Windows Analysis Report
https://aka.ms/AAb9ysg__;!!JywAMcrl3w!-ETt_Rmq2qic6h9-r-A2Pg2Rw6IBmkz7xvd8Zk06m26oaz1wBBb2mB1uKoKqOCmdEVt0NuzHVqY6S4CNViUA$

Overview

General Information

Sample URL: https://aka.ms/AAb9ysg__;!!JywAMcrl3w!-ETt_Rmq2qic6h9-r-A2Pg2Rw6IBmkz7xvd8Zk06m26oaz1wBBb2mB1uKoKqOCmdEVt0NuzHVqY6S4CNViUA$
Analysis ID: 1432323
Infos:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Source: https://www.bing.com/secure/Passport.aspx?popup=1&ssl=1 HTTP Parser: No favicon
Source: unknown HTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.4:49749 version: TLS 1.2
Source: unknown TCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknown TCP traffic detected without corresponding DNS query: 23.45.182.76
Source: unknown TCP traffic detected without corresponding DNS query: 23.45.182.76
Source: unknown TCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknown TCP traffic detected without corresponding DNS query: 72.21.81.240
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /AAb9ysg__;!!JywAMcrl3w!-ETt_Rmq2qic6h9-r-A2Pg2Rw6IBmkz7xvd8Zk06m26oaz1wBBb2mB1uKoKqOCmdEVt0NuzHVqY6S4CNViUA$ HTTP/1.1Host: aka.msConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /shared/1.0/content/js/BssoInterrupt_Core_ChpboAn7HyXj89A22M8mzg2.js HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://login.microsoftonline.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://login.microsoftonline.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /instrument/cookieenabled HTTP/1.1Host: 3pcookiecheck.azureedge.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://www.bing.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: chromecache_286.2.dr String found in binary or memory: (function() { var sharingGlobalConfig ={"thumbnailUrlFormat":"https://www.bing.com/th?id={0}","defaultFormCode":"EX0023","facebookShareFormat":"https://www.facebook.com/dialog/feed?app_id={3}\u0026display=popup\u0026link={0}\u0026redirect_uri={1}\u0026ref={2}","facebookMessengerUrlFormat":"http://www.facebook.com/dialog/send?app_id={0}\u0026display=popup\u0026link={1}\u0026redirect_uri={2}","facebookFormCode":"EX0023","fbInitialHeight":576,"fbmInitialWidth":640,"facebookAppId":"3732605936979161","twitterApi":"https://twitter.com/intent/tweet?hashtags={0}\u0026text={1}\u0026url={2}","twitterFormCode":"EX0024","twitterInitialHeight":576,"twitterInitialWidth":720,"defaultInitialHeight":255,"whatsAppSchema":"whatsapp://send?text={0}","whatsAppStoreUrl":"","whatsAppFormCode":"EX0053","mailLauncherUrl":"mailto:?subject={0} \u0026body={1}","mailFormCode":"EX0025","smsProtocol":"","smsFormCode":"EX0052","loadingUrl":"/loading","useBlankLoadingPage":false,"closeRedirectUrl":"/share/fbre","pinterestUrlFormat":"https://pinterest.com/pin/create/button/?url={0}\u0026media={1}\u0026description={2}","pinterestFormCode":"EX0051","mybingFormCode":"shtomb","mybingRedirectUrl":"https://www.bing.com/myprofile?tid=id_chatmessagetab\u0026FORM=shtomb","skypeUrlFormat":"https://web.skype.com/share?url={0}\u0026source=button\u0026text={1}","skypeInitialHeight":665,"skypeInitialWidth":305,"outlookComLauncherUrl":"https://outlook.live.com/owa/?subject={0}\u0026body={1}\u0026path=/mail/action/compose","gmailLauncherUrl":"https://mail.google.com/mail/?view=cm\u0026fs=1\u0026tf=1\u0026su={0}\u0026body={1}","linkedInUrlFormat":"https://www.linkedin.com/shareArticle?mini=true\u0026url={0}\u0026title={1}\u0026summary={2}","linkedInFormCode":"EX0062","oneNoteUrlFormat":"https://www.onenote.com/clipper/save?attributionUrl={0}\u0026sourceUrl={1}\u0026imgUrl={1}\u0026title={2}\u0026description={3}","oneNoteInitialHeight":565,"oneNoteInitialWidth":550,"oneNoteFormCode":"EX0060","checkAppInstall":"","checkAppTimeout":200,"weiboShareFormat":"https://service.weibo.com/share/share.php?title={0}\u0026placeholder=Bing\u0026url={1}\u0026pic={2}","weiboFormCode":"SHDLWE","qzoneShareFormat":"https://sns.qzone.qq.com/cgi-bin/qzshare/cgi_qzshare_onekey?title={0}\u0026summary={1}\u0026url={2}\u0026pics={3}","qzoneFormCode":"SHDLQZ","isCNEnglishSearch":false,"redditShareFormat":"https://www.reddit.com/submit?url={0}\u0026title={1}","redditFormCode":"EX0061","useLocationReplace":false,"getUrlFormCode":"EX0050","enableGetShareLinkFromServerForGetUrl":true,"isUnderside":false}; if(sj_evt) { sj_evt.fire("GlobalActionMenuV2Wrapper.InitSharingGlobalConfig", sharingGlobalConfig); } })();; equals www.facebook.com (Facebook)
