Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://msn.com

Overview

General Information

Sample URL:http://msn.com
Analysis ID:1458477

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

HTML body contains low number of good links
HTML title does not match URL
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6160 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://msn.com/ MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 6332 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1952,i,8741709652274188138,9882551441691566282,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2536 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4188 --field-trial-handle=1952,i,8741709652274188138,9882551441691566282,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=d7b530a4-7680-4c23-a8bf-c52c121d2e87&scope=User.Read%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fwww.msn.com%2Fstaticsb%2Fstatics%2Flatest%2Fauth%2Fauth-redirect-blank.html&client-request-id=4362c772-8af9-495c-a64f-3fa3e8ba5c49&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=2.18.0&x-client-OS=&x-client-CPU=&client_info=1&code_challenge=MsPL_NyeFGkcHRF84viDBMtgFCgBjac05sxOU-5fIVw&code_challenge_method=S256&prompt=none&nonce=26820882-70a0-4e61-9463-0baa3817ce36&state=eyJpZCI6Ijk3Y2ZmOWM4LTIzYTgtNGU4MC1iNmU1LWM1OTUzMjI0Y2NlMSIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoic2lsZW50In19HTTP Parser: Number of links: 0
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=d7b530a4-7680-4c23-a8bf-c52c121d2e87&scope=User.Read%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fwww.msn.com%2Fstaticsb%2Fstatics%2Flatest%2Fauth%2Fauth-redirect-blank.html&client-request-id=4362c772-8af9-495c-a64f-3fa3e8ba5c49&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=2.18.0&x-client-OS=&x-client-CPU=&client_info=1&code_challenge=MsPL_NyeFGkcHRF84viDBMtgFCgBjac05sxOU-5fIVw&code_challenge_method=S256&prompt=none&nonce=26820882-70a0-4e61-9463-0baa3817ce36&state=eyJpZCI6Ijk3Y2ZmOWM4LTIzYTgtNGU4MC1iNmU1LWM1OTUzMjI0Y2NlMSIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoic2lsZW50In19HTTP Parser: Title: Redirecting does not match URL
Source: https://www.msn.com/HTTP Parser: No favicon
Source: https://www.msn.com/HTTP Parser: No favicon
Source: https://www.msn.com/HTTP Parser: No favicon
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=d7b530a4-7680-4c23-a8bf-c52c121d2e87&scope=User.Read%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fwww.msn.com%2Fstaticsb%2Fstatics%2Flatest%2Fauth%2Fauth-redirect-blank.html&client-request-id=4362c772-8af9-495c-a64f-3fa3e8ba5c49&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=2.18.0&x-client-OS=&x-client-CPU=&client_info=1&code_challenge=MsPL_NyeFGkcHRF84viDBMtgFCgBjac05sxOU-5fIVw&code_challenge_method=S256&prompt=none&nonce=26820882-70a0-4e61-9463-0baa3817ce36&state=eyJpZCI6Ijk3Y2ZmOWM4LTIzYTgtNGU4MC1iNmU1LWM1OTUzMjI0Y2NlMSIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoic2lsZW50In19HTTP Parser: No favicon
Source: https://www.msn.com/HTTP Parser: No favicon
Source: https://www.msn.com/HTTP Parser: No favicon
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=d7b530a4-7680-4c23-a8bf-c52c121d2e87&scope=User.Read%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fwww.msn.com%2Fstaticsb%2Fstatics%2Flatest%2Fauth%2Fauth-redirect-blank.html&client-request-id=4362c772-8af9-495c-a64f-3fa3e8ba5c49&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=2.18.0&x-client-OS=&x-client-CPU=&client_info=1&code_challenge=MsPL_NyeFGkcHRF84viDBMtgFCgBjac05sxOU-5fIVw&code_challenge_method=S256&prompt=none&nonce=26820882-70a0-4e61-9463-0baa3817ce36&state=eyJpZCI6Ijk3Y2ZmOWM4LTIzYTgtNGU4MC1iNmU1LWM1OTUzMjI0Y2NlMSIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoic2lsZW50In19HTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=d7b530a4-7680-4c23-a8bf-c52c121d2e87&scope=User.Read%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fwww.msn.com%2Fstaticsb%2Fstatics%2Flatest%2Fauth%2Fauth-redirect-blank.html&client-request-id=4362c772-8af9-495c-a64f-3fa3e8ba5c49&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=2.18.0&x-client-OS=&x-client-CPU=&client_info=1&code_challenge=MsPL_NyeFGkcHRF84viDBMtgFCgBjac05sxOU-5fIVw&code_challenge_method=S256&prompt=none&nonce=26820882-70a0-4e61-9463-0baa3817ce36&state=eyJpZCI6Ijk3Y2ZmOWM4LTIzYTgtNGU4MC1iNmU1LWM1OTUzMjI0Y2NlMSIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoic2lsZW50In19HTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: 23.43.61.160:443 -> 192.168.2.16:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.43.61.160:443 -> 192.168.2.16:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49754 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:50262 version: TLS 1.2
Source: chrome.exeMemory has grown: Private usage: 1MB later: 26MB
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 23.43.61.160
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 40.68.123.157
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: msn.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: msn.com
Source: global trafficDNS traffic detected: DNS query: www.msn.com
Source: global trafficDNS traffic detected: DNS query: assets.msn.com
Source: global trafficDNS traffic detected: DNS query: sb.scorecardresearch.com
Source: global trafficDNS traffic detected: DNS query: c.msn.com
Source: global trafficDNS traffic detected: DNS query: api.msn.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: browser.events.data.msn.com
Source: global trafficDNS traffic detected: DNS query: cdn.taboola.com
Source: global trafficDNS traffic detected: DNS query: px.ads.linkedin.com
Source: global trafficDNS traffic detected: DNS query: sync.outbrain.com
Source: global trafficDNS traffic detected: DNS query: pr-bh.ybp.yahoo.com
Source: global trafficDNS traffic detected: DNS query: hbx.media.net
Source: global trafficDNS traffic detected: DNS query: cm.mgid.com
Source: global trafficDNS traffic detected: DNS query: api.taboola.com
Source: global trafficDNS traffic detected: DNS query: eb2.3lift.com
Source: global trafficDNS traffic detected: DNS query: code.yengo.com
Source: global trafficDNS traffic detected: DNS query: visitor.omnitagjs.com
Source: global trafficDNS traffic detected: DNS query: trace.mediago.io
Source: global trafficDNS traffic detected: DNS query: m.adnxs.com
Source: global trafficDNS traffic detected: DNS query: trace.popin.cc
Source: global trafficDNS traffic detected: DNS query: ib.adnxs.com
Source: global trafficDNS traffic detected: DNS query: sync.inmobi.com
Source: global trafficDNS traffic detected: DNS query: sync.im-apps.net
Source: global trafficDNS traffic detected: DNS query: tsdtocl.com
Source: global trafficDNS traffic detected: DNS query: srtb.msn.com
Source: global trafficDNS traffic detected: DNS query: login.microsoftonline.com
Source: global trafficDNS traffic detected: DNS query: deff.nelreports.net
Source: global trafficDNS traffic detected: DNS query: aadcdn.msftauth.net
Source: global trafficDNS traffic detected: DNS query: btloader.com
Source: global trafficDNS traffic detected: DNS query: acdn.adnxs.com
Source: global trafficDNS traffic detected: DNS query: confiant.msn.com
Source: global trafficDNS traffic detected: DNS query: api.btloader.com
Source: global trafficDNS traffic detected: DNS query: mem.gfx.ms
Source: global trafficDNS traffic detected: DNS query: ad-delivery.net
Source: global trafficDNS traffic detected: DNS query: ad.doubleclick.net
Source: global trafficDNS traffic detected: DNS query: js.monitor.azure.com
Source: unknownNetwork traffic detected: HTTP traffic on port 50311 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 50042 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50176
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50179
Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50059 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50178
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50059
Source: unknownNetwork traffic detected: HTTP traffic on port 49961 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50184
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50183
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50064
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50185
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50460
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50205 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50183 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50191
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50190
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50192
Source: unknownNetwork traffic detected: HTTP traffic on port 50162 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50359
Source: unknownNetwork traffic detected: HTTP traffic on port 50252 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50359 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49961
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50196
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50303 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50129
Source: unknownNetwork traffic detected: HTTP traffic on port 50192 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50178 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50252
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50049 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50129 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50184 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50169 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50303
