB42A27A5ACC2A3BFB25A0DE0EB08AB53983132016E7D43132EA4292E439BB636AAFD53FB6EF907E
                            Malicious:false
                            Reputation:unknown
                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:FoxPro FPT, blocks size 768, next free block index 3284796353, field type 0
                            Category:dropped
                            Size (bytes):262512
                            Entropy (8bit):9.553120663130604E-4
                            Encrypted:false
                            SSDEEP:
                            MD5:CDC416A4C923EE974F731255BB6C8EBB
                            SHA1:B25EFC5CD4341122CA3D403A50C194EA9E51CBE7
                            SHA-256:FBE681B833645FD18F64F4A942BB7041C16A99AC53B25F0DD3F5C28AB74F4473
                            SHA-512:D6D37CE17E8A59D381298FAB239E7FC1A07DE6F25D076AA31FA031C763EBDA9212C9D89BA91A44F3300EC331D50123BC9A3704476ABB466795F3B5739EBCC512
                            Malicious:false
                            Reputation:unknown
                            Preview:............................................ju/.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text, with no line terminators
                            Category:dropped
                            Size (bytes):47
                            Entropy (8bit):4.3818353308528755
                            Encrypted:false
                            SSDEEP:
                            MD5:48324111147DECC23AC222A361873FC5
                            SHA1:0DF8B2267ABBDBD11C422D23338262E3131A4223
                            SHA-256:D8D672F953E823063955BD9981532FC3453800C2E74C0CC3653D091088ABD3B3
                            SHA-512:E3B5DB7BA5E4E3DE3741F53D91B6B61D6EB9ECC8F4C07B6AE1C2293517F331B716114BAB41D7935888A266F7EBDA6FABA90023EFFEC850A929986053853F1E02
                            Malicious:false
                            Reputation:unknown
                            Preview:customSettings_F95BA787499AB4FA9EFFF472CE383A14
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):35
                            Entropy (8bit):4.014438730983427
                            Encrypted:false
                            SSDEEP:
                            MD5:BB57A76019EADEDC27F04EB2FB1F1841
                            SHA1:8B41A1B995D45B7A74A365B6B1F1F21F72F86760
                            SHA-256:2BAE8302F9BD2D87AE26ACF692663DF1639B8E2068157451DA4773BD8BD30A2B
                            SHA-512:A455D7F8E0BE9A27CFB7BE8FE0B0E722B35B4C8F206CAD99064473F15700023D5995CC2C4FAFDB8FBB50F0BAB3EC8B241E9A512C0766AAAE1A86C3472C589FFD
                            Malicious:false
                            Reputation:unknown
                            Preview:{"forceServiceDetermination":false}
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text, with no line terminators
                            Category:dropped
                            Size (bytes):29
                            Entropy (8bit):3.922828737239167
                            Encrypted:false
                            SSDEEP:
                            MD5:7BAAFE811F480ACFCCCEE0D744355C79
                            SHA1:24B89AE82313084BB8BBEB9AD98A550F41DF7B27
                            SHA-256:D5743766AF0312C7B7728219FC24A03A4FB1C2A54A506F337953FBC2C1B847C7
                            SHA-512:70FE1C197AF507CC0D65E99807D245C896A40A4271BA1121F9B621980877B43019E584C48780951FC1AD2A5D7D146FC6EA4678139A5B38F9B6F7A5F1E2E86BA3
                            Malicious:false
                            Reputation:unknown
                            Preview:customSynchronousLookupUris_0
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):35302
                            Entropy (8bit):7.99333285466604
                            Encrypted:true
                            SSDEEP:
                            MD5:0E06E28C3536360DE3486B1A9E5195E8
                            SHA1:EB768267F34EC16A6CCD1966DCA4C3C2870268AB
                            SHA-256:F2658B1C913A96E75B45E6ADB464C8D796B34AC43BAF1635AA32E16D1752971C
                            SHA-512:45F1E909599E2F63372867BC359CF72FD846619DFEB5359E52D5700E0B1BCFFE5FF07606511A3BFFDDD933A0507195439457E4E29A49EB6451F26186B7240041
                            Malicious:false
                            Reputation:unknown
                            Preview:.......murmur3.....IN...9.......0..X..#l....C....]......pv..E..........,..?.N?....V..B-.*.F.1....g|..._.>'.-(V... .=.7P.m....#}.r.....>.LE...G.A.h5........J..=..L^-.Zl++,..h..o.y..~j.]u...W...&s.........M..........h3b..[.5.]..V^w.........a.*...6g3..%.gy../{|Z.B..X.}5.]..t.1.H&B.[.).$Y......2....L.t...{...[WE.yy.]..e.v0..\.J3..T.`1Lnh.../..-=w...W.&N7.nz.P...z......'i..R6....../....t.[..&-.....T&l..e....$.8.."....Iq....J.v..|.6.M...zE...a9uw..'.$6.L..m$......NB).JL.G.7}8(`....J.)b.E.m...c.0I.V...|$....;.k.......*8v..l.:..@.F.........K..2...%(...kA......LJd~._A.N.....$3...5....Z"...X=.....%.........6.k.....F..1..l,ia..i.i....y.M..Cl.....*...}.I..r..-+=b.6....%...#...W..K.....=.F....~.....[.......-...../;....~.09..d.....GR..H.lR...m.Huh9.:..A H./)..D.F..Y.n7.....7D.O.a;>Z.K....w...sq..qo3N...8@.zpD.Ku......+.Z=.zNFgP._@.z.ic.......3.....+..j...an%...X..7.q..A.l.7.S2..+....1.s.b..z...@v..!.y...N.C.XQ.p.\..x8(.<.....cq.(