Source: chromecache_735.2.dr, chromecache_286.2.dr String found in binary or memory: (function() { var sharingGlobalConfig ={"thumbnailUrlFormat":"https://www.bing.com/th?id={0}","defaultFormCode":"EX0023","facebookShareFormat":"https://www.facebook.com/dialog/feed?app_id={3}\u0026display=popup\u0026link={0}\u0026redirect_uri={1}\u0026ref={2}","facebookMessengerUrlFormat":"http://www.facebook.com/dialog/send?app_id={0}\u0026display=popup\u0026link={1}\u0026redirect_uri={2}","facebookFormCode":"EX0023","fbInitialHeight":576,"fbmInitialWidth":640,"facebookAppId":"3732605936979161","twitterApi":"https://twitter.com/intent/tweet?hashtags={0}\u0026text={1}\u0026url={2}","twitterFormCode":"EX0024","twitterInitialHeight":576,"twitterInitialWidth":720,"defaultInitialHeight":255,"whatsAppSchema":"whatsapp://send?text={0}","whatsAppStoreUrl":"","whatsAppFormCode":"EX0053","mailLauncherUrl":"mailto:?subject={0} \u0026body={1}","mailFormCode":"EX0025","smsProtocol":"","smsFormCode":"EX0052","loadingUrl":"/loading","useBlankLoadingPage":false,"closeRedirectUrl":"/share/fbre","pinterestUrlFormat":"https://pinterest.com/pin/create/button/?url={0}\u0026media={1}\u0026description={2}","pinterestFormCode":"EX0051","mybingFormCode":"shtomb","mybingRedirectUrl":"https://www.bing.com/myprofile?tid=id_chatmessagetab\u0026FORM=shtomb","skypeUrlFormat":"https://web.skype.com/share?url={0}\u0026source=button\u0026text={1}","skypeInitialHeight":665,"skypeInitialWidth":305,"outlookComLauncherUrl":"https://outlook.live.com/owa/?subject={0}\u0026body={1}\u0026path=/mail/action/compose","gmailLauncherUrl":"https://mail.google.com/mail/?view=cm\u0026fs=1\u0026tf=1\u0026su={0}\u0026body={1}","linkedInUrlFormat":"https://www.linkedin.com/shareArticle?mini=true\u0026url={0}\u0026title={1}\u0026summary={2}","linkedInFormCode":"EX0062","oneNoteUrlFormat":"https://www.onenote.com/clipper/save?attributionUrl={0}\u0026sourceUrl={1}\u0026imgUrl={1}\u0026title={2}\u0026description={3}","oneNoteInitialHeight":565,"oneNoteInitialWidth":550,"oneNoteFormCode":"EX0060","checkAppInstall":"","checkAppTimeout":200,"weiboShareFormat":"https://service.weibo.com/share/share.php?title={0}\u0026placeholder=Bing\u0026url={1}\u0026pic={2}","weiboFormCode":"SHDLWE","qzoneShareFormat":"https://sns.qzone.qq.com/cgi-bin/qzshare/cgi_qzshare_onekey?title={0}\u0026summary={1}\u0026url={2}\u0026pics={3}","qzoneFormCode":"SHDLQZ","isCNEnglishSearch":false,"redditShareFormat":"https://www.reddit.com/submit?url={0}\u0026title={1}","redditFormCode":"EX0061","useLocationReplace":false,"getUrlFormCode":"EX0050","enableGetShareLinkFromServerForGetUrl":true,"isUnderside":false}; if(sj_evt) { sj_evt.fire("GlobalActionMenuV2Wrapper.InitSharingGlobalConfig", sharingGlobalConfig); } })();; equals www.linkedin.com (Linkedin)
Source: chromecache_735.2.dr, chromecache_286.2.dr String found in binary or memory: (function() { var sharingGlobalConfig ={"thumbnailUrlFormat":"https://www.bing.com/th?id={0}","defaultFormCode":"EX0023","facebookShareFormat":"https://www.facebook.com/dialog/feed?app_id={3}\u0026display=popup\u0026link={0}\u0026redirect_uri={1}\u0026ref={2}","facebookMessengerUrlFormat":"http://www.facebook.com/dialog/send?app_id={0}\u0026display=popup\u0026link={1}\u0026redirect_uri={2}","facebookFormCode":"EX0023","fbInitialHeight":576,"fbmInitialWidth":640,"facebookAppId":"3732605936979161","twitterApi":"https://twitter.com/intent/tweet?hashtags={0}\u0026text={1}\u0026url={2}","twitterFormCode":"EX0024","twitterInitialHeight":576,"twitterInitialWidth":720,"defaultInitialHeight":255,"whatsAppSchema":"whatsapp://send?text={0}","whatsAppStoreUrl":"","whatsAppFormCode":"EX0053