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49896
Source: unknownNetwork traffic detected: HTTP traffic on port 50064 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 50173 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 50190 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50262
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50265
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49911 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50176 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 50191 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50262 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50311
Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50265 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50179 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50162
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49911
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50205
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49875
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50196 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50042
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50049
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50169
Source: unknownNetwork traffic detected: HTTP traffic on port 50185 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50460 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50173
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 23.43.61.160:443 -> 192.168.2.16:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.43.61.160:443 -> 192.168.2.16:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:49754 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.68.123.157:443 -> 192.168.2.16:50262 version: TLS 1.2
Source: classification engineClassification label: clean1.win@19/6@132/758
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://msn.com/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1952,i,8741709652274188138,9882551441691566282,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1952,i,8741709652274188138,9882551441691566282,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4188 --field-trial-handle=1952,i,8741709652274188138,9882551441691566282,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4188 --field-trial-handle=1952,i,8741709652274188138,9882551441691566282,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
Extra Window Memory Injection
1
Extra Window Memory Injection
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://msn.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://msn.com/0%Avira URL Cloudsafe
about:blank0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
s-part-0044.t-0009.fb-t-msedge.net
13.107.253.72
truefalse
    unknown
    tls13.taboola.map.fastly.net
    151.101.129.44
    truefalse
      unknown
      cm.mgid.com
      104.19.129.76
      truefalse
        unknown
        api.btloader.com
        130.211.23.194
        truefalse
          unknown
          hbx.media.net
          23.212.88.20
          truefalse
            unknown
            eu-eb2.3lift.com
            76.223.111.18
            truefalse
              unknown
              tsdtocl.com
              151.101.1.44
              truefalse
                unknown
                ds-pr-bh.ybp.gysm.yahoodns.net
                54.246.18.125
                truefalse
                  unknown
                  sync.im-apps.net
                  2.19.97.35
                  truefalse
                    unknown
                    sni1gl.wpc.omegacdn.net
                    152.199.21.175
                    truefalse
                      unknown
                      www.google.com
                      142.250.186.164
                      truefalse
                        unknown
                        chidc2.outbrain.org
                        50.31.142.159
                        truefalse
                          unknown
                          nydc1.outbrain.org
                          64.202.112.63
                          truefalse
                            unknown
                            ad.doubleclick.net
                            172.217.16.198
                            truefalse
                              unknown
                              s-part-0017.t-0009.t-msedge.net
                              13.107.246.45
                              truefalse
                                unknown
                                s-part-0017.t-0009.fb-t-msedge.net
                                13.107.253.45
                                truefalse
                                  unknown
                                  lb-sin.mgid.com
                                  172.241.51.69
                                  truefalse
                                    unknown
                                    trace.popin.cc
                                    35.213.89.133
                                    truefalse
                                      unknown
                                      trace.mediago.io
                                      35.208.249.213
                                      truefalse
                                        unknown
                                        ad-delivery.net
                                        104.26.3.70
                                        truefalse
                                          unknown
                                          msn.com
                                          204.79.197.219
                                          truefalse
                                            unknown
                                            sb.scorecardresearch.com
                                            18.239.83.98
                                            truefalse
                                              unknown
                                              prod.appnexus.map.fastly.net
                                              151.101.65.108
                                              truefalse
                                                unknown
                                                btloader.com
                                                104.22.74.216
                                                truefalse
                                                  unknown
                                                  m.anycast.adnxs.com
                                                  185.89.210.20
                                                  truefalse
                                                    unknown
                                                    visitor-fra02.omnitagjs.com
                                                    185.255.84.152
                                                    truefalse
                                                      unknown
                                                      ib.anycast.adnxs.com
                                                      37.252.173.215
                                                      truefalse
                                                        unknown
                                                        js.monitor.azure.com
                                                        unknown
                                                        unknownfalse
                                                          unknown
                                                          api.taboola.com
                                                          unknown
                                                          unknownfalse
                                                            unknown
                                                            sync.inmobi.com
                                                            unknown
                                                            unknownfalse
                                                              unknown
                                                              c.msn.com
                                                              unknown
                                                              unknownfalse
                                                                unknown
                                                                srtb.msn.com
                                                                unknown
                                                                unknownfalse
                                                                  unknown
                                                                  deff.nelreports.net
                                                                  unknown
                                                                  unknownfalse
                                                                    unknown
                                                                    sync.outbrain.com
                                                                    unknown
                                                                    unknownfalse
                                                                      unknown
                                                                      browser.events.data.msn.com
                                                                      unknown