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text, with no line terminators
                            Category:dropped
                            Size (bytes):81
                            Entropy (8bit):4.3439888556902035
                            Encrypted:false
                            SSDEEP:
                            MD5:177F4D75F4FEE84EF08C507C3476C0D2
                            SHA1:08E17AEB4D4066AC034207420F1F73DD8BE3FAA0
                            SHA-256:21EE7A30C2409E0041CDA6C04EEE72688EB92FE995DC94487FF93AD32BD8F849
                            SHA-512:94FC142B3CC4844BF2C0A72BCE57363C554356C799F6E581AA3012E48375F02ABD820076A8C2902A3C6BE6AC4D8FA8D4F010D4FF261327E878AF5E5EE31038FB
                            Malicious:false
                            Reputation:unknown
                            Preview:edgeSettings_2.0-48b11410dc937a1723bf4c5ad33ecdb286d8ec69544241bc373f753e64b396c1
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):3581
                            Entropy (8bit):4.459693941095613
                            Encrypted:false
                            SSDEEP:
                            MD5:BDE38FAE28EC415384B8CFE052306D6C
                            SHA1:3019740AF622B58D573C00BF5C98DD77F3FBB5CD
                            SHA-256:1F4542614473AE103A5EE3DEEEC61D033A40271CFF891AAA6797534E4DBB4D20
                            SHA-512:9C369D69298EBF087412EDA782EE72AFE5448FD0D69EA5141C2744EA5F6C36CDF70A51845CDC174838BAC0ADABDFA70DF6AEDBF6E7867578AE7C4B7805A8B55E
                            Malicious:false
                            Reputation:unknown
                            Preview:{"models":[],"geoidMaps":{"gw_my":"https://malaysia.smartscreen.microsoft.com/","gw_tw":"https://taiwan.smartscreen.microsoft.com/","gw_at":"https://austria.smartscreen.microsoft.com/","gw_es":"https://spain.smartscreen.microsoft.com/","gw_pl":"https://poland.smartscreen.microsoft.com/","gw_se":"https://sweden.smartscreen.microsoft.com/","gw_kr":"https://southkorea.smartscreen.microsoft.com/","gw_br":"https://brazil.smartscreen.microsoft.com/","au":"https://australia.smartscreen.microsoft.com/","dk":"https://denmark.smartscreen.microsoft.com/","gw_sg":"https://singapore.smartscreen.microsoft.com/","gw_fr":"https://france.smartscreen.microsoft.com/","gw_ca":"https://canada.smartscreen.microsoft.com/","test":"https://eu-9.smartscreen.microsoft.com/","gw_il":"https://israel.smartscreen.microsoft.com/","gw_au":"https://australia.smartscreen.microsoft.com/","gw_ffl4mod":"https://unitedstates4.ss.wd.microsoft.us/","gw_ffl4":"https://unitedstates1.ss.wd.microsoft.us/","gw_eu":"https://europe.
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):130439
                            Entropy (8bit):3.80180718117079
                            Encrypted:false
                            SSDEEP:
                            MD5:EB75CEFFE37E6DF9C171EE8380439EDA
                            SHA1:F00119BA869133D64E4F7F0181161BD47968FA23
                            SHA-256:48B11410DC937A1723BF4C5AD33ECDB286D8EC69544241BC373F753E64B396C1
                            SHA-512:044C5113D877CE2E3B42CF07670620937ED7BE2D8B3BF2BAB085C43EF4F64598A7AC56328DDBBE7F0F3CFB9EA49D38CA332BB4ECBFEDBE24AE53B14334A30C8E
                            Malicious:false
                            Reputation:unknown
                            Preview:{.. "geoidMaps": {.. "au": "https://australia.smartscreen.microsoft.com/",.. "ch": "https://switzerland.smartscreen.microsoft.com/",.. "eu": "https://europe.smartscreen.microsoft.com/",.. "ffl4": "https://unitedstates1.ss.wd.microsoft.us/",.. "ffl4mod": "https://unitedstates4.ss.wd.microsoft.us/",.. "ffl5": "https://unitedstates2.ss.wd.microsoft.us/",.. "in": "https://india.smartscreen.microsoft.com/",.. "test": "https://eu-9.smartscreen.microsoft.com/",.. "uk": "https://unitedkingdom.smartscreen.microsoft.com/",.. "us": "https://unitedstates.smartscreen.microsoft.com/",.. "gw_au": "https://australia.smartscreen.microsoft.com/",.. "gw_ch": "https://switzerland.smartscreen.microsoft.com/",.. "gw_eu": "https://europe.smartscreen.microsoft.com/",.. "gw_ffl4": "https://unitedstates1.ss.wd.microsoft.us/",.. "gw_ffl4mod": "https://unitedstates4.ss.wd.microsoft.us/",.. "gw_ffl5": "https://unitedstates2.ss.wd.microsoft.us/",.. "gw_in": "https
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text, with no line terminators
                            Category:dropped
                            Size (bytes):40
                            Entropy (8bit):4.346439344671015
                            Encrypted:false
                            SSDEEP:
                            MD5:6A3A60A3F78299444AACAA89710A64B6
                            SHA1:2A052BF5CF54F980475085EEF459D94C3CE5EF55
                            SHA-256:61597278D681774EFD8EB92F5836EB6362975A74CEF807CE548E50A7EC38E11F
                            SHA-512:C5D0419869A43D712B29A5A11DC590690B5876D1D95C1F1380C2F773CA0CB07B173474EE16FE66A6AF633B04CC84E58924A62F00DCC171B2656D554864BF57A4