","mailLauncherUrl":"mailto:?subject={0} \u0026body={1}","mailFormCode":"EX0025","smsProtocol":"","smsFormCode":"EX0052","loadingUrl":"/loading","useBlankLoadingPage":false,"closeRedirectUrl":"/share/fbre","pinterestUrlFormat":"https://pinterest.com/pin/create/button/?url={0}\u0026media={1}\u0026description={2}","pinterestFormCode":"EX0051","mybingFormCode":"shtomb","mybingRedirectUrl":"https://www.bing.com/myprofile?tid=id_chatmessagetab\u0026FORM=shtomb","skypeUrlFormat":"https://web.skype.com/share?url={0}\u0026source=button\u0026text={1}","skypeInitialHeight":665,"skypeInitialWidth":305,"outlookComLauncherUrl":"https://outlook.live.com/owa/?subject={0}\u0026body={1}\u0026path=/mail/action/compose","gmailLauncherUrl":"https://mail.google.com/mail/?view=cm\u0026fs=1\u0026tf=1\u0026su={0}\u0026body={1}","linkedInUrlFormat":"https://www.linkedin.com/shareArticle?mini=true\u0026url={0}\u0026title={1}\u0026summary={2}","linkedInFormCode":"EX0062","oneNoteUrlFormat":"https://www.onenote.com/clipper/save?attributionUrl={0}\u0026sourceUrl={1}\u0026imgUrl={1}\u0026title={2}\u0026description={3}","oneNoteInitialHeight":565,"oneNoteInitialWidth":550,"oneNoteFormCode":"EX0060","checkAppInstall":"","checkAppTimeout":200,"weiboShareFormat":"https://service.weibo.com/share/share.php?title={0}\u0026placeholder=Bing\u0026url={1}\u0026pic={2}","weiboFormCode":"SHDLWE","qzoneShareFormat":"https://sns.qzone.qq.com/cgi-bin/qzshare/cgi_qzshare_onekey?title={0}\u0026summary={1}\u0026url={2}\u0026pics={3}","qzoneFormCode":"SHDLQZ","isCNEnglishSearch":false,"redditShareFormat":"https://www.reddit.com/submit?url={0}\u0026title={1}","redditFormCode":"EX0061","useLocationReplace":false,"getUrlFormCode":"EX0050","enableGetShareLinkFromServerForGetUrl":true,"isUnderside":false}; if(sj_evt) { sj_evt.fire("GlobalActionMenuV2Wrapper.InitSharingGlobalConfig", sharingGlobalConfig); } })();; equals www.twitter.com (Twitter)
Source: global traffic DNS traffic detected: DNS query: aka.ms
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: aefd.nelreports.net
Source: global traffic DNS traffic detected: DNS query: assets.msn.com
Source: global traffic DNS traffic detected: DNS query: www.msn.com
Source: global traffic DNS traffic detected: DNS query: services.bingapis.com
Source: global traffic DNS traffic detected: DNS query: login.microsoftonline.com
Source: global traffic DNS traffic detected: DNS query: aadcdn.msftauth.net
Source: global traffic DNS traffic detected: DNS query: browser.events.data.msn.com
Source: global traffic DNS traffic detected: DNS query: tse3.mm.bing.net
Source: global traffic DNS traffic detected: DNS query: tse1.mm.bing.net
Source: global traffic DNS traffic detected: DNS query: tse2.mm.bing.net
Source: global traffic DNS traffic detected: DNS query: c.msn.com
Source: global traffic DNS traffic detected: DNS query: tse4.mm.bing.net
Source: chromecache_369.2.dr String found in binary or memory: http://adaptivecards.io/schemas/adaptive-card.json
Source: chromecache_299.2.dr, chromecache_389.2.dr String found in binary or memory: http://feross.org
Source: chromecache_706.2.dr String found in binary or memory: http://knockoutjs.com/
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: http://www.foreca.com
Source: chromecache_706.2.dr String found in binary or memory: http://www.opensource.org/licenses/mit-license.php)
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: https://assets.msn.com/weathermapdata/1/static/background/v2.0/jpg/
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: https://assets.msn.com/weathermapdata/1/static/weather/Icons/LFlOFwA=/Condition/
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: https://assets.msn.com/weathermapdata/1/static/weather/Icons/taskbar_v10/
Source: chromecache_588.2.dr String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gDrC
Source: chromecache_588.2.dr String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gDrC-dark
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gKhb
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gKhb-dark