                                                                      unknownfalse
                                                                        unknown
                                                                        visitor.omnitagjs.com
                                                                        unknown
                                                                        unknownfalse
                                                                          unknown
                                                                          pr-bh.ybp.yahoo.com
                                                                          unknown
                                                                          unknownfalse
                                                                            unknown
                                                                            assets.msn.com
                                                                            unknown
                                                                            unknownfalse
                                                                              unknown
                                                                              code.yengo.com
                                                                              unknown
                                                                              unknownfalse
                                                                                unknown
                                                                                www.msn.com
                                                                                unknown
                                                                                unknownfalse
                                                                                  unknown
                                                                                  acdn.adnxs.com
                                                                                  unknown
                                                                                  unknownfalse
                                                                                    unknown
                                                                                    aadcdn.msftauth.net
                                                                                    unknown
                                                                                    unknownfalse
                                                                                      unknown
                                                                                      px.ads.linkedin.com
                                                                                      unknown
                                                                                      unknownfalse
                                                                                        unknown
                                                                                        m.adnxs.com
                                                                                        unknown
                                                                                        unknownfalse
                                                                                          unknown
                                                                                          confiant.msn.com
                                                                                          unknown
                                                                                          unknownfalse
                                                                                            unknown
                                                                                            mem.gfx.ms
                                                                                            unknown
                                                                                            unknownfalse
                                                                                              unknown
                                                                                              cdn.taboola.com
                                                                                              unknown
                                                                                              unknownfalse
                                                                                                unknown
                                                                                                ib.adnxs.com
                                                                                                unknown
                                                                                                unknownfalse
                                                                                                  unknown
                                                                                                  login.microsoftonline.com
                                                                                                  unknown
                                                                                                  unknownfalse
                                                                                                    unknown
                                                                                                    api.msn.com
                                                                                                    unknown
                                                                                                    unknownfalse
                                                                                                      unknown
                                                                                                      eb2.3lift.com
                                                                                                      unknown
                                                                                                      unknownfalse
                                                                                                        unknown
                                                                                                        NameMaliciousAntivirus DetectionReputation
                                                                                                        https://www.msn.com/false
                                                                                                          unknown
                                                                                                          http://msn.com/false
                                                                                                          • Avira URL Cloud: safe
                                                                                                          unknown
                                                                                                          about:blankfalse
                                                                                                          • Avira URL Cloud: safe
                                                                                                          unknown
                                                                                                          https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=d7b530a4-7680-4c23-a8bf-c52c121d2e87&scope=User.Read%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fwww.msn.com%2Fstaticsb%2Fstatics%2Flatest%2Fauth%2Fauth-redirect-blank.html&client-request-id=4362c772-8af9-495c-a64f-3fa3e8ba5c49&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=2.18.0&x-client-OS=&x-client-CPU=&client_info=1&code_challenge=MsPL_NyeFGkcHRF84viDBMtgFCgBjac05sxOU-5fIVw&code_challenge_method=S256&prompt=none&nonce=26820882-70a0-4e61-9463-0baa3817ce36&state=eyJpZCI6Ijk3Y2ZmOWM4LTIzYTgtNGU4MC1iNmU1LWM1OTUzMjI0Y2NlMSIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoic2lsZW50In19false
                                                                                                            unknown
                                                                                                            https://tsdtocl.com/false
                                                                                                              unknown
                                                                                                              • No. of IPs < 25%
                                                                                                              • 25% < No. of IPs < 50%
                                                                                                              • 50% < No. of IPs < 75%
                                                                                                              • 75% < No. of IPs
                                                                                                              IPDomainCountryFlagASNASN NameMalicious
                                                                                                              2.18.64.224