                            Malicious:false
                            Reputation:unknown
                            Preview:synchronousLookupUris_638343870221005468
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):57
                            Entropy (8bit):4.556488479039065
                            Encrypted:false
                            SSDEEP:
                            MD5:3A05EAEA94307F8C57BAC69C3DF64E59
                            SHA1:9B852B902B72B9D5F7B9158E306E1A2C5F6112C8
                            SHA-256:A8EF112DF7DAD4B09AAA48C3E53272A2EEC139E86590FD80E2B7CBD23D14C09E
                            SHA-512:6080AEF2339031FAFDCFB00D3179285E09B707A846FD2EA03921467DF5930B3F9C629D37400D625A8571B900BC46021047770BAC238F6BAC544B48FB3D522FB0
                            Malicious:false
                            Reputation:unknown
                            Preview:9.......murmur3.............,M.h...Z...8.\..<&Li.H..[.?m
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text, with no line terminators
                            Category:dropped
                            Size (bytes):50
                            Entropy (8bit):3.9904355005135823
                            Encrypted:false
                            SSDEEP:
                            MD5:E144AFBFB9EE10479AE2A9437D3FC9CA
                            SHA1:5AAAC173107C688C06944D746394C21535B0514B
                            SHA-256:EB28E8ED7C014F211BD81308853F407DF86AEBB5F80F8E4640C608CD772544C2
                            SHA-512:837D15B3477C95D2D71391D677463A497D8D9FFBD7EB42E412DA262C9B5C82F22CE4338A0BEAA22C81A06ECA2DF7A9A98B7D61ECACE5F087912FD9BA7914AF3F
                            Malicious:false
                            Reputation:unknown
                            Preview:topTraffic_170540185939602997400506234197983529371
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:data
                            Category:dropped
                            Size (bytes):575056
                            Entropy (8bit):7.999649474060713
                            Encrypted:true
                            SSDEEP:
                            MD5:BE5D1A12C1644421F877787F8E76642D
                            SHA1:06C46A95B4BD5E145E015FA7E358A2D1AC52C809
                            SHA-256:C1CE928FBEF4EF5A4207ABAFD9AB6382CC29D11DDECC215314B0522749EF6A5A
                            SHA-512:FD5B100E2F192164B77F4140ADF6DE0322F34D7B6F0CF14AED91BACAB18BB8F195F161F7CF8FB10651122A598CE474AC4DC39EDF47B6A85C90C854C2A3170960
                            Malicious:false
                            Reputation:unknown
                            Preview:...._+jE.`..}....S..1....G}s..E....y".Wh.^.W.H...-...#.A...KR...9b........>k......bU.IVo...D......Y..[l.yx.......'c=..I0.....E.d...-...1 ....m../C...OQ.........qW..<:N.....38.u..X-..s....<..U.,Mi..._.......`.Y/.........^..,.E..........j@..G8..N.... ..Ea...4.+.79k.!T.-5W..!..@+..!.P..LDG.....V."....L.... .(#..$..&......C.....%A.T}....K_.S..'Q.".d....s....(j.D!......Ov..)*d0)."(..%..-..G..L.}....i.....m9;.....t.w..0....f?..-..M.c.3.....N7K.T..D>.3.x...z..u$5!..4..T.....U.O^L{.5..=E..'..;.}(|.6.:..f!.>...?M.8......P.D.J.I4.<...*.y.E....>....i%.6..Y.@..n.....M..r..C.f.;..<..0.H...F....h.......HB1]1....u..:...H..k....B.Q..J...@}j~.#...'Y.J~....I...ub.&..L[z..1.W/.Ck....M.......[.......N.F..z*.{nZ~d.V.4.u.K.V.......X.<p..cz..>*....X...W..da3(..g..Z$.L4.j=~.p.l.\.[e.&&.Y ...U)..._.^r0.,.{_......`S..[....(.\..p.bt.g..%.$+....f.....d....Im..f...W ......G..i_8a..ae..7....pS.....z-H..A.s.4.3..O.r.....u.S......a.}..v.-/..... ...a.x#./:...sS&U.().xL...pg
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:ASCII text, with no line terminators
                            Category:dropped
                            Size (bytes):9
                            Entropy (8bit):3.169925001442312
                            Encrypted:false
                            SSDEEP:
                            MD5:B6F7A6B03164D4BF8E3531A5CF721D30
                            SHA1:A2134120D4712C7C629CDCEEF9DE6D6E48CA13FA
                            SHA-256:3D6F3F8F1456D7CE78DD9DFA8187318B38E731A658E513F561EE178766E74D39
                            SHA-512:4B473F45A5D45D420483EA1D9E93047794884F26781BBFE5370A554D260E80AD462E7EEB74D16025774935C3A80CBB2FD1293941EE3D7B64045B791B365F2B63
                            Malicious:false
                            Reputation:unknown
                            Preview:uriCache_
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):180
                            Entropy (8bit):4.968404374650785
                            Encrypted:false
                            SSDEEP:
                            MD5:940327716FC520E30DF830D1A84A694A
                            SHA1:21A7C844D5A36E92E940CE68717DC503D5547720
                            SHA-256:F6D4FDFAD2AD4C5AEC5792A56AD2E4DD11FF144F214B268973801886E4DCD939
                            SHA-512:DEE248F47BC041DBFC7D123B3BBFD41F042F6BC8EF3704BBBD54092F6D3E5EA2E8196C123968727F1ECD87D9F309EEBFD276E7F1A766A6C728FC58FFDCADE9DA
                            Malicious:false
                            Reputation:unknown
                            Preview:{"version":1,"cache_data":[{"file_hash":"01c58ac4193284b2","server_context":"1;c5faad59-a2e3-31f2-b86e-aaf958e12824;phsh:005;7e-05","result":0,"expiration_time":1714058467980407}]}
                            Process:C:\Program Files (x86)\Microsoft\EdgeWebView\Application\117.0.2045.47\msedgewebview2.exe
                            File Type:JSON data
                            Category:dropped
                            Size (bytes):85
                            Entropy (8bit):4.3488360343066725
                            Encrypted:false
                            SSDEEP:
                            MD5:BC6142469CD7DADF107BE9AD87EA4753
                            SHA1:72A9AA05003FAB742B0E4DC4C5D9EDA6B9F7565C
                            SHA-256:B26DA4F8C7E283AA74386DA0229D66AF14A37986B8CA828E054FC932F68DD557
                            SHA-512:47D1A67A16F5DC6D50556C5296E65918F0A2FCAD0E8CEE5795B100FE8CD89EAF5E1FD67691E8A57AF3677883A5D8F104723B1901D11845B286474C8AC56F6182
                            Malicious:false
                            Reputation:unknown
                            Preview:{"user_experience_metrics.stability.exited_cleanly":true,"variations_crash_streak":0}
                            Process:C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
                            File Type:XML 1.0 document, ASCII text, with very long lines (938), with CRLF line terminators
                            Category:dropped
                            Size (bytes):1099
                            Entropy (8bit):6.032683923436026
                            Encrypted:false
                            SSDEEP:
                            MD5:DF8B8B1D63CC4B8EFEC95A770A334E60
                            SHA1:9B27730093CD3998497A982EAC383052B259B102
                            SHA-256:EE7601182749F0ED0635FB152699B5C597D42C5CE29391A81C348C74DD5B50CD
                            SHA-512:DBEDF68E5AF923EA073E17E627C5360AE1DA08E0A0FF5DBB5640DDDCEAF6760E2312535CBED2D8168696275AF1DB3C9E4516D6BA081C6180594A416CF87A030B
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <appSettings>.. <add key="UserCredentials" value="4rbS3lZLpsMBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaAAAAAAIAAAAAABBmAAAAAQAAIAAAABB4JkeJnTmXsXXR30K7fhDJ3SOmsolPvfde6MOHkQoyAAAAAA6AAAAAAgAAIAAAANxWjN8Ew/3jpPiBP662JACwetpGTWoc9Wg5+w2vMni+wAEAANac54Nr5WrNjGOl2R0T0Ft1e++nOsVRqfulsmrRVoG0XihGFAKuDV9d5ywtNDkq51BAWZJpXo5h0gBe307I8IgzKTgcl95i7N/L+B3wrKyYBR0IZem1EecnfN2JJcEscuq7K7Fw12l+MqNNNNsomJuVJlBhdm9oZEi/TOgfrQ74Xc3axYMmGOh1VRJys5gHsUjI7AFo0PDZQptTm3jAF7xC8zbvTBYOnHxYBOfCK1rct+z4n86q3tVbITkgptRDVpnicJWg9AM9N4gn9iZyU5BPPyCC1MGHi8pHkFbKZ/Z9XP5AwL3qff5dPldUdf8JT7Tx8ZxKIcSvcBM/MU+RwA6814QHqT84vbkRLOmY9mXVVoOaaSah/1tFe5DXQp9xNanu1b4rjOHrSz2wACHR4xcB2SPWZ9dkQRrKqldSDOwpbRAC5fJCdy+xE4tqw7Stu0XqW7F+v56fcV05PsCjtJVPcxoZMuktf28aULch4LqYgzRF3ywHLGER+PS0vy+PhcnU/J17kQ3D5BDZOMC8VycrA+cwDwa9DfdJKTTSQENAfVxYHs9q8xBGTWBBtoVRkizcE16vgnPrrCFahcaTUqlAAAAA7zFYyaObrN8QUz0R0XJjmKxwdU/d1GjIkooRmlq1+jh5rXmqi4DkHMIrCn7UtHMbBRAfKds4YQVjk2Em
                            Process:C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
                            File Type:XML 1.0 document, ASCII text, with very long lines (7215), with CRLF line terminators
                            Category:dropped
                            Size (bytes):8316
                            Entropy (8bit):6.037238242488497
                            Encrypted:false
                            SSDEEP:
                            MD5:60C3B9AC4218698C2E2094F3AC3F92AD
                            SHA1:7E63C9A39DE1AF43209A6BF249393BE3D89273F3
                            SHA-256:F2A2351AC65EDD542160D03A709CB44926C55379AB64E363060FCC780BE3ED4A
                            SHA-512:79709E7FD408680B7633ECF6A1DF3C598CFF625AB1DC8BB1CF45619545D4ACFBA2BE6E3422EBDBB64F1393BDBFA07BE692C891B20A81353F8CEAAFDA4B837DEA
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <appSettings>.. <add key="UserCredentials" value="4rbS3lZLpsMBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaAAAAAAIAAAAAABBmAAAAAQAAIAAAABB4JkeJnTmXsXXR30K7fhDJ3SOmsolPvfde6MOHkQoyAAAAAA6AAAAAAgAAIAAAANxWjN8Ew/3jpPiBP662JACwetpGTWoc9Wg5+w2vMni+wAEAANac54Nr5WrNjGOl2R0T0Ft1e++nOsVRqfulsmrRVoG0XihGFAKuDV9d5ywtNDkq51BAWZJpXo5h0gBe307I8IgzKTgcl95i7N/L+B3wrKyYBR0IZem1EecnfN2JJcEscuq7K7Fw12l+MqNNNNsomJuVJlBhdm9oZEi/TOgfrQ74Xc3axYMmGOh1VRJys5gHsUjI7AFo0PDZQptTm3jAF7xC8zbvTBYOnHxYBOfCK1rct+z4n86q3tVbITkgptRDVpnicJWg9AM9N4gn9iZyU5BPPyCC1MGHi8pHkFbKZ/Z9XP5AwL3qff5dPldUdf8JT7Tx8ZxKIcSvcBM/MU+RwA6814QHqT84vbkRLOmY9mXVVoOaaSah/1tFe5DXQp9xNanu1b4rjOHrSz2wACHR4xcB2SPWZ9dkQRrKqldSDOwpbRAC5fJCdy+xE4tqw7Stu0XqW7F+v56fcV05PsCjtJVPcxoZMuktf28aULch4LqYgzRF3ywHLGER+PS0vy+PhcnU/J17kQ3D5BDZOMC8VycrA+cwDwa9DfdJKTTSQENAfVxYHs9q8xBGTWBBtoVRkizcE16vgnPrrCFahcaTUqlAAAAA7zFYyaObrN8QUz0R0XJjmKxwdU/d1GjIkooRmlq1+jh5rXmqi4DkHMIrCn7UtHMbBRAfKds4YQVjk2Em
                            Process:C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
                            File Type:XML 1.0 document, ASCII text, with very long lines (31485), with CRLF line terminators
                            Category:dropped
                            Size (bytes):39803
                            Entropy (8bit):6.01646361858526
                            Encrypted:false
                            SSDEEP:
                            MD5:1EDF55E33F6DB68CD83F71EEE067D63D
                            SHA1:79808DD9091F067D94B164C48BDAE0128C8F04E9
                            SHA-256:F6411ECC8400C9F9A50F1A67E6D238E13C3DB2EB745D5C1C29342A60F6C698AD
                            SHA-512:1DC7F87A236C850B37AB773D7FE17FBE532E444AE093B712AC11D819405CEF813063A4E5472F66BC8B0504C8F1800734EFFE93B199FA2C5F71EBEC4AE7EBC62E
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <appSettings>.. <add key="UserCredentials" value="4rbS3lZLpsMBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaAAAAAAIAAAAAABBmAAAAAQAAIAAAABB4JkeJnTmXsXXR30K7fhDJ3SOmsolPvfde6MOHkQoyAAAAAA6AAAAAAgAAIAAAANxWjN8Ew/3jpPiBP662JACwetpGTWoc9Wg5+w2vMni+wAEAANac54Nr5WrNjGOl2R0T0Ft1e++nOsVRqfulsmrRVoG0XihGFAKuDV9d5ywtNDkq51BAWZJpXo5h0gBe307I8IgzKTgcl95i7N/L+B3wrKyYBR0IZem1EecnfN2JJcEscuq7K7Fw12l+MqNNNNsomJuVJlBhdm9oZEi/TOgfrQ74Xc3axYMmGOh1VRJys5gHsUjI7AFo0PDZQptTm3jAF7xC8zbvTBYOnHxYBOfCK1rct+z4n86q3tVbITkgptRDVpnicJWg9AM9N4gn9iZyU5BPPyCC1MGHi8pHkFbKZ/Z9XP5AwL3qff5dPldUdf8JT7Tx8ZxKIcSvcBM/MU+RwA6814QHqT84vbkRLOmY9mXVVoOaaSah/1tFe5DXQp9xNanu1b4rjOHrSz2wACHR4xcB2SPWZ9dkQRrKqldSDOwpbRAC5fJCdy+xE4tqw7Stu0XqW7F+v56fcV05PsCjtJVPcxoZMuktf28aULch4LqYgzRF3ywHLGER+PS0vy+PhcnU/J17kQ3D5BDZOMC8VycrA+cwDwa9DfdJKTTSQENAfVxYHs9q8xBGTWBBtoVRkizcE16vgnPrrCFahcaTUqlAAAAA7zFYyaObrN8QUz0R0XJjmKxwdU/d1GjIkooRmlq1+jh5rXmqi4DkHMIrCn7UtHMbBRAfKds4YQVjk2Em
                            Process:C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
                            File Type:XML 1.0 document, ASCII text, with very long lines (31485), with CRLF line terminators
                            Category:dropped
                            Size (bytes):40270
                            Entropy (8bit):6.017897593108082
                            Encrypted:false
                            SSDEEP:
                            MD5:0318B8040ACF6AB9762A1CAA3FAE4107
                            SHA1:913FF31845B7598E2498A4D1C4A9962FECA1F2F6
                            SHA-256:C54B381E6EE36D01BBFBDDC9C71ED91F3CF4C0F059F843D9EF838CA71A9ADB37
                            SHA-512:7A08BBE8DFFEDDFA5695F6950F7842233C9D7AD8CE5C8AD7BC54F309765751B7BC4E7B8DBD8008310160D7AAA9A2FD9F5AB298704BF84F77574543DF8B027CA8
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <appSettings>.. <add key="UserCredentials" value="4rbS3lZLpsMBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaAAAAAAIAAAAAABBmAAAAAQAAIAAAABB4JkeJnTmXsXXR30K7fhDJ3SOmsolPvfde6MOHkQoyAAAAAA6AAAAAAgAAIAAAANxWjN8Ew/3jpPiBP662JACwetpGTWoc9Wg5+w2vMni+wAEAANac54Nr5WrNjGOl2R0T0Ft1e++nOsVRqfulsmrRVoG0XihGFAKuDV9d5ywtNDkq51BAWZJpXo5h0gBe307I8IgzKTgcl95i7N/L+B3wrKyYBR0IZem1EecnfN2JJcEscuq7K7Fw12l+MqNNNNsomJuVJlBhdm9oZEi/TOgfrQ74Xc3axYMmGOh1VRJys5gHsUjI7AFo0PDZQptTm3jAF7xC8zbvTBYOnHxYBOfCK1rct+z4n86q3tVbITkgptRDVpnicJWg9AM9N4gn9iZyU5BPPyCC1MGHi8pHkFbKZ/Z9XP5AwL3qff5dPldUdf8JT7Tx8ZxKIcSvcBM/MU+RwA6814QHqT84vbkRLOmY9mXVVoOaaSah/1tFe5DXQp9xNanu1b4rjOHrSz2wACHR4xcB2SPWZ9dkQRrKqldSDOwpbRAC5fJCdy+xE4tqw7Stu0XqW7F+v56fcV05PsCjtJVPcxoZMuktf28aULch4LqYgzRF3ywHLGER+PS0vy+PhcnU/J17kQ3D5BDZOMC8VycrA+cwDwa9DfdJKTTSQENAfVxYHs9q8xBGTWBBtoVRkizcE16vgnPrrCFahcaTUqlAAAAA7zFYyaObrN8QUz0R0XJjmKxwdU/d1GjIkooRmlq1+jh5rXmqi4DkHMIrCn7UtHMbBRAfKds4YQVjk2Em
                            Process:C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
                            File Type:XML 1.0 document, ASCII text, with very long lines (31485), with CRLF line terminators
                            Category:dropped
                            Size (bytes):41118
                            Entropy (8bit):6.01902903595747
                            Encrypted:false
                            SSDEEP:
                            MD5:78167DB437142C9D6AB6173B4888258B
                            SHA1:0CD22A12DEE7EBB0F5055A5973E7768DBDC39E0E
                            SHA-256:6F68AEFE57CD2C7043E27C35BE50E3C7A20C56DB7ED4461A1A782B2029F638E0
                            SHA-512:EABD4AA78EDD49D58BE972F5FD83A55B54868941BCD041C3657D5739732F3A34C752DEF9A0196635E9B3F945CB1EA3AA6A81B96423B0FDD27B3F1F07700BA5ED
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <appSettings>.. <add key="UserCredentials" value="4rbS3lZLpsMBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaAAAAAAIAAAAAABBmAAAAAQAAIAAAABB4JkeJnTmXsXXR30K7fhDJ3SOmsolPvfde6MOHkQoyAAAAAA6AAAAAAgAAIAAAANxWjN8Ew/3jpPiBP662JACwetpGTWoc9Wg5+w2vMni+wAEAANac54Nr5WrNjGOl2R0T0Ft1e++nOsVRqfulsmrRVoG0XihGFAKuDV9d5ywtNDkq51BAWZJpXo5h0gBe307I8IgzKTgcl95i7N/L+B3wrKyYBR0IZem1EecnfN2JJcEscuq7K7Fw12l+MqNNNNsomJuVJlBhdm9oZEi/TOgfrQ74Xc3axYMmGOh1VRJys5gHsUjI7AFo0PDZQptTm3jAF7xC8zbvTBYOnHxYBOfCK1rct+z4n86q3tVbITkgptRDVpnicJWg9AM9N4gn9iZyU5BPPyCC1MGHi8pHkFbKZ/Z9XP5AwL3qff5dPldUdf8JT7Tx8ZxKIcSvcBM/MU+RwA6814QHqT84vbkRLOmY9mXVVoOaaSah/1tFe5DXQp9xNanu1b4rjOHrSz2wACHR4xcB2SPWZ9dkQRrKqldSDOwpbRAC5fJCdy+xE4tqw7Stu0XqW7F+v56fcV05PsCjtJVPcxoZMuktf28aULch4LqYgzRF3ywHLGER+PS0vy+PhcnU/J17kQ3D5BDZOMC8VycrA+cwDwa9DfdJKTTSQENAfVxYHs9q8xBGTWBBtoVRkizcE16vgnPrrCFahcaTUqlAAAAA7zFYyaObrN8QUz0R0XJjmKxwdU/d1GjIkooRmlq1+jh5rXmqi4DkHMIrCn7UtHMbBRAfKds4YQVjk2Em