Source: chromecache_617.2.dr String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gRmH
Source: chromecache_617.2.dr String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13gRmH-dark
Source: chromecache_588.2.dr String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13glq6
Source: chromecache_588.2.dr String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13glq6-dark
Source: chromecache_706.2.dr String found in binary or memory: https://github.com/douglascrockford/JSON-js
Source: chromecache_446.2.dr String found in binary or memory: https://highlightjs.org/
Source: chromecache_588.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA13slaS.img
Source: chromecache_588.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nFAJL.img
Source: chromecache_588.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nFneM.img
Source: chromecache_588.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nFvKb.img
Source: chromecache_588.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nI1c4.img
Source: chromecache_588.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nI3u4.img
Source: chromecache_588.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nIeqX.img
Source: chromecache_588.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nIuZ6.img
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nJ9hG.img
Source: chromecache_588.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nJkQ5.img
Source: chromecache_588.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nmhpC.img
Source: chromecache_588.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nmhpz.img
Source: chromecache_617.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nnOZD.img
Source: chromecache_617.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nnRrv.img
Source: chromecache_617.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1nnU4F.img
Source: chromecache_617.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AAADLcm.img
Source: chromecache_588.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AAwgl5h.img
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/BB1e6XdQ.img
Source: chromecache_588.2.dr String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/BB1jtbc8.img
Source: chromecache_707.2.dr, chromecache_587.2.dr String found in binary or memory: https://login.chinacloudapi.cn
Source: chromecache_707.2.dr, chromecache_587.2.dr String found in binary or memory: https://login.microsoftonline.com
Source: chromecache_707.2.dr, chromecache_587.2.dr String found in binary or memory: https://login.microsoftonline.de
Source: chromecache_707.2.dr, chromecache_587.2.dr String found in binary or memory: https://login.microsoftonline.us
Source: chromecache_707.2.dr, chromecache_587.2.dr String found in binary or memory: https://login.windows-ppe.net
Source: chromecache_369.2.dr String found in binary or memory: https://msasg.visualstudio.com/Bing_Ads/_workitems/edit/3905327
Source: chromecache_369.2.dr String found in binary or memory: https://msasg.visualstudio.com/ContentServices/_workitems/edit/3620803
Source: chromecache_617.2.dr String found in binary or memory: https://prod-streaming-video-msn-com.akamaized.net/59a18f1a-e762-490c-a8d0-e89a3d8111e9/3770951d-c67
Source: chromecache_617.2.dr String found in binary or memory: https://prod-streaming-video-msn-com.akamaized.net/c93a164f-41e5-4c79-9169-c10768462ad4/3770951d-c67
Source: chromecache_617.2.dr String found in binary or memory: https://prod-video-cms-amp-microsoft-com.akamaized.net/tenant/amp/entityid/AA1nFMp1?blobrefkey=close
Source: chromecache_617.2.dr String found in binary or memory: https://stacker.com/
Source: chromecache_588.2.dr String found in binary or memory: https://www.azcentral.com/story/news/local/scottsdale/2024/03/26/scottsdale-second-fastest-growing-m
Source: chromecache_588.2.dr String found in binary or memory: https://www.businessinsider.com/arizona-cities-us-economy-scottsdale-glendale-chicago-bankruptcy-loa
Source: chromecache_588.2.dr String found in binary or memory: https://www.businessinsider.com/city-metro-population-growth-from-2022-to-2023-florida-2024-3
Source: chromecache_588.2.dr String found in binary or memory: https://www.businessinsider.com/fat-fire-early-retirement-usa-thailand-passive-income-dad-hobbies-20
Source: chromecache_588.2.dr String found in binary or memory: https://www.businessinsider.com/fortune-100-c-suite-executives-getting-older-trend-study-2023-12
Source: chromecache_588.2.dr String found in binary or memory: https://www.businessinsider.com/heres-where-all-the-wealthy-young-people-are-moving-this-year-2023-8
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: https://www.businessinsider.com/life-of-the-walton-family-behind-walmart-and-sams-club-2018-12
Source: chromecache_588.2.dr String found in binary or memory: https://www.businessinsider.com/mortgage-rates-housing-market-luxury-home-prices-rich-people-mansion
Source: chromecache_588.2.dr String found in binary or memory: https://www.businessinsider.com/moving-to-arizona-luxury-real-estate-phoenix-scottsdale-paradise-val
Source: chromecache_588.2.dr String found in binary or memory: https://www.businessinsider.com/scottsdale-arizona-millionaires-moving-what-its-like-photos-2024-4
Source: chromecache_588.2.dr String found in binary or memory: https://www.businessinsider.com/us-cities-fastest-growing-populations-of-millionaires-report-2024-3#
Source: chromecache_588.2.dr String found in binary or memory: https://www.businessinsider.com/zillow-searches-users-obsessed-with-these-neighborhoods-2023-4
Source: chromecache_588.2.dr String found in binary or memory: https://www.cnn.com/travel/article/cell-phones-devices-on-airplanes/index.html
Source: chromecache_588.2.dr String found in binary or memory: https://www.eff.org/https-everywhere/set-https-default-your-browser
Source: chromecache_588.2.dr String found in binary or memory: https://www.faa.gov/travelers/fly_safe/information
Source: chromecache_588.2.dr String found in binary or memory: https://www.henleyglobal.com/publications/usa-wealth-report-2024
Source: chromecache_369.2.dr String found in binary or memory: https://www.lotteryusa.com/mega-millions/
Source: chromecache_369.2.dr String found in binary or memory: https://www.lotteryusa.com/powerball/
Source: chromecache_369.2.dr String found in binary or memory: https://www.msn.com/$
Source: chromecache_617.2.dr String found in binary or memory: https://www.msn.com/en-us/foodanddrink/foodnews/the-only-way-you-should-store-hot-sauce-according-to
Source: chromecache_617.2.dr String found in binary or memory: https://www.msn.com/en-us/foodanddrink/recipes/the-unexpected-sauce-you-should-fry-eggs-in-for-an-el
Source: chromecache_617.2.dr String found in binary or memory: https://www.msn.com/en-us/health/other/experts-say-these-are-the-5-worst-foods-for-your-cholesterol/
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: https://www.msn.com/en-us/money/careersandeducation/a-psychology-expert-shares-5-toxic-phrases-highl
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: https://www.msn.com/en-us/money/markets/president-biden-has-canceled-plans-to-refill-america-s-emerg
Source: chromecache_588.2.dr String found in binary or memory: https://www.msn.com/en-us/money/other/why-you-should-be-putting-aluminum-foil-behind-your-router/ar-
Source: chromecache_617.2.dr String found in binary or memory: https://www.msn.com/en-us/money/personalfinance/barber-coins-are-worth-thousands-here-s-how-to-spot-
Source: chromecache_588.2.dr String found in binary or memory: https://www.msn.com/en-us/money/personalfinance/i-m-a-bank-teller-3-times-you-should-never-ask-for-1
Source: chromecache_588.2.dr String found in binary or memory: https://www.msn.com/en-us/money/realestate/here-is-the-true-value-of-having-a-fully-paid-off-home-in
Source: chromecache_617.2.dr String found in binary or memory: https://www.msn.com/en-us/money/realestate/hippies-settled-this-unusual-california-community-now-its