                                                                                                              unknownEuropean Union
                                                                                                              6057AdministracionNacionaldeTelecomunicacionesUYfalse
                                                                                                              37.252.171.149
                                                                                                              unknownEuropean Union
                                                                                                              29990ASN-APPNEXUSfalse
                                                                                                              13.107.246.45
                                                                                                              s-part-0017.t-0009.t-msedge.netUnited States
                                                                                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              54.229.168.32
                                                                                                              unknownUnited States
                                                                                                              16509AMAZON-02USfalse
                                                                                                              20.190.159.64
                                                                                                              unknownUnited States
                                                                                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              130.211.23.194
                                                                                                              api.btloader.comUnited States
                                                                                                              15169GOOGLEUSfalse
                                                                                                              2.19.97.35
                                                                                                              sync.im-apps.netEuropean Union
                                                                                                              20940AKAMAI-ASN1EUfalse
                                                                                                              20.199.58.43
                                                                                                              unknownUnited States
                                                                                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              2.23.209.181
                                                                                                              unknownEuropean Union
                                                                                                              1273CWVodafoneGroupPLCEUfalse
                                                                                                              68.219.88.97
                                                                                                              unknownUnited States
                                                                                                              6389BELLSOUTH-NET-BLKUSfalse
                                                                                                              185.89.210.20
                                                                                                              m.anycast.adnxs.comGermany
                                                                                                              29990ASN-APPNEXUSfalse
                                                                                                              20.50.80.209
                                                                                                              unknownUnited States
                                                                                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              2.23.209.185
                                                                                                              unknownEuropean Union
                                                                                                              1273CWVodafoneGroupPLCEUfalse
                                                                                                              2.23.209.140
                                                                                                              unknownEuropean Union
                                                                                                              1273CWVodafoneGroupPLCEUfalse
                                                                                                              172.217.16.142
                                                                                                              unknownUnited States
                                                                                                              15169GOOGLEUSfalse
                                                                                                              204.79.197.237
                                                                                                              unknownUnited States
                                                                                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              23.212.88.19
                                                                                                              unknownUnited States
                                                                                                              16625AKAMAI-ASUSfalse
                                                                                                              2.23.209.187
                                                                                                              unknownEuropean Union
                                                                                                              1273CWVodafoneGroupPLCEUfalse
                                                                                                              151.101.193.44
                                                                                                              unknownUnited States
                                                                                                              54113FASTLYUSfalse
                                                                                                              142.250.186.35
                                                                                                              unknownUnited States
                                                                                                              15169GOOGLEUSfalse
                                                                                                              142.250.186.78
                                                                                                              unknownUnited States
                                                                                                              15169GOOGLEUSfalse
                                                                                                              1.1.1.1
                                                                                                              unknownAustralia
                                                                                                              13335CLOUDFLARENETUSfalse
                                                                                                              20.74.47.205
                                                                                                              unknownUnited States
                                                                                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              2.23.209.45
                                                                                                              unknownEuropean Union
                                                                                                              1273CWVodafoneGroupPLCEUfalse
                                                                                                              13.107.21.237
                                                                                                              unknownUnited States
                                                                                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              54.246.18.125
                                                                                                              ds-pr-bh.ybp.gysm.yahoodns.netUnited States
                                                                                                              16509AMAZON-02USfalse
                                                                                                              74.125.133.84
                                                                                                              unknownUnited States
                                                                                                              15169GOOGLEUSfalse
                                                                                                              35.213.89.133
                                                                                                              trace.popin.ccUnited States
                                                                                                              19527GOOGLE-2USfalse
                                                                                                              151.101.1.44
                                                                                                              tsdtocl.comUnited States
                                                                                                              54113FASTLYUSfalse
                                                                                                              13.107.42.14
                                                                                                              unknownUnited States
                                                                                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              239.255.255.250
                                                                                                              unknownReserved
                                                                                                              unknownunknownfalse
                                                                                                              20.190.160.22
                                                                                                              unknownUnited States
                                                                                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              23.212.88.20
                                                                                                              hbx.media.netUnited States
                                                                                                              16625AKAMAI-ASUSfalse
                                                                                                              152.199.21.175
                                                                                                              sni1gl.wpc.omegacdn.netUnited States
                                                                                                              15133EDGECASTUSfalse
                                                                                                              2.18.64.219
                                                                                                              unknownEuropean Union
                                                                                                              6057AdministracionNacionaldeTelecomunicacionesUYfalse
                                                                                                              2.18.64.218
                                                                                                              unknownEuropean Union
                                                                                                              6057AdministracionNacionaldeTelecomunicacionesUYfalse
                                                                                                              172.217.16.198
                                                                                                              ad.doubleclick.netUnited States
                                                                                                              15169GOOGLEUSfalse
                                                                                                              104.19.129.76
                                                                                                              cm.mgid.comUnited States
                                                                                                              13335CLOUDFLARENETUSfalse
                                                                                                              2.18.64.214
                                                                                                              unknownEuropean Union
                                                                                                              6057AdministracionNacionaldeTelecomunicacionesUYfalse
                                                                                                              104.26.3.70
                                                                                                              ad-delivery.netUnited States
                                                                                                              13335CLOUDFLARENETUSfalse
                                                                                                              2.23.209.12
                                                                                                              unknownEuropean Union
                                                                                                              1273CWVodafoneGroupPLCEUfalse
                                                                                                              185.255.84.152
                                                                                                              visitor-fra02.omnitagjs.comFrance
                                                                                                              200271IGUANE-FRfalse
                                                                                                              185.255.84.153
                                                                                                              unknownFrance
                                                                                                              200271IGUANE-FRfalse
                                                                                                              37.252.173.215
                                                                                                              ib.anycast.adnxs.comEuropean Union
                                                                                                              29990ASN-APPNEXUSfalse
                                                                                                              20.42.72.131
                                                                                                              unknownUnited States
                                                                                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              20.189.173.11
                                                                                                              unknownUnited States
                                                                                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              2.16.164.88
                                                                                                              unknownEuropean Union
                                                                                                              20940AKAMAI-ASN1EUfalse
                                                                                                              95.101.111.136
                                                                                                              unknownEuropean Union
                                                                                                              12956TELEFONICATELXIUSESfalse
                                                                                                              142.250.186.131
                                                                                                              unknownUnited States
                                                                                                              15169GOOGLEUSfalse
                                                                                                              204.79.197.219
                                                                                                              msn.comUnited States
                                                                                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              35.208.249.213
                                                                                                              trace.mediago.ioUnited States
                                                                                                              19527GOOGLE-2USfalse
                                                                                                              2.19.96.88
                                                                                                              unknownEuropean Union
                                                                                                              20940AKAMAI-ASN1EUfalse
                                                                                                              142.250.186.134
                                                                                                              unknownUnited States
                                                                                                              15169GOOGLEUSfalse
                                                                                                              20.42.73.25
                                                                                                              unknownUnited States
                                                                                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              2.18.64.205
                                                                                                              unknownEuropean Union
                                                                                                              6057AdministracionNacionaldeTelecomunicacionesUYfalse
                                                                                                              2.18.64.203
                                                                                                              unknownEuropean Union
                                                                                                              6057AdministracionNacionaldeTelecomunicacionesUYfalse
                                                                                                              76.223.111.18
                                                                                                              eu-eb2.3lift.comUnited States
                                                                                                              16509AMAZON-02USfalse
                                                                                                              50.31.142.159
                                                                                                              chidc2.outbrain.orgUnited States
                                                                                                              22075AS-OUTBRAINUSfalse
                                                                                                              2.23.209.21
                                                                                                              unknownEuropean Union
                                                                                                              1273CWVodafoneGroupPLCEUfalse
                                                                                                              23.15.178.217
                                                                                                              unknownUnited States
                                                                                                              20940AKAMAI-ASN1EUfalse
                                                                                                              151.101.65.108
                                                                                                              prod.appnexus.map.fastly.netUnited States
                                                                                                              54113FASTLYUSfalse
                                                                                                              13.107.253.45
                                                                                                              s-part-0017.t-0009.fb-t-msedge.netUnited States
                                                                                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              20.253.0.30
                                                                                                              unknownUnited States
                                                                                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              2.19.126.136
                                                                                                              unknownEuropean Union
                                                                                                              16625AKAMAI-ASUSfalse
                                                                                                              151.101.129.44
                                                                                                              tls13.taboola.map.fastly.netUnited States
                                                                                                              54113FASTLYUSfalse
                                                                                                              2.16.164.16
                                                                                                              unknownEuropean Union
                                                                                                              20940AKAMAI-ASN1EUfalse
                                                                                                              104.22.74.216
                                                                                                              btloader.comUnited States
                                                                                                              13335CLOUDFLARENETUSfalse
                                                                                                              18.239.83.98
                                                                                                              sb.scorecardresearch.comUnited States
                                                                                                              16509AMAZON-02USfalse
                                                                                                              142.250.186.164
                                                                                                              www.google.comUnited States
                                                                                                              15169GOOGLEUSfalse
                                                                                                              104.124.11.146
                                                                                                              unknownUnited States
                                                                                                              20940AKAMAI-ASN1EUfalse
                                                                                                              2.23.209.130
                                                                                                              unknownEuropean Union
                                                                                                              1273CWVodafoneGroupPLCEUfalse
                                                                                                              172.241.51.68
                                                                                                              unknownNetherlands
                                                                                                              394380LEASEWEB-USA-DAL-10USfalse
                                                                                                              172.241.51.69
                                                                                                              lb-sin.mgid.comNetherlands
                                                                                                              394380LEASEWEB-USA-DAL-10USfalse
                                                                                                              64.202.112.63
                                                                                                              nydc1.outbrain.orgUnited States
                                                                                                              22075AS-OUTBRAINUSfalse
                                                                                                              204.79.197.203
                                                                                                              unknownUnited States
                                                                                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                              2.23.209.133
                                                                                                              unknownEuropean Union
                                                                                                              1273CWVodafoneGroupPLCEUfalse
                                                                                                              IP
                                                                                                              192.168.2.16
                                                                                                              Joe Sandbox version:40.0.0 Tourmaline
                                                                                                              Analysis ID:1458477
                                                                                                              Start date and time:2024-06-17 17:56:41 +02:00
                                                                                                              Joe Sandbox product:CloudBasic
                                                                                                              Overall analysis duration:
                                                                                                              Hypervisor based Inspection enabled:false
                                                                                                              Report type:full
                                                                                                              Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                                                              Sample URL:http://msn.com
                                                                                                              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                              Number of analysed new started processes analysed:16
                                                                                                              Number of new started drivers analysed:0
                                                                                                              Number of existing processes analysed:0
                                                                                                              Number of existing drivers analysed:0
                                                                                                              Number of injected processes analysed:0
                                                                                                              Technologies:
                                                                                                              • EGA enabled
                                                                                                              Analysis Mode:stream
                                                                                                              Analysis stop reason:Timeout
                                                                                                              Detection:CLEAN
                                                                                                              Classification:clean1.win@19/6@132/758
                                                                                                              • Exclude process from analysis (whitelisted): svchost.exe
                                                                                                              • Excluded IPs from analysis (whitelisted): 142.250.186.131, 172.217.16.142, 74.125.133.84, 34.104.35.123, 204.79.197.203, 2.23.209.21, 2.23.209.28, 2.23.209.34, 2.23.209.26, 2.23.209.30, 2.23.209.27, 2.23.209.32, 2.23.209.33, 2.23.209.31, 2.18.64.203, 2.18.64.218, 2.23.209.187, 2.23.209.141, 2.23.209.148, 2.23.209.133, 2.23.209.144, 2.23.209.130, 2.23.209.135, 2.23.209.140, 2.23.209.185, 2.23.209.189, 2.23.209.183, 68.219.88.97, 13.107.21.237, 204.79.197.237, 23.15.178.217, 23.15.178.227, 23.15.178.201, 23.15.178.154, 23.15.178.225, 23.15.178.145, 23.15.178.146, 23.15.178.194, 20.189.173.11, 13.107.42.14, 20.253.0.30
                                                                                                              • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, img-s-msn-com.akamaized.net, c-msn-com-nsatc.trafficmanager.net, clientservices.googleapis.com, l-0005.l-msedge.net, clients2.google.com, e86303.dscx.akamaiedge.net, www.bing.com.edgekey.net, onedscolprdwus10.westus.cloudapp.azure.com, th.bing.com, e28578.d.akamaiedge.net, www.bing.com, www-linkedin-com.l-0005.l-msedge.net, assets.msn.com.edgekey.net, fs.microsoft.com, accounts.google.com, th.bing.com.edgekey.net, c-bing-com.dual-a-0034.a-msedge.net, a-0003.a-msedge.net, pixel-sync.trafficmanager.net, p-th.bing.com.trafficmanager.net, www-msn-com.a-0003.a-msedge.net, xandr-ms-geo.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, a1834.dscg2.akamai.net, edgedl.me.gvt1.com, c.bing.com, xandr-g-geo.trafficmanager.net, wwwprod.www-bing-com.akadns.net, dual-a-0034.a-msedge.net, clients.l.google.com, global.asimov.events.data.trafficmanager.net, api-msn-com.a-0003.a-msedge.net
                                                                                                              • Not all processes where analyzed, report is missing behavior information
                                                                                                              • VT rate limit hit for: http://msn.com
                                                                                                              InputOutput
                                                                                                              URL: https://www.msn.com Model: gpt-4o
                                                                                                              ```json
                                                                                                              {
                                                                                                                "phishing_score": 0,
                                                                                                                "brands": "MSN",
                                                                                                                "phishing": false,
                                                                                                                "suspicious_domain": false,
                                                                                                                "has_loginform": false,
                                                                                                                "has_captcha": false,
                                                                                                                "setechniques": false,
                                                                                                                "has_suspicious_link": false,
                                                                                                                "legitmate_domain": "msn.com",
                                                                                                                "reasons": "The URL 'https://www.msn.com' matches the legitimate domain name associated with MSN. The webpage design and content appear consistent with the legitimate MSN website. There are no login forms, captchas, or suspicious links present. No social engineering techniques are evident. Therefore, this site is determined to be legitimate."
                                                                                                              }
                                                                                                              URL: https://www.msn.com Model: gpt-4o
                                                                                                              ```json
                                                                                                              {
                                                                                                                "phishing_score": 0,
                                                                                                                "brands": "MSN",
                                                                                                                "phishing": false,
                                                                                                                "suspicious_domain": false,
                                                                                                                "has_loginform": false,
                                                                                                                "has_captcha": false,
                                                                                                                "setechniques": false,
                                                                                                                "has_suspicious_link": false,
                                                                                                                "legitmate_domain": "msn.com",
                                                                                                                "reasons": "The URL 'https://www.msn.com' is a legitimate domain associated with MSN, a well-known web portal and information service provider. The webpage design and content appear consistent with what is expected from MSN. There are no evident social engineering techniques, suspicious links, login forms, or captchas present on the page. Therefore, there is no indication that this is a phishing site."
                                                                                                              }
                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jun 17 14:57:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                              Category:dropped
                                                                                                              Size (bytes):2673
                                                                                                              Entropy (8bit):3.9898884008750817
                                                                                                              Encrypted:false
                                                                                                              SSDEEP:
                                                                                                              MD5:08DDA840F13D0CA833F5FC222F71DDF9
                                                                                                              SHA1:B89FF4F4FC670B2B142DFCAB6AA9152DF4A1A9BF
                                                                                                              SHA-256:F5CDC4B20CF253FBD3B8F76711826C8027D3F8F87558225E30AFC9C7F084C71C
                                                                                                              SHA-512:07D23D1FA96F6268968B1E2ADFE0E81627721DF76E85C688622FA04BF413F491449D5FCF464E566DFD5805E9C496FC5AE388A3416E59F4D3D99E9CB092F3DD3B
                                                                                                              Malicious:false
                                                                                                              Reputation:unknown
                                                                                                              Preview:L..................F.@.. ...$+.,......d.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X&.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X&.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X&............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X(............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jun 17 14:57:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                              Category:dropped
                                                                                                              Size (bytes):2675
                                                                                                              Entropy (8bit):4.006694574891017
                                                                                                              Encrypted:false
                                                                                                              SSDEEP:
                                                                                                              MD5:492A80789955C13FA7169A9A0F014475
                                                                                                              SHA1:9A73C6A8B5A82E9D42938D2415F2F8A0E131DA20
                                                                                                              SHA-256:6968292EAEBFD2E4ECB0D507F5C478573C0D2DDF9CCA36FC06585A9B572F53BE
                                                                                                              SHA-512:640F6E47336FEC4B4E3BDF7FA4149739ACA369950F250AC778E4CC44C916E27458543023802BD36FD0580B63C8FE0265D10802CC15662B325416F73DB70187E9
                                                                                                              Malicious:false
                                                                                                              Reputation:unknown
                                                                                                              Preview:L..................F.@.. ...$+.,....w.T.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X&.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X&.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X&............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X(............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                              Category:dropped
                                                                                                              Size (bytes):2689
                                                                                                              Entropy (8bit):4.011954377322807
                                                                                                              Encrypted:false
                                                                                                              SSDEEP:
                                                                                                              MD5:24AC9839A0A545C4967CA38F9E4DCFC0
                                                                                                              SHA1:2AE0C02D5CBF82E618792FAC5890F07099FF6267
                                                                                                              SHA-256:3F873A8460B096B2B84882B50BFAB6431688B897D347DBDF558FE76F52A59F57
                                                                                                              SHA-512:53DE6ADAD8AE7EA7892C14224224384A27F6D10D26E417D5B538E30C29B28D1B95F04842629AA9A796CC8696D88A33E8764B60BE220A3B64CD7640EC85F319CA
                                                                                                              Malicious:false
                                                                                                              Reputation:unknown
                                                                                                              Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X&.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X&.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X&............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jun 17 14:57:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                              Category:dropped
                                                                                                              Size (bytes):2677
                                                                                                              Entropy (8bit):4.004113683526723
                                                                                                              Encrypted:false
                                                                                                              SSDEEP:
                                                                                                              MD5:4D2BD0335D6BC696E1AB01A7CBF97C3A
                                                                                                              SHA1:8BACF6A24E49196EB68B5284FBB4B695E224B4CA
                                                                                                              SHA-256:14AB6189F97B53616BCC14A34A72BD37ADEB16C65932434551BE4F7A4EEBB6A7
                                                                                                              SHA-512:1A8428A328FC390963AEA60F092668919968CF986A8A6EE7C44A6BBF087290AF274577CF0F6B26017AA951679B89BD9DCFFC46F6F1A232BBD718186DF2064BAC
                                                                                                              Malicious:false
                                                                                                              Reputation:unknown
                                                                                                              Preview:L..................F.@.. ...$+.,.....>L.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X&.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X&.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X&............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X(............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jun 17 14:57:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                              Category:dropped
                                                                                                              Size (bytes):2677
                                                                                                              Entropy (8bit):3.991822423377786
                                                                                                              Encrypted:false
                                                                                                              SSDEEP:
                                                                                                              MD5:1F3DBDF66D6EA69B3F4E1B3795ABF07C
                                                                                                              SHA1:BF8FDC64B1F3BF404F48E18019C706A39B2D4C32
                                                                                                              SHA-256:9295A200190C1506D99F46EB8650D482FF57BC8869845599598B02E3E729ED81
                                                                                                              SHA-512:AF039AF7AE26369B7F761A2AAE6555FB8F76F11E8BB5F9B4190CD02E01F476B9332717C75DC3CFCA53304303C85C1FB7BE8CAB265F5C989058F4BA8E61385B1B
                                                                                                              Malicious:false
                                                                                                              Reputation:unknown
                                                                                                              Preview:L..................F.@.. ...$+.,.....D\.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X&.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X&.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X&............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X(............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jun 17 14:57:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                              Category:dropped
                                                                                                              Size (bytes):2679
                                                                                                              Entropy (8bit):4.004149879932813
                                                                                                              Encrypted:false
                                                                                                              SSDEEP:
                                                                                                              MD5:099E427A77476911B09954A36FDD6507
                                                                                                              SHA1:77180E19D5E7032DF596A41078A808FC0A99BCEC
                                                                                                              SHA-256:6B4F6BDC8DD5AA827CA526B3B6BA1E916B5EF098EDA2AE85A65710812A180193
                                                                                                              SHA-512:6B358175BE4C889CAFBF33A456CA0B76F20C52E5FDCAE5A44003D725FFAFFA9A3693E8ACFD9F7A75DBAC1B92A931BF57D26E663C99E852DD2780877E5B7BEC77
                                                                                                              Malicious:false
                                                                                                              Reputation:unknown
                                                                                                              Preview:L..................F.@.. ...$+.,......?.....N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X&.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X&.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X&............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X(............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i....................C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                              No static file info