                            Process:C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
                            File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                            Category:dropped
                            Size (bytes):111
                            Entropy (8bit):4.832220204997265
                            Encrypted:false
                            SSDEEP:
                            MD5:A4B94AB25D76B7A77F01C2AF649ACB26
                            SHA1:F7026FB6D96302FA287F6DD17EA63C9A1808D14A
                            SHA-256:24527FDD41E62B48F0A7237B96DE7CE0F5E44A38ED5262277CE3DA516F0DE975
                            SHA-512:D788C5940232BC6BF5138EA0068B971998990B51A490CBA1E598B5764805051E89B918190A990E37CD353A309BCFA5A27FD1F9146CA90DA004C812E31C73ED5E
                            Malicious:false
                            Reputation:unknown
                            Preview:.<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <appSettings>.. </appSettings>..</configuration>
                            Process:C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe
                            File Type:XML 1.0 document, ASCII text, with very long lines (938), with CRLF line terminators
                            Category:dropped
                            Size (bytes):1048
                            Entropy (8bit):6.024413583000892
                            Encrypted:false
                            SSDEEP:
                            MD5:51EAAF3DAFDE5E59F54DD5988CD2945E
                            SHA1:015681EE4BEFAC4C75974A2FF0AC62C2B5D468A1
                            SHA-256:23856AB7E6E6E3DF0DFE9E8C1EF899A1E90EFAC97A25441F37D6B9475E986C73
                            SHA-512:4BF3D13F2FB83B9AA1E14DDD04AD216133232CE3CAD6C9A5E22747C278523BAFC947013AF914D14A86BBD57A5E07B148CDDB3F3F85758A2298EA9EFF6CDE7AE0
                            Malicious:false
                            Reputation:unknown
                            Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <appSettings>.. <add key="UserCredentials" value="4rbS3lZLpsMBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAADJ6nshPHp9TrQm6N6Y2njaAAAAAAIAAAAAABBmAAAAAQAAIAAAABB4JkeJnTmXsXXR30K7fhDJ3SOmsolPvfde6MOHkQoyAAAAAA6AAAAAAgAAIAAAANxWjN8Ew/3jpPiBP662JACwetpGTWoc9Wg5+w2vMni+wAEAANac54Nr5WrNjGOl2R0T0Ft1e++nOsVRqfulsmrRVoG0XihGFAKuDV9d5ywtNDkq51BAWZJpXo5h0gBe307I8IgzKTgcl95i7N/L+B3wrKyYBR0IZem1EecnfN2JJcEscuq7K7Fw12l+MqNNNNsomJuVJlBhdm9oZEi/TOgfrQ74Xc3axYMmGOh1VRJys5gHsUjI7AFo0PDZQptTm3jAF7xC8zbvTBYOnHxYBOfCK1rct+z4n86q3tVbITkgptRDVpnicJWg9AM9N4gn9iZyU5BPPyCC1MGHi8pHkFbKZ/Z9XP5AwL3qff5dPldUdf8JT7Tx8ZxKIcSvcBM/MU+RwA6814QHqT84vbkRLOmY9mXVVoOaaSah/1tFe5DXQp9xNanu1b4rjOHrSz2wACHR4xcB2SPWZ9dkQRrKqldSDOwpbRAC5fJCdy+xE4tqw7Stu0XqW7F+v56fcV05PsCjtJVPcxoZMuktf28aULch4LqYgzRF3ywHLGER+PS0vy+PhcnU/J17kQ3D5BDZOMC8VycrA+cwDwa9DfdJKTTSQENAfVxYHs9q8xBGTWBBtoVRkizcE16vgnPrrCFahcaTUqlAAAAA7zFYyaObrN8QUz0R0XJjmKxwdU/d1GjIkooRmlq1+jh5rXmqi4DkHMIrCn7UtHMbBRAfKds4YQVjk2Em
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Archive, ctime=Wed Apr 17 12:10:54 2024, mtime=Wed Apr 24 08:52:00 2024, atime=Wed Apr 17 12:10:54 2024, length=235104, window=hide
                            Category:dropped
                            Size (bytes):1424
                            Entropy (8bit):4.841124201875755
                            Encrypted:false
                            SSDEEP:
                            MD5:4E2F3D29E6FBA5BE0659DBF978927144
                            SHA1:27A0C259C9F6EEC6477B15BB4CFC50FDFD341E6F
                            SHA-256:FEAAE79C620BB9E1217A0D35E846559399BC918E177D4794EE98C2195CEF52DD
                            SHA-512:4A1C4B7FE2AD80529A64A00CCE44C01B4B92158FBD58594751041805E1BDB06413529A7849F442E2A27F7D619AF9ECB2F5C5FB6893F01515834C94F10D4235AF
                            Malicious:false
                            Reputation:unknown
                            Preview:L..................F.... ..........[h.-.........`.......................R.:..DG..Yr?.D..U..k0.&...&.........{4......-...=.[.-.......t...CFSF..1.....FW.H..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......FW.H.XoN..............................A.p.p.D.a.t.a...B.P.1......X{N..Local.<......FW.H.X{N..........................T.~.L.o.c.a.l.....\.1......X{N..GRAMMA~1..D......X{N.X{N..........................T.~.G.r.a.m.m.a.r.l.y.....p.1......X.N..DESKTO~1..X......X{N.X.N..............................D.e.s.k.t.o.p.I.n.t.e.g.r.a.t.i.o.n.s.....x.2.`....X[i .GRAMMA~1.EXE..\......X[i.X|N..............................G.r.a.m.m.a.r.l.y...D.e.s.k.t.o.p...e.x.e.......~...............-.......}............s@......C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe..H.....\.....\.....\.....\.....\.L.o.c.a.l.\.G.r.a.m.m.a.r.l.y.\.D.e.s.k.t.o.p.I.n.t.e.g.r.a.t.i.o.n.s.\.G.r.a.m.m.a.r.l.y...D.e.s.k.t.o.p...e.x.e.9.C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.
                            Process:C:\Users\user\Desktop\GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Archive, ctime=Wed Apr 17 12:10:54 2024, mtime=Wed Apr 24 08:51:54 2024, atime=Wed Apr 17 12:10:54 2024, length=235104, window=hide
                            Category:dropped
                            Size (bytes):1416
                            Entropy (8bit):4.846120228795159
                            Encrypted:false
                            SSDEEP:
                            MD5:5A36821274960E4545A6CFFBC01494B4
                            SHA1:D83EA6824C8EB551FBC7F9C5E3AD3F15FA9DAE6D
                            SHA-256:62F593D92E0B842F9B92012ED6E138A0CC6E83F776322FB6CE11713323268132
                            SHA-512:53D42DFCD6EF4482BA62A6F8700BD5E611AB5B66081472804C8CE68533E3D176629B432A8F1F19BCA6B09FE2071CBBED5AC5881FA77F2E815851F8A5014C122F
                            Malicious:false
                            Reputation:unknown
                            Preview:L..................F.... .............-.........`.......................R.:..DG..Yr?.D..U..k0.&...&.........{4......-...=.[.-.......t...CFSF..1.....FW.H..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......FW.H.XoN..............................A.p.p.D.a.t.a...B.P.1......X{N..Local.<......FW.H.X{N..........................T.~.L.o.c.a.l.....\.1......X{N..GRAMMA~1..D......X{N.X{N..........................T.~.G.r.a.m.m.a.r.l.y.....p.1......X.N..DESKTO~1..X......X{N.X.N...........................@%.D.e.s.k.t.o.p.I.n.t.e.g.r.a.t.i.o.n.s.....x.2.`....X[i .GRAMMA~1.EXE..\......X[i.X|N..............................G.r.a.m.m.a.r.l.y...D.e.s.k.t.o.p...e.x.e.......~...............-.......}............s@......C:\Users\user\AppData\Local\Grammarly\DesktopIntegrations\Grammarly.Desktop.exe..D.....\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.G.r.a.m.m.a.r.l.y.\.D.e.s.k.t.o.p.I.n.t.e.g.r.a.t.i.o.n.s.\.G.r.a.m.m.a.r.l.y...D.e.s.k.t.o.p...e.x.e.9.C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.G.r.a.
                            File type:PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
                            Entropy (8bit):7.999861350676348
                            TrID:
                            • Win32 Executable (generic) a (10002005/4) 99.96%
                            • Generic Win/DOS Executable (2004/3) 0.02%
                            • DOS Executable Generic (2002/1) 0.02%
                            • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                            File name:GrammarlyInstaller.ej4bHc8fzjsm8sfmuc7404o2.exe
                            File size:18'314'104 bytes
                            MD5:fd2c102f6b2dac90179d7981dc7299e1
                            SHA1:36b30f7173dae7c450e24204cd432b122121ebb3
                            SHA256:4627b4f84258eede9176028143c17f0ef56d649b4ff4ba4d218a2609bf0193f5
                            SHA512:f03d0e7a9861ae9eb3c222cd7c9712be018c672b185f73444c973e02d1b603cccf593b71caf16a9c9b165c3232f21198dabfc2ab6ed9bd5369d2a52b6dfd17bc
                            SSDEEP:393216:SYVjSvFo197p6SzmhRRNGbxr30XA2x/60tXzAV2sMjL:SYVmSn0SzmhnAbxr3CAI/K2skL
                            TLSH:C70733389F59EC32E460CB765BF8C8AAF5091C26D870347F96A13B1115B606FC9DBA03
                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1...Pf..Pf..Pf.*_9..Pf..Pg.LPf.*_;..Pf..sV..Pf..V`..Pf.Rich.Pf.........................PE..L.....Oa.................h...*.....
                            Icon Hash:17696cc6c64c3106
                            Entrypoint:0x403640
                            Entrypoint Section:.text
                            Digitally signed:true
                            Imagebase:0x400000
                            Subsystem:windows gui
                            Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                            DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                            Time Stamp:0x614F9B1F [Sat Sep 25 21:56:47 2021 UTC]
                            TLS Callbacks:
                            CLR (.Net) Version:
                            OS Version Major:4
                            OS Version Minor:0
                            File Version Major:4
                            File Version Minor:0
                            Subsystem Version Major:4
                            Subsystem Version Minor:0
                            Import Hash:61259b55b8912888e90f516ca08dc514
                            Signature Valid:true
                            Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
                            Signature Validation Error:The operation completed successfully
                            Error Number:0
                            Not Before, Not After
                            • 08/06/2023 02:00:00 08/06/2026 01:59:59
                            Subject Chain
                            • CN="Grammarly, Inc.", OU="Grammarly, Inc.", O="Grammarly, Inc.", L=San Francisco, S=California, C=US
                            Version:3
                            Thumbprint MD5:F2D497EF480B89D03E177C8C5B464505
                            Thumbprint SHA-1:88414119618A8FD78726A2690042F4D349AF0B8F
                            Thumbprint SHA-256:7D9A1B3E0DED5AEECE6F73B0488FA241B206AB4DD0D425A3B19CF34C0B2C0E9A
                            Serial:03FAAAC80204F9721AC1E44F59CACA7B
                            Instruction
                            push ebp
                            mov ebp, esp
                            sub esp, 000003F4h
                            push ebx
                            push esi
                            push edi
                            push 00000020h
                            pop edi
                            xor ebx, ebx
                            push 00008001h
                            mov dword ptr [ebp-14h], ebx
                            mov dword ptr [ebp-04h], 0040A230h
                            mov dword ptr [ebp-10h], ebx
                            call dword ptr [004080C8h]
                            mov esi, dword ptr [004080CCh]
                            lea eax, dword ptr [ebp-00000140h]
                            push eax
                            mov dword ptr [ebp-0000012Ch], ebx
                            mov dword ptr [ebp-2Ch], ebx
                            mov dword ptr [ebp-28h], ebx
                            mov dword ptr [ebp-00000140h], 0000011Ch
                            call esi
                            test eax, eax
                            jne 00007F1074EFD58Ah
                            lea eax, dword ptr [ebp-00000140h]
                            mov dword ptr [ebp-00000140h], 00000114h
                            push eax
                            call esi
                            mov ax, word ptr [ebp-0000012Ch]
                            mov ecx, dword ptr [ebp-00000112h]
                            sub ax, 00000053h
                            add ecx, FFFFFFD0h
                            neg ax
                            sbb eax, eax
                            mov byte ptr [ebp-26h], 00000004h
                            not eax
                            and eax, ecx
                            mov word ptr [ebp-2Ch], ax
                            cmp dword ptr [ebp-0000013Ch], 0Ah
                            jnc 00007F1074EFD55Ah
                            and word ptr [ebp-00000132h], 0000h
                            mov eax, dword ptr [ebp-00000134h]
                            movzx ecx, byte ptr [ebp-00000138h]
                            mov dword ptr [0042A318h], eax
                            xor eax, eax
                            mov ah, byte ptr [ebp-0000013Ch]
                            movzx eax, ax
                            or eax, ecx
                            xor ecx, ecx
                            mov ch, byte ptr [ebp-2Ch]
                            movzx ecx, cx
                            shl eax, 10h
                            or eax, ecx
                            Programming Language:
                            • [EXP] VC++ 6.0 SP5 build 8804
                            NameVirtual AddressVirtual Size Is in Section
                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                            IMAGE_DIRECTORY_ENTRY_IMPORT0x85040xa0.rdata
                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x4d0000x80f8.rsrc
                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                            IMAGE_DIRECTORY_ENTRY_SECURITY0x1174b180x2860
                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                            IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                            IMAGE_DIRECTORY_ENTRY_IAT0x80000x2b0.rdata
                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                            .text0x10000x66760x68006f5abe9eeda26ee84b3c1ed1a6c82001False0.6568134014423077data6.4174599871908855IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                            .rdata0x80000x139a0x14008c5edfd8ff9cc0135e197611be38ca18False0.4498046875data5.141066817170598IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                            .data0xa0000x203780x6004b2421975c21b032f7ea000f5e7f9fbfFalse0.509765625data4.110582127654237IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                            .ndata0x2b0000x220000x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                            .rsrc0x4d0000x80f80x8200d0d5ba30cb532675c40785584eb4fe04False0.3800480769230769data5.188762161238905IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                            NameRVASizeTypeLanguageCountryZLIB Complexity
                            RT_ICON0x4d2680x4228Device independent bitmap graphic, 64 x 128 x 32, image size 0EnglishUnited States0.15729806329711857
                            RT_ICON0x514900x1d5ePNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.98829475924448
                            RT_ICON0x531f00x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishUnited States0.149859287054409
                            RT_ICON0x542980x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.3129432624113475
                            RT_DIALOG0x547000xe0dataEnglishUnited States0.42410714285714285
                            RT_DIALOG0x547e00xf8dataEnglishUnited States0.592741935483871
                            RT_DIALOG0x548d80x60dataEnglishUnited States0.7291666666666666
                            RT_GROUP_ICON0x549380x3edataEnglishUnited States0.8064516129032258
                            RT_VERSION0x549780x294OpenPGP Secret KeyEnglishUnited States0.4636363636363636
                            RT_MANIFEST0x54c100x4e1XML 1.0 document, ASCII text, with very long lines (1249), with no line terminatorsEnglishUnited States0.4851881505204163
                            DLLImport
                            ADVAPI32.dllRegCreateKeyExW, RegEnumKeyW, RegQueryValueExW, RegSetValueExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, SetFileSecurityW, RegOpenKeyExW, RegEnumValueW
                            SHELL32.dllSHGetSpecialFolderLocation, SHFileOperationW, SHBrowseForFolderW, SHGetPathFromIDListW, ShellExecuteExW, SHGetFileInfoW
                            ole32.dllOleInitialize, OleUninitialize, CoCreateInstance, IIDFromString, CoTaskMemFree
                            COMCTL32.dllImageList_Create, ImageList_Destroy, ImageList_AddMasked
                            USER32.dllGetClientRect, EndPaint, DrawTextW, IsWindowEnabled, DispatchMessageW, wsprintfA, CharNextA, CharPrevW, MessageBoxIndirectW, GetDlgItemTextW, SetDlgItemTextW, GetSystemMetrics, FillRect, AppendMenuW, TrackPopupMenu, OpenClipboard, SetClipboardData, CloseClipboard, IsWindowVisible, CallWindowProcW, GetMessagePos, CheckDlgButton, LoadCursorW, SetCursor, GetSysColor, SetWindowPos, GetWindowLongW, PeekMessageW, SetClassLongW, GetSystemMenu, EnableMenuItem, GetWindowRect, ScreenToClient, EndDialog, RegisterClassW, SystemParametersInfoW, CreateWindowExW, GetClassInfoW, DialogBoxParamW, CharNextW, ExitWindowsEx, DestroyWindow, CreateDialogParamW, SetTimer, SetWindowTextW, PostQuitMessage, SetForegroundWindow, ShowWindow, wsprintfW, SendMessageTimeoutW, FindWindowExW, IsWindow, GetDlgItem, SetWindowLongW, LoadImageW, GetDC, ReleaseDC, EnableWindow, InvalidateRect, SendMessageW, DefWindowProcW, BeginPaint, EmptyClipboard, CreatePopupMenu
                            GDI32.dllSetBkMode, SetBkColor, GetDeviceCaps, CreateFontIndirectW, CreateBrushIndirect, DeleteObject, SetTextColor, SelectObject
                            KERNEL32.dllGetExitCodeProcess, WaitForSingleObject, GetModuleHandleA, GetProcAddress, GetSystemDirectoryW, lstrcatW, Sleep, lstrcpyA, WriteFile, GetTempFileNameW, lstrcmpiA, RemoveDirectoryW, CreateProcessW, CreateDirectoryW, GetLastError, CreateThread, GlobalLock, GlobalUnlock, GetDiskFreeSpaceW, WideCharToMultiByte, lstrcpynW, lstrlenW, SetErrorMode, GetVersionExW, GetCommandLineW, GetTempPathW, GetWindowsDirectoryW, SetEnvironmentVariableW, CopyFileW, ExitProcess, GetCurrentProcess, GetModuleFileNameW, GetFileSize, CreateFileW, GetTickCount, MulDiv, SetFileAttributesW, GetFileAttributesW, SetCurrentDirectoryW, MoveFileW, GetFullPathNameW, GetShortPathNameW, SearchPathW, CompareFileTime, SetFileTime, CloseHandle, lstrcmpiW, lstrcmpW, ExpandEnvironmentStringsW, GlobalFree, GlobalAlloc, GetModuleHandleW, LoadLibraryExW, MoveFileExW, FreeLibrary, WritePrivateProfileStringW, GetPrivateProfileStringW, lstrlenA, MultiByteToWideChar, ReadFile, SetFilePointer, FindClose, FindNextFileW, FindFirstFileW, DeleteFileW
                            Language of compilation systemCountry where language is spokenMap
                            EnglishUnited States