Source: chromecache_617.2.dr String found in binary or memory: https://www.msn.com/en-us/news/politics/a-big-mistake-ex-trump-white-house-lawyer-reacts-to-trump-s-
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: https://www.msn.com/en-us/news/politics/judge-upholds-disqualification-of-challenger-to-judge-in-tru
Source: chromecache_588.2.dr String found in binary or memory: https://www.msn.com/en-us/news/politics/mitch-mcconnell-breaks-with-trump-on-absolute-presidential-i
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: https://www.msn.com/en-us/news/technology/tech-trick-how-to-tell-who-s-calling-when-you-don-t-recogn
Source: chromecache_588.2.dr String found in binary or memory: https://www.msn.com/en-us/news/us/nypd-chief-hits-back-at-aoc-over-columbia-anti-israel-protests-sel
Source: chromecache_588.2.dr String found in binary or memory: https://www.msn.com/en-us/news/us/what-you-need-to-know-about-the-6-constitutional-amendments-on-flo
Source: chromecache_617.2.dr String found in binary or memory: https://www.msn.com/en-us/news/world/hms-diamond-has-just-taught-our-enemies-an-important-lesson-don
Source: chromecache_617.2.dr String found in binary or memory: https://www.msn.com/en-us/news/world/russia-has-found-the-critical-vulnerability-in-nato-s-american-
Source: chromecache_588.2.dr, chromecache_617.2.dr String found in binary or memory: https://www.pollensense.com/
Source: chromecache_588.2.dr String found in binary or memory: https://www.prnewswire.com/news-releases/americans-are-pro-connectivity-even-in-one-of-the-few-place
Source: chromecache_588.2.dr String found in binary or memory: https://www.realtor.com/realestateandhomes-search/Scottsdale_AZ/overview
Source: chromecache_404.2.dr, chromecache_376.2.dr, chromecache_263.2.dr String found in binary or memory: https://www.suno.ai/legal/privacy
Source: chromecache_404.2.dr, chromecache_376.2.dr, chromecache_263.2.dr String found in binary or memory: https://www.suno.ai/legal/terms
Source: chromecache_480.2.dr, chromecache_582.2.dr String found in binary or memory: https://www.suno.ai/privacy)
Source: chromecache_480.2.dr, chromecache_582.2.dr String found in binary or memory: https://www.suno.ai/terms)
Source: chromecache_588.2.dr String found in binary or memory: https://www.theshackeltongroup.com/
Source: chromecache_588.2.dr String found in binary or memory: https://www.visible.com/
Source: chromecache_588.2.dr String found in binary or memory: https://www.washingtonpost.com/technology/2022/09/26/public-wifi-privacy/
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50017
Source: unknown Network traffic detected: HTTP traffic on port 50276 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50017 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50276
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50048
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50048 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown HTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.4:49740 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.4:49749 version: TLS 1.2
Source: classification engine Classification label: clean0.win@29/832@52/6
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1976,i,18040725601511233497,2429594081516233329,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://aka.ms/AAb9ysg__;!!JywAMcrl3w!-ETt_Rmq2qic6h9-r-A2Pg2Rw6IBmkz7xvd8Zk06m26oaz1wBBb2mB1uKoKqOCmdEVt0NuzHVqY6S4CNViUA$"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3176 --field-trial-handle=1976,i,18040725601511233497,2429594081516233329,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2948 --field-trial-handle=1976,i,18040725601511233497,2429594081516233329,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1976,i,18040725601511233497,2429594081516233329,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3176 --field-trial-handle=1976,i,18040725601511233497,2429594081516233329,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2948 --field-trial-handle=1976,i,18040725601511233497,2429594081516233329,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs