Windows Analysis Report


General Information

Sample URL:
Analysis ID: 1438602


Score: 60
Range: 0 - 100
Whitelisted: false
Confidence: 100%


Antivirus / Scanner detection for submitted sample
LLM detected suspicious URL
LLM detected suspicious webpage text
Phishing site or detected (based on various text indicators)
Drops files with a non-matching file extension (content does not match file extension)
HTML body contains low number of good links
HTML body contains password input but no form action


AV Detection

Source: SlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering
Source: chromecache_412.2.dr Binary or memory string: -----BEGIN PUBLIC KEY----- memstr_c085c674-f


Source: LLM: Score: 7 Reasons: The URL '' appears to be a legitimate Adobe subdomain, ''. However, the query parameter 'callback' in the URL contains a URL that is not an Adobe domain, ''. This could indicate a potential typosquatting attempt. It is recommended to verify the authenticity of the URL before proceeding. DOM: 8.10.pages.csv
Source: LLM: Score: 8 Reasons: The text contains a call-to-action to click a button and log in with an email account, which could potentially be a phishing attempt. The URL provided does not match the expected One Drive URL, adding to the suspicion of malicious intent. However, without further analysis of the actual URL and the behavior of the page it leads to, a definitive verdict cannot be given. DOM: 0.0.pages.csv
Source: Chrome DOM: 4.6 OCR Text: @ Edit Convert Q 6) E-sign A1 ASWnt Sign in Closing Docume... Welcome to Acrobat Sign in to do more with the file shared with you. SWI in O Office 365 YOU MAY LIKE Ask A1 Assistant Generate a summary Edit text & images A document has been sent through One Drive. Click theAccess Document button below and Log in with your email accountto Compress a PDF viewit. PDF to JPG Export a PDF z Access Document Fill & Sign c
Source: Chrome DOM: 3.3 OCR Text: O Office 365 A document has been sent through One Drive. Click theAccess Document button below and Log in with your email accountto viewit. Access Document
Source: Chrome DOM: 5.7 OCR Text: Edit Convert E-sign A1 AssWnt Sign in Closing Docume... PDF x Generative summary O Office 365 A document has been sent through One Drive. Click theAccess Document button below and Log in with your email accountto Get a document outline and summaries, automatically viewit. generated with A1. Quickly understand this document Get detailed summaries of key sections Access mcument Find and easily navigate to the information you Please double-check summaries and sources as they may not always be accurate. You shouldn't rely on summaries for professional advice. Leam more Adobe protects your dcKuments and content using c cesponsible practices. Sign in to start using A1 Assistant. gy clicking Get started, you agree to our User Guidelines. Get
Source: HTTP Parser: Number of links: 0
Source: HTTP Parser: <input type="password" .../> found but no <form action="...
Source: HTTP Parser: <input type="password" .../> found
Source: HTTP Parser: No favicon
Source: HTTP Parser: No favicon
Source: HTTP Parser: No <meta name="author".. found
Source: HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host:
Source: global traffic HTTP traffic detected: GET /content/storage/id/urn:aaid:sc:VA6C2:3714f03d-8378-499c-988f-2b11077fcd8a/:rendition;page=0;size=1200;type=image%2Fjpeg?access_token=1715242038_urn%3Aaaid%3Asc%3AVA6C2%3A3714f03d-8378-499c-988f-2b11077fcd8a%3Bpublic_d535363e2ccf8aaf980bed926867af61c96a10b4&api_key=dc_sendtrack HTTP/1.1Host: cdn-sharing.adobecc.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://acrobat.adobe.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /content/storage/id/urn:aaid:sc:VA6C2:3714f03d-8378-499c-988f-2b11077fcd8a/:rendition;page=0;size=1200;type=image%2Fjpeg?access_token=1715242038_urn%3Aaaid%3Asc%3AVA6C2%3A3714f03d-8378-499c-988f-2b11077fcd8a%3Bpublic_d535363e2ccf8aaf980bed926867af61c96a10b4&api_key=dc_sendtrack HTTP/1.1Host: cdn-sharing.adobecc.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://acrobat.adobe.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9If-None-Match: "NTIxNTM2YTUtMWNkMS00MjJmLWIzNDItYTZkYmNjN2Y3Yjg2L2pwZy8xMjAwLzAvdHJ1ZQ=="
Source: global traffic HTTP traffic detected: GET /content/storage/id/urn:aaid:sc:VA6C2:3714f03d-8378-499c-988f-2b11077fcd8a/:rendition;page=0;size=1200;type=image%2Fjpeg?access_token=1715242038_urn%3Aaaid%3Asc%3AVA6C2%3A3714f03d-8378-499c-988f-2b11077fcd8a%3Bpublic_d535363e2ccf8aaf980bed926867af61c96a10b4&api_key=dc_sendtrack HTTP/1.1Host: cdn-sharing.adobecc.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /content/storage/id/urn:aaid:sc:VA6C2:3714f03d-8378-499c-988f-2b11077fcd8a/:rendition;page=0;size=1200;type=image%2Fjpeg?access_token=1715242038_urn%3Aaaid%3Asc%3AVA6C2%3A3714f03d-8378-499c-988f-2b11077fcd8a%3Bpublic_d535363e2ccf8aaf980bed926867af61c96a10b4&api_key=dc_sendtrack HTTP/1.1Host: cdn-sharing.adobecc.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9If-None-Match: "NTIxNTM2YTUtMWNkMS00MjJmLWIzNDItYTZkYmNjN2Y3Yjg2L2pwZy8xMjAwLzAvdHJ1ZQ=="
Source: global traffic HTTP traffic detected: GET /content/storage/id/urn:aaid:sc:VA6C2:3714f03d-8378-499c-988f-2b11077fcd8a/:rendition;page=0;size=1200;type=image%2Fjpeg?access_token=1715242038_urn%3Aaaid%3Asc%3AVA6C2%3A3714f03d-8378-499c-988f-2b11077fcd8a%3Bpublic_d535363e2ccf8aaf980bed926867af61c96a10b4&api_key=dc_sendtrack HTTP/1.1Host: cdn-sharing.adobecc.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9If-None-Match: "NTIxNTM2YTUtMWNkMS00MjJmLWIzNDItYTZkYmNjN2Y3Yjg2L2pwZy8xMjAwLzAvdHJ1ZQ=="
Source: global traffic HTTP traffic detected: GET /utilnav/9.2/utilitynav.css HTTP/1.1Host: prod.adobeccstatic.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /utilnav/9.2/utilitynav.js HTTP/1.1Host: prod.adobeccstatic.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /6gNXXegDB6rtHARrNKRF8w.js HTTP/1.1Host: widget.uservoice.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /t2/496015/web/track.js?_=1715198878489&s=0&c=__uvSessionData0&d=eyJlIjp7InUiOiJodHRwczovL2Fjcm9iYXQuYWRvYmUuY29tL2lkL3VybjphYWlkOnNjOlZBNkMyOjM3MTRmMDNkLTgzNzgtNDk5Yy05ODhmLTJiMTEwNzdmY2Q4YT92aWV3ZXIlMjFtZWdhVmVyYj1ncm91cC1kaXNjb3ZlciIsInIiOiIifX0%3D HTTP/1.1Host: by2.uservoice.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=PE0gKkNkJUc8m3HgRubbbiQWjBSoo6sdrvaftg_EGU8-1715198860-
Source: global traffic HTTP traffic detected: GET /?q=dSMHmEUM9QSIKQm9iy0W HTTP/1.1Host: use1.fptls.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://commerce.adobe.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /?q=dSMHmEUM9QSIKQm9iy0W HTTP/1.1Host: use1.fptls.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /id?d_visid_ver=5.4.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_verify=1&d_orgid=9E1005A551ED61CA0A490D45%40AdobeOrg&d_nsid=0&ts=1715198905997 HTTP/1.1Host: dpm.demdex.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Content-Type: application/x-www-form-urlencodedAccept: */*Origin: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer:
Source: global traffic HTTP traffic detected: GET /id/rd?d_visid_ver=5.4.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_verify=1&d_orgid=9E1005A551ED61CA0A490D45%40AdobeOrg&d_nsid=0&ts=1715198905997 HTTP/1.1Host: dpm.demdex.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Content-Type: application/x-www-form-urlencodedAccept: */*Origin: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer:
Source: global traffic HTTP traffic detected: GET /id?d_visid_ver=5.4.0&d_fieldgroup=A&mcorgid=9E1005A551ED61CA0A490D45%40AdobeOrg&mid=71473923911726687243962295091633716325&ts=1715198907572 HTTP/1.1Host: sstats.adobe.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Content-Type: application/x-www-form-urlencodedAccept: */*Origin: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer:
Source: global traffic HTTP traffic detected: GET /id/rd?d_visid_ver=5.4.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_verify=1&d_orgid=9E1005A551ED61CA0A490D45%40AdobeOrg&d_nsid=0&ts=1715198905997 HTTP/1.1Host: dpm.demdex.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: demdex=71675608569673998663941792589102811371
Source: global traffic HTTP traffic detected: GET /id?d_visid_ver=5.4.0&d_fieldgroup=A&mcorgid=9E1005A551ED61CA0A490D45%40AdobeOrg&mid=71473923911726687243962295091633716325&ts=1715198907572 HTTP/1.1Host: sstats.adobe.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: AKA_A2=A; platformMetaData=%7B%22isAndroidAppInstalled%22%3Afalse%7D; fg=YNYXRWTTFPP5EDEKFAQVYHAADQ======; gpv=Account:IMS:GetStarted:OnLoad; AMCVS_9E1005A551ED61CA0A490D45%40AdobeOrg=1; s_ecid=MCMID%7C71473923911726687243962295091633716325; s_cc=true; AMCV_9E1005A551ED61CA0A490D45%40AdobeOrg=1176715910%7CMCMID%7C71473923911726687243962295091633716325%7CMCAAMLH-1715803707%7C9%7CMCAAMB-1715803707%7CRKhpRz8krg2tLO6pguXWp5olkAcUniQYPHaMWWgdJ3xzPWQmdj0y%7CMCOPTOUT-1715206108s%7CNONE%7CMCAID%7CNONE%7CvVersion%7C5.4.0
Source: global traffic HTTP traffic detected: GET /b/ss/adbims,adbadobenonacdcprod,adbdcwebprod,adbadobeprototype/1/JS-2.22.4-LCS4/s47632546992862 HTTP/1.1Host: sstats.adobe.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: AKA_A2=A; platformMetaData=%7B%22isAndroidAppInstalled%22%3Afalse%7D; fg=YNYXRWTTFPP5EDEKFAQVYHAADQ======; gpv=Account:IMS:GetStarted:OnLoad; AMCVS_9E1005A551ED61CA0A490D45%40AdobeOrg=1; s_ecid=MCMID%7C71473923911726687243962295091633716325; s_cc=true; AMCV_9E1005A551ED61CA0A490D45%40AdobeOrg=1176715910%7CMCMID%7C71473923911726687243962295091633716325%7CMCAAMLH-1715803707%7C9%7CMCAAMB-1715803707%7CRKhpRz8krg2tLO6pguXWp5olkAcUniQYPHaMWWgdJ3xzPWQmdj0y%7CMCOPTOUT-1715206108s%7CNONE%7CMCAID%7CNONE%7CvVersion%7C5.4.0
Source: global traffic HTTP traffic detected: GET /b/ss/adbims,adbadobenonacdcprod,adbdcwebprod,adbadobeprototype/1/JS-2.22.4-LCS4/s41908733897725 HTTP/1.1Host: sstats.adobe.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: AKA_A2=A; platformMetaData=%7B%22isAndroidAppInstalled%22%3Afalse%7D; fg=YNYXRWTTFPP5EDEKFAQVYHAADQ======; gpv=Account:IMS:GetStarted:OnLoad; AMCVS_9E1005A551ED61CA0A490D45%40AdobeOrg=1; s_ecid=MCMID%7C71473923911726687243962295091633716325; s_cc=true; AMCV_9E1005A551ED61CA0A490D45%40AdobeOrg=1176715910%7CMCMID%7C71473923911726687243962295091633716325%7CMCAAMLH-1715803707%7C9%7CMCAAMB-1715803707%7CRKhpRz8krg2tLO6pguXWp5olkAcUniQYPHaMWWgdJ3xzPWQmdj0y%7CMCOPTOUT-1715206108s%7CNONE%7CMCAID%7CNONE%7CvVersion%7C5.4.0
Source: global traffic HTTP traffic detected: GET /b/ss/adbims,adbadobenonacdcprod,adbdcwebprod,adbadobeprototype/1/JS-2.22.4-LCS4/s47632546992862?AQB=1&pccr=true&vidn=331DEDDF2A6CF012-60000C2342DFDFC1&g=none&AQE=1 HTTP/1.1Host: sstats.adobe.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: AKA_A2=A; platformMetaData=%7B%22isAndroidAppInstalled%22%3Afalse%7D; fg=YNYXRWTTFPP5EDEKFAQVYHAADQ======; gpv=Account:IMS:GetStarted:OnLoad; AMCVS_9E1005A551ED61CA0A490D45%40AdobeOrg=1; s_ecid=MCMID%7C71473923911726687243962295091633716325; s_cc=true; AMCV_9E1005A551ED61CA0A490D45%40AdobeOrg=1176715910%7CMCMID%7C71473923911726687243962295091633716325%7CMCAAMLH-1715803707%7C9%7CMCAAMB-1715803707%7CRKhpRz8krg2tLO6pguXWp5olkAcUniQYPHaMWWgdJ3xzPWQmdj0y%7CMCOPTOUT-1715206108s%7CNONE%7CMCAID%7CNONE%7CvVersion%7C5.4.0; s_vi=[CS]v1|331DEDDF2A6CF012-60000C2342DFDFC1[CE]
Source: global traffic HTTP traffic detected: GET /b/ss/adbims,adbadobenonacdcprod,adbdcwebprod,adbadobeprototype/1/JS-2.22.4-LCS4/s41908733897725?AQB=1&pccr=true&vidn=331DEDDF64FB486A-6000045DAACA9C6E&g=none&AQE=1 HTTP/1.1Host: sstats.adobe.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: AKA_A2=A; platformMetaData=%7B%22isAndroidAppInstalled%22%3Afalse%7D; fg=YNYXRWTTFPP5EDEKFAQVYHAADQ======; gpv=Account:IMS:GetStarted:OnLoad; AMCVS_9E1005A551ED61CA0A490D45%40AdobeOrg=1; s_ecid=MCMID%7C71473923911726687243962295091633716325; s_cc=true; AMCV_9E1005A551ED61CA0A490D45%40AdobeOrg=1176715910%7CMCMID%7C71473923911726687243962295091633716325%7CMCAAMLH-1715803707%7C9%7CMCAAMB-1715803707%7CRKhpRz8krg2tLO6pguXWp5olkAcUniQYPHaMWWgdJ3xzPWQmdj0y%7CMCOPTOUT-1715206108s%7CNONE%7CMCAID%7CNONE%7CvVersion%7C5.4.0; s_vi=[CS]v1|331DEDDF64FB486A-6000045DAACA9C6E[CE]
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: unknown HTTP traffic detected: POST /b/ss/adbims,adbadobenonacdcprod,adbdcwebprod,adbadobeprototype/1/JS-2.22.4-LCS4/s47632546992862 HTTP/1.1Host: sstats.adobe.comConnection: keep-aliveContent-Length: 11142sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/ Safari/537.36Content-Type: text/plain;charset=UTF-8Accept: */*Origin: same-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer:
Source: chromecache_454.2.dr String found in binary or memory:
Source: chromecache_579.2.dr String found in binary or memory:
Source: chromecache_412.2.dr, chromecache_455.2.dr String found in binary or memory:
Source: chromecache_412.2.dr, chromecache_455.2.dr String found in binary or memory:
Source: chromecache_508.2.dr String found in binary or memory:
Source: chromecache_625.2.dr, chromecache_634.2.dr String found in binary or memory:
Source: chromecache_625.2.dr, chromecache_634.2.dr String found in binary or memory:
Source: chromecache_625.2.dr String found in binary or memory:
Source: chromecache_625.2.dr, chromecache_634.2.dr String found in binary or memory:
Source: chromecache_625.2.dr String found in binary or memory:
Source: chromecache_625.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_375.2.dr, chromecache_575.2.dr, chromecache_508.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_590.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_590.2.dr String found in binary or memory:
Source: chromecache_650.2.dr String found in binary or memory:
Source: chromecache_539.2.dr String found in binary or memory:
Source: chromecache_470.2.dr String found in binary or memory:
Source: chromecache_625.2.dr, chromecache_634.2.dr String found in binary or memory:
Source: chromecache_417.2.dr, chromecache_394.2.dr String found in binary or memory:
Source: chromecache_360.2.dr, chromecache_501.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_625.2.dr, chromecache_634.2.dr String found in binary or memory:
Source: chromecache_625.2.dr String found in binary or memory:
Source: chromecache_625.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_625.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_609.2.dr String found in binary or memory:
Source: chromecache_625.2.dr, chromecache_634.2.dr String found in binary or memory:
Source: chromecache_625.2.dr, chromecache_634.2.dr String found in binary or memory:
Source: chromecache_601.2.dr, chromecache_652.2.dr String found in binary or memory:
Source: unknown Network traffic detected: HTTP traffic on port 49817 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50138
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50218
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 49672 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49813 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50219
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49782
Source: unknown Network traffic detected: HTTP traffic on port 50225 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50178
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50136
Source: unknown Network traffic detected: HTTP traffic on port 50206 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49799 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49817
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49816
Source: unknown Network traffic detected: HTTP traffic on port 50125 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50219 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49813
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49778
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49899
Source: unknown Network traffic detected: HTTP traffic on port 49816 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50226
Source: unknown Network traffic detected: HTTP traffic on port 50123 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50185
Source: unknown Network traffic detected: HTTP traffic on port 50226 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50225
Source: unknown Network traffic detected: HTTP traffic on port 49763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50205 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50191
Source: unknown Network traffic detected: HTTP traffic on port 50004 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50195
Source: unknown Network traffic detected: HTTP traffic on port 50138 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49805
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49804
Source: unknown Network traffic detected: HTTP traffic on port 50084 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49756 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 50195 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50124 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50191 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50111
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50231
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50083
Source: unknown Network traffic detected: HTTP traffic on port 49805 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50084
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49778 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50083 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49756
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49799
Source: unknown Network traffic detected: HTTP traffic on port 49782 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50205
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50206
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49672
Source: unknown Network traffic detected: HTTP traffic on port 50093 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50124
Source: unknown Network traffic detected: HTTP traffic on port 49899 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50111 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50123
Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50004
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50125
Source: unknown Network traffic detected: HTTP traffic on port 49804 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50136 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50178 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50185 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50093
Source: unknown Network traffic detected: HTTP traffic on port 50218 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50231 -> 443
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: classification engine Classification label:
Source: chromecache_652.2.dr Initial sample:
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2196 --field-trial-handle=1976,i,11233652730624539999,3457103367940332808,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" ""
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5532 --field-trial-handle=1976,i,11233652730624539999,3457103367940332808,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5504 --field-trial-handle=1976,i,11233652730624539999,3457103367940332808,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2196 --field-trial-handle=1976,i,11233652730624539999,3457103367940332808,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5532 --field-trial-handle=1976,i,11233652730624539999,3457103367940332808,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5504 --field-trial-handle=1976,i,11233652730624539999,3457103367940332808,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5532 --field-trial-handle=1976,i,11233652730624539999,3457103367940332808,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 601 Jump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 652
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: Chrome Cache Entry: 652 Jump to dropped file